To pass the CIPP/E in 2026, study the GDPR as a set of decisions, not a list of articles. Spend most of your time on the core of the regulation — principles, lawful bases, data subject rights, controller and processor obligations, and international transfers — and practise them through scenario questions. Most working professionals need 6–10 weeks at 5–8 hours a week. The plan below covers it in 8 weeks, with the final two reserved for timed practice and weak-area repair.
The CIPP/E is 90 multiple-choice questions in 2.5 hours, 75 of them scored, marked on a 100–500 scale with 300 to pass. Those are the facts in every exam guide (ours is here). What most guides skip is the part that decides whether you pass: how the exam asks about the GDPR.
Very few questions ask "what does Article X say?" Most give you a company, a processing activity and a problem, and ask what the GDPR requires. You can know every article number and still fail, because you've learned the regulation as text instead of as a set of decisions. This guide is built around those decisions.
Before You Start: Three Things to Set Up
- Download the current Body of Knowledge. The CIPP/E Body of Knowledge and Exam Blueprint on the IAPP CIPP/E page lists every topic and the question ranges per domain. The version effective September 2025 (v1.3.3) brought in EU AI Act and NIS2 context. Our BoK change guide lists what moved.
- Keep the GDPR text open. Use the official consolidated text on EUR-Lex. Read the recitals for anything confusing — the exam's scenarios often hinge on the reasoning in the recitals.
- Book a tentative exam date. A date eight to ten weeks out keeps the plan honest. You have 12 months from purchase to sit the exam, and in-person appointments can be rescheduled up to 48 hours ahead.
What to Study: The Six Topic Blocks
The Body of Knowledge is organised into domains, but for studying it's more useful to think in six blocks. The middle three carry most of the exam.
| Block | Key content | Exam weight | Typical difficulty |
|---|---|---|---|
| 1. Foundations and institutions | ECHR Art. 8, EU Charter Arts. 7–8, Convention 108, the 1995 Directive, EU institutions | Light | Low — memorisable |
| 2. GDPR core concepts | Definitions, material and territorial scope (Arts. 2–3), principles (Art. 5), lawful bases (Art. 6), consent (Art. 7), special categories (Art. 9) | Heavy | High — applied judgement |
| 3. Data subject rights | Transparency and the rights in Arts. 12–22, including conditions and exceptions | Heavy | Medium-high |
| 4. Controller and processor obligations | Accountability, privacy by design (Art. 25), processor contracts (Art. 28), records (Art. 30), security (Art. 32), breaches (Arts. 33–34), DPIAs (Art. 35), DPOs (Arts. 37–39) | Heavy | Medium-high |
| 5. Transfers, supervision and enforcement | Chapter V transfers, one-stop shop, EDPB, fines (Art. 83), compensation (Art. 82) | Moderate | High for transfers |
| 6. Compliance in specific contexts | Employment, surveillance, direct marketing, cookies and ePrivacy, internet technologies, AI Act interplay | Moderate | Medium |
Block 1 — Foundations and institutions
Know the lineage: Article 8 of the European Convention on Human Rights, Articles 7 and 8 of the Charter of Fundamental Rights, Convention 108, the 1995 Data Protection Directive and the GDPR that replaced it in 2018. Know which EU institution does what (the Commission proposes, Parliament and Council legislate, the CJEU interprets). These questions are mostly recall. Don't overspend here — it's the lightest part of the exam.
Block 2 — GDPR core concepts
This is where the exam is won or lost. For each concept, learn the test you'd apply, not just the definition:
- Personal data and pseudonymisation: pseudonymised data is still personal data; truly anonymous data is not.
- Territorial scope (Art. 3): establishment in the EU, or offering goods and services to people in the EU, or monitoring their behaviour there. A non-EU company with no EU office can be fully in scope.
- The seven principles (Art. 5): lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability.
- Lawful bases (Art. 6): the six bases, when each is available, and when each is not — legitimate interests isn't available to public authorities performing their tasks, and consent is rarely valid in employment.
- Special categories (Art. 9): need an Article 6 basis and an Article 9(2) condition. Criminal conviction data is Article 10, not Article 9.
Our breakdown of the GDPR concepts that cost candidates the most points has worked scenarios for the hardest of these.
Block 3 — Data subject rights
Learn each right with its trigger, its limits and its deadline. The exam tests the limits more than the rights:
- Responses are due within one month, extendable by two further months for complex or numerous requests (Art. 12(3)).
- Erasure (Art. 17) has grounds and exceptions — freedom of expression, legal obligations, public health, archiving and legal claims.
- Portability (Art. 20) applies only to data the person provided, processed by automated means, on the basis of consent or contract.
- Article 22 applies only to decisions based solely on automated processing with legal or similarly significant effects.
Block 4 — Controller and processor obligations
Expect questions where you have to decide who is the controller, who is the processor and who is a joint controller — and what each must do. Know the mandatory content of an Article 28 contract, when records of processing are required, the 72-hour breach notification to the authority (Art. 33) versus the "high risk" threshold for notifying individuals (Art. 34), when a DPIA is mandatory, and when a DPO must be appointed.
Block 5 — Transfers, supervision and enforcement
Transfers are consistently one of the hardest areas. Apply the hierarchy: adequacy decision first, then appropriate safeguards (standard contractual clauses, binding corporate rules), and only then the narrow Article 49 derogations. Know what Schrems II changed and why transfer impact assessments followed. For enforcement, know the two fine tiers in Article 83 (up to EUR 10 million or 2% of global turnover, and up to EUR 20 million or 4%) and how the one-stop-shop mechanism assigns a lead supervisory authority.
Block 6 — Compliance in specific contexts
These are applied scenarios: employee monitoring, CCTV, marketing emails, cookie banners. The key is the interplay between the GDPR and the ePrivacy Directive — for cookies, consent under ePrivacy Article 5(3) is required for non-essential cookies regardless of what the GDPR lawful basis would otherwise be. Since 2025 you should also be comfortable with how the EU AI Act and NIS2 sit alongside the GDPR.
Reading the GDPR isn't the same as answering CIPP/E questions.
The CIPP/E Complete Pack has 300 practice questions — 220 of them scenario-based across 18 scenario blocks — plus a cram guide with a five-scenario masterclass, mapped to BoK v1.3.3.
Get the Complete Pack →The 8-Week CIPP/E Study Plan
Built for 5–8 hours a week. If you have no GDPR background, stretch weeks 2–5 to two weeks each. If you work with the GDPR daily, you can compress to five or six weeks — see how many hours to study for the CIPP/E for estimates by background.
Block 1 in full. Read the GDPR's chapter structure and Articles 1–4 closely. Take a 25-question diagnostic to find your starting point — don't worry about the score.
Articles 2, 3, 5, 6 and 7. For every lawful basis, write one scenario where it applies and one where it doesn't. Finish with 30 scenario questions on these topics.
Articles 9, 10 and 12–22. Build a one-page table of each right: trigger, exceptions, deadline. Practise 30–40 questions.
Articles 24–39. Focus on role classification, Article 28 contracts, breach notification thresholds, DPIAs and DPO rules. Practise 40 questions, including joint controller scenarios.
Chapter V, Schrems II, SCCs, BCRs and derogations; then supervisory authorities, the EDPB, fines and remedies. Practise 40 questions. Expect this week to feel hardest.
Employment, surveillance, marketing, cookies, ePrivacy, AI Act and NIS2 interplay. Practise 30 questions, then review every wrong answer from weeks 2–5.
One full 90-question mock in 2.5 hours under exam conditions. Spend more time reviewing than sitting it: for every miss, write down why the right answer is right and why yours was wrong.
Target your two weakest blocks. A second full mock mid-week. Last three days: a condensed cram review, not new material — our CIPP/E last-week cram guide lays it out day by day.
Study Resources: What to Use and What to Skip
| Resource | Cost | Verdict |
|---|---|---|
| GDPR text and recitals (EUR-Lex) | Free | Essential — the exam is built on it |
| EDPB guidelines | Free | Use selectively: consent, controller/processor, Art. 22, transfers, breach notification |
| IAPP official textbook | Paid | Good coverage of the Body of Knowledge; dense |
| IAPP official practice test | Paid | Useful calibration, but too short to be your only practice |
| Scenario question bank | Paid | The highest-impact resource for applied questions — see what to look for in a CIPP/E question bank |
| Flashcards and article-number drills | Free–cheap | Skip as a main method — the exam rarely asks for article numbers alone |
How to Know You're Ready
Because the exam is scaled, there's no published raw score that guarantees a pass. Use these signals instead:
- You consistently score 80% or more on fresh scenario questions you haven't seen before.
- You can explain why each wrong option is wrong, not only why the right one is right.
- You finish a 90-question timed mock with at least 15 minutes to spare.
- No single block is below 70% in your practice data.
If you're not there, move your date. Rescheduling is free inside the allowed window; a retake costs USD 375. Our CIPP/E pass rate analysis explains where first attempts usually go wrong.
The one rule that matters
Every hour you spend reading the GDPR should be matched by time applying it to scenarios. Candidates who fail the CIPP/E rarely fail for lack of knowledge — they fail because they recognise the right article and still pick the wrong answer when the facts get specific.
Frequently Asked Questions
How long should I study for the CIPP/E?
Most working professionals need 6–10 weeks at 5–8 hours per week, roughly 40–70 hours in total. People who work with the GDPR daily can often prepare in 5–6 weeks; those new to EU data protection should plan for 10 weeks or more.
What is the hardest part of the CIPP/E?
International transfers, lawful basis selection, controller and processor classification, and automated decision-making under Article 22 are the areas candidates most often get wrong, because they require applying the rules to specific facts rather than recalling them.
Can I pass the CIPP/E with self-study?
Yes. Many candidates pass with the GDPR text, selected EDPB guidelines, a structured plan and a large bank of scenario practice questions. Official IAPP training helps if you need structure, but it isn't required.
Do I need to memorise GDPR article numbers?
It helps to know the key ones, but the exam mostly asks what the GDPR requires in a given scenario. Understanding how each rule applies, and its exceptions, matters far more than memorising numbers.
Is the CIPP/E exam open book?
No. IAPP exams are closed book, taken through Pearson VUE either at a test centre or by online proctoring.