1. Home
  2. IAPP
  3. CIPM Exam Syllabus

IAPP CIPM Exam Syllabus

Start Free CIPM Exam Practice After Reviewing the Topics

Before starting your CIPM exam preparation, it is recommended to review the complete IAPP Certified Information Privacy Manager (CIPM) exam syllabus and carefully go through the exam objectives listed below. Once you understand the exam structure and objectives, you should practice using our free CIPM questions. We also provide premium CIPM practice test, fully updated according to the latest exam objectives, to help you accurately assess your preparedness for the actual exam.

IAPP CIPM Exam Objectives

Section Weight Objectives
Privacy Program: Developing a Framework 14-18%
  • Define program scope and develop a privacy strategy. 
  • Communicate organizational vision and mission statement.
  • Indicate in-scope laws, regulations and standards applicable to the program.
Privacy Program: Establishing Program Governance 12-16%
  • Create policies and processes to be followed across all stages of the privacy program life cycle.
  • Clarify roles and responsibilities.
  • Define privacy metrics for oversight and governance.
  • Establish training and awareness activities.
Privacy Program Operational Life Cycle: Assessing Data 12-16%
  • Document data governance systems. 
  • Evaluate processors and third-party vendors.
  • Evaluate physical and environmental controls.
  • Evaluate technical controls.
  • Evaluate risks associated with shared data in mergers, acquisitions, and divestitures.
Privacy Program Operational Life Cycle: Protecting Personal Data 9-13%
  • Apply information security practices and policies. 
  • Integrate the main principles of Privacy by Design (PbD). 
  • Apply organizational guidelines for data use and ensure technical controls are enforced.
Privacy Program Operational Life Cycle: Sustaining Program Performance 7-9%
  • Use metrics to measure the performance of the privacy program.
  • Audit the privacy program.
  • Manage continuous assessment of the privacy program.
Privacy Program Operational Life Cycle: Responding to Requests and Incidents 10-14%
  • Respond to data subject access requests and privacy rights.
  • Follow organizational incident handling and response procedures.
  • Evaluate and modify current incident response plan.
Official Information https://iapp.org/certify/get-certified/cipm/