CDPSE Master Guide 2026
CDPSE tests how professionals apply privacy principles across governance, risk, the data life cycle, and technical systems.
- The exam has 120 multiple-choice questions in 3.5 hours, and ISACA requires a scaled score of 450/800.
- Certification also requires verified work experience and an application.
On this page14 sections
- What CDPSE covers
- The four domains
- Connect governance, risk, data, and technology
- Privacy Governance
- Privacy Risk Management and Compliance
- Data Life Cycle Management
- Privacy Engineering
- Worked scenario: redesigning a loyalty program
- How to prepare
- Exam and certification are separate steps
- How to make a privacy decision in a scenario
- A second worked scenario: deletion across a service
- Build a balanced preparation routine
- Exam-day pacing
What CDPSE covers
The Certified Data Privacy Solutions Engineer credential focuses on putting privacy requirements into organizational processes and technical systems. It brings together privacy governance, risk and compliance, data life cycle management, and privacy engineering. The exam is relevant to professionals who assess how personal information moves through products and services, then help design controls that support responsible, transparent, and secure use.
The exam contains 120 multiple-choice questions and allows 3.5 hours. ISACA reports a scaled score from 200 to 800, with 450 required to pass. The score is not a raw percentage. Passing is one step toward certification; applicants also need qualifying professional experience and must submit the certification application.
The four domains
| Domain | Weight | Work covered |
|---|---|---|
| Privacy Governance | 20% | Principles, policies, roles, vendors, incidents, and individual rights |
| Privacy Risk Management and Compliance | 18% | Assessments, risk response, compliance evidence, monitoring, and metrics |
| Data Life Cycle Management | 23% | Inventory, collection, use, transfer, retention, and destruction |
| Privacy Engineering | 39% | Technology stacks, security controls, consent, tracking, PETs, and AI/ML |
Privacy Engineering is the largest domain, but the other three are substantial. A technical design can fail if no one has established purpose, access authority, retention, or the process for handling a rights request. Use the weights to allocate effort, then practise joining concepts across the life cycle.
Connect governance, risk, data, and technology
Imagine a company adding a support chatbot that can search order histories. Governance clarifies the purpose, accountability, transparency, and vendor responsibilities. Risk work identifies the information involved, likely harms, obligations, and evidence needed to assess controls. Life cycle management maps what the bot collects, how it is used, where it is stored, and when it is deleted. Engineering applies access restrictions, logging, secure interfaces, and safeguards around model use.
No single control resolves every concern. Encryption can protect data in transit or at rest, but does not make an excessive purpose appropriate. A privacy notice does not enforce access boundaries. An inventory is useful only if it reflects actual flows, including vendor copies and derived data. CDPSE reasoning connects a control to a risk and to the operational process that keeps it working.
Privacy Governance
Governance establishes how an organization identifies requirements, assigns accountability, communicates policy, and oversees privacy operations. Candidates should understand personal information in context rather than assume one universal definition. Direct identifiers, account-linked data, and combinations that permit identification can require protection depending on the applicable rules and purpose.
Privacy principles include purpose limitation, transparency, minimization, accuracy, security, and accountability. The practical task is to translate a principle into a decision. If a product team wants to collect precise location continuously for a feature that only needs a city, ask whether the extra precision serves a defined purpose and whether a less intrusive design would work.
Operations also cover organizational roles, vendors, incidents, and requests from individuals. A provider may perform tasks, but the organization needs oversight, clear instructions, suitable contractual terms, and evidence. A rights request needs a controlled process to locate records, verify the requester appropriately, coordinate the response, and document the outcome.
Privacy Risk Management and Compliance
A privacy impact assessment or similar focused assessment examines how a proposed process or change affects people and the organization. Start with actual processing: purpose, data categories, people affected, sources, recipients, system boundaries, and retention. Then consider plausible harms, applicable requirements, current controls, and feasible design changes. The assessment should shape the solution before decisions become costly to reverse.
Risk analysis considers likelihood and impact, including unwanted disclosure, loss of control, unfair decisions, identity misuse, or inability to exercise a right. A security vulnerability can contribute to privacy risk, but privacy concerns also arise from excessive collection, incompatible use, inaccurate records, poor notice, or inaccessible correction processes.
Compliance work maps obligations and framework commitments to evidence. Useful evidence includes approved assessments, inventories, consent configurations, training records, access reviews, vendor oversight, incident records, and metrics. A policy alone does not prove implementation. Monitoring should show whether controls operate and still fit changing requirements, technology, and expectations.
Data Life Cycle Management
A data inventory and flow diagram describe information from collection through use, sharing, storage, retention, archival, and destruction. Classification helps teams apply suitable controls. Accuracy matters because decisions based on incorrect information can harm individuals and undermine business processes. Use limitation asks whether a proposed use fits the stated purpose and applicable requirements, not merely whether the data is available.
Minimization means collecting and retaining what is needed for a defined purpose. It does not always mean deleting every record immediately. Legal holds, accounting duties, safety needs, or disputes can require retention. State the basis, restrict access, set a review or expiry point, and remove data when the reason ends.
Disclosure and transfer require attention to recipient, purpose, safeguards, location, onward use, and contractual or legal restrictions. Destruction must account for replicas, backups, exports, caches, and vendor systems. If immediate deletion from a backup is not feasible, isolate it, prevent restoration into ordinary use, and ensure deletion follows the backup lifecycle. The operational process should match the promise made to people.
Privacy Engineering
Privacy engineering builds requirements into infrastructure, applications, devices, APIs, and operations. The outline includes cloud and legacy platforms, endpoints, connectivity, secure development, cloud-native services, asset management, identity and access management, patching, hardening, protocols, encryption, hashing, monitoring, and logging.
Technical decisions should follow the data and threat model. Least privilege, separation of environments, secure defaults, and reviewed service identities can reduce unnecessary access. Encryption protects confidentiality under defined conditions; hashing supports integrity or comparison depending on the design. Neither prevents misuse by an authorized user with excessive access.
Privacy-specific engineering includes consent tagging, tracking controls, anonymization and pseudonymization, privacy-enhancing technologies, and AI/ML considerations. Pseudonymized data may be linked back when additional information exists, so it should not be treated as anonymous. Anonymization claims need testing against available auxiliary data and realistic threats.
For analytics and machine learning, examine input provenance, permitted purpose, representation, access, retention, outputs, and inference risks. Aggregation can reduce exposure, but small groups or rare attributes may still reveal individuals. A model can reproduce sensitive patterns or expose training data. Safeguards may include access limits, minimization, testing, output review, retention controls, and human oversight.
Worked scenario: redesigning a loyalty program
A retailer plans to combine purchase history with mobile location data to send personalized offers. Marketing proposes a notice at account creation and a single opt-in toggle. A vendor will host the analytics environment. The team has not established whether location records include precise coordinates, and the proposed retention is simply “as long as useful.”
Clarify the purpose and necessity first. Which offers require location, and could a coarser region or shorter window work? Map the flow from collection through analytics, vendor access, offer generation, logs, backups, and deletion. Identify applicable requirements, who decides the purpose, and what choices or rights apply. A generic notice does not establish that the processing is appropriate.
Assess risks from unauthorized access, unexpected inference, inaccurate location, excessive retention, vendor onward use, and difficulty withdrawing consent or honoring requests. Translate findings into requirements: collect only the needed precision, separate optional personalization from essential service, constrain vendor access, propagate consent state, log access, define retention by purpose, and test deletion across derived data and backups.
Before launch, assign control owners and evidence. Test that a user choice reaches analytics and campaign systems. Sample records to verify location precision is reduced as intended. Confirm vendor access and deletion evidence. Set a measure for opt-out propagation or deletion completion, with an owner and escalation threshold. Reassess when purpose, model, data source, or vendor changes.
The sequence is useful: establish context and data flows, assess risk and requirements, design controls, then test and monitor. A cookie banner or encryption product cannot resolve unclear purpose, excessive retention, or missing rights procedures.
How to prepare
Start with the current official outline. For each task, write what decision or evidence a CDPSE professional needs, then connect it to a concrete system or process. Reading about consent management should lead you to ask how a preference is recorded, transmitted, enforced, audited, and withdrawn.
ISACA lists an Official Review Manual, an Online Review Course, a six-month Questions, Answers and Explanations database, and a free 10-question practice quiz. These are separate options. Choose according to whether you need structured teaching, a reference, or question practice. The free quiz is not a full mock.
Practise explaining why one option best fits and why other actions are premature or incomplete. A proposed new data use may call for mapping purpose and impact before choosing controls. A known breach may call for incident response and containment first. A deletion question may require tracing copies and retention constraints. Use the facts and requested decision to choose the sequence.
- Read one outline task and explain it from memory.
- Apply it to a new data or system scenario.
- Answer a question without notes and explain each option.
- Record the underlying gap, such as purpose, authority, evidence, or control design.
- Revisit the concept after a delay and test it in a different context.
Exam and certification are separate steps
The exam is open to people interested in information security; experience is required for certification. To earn CDPSE, pass the exam, demonstrate at least three years of cumulative CDPSE-related work across the four domains, pay the US$50 application fee, and submit an application with supervisor or manager verification. Experience must fall within the ten years before applying, and the application is due within five years of passing. ISACA allows no experience waivers or substitutions for CDPSE.
Holders follow the Code of Professional Ethics and continuing education policy. They need at least 20 related CPE hours each year and 120 over a three-year reporting period, plus an annual maintenance fee. Passing shows exam performance; it does not itself approve experience or complete the application.
How to make a privacy decision in a scenario
When a question describes a proposed system or process, begin by stating what the organization is trying to accomplish. Separate that objective from the information it proposes to use. Identify the people affected, data sources, recipients, systems, purpose, and retention. This simple map prevents a technical detail from obscuring a more basic question about whether the processing is necessary or expected.
Next identify the decision owner and applicable requirements. A privacy specialist can analyze and advise, an engineering team can implement controls, and a business owner may authorize a purpose or accept residual risk. The organization should not allow a control implementer to make an unassigned legal or business decision simply because that person owns the system.
Assess the plausible harms and existing safeguards. Consider confidentiality, but also accuracy, access, unexpected inference, exclusion, inability to exercise a right, or use beyond the stated purpose. The best answer should use the evidence given. If key facts are missing, an assessment or validation step may be appropriate; if harm is already occurring, containment and incident response may need to happen while the investigation continues.
Translate the decision into a control and an operating process. A design requirement should have an owner, test, evidence, and review trigger. For a deletion promise, test the application, analytics store, vendor environment, and backups. For a consent choice, test that downstream systems receive and enforce the preference. For access restrictions, review both permissions and logs. A written policy without operating evidence is incomplete.
Finally, decide how the organization will monitor the outcome. Define measures with a source, frequency, owner, threshold, and response. Report limitations such as incomplete inventories or delayed vendor evidence. Reassess when the purpose, system, data source, model, or applicable requirements change. Privacy design is maintained over time, not finished when a project launches.
A second worked scenario: deletion across a service
A customer closes an account and asks for deletion. The primary service can remove the profile immediately, but transaction records are subject to a documented retention period. Analytics extracts and support logs may contain some of the same identifiers, while the service provider keeps encrypted backups on a rotation schedule.
The first task is to map the request to systems and purposes. Separate records that can be deleted from those that must remain for the stated retention basis. Restrict retained records to that purpose, and ensure the data are not used for personalization or marketing. Coordinate deletion or suppression in analytics and support systems, and obtain evidence from the provider about its copy and backup lifecycle.
If a backup cannot support immediate record-level deletion, the team needs a documented process that prevents ordinary restoration and applies the deletion again if a backup is restored. Record the exception, owner, expiry, and verification method. A “deleted” status in the primary database is not enough to show the request was handled across the service.
This scenario draws on governance, because the retention decision needs authority and documentation; risk and compliance, because the organization must assess the exception and preserve evidence; life cycle management, because data copies and expiry must be tracked; and engineering, because systems must enforce suppression and deletion. One decision can span all four domains.
Build a balanced preparation routine
Use a main learning source, the current outline, and a question resource with explanations. Keep a compact error log with the task, why your answer was weak, and what fact would change the decision. A note such as “privacy engineering weak” is too broad; “treated tokenization as anonymity when a lookup key exists” points to a clear review task.
Revisit errors after a delay and apply the principle to a different example. If you missed a vendor question, practise with a cloud analytics provider, then with an internal data-sharing team. If you missed retention, compare a routine account record, a legal hold, and a temporary fraud investigation. Variation makes it harder to memorize one answer and easier to transfer the underlying rule.
Protect study time for each domain. The 39 percent Privacy Engineering weight deserves meaningful attention, but a lower weighted domain can still reveal a major personal gap. Review the full cycle and use diagnostics to decide where to spend extra effort. ISACA does not publish a fixed number of hours candidates must study, so set a schedule from your baseline and responsibilities.
Exam-day pacing
The 120-question, 210-minute allowance averages 105 seconds per question. Treat this as a planning reference, not a command to rush. Identify what the scenario establishes and what decision it requests. ISACA says incorrect answers carry no penalty, so answer every item. Eliminate options that ignore purpose, authority, evidence, or the stated risk, then choose the best remaining answer.
Before the appointment, prepare the required identification and test location or remote setup. ISACA allows authorized PSI test centers and remote proctoring, subject to availability and technical conditions. For remote testing, check the device and room in advance. At a center, plan to arrive early and allow time for check-in.
Common questions
How many questions are on CDPSE?
The exam has 120 multiple-choice questions and a 3.5-hour limit.
What score is required to pass CDPSE?
ISACA requires a scaled score of 450 on a 200-to-800 scale. It is not a raw percentage.
Which domain is largest?
Privacy Engineering is 39 percent of the current outline. Balance its weight with your diagnosed gaps.
Can I take CDPSE before meeting the experience requirement?
Yes. The exam is open, but qualifying experience and application approval are required for certification.
Does passing the exam make me CDPSE?
No. Submit the experience application, pay the processing fee, and meet the other certification requirements.