About the CIPP/US Certification and How to Study for It

This article briefly summarizes the CIPP/US certification, how to study for it, and provides some important resources. CIPP/US stands for Certified Information Privacy Professional, United States and focuses on US privacy law and practice. The certification is administered by the International Association of Privacy Professionals (IAPP). I have just completed an online course to help people learn about privacy and prepare for this certification exam.

Your goal

If you have decided to study for and take the CIPP/US certification, then I suggest that your goal should be:

  • Learn the material well enough to pass the test easily and remember it long after you passed the test
  • Earn the certification by passing the test
  • After you have earned the certification, use your learning to continually demonstrate to yourself and others that this learning and certification has improved you professionally.

If you have decided to learn more about privacy in the United States without pursuing the CIPP/US certification, these materials are a helpful guide for that. Take a look at the substantive information and references below relating to privacy and the CIPP/US body of knowledge.

Privacy has growing importance in all of our professional and personal lives, and is the subject of increasing law and regulation. Privacy is not an isolated field, but overlaps with many others (including cybersecurity, compliance, information governance, organization management) and is a pressing societal issue.

About the IAPP

The IAPP is a non-profit organization based in New Hampshire and with global reach. According to their website, they are the largest and most comprehensive global information privacy community and resource. In addition to their CIPP/US certification, they offer CIPP certifications for other regions and more specific privacy certifications including Certified Information Privacy Manager (CIPM) and Certified Information Privacy Technologist (CIPT).

You can join the IAPP and maintain your membership for an annual fee of $275. I recommend this if you are pursuing one of their certifications or if you are interested in a career path involving privacy. I find their materials to be well done and exceptionally well organized, and they seem to be a leader in privacy.

About the CIPP/US certification

The CIPP/US certification is well suited for anyone desiring to learn and demonstrate their knowledge regarding US privacy law and practice. To earn the certification, one needs to study the materials, take and pass the test (which costs money), and also pay a certification maintenance fee. That is the basics and you should also read and follow their other rules and guidance as laid out in the Candidate Handbook and elsewhere. As IAPP points out, their certification is accredited and designed to “assess professional competence and experience”.

The exam topics are laid out in IAPP documents including their “Body of Knowledge”, “Exam Blueprint”, and their list of references. Essentially, the main topics tested are:

  1. Introduction to the U.S. Privacy Environment
  2. Limits on Private-sector Collection and Use of Data
  3. Government and Court Access to Private-sector Information
  4. Workplace Privacy
  5. State Privacy Laws

The exam costs $550 (last I checked) and is taken at a Pearson VUE testing center or remotely in the comfort of your home or office (Pearson OnVUE).

The CIPP/US materials from IAPP are well organized, and are listed and linked to below. Given my background in law I found the certification exam to be relatively straightforward. For many non lawyers and those not familiar with law it will be more of a challenge (but I believe my course lays it out well).

Often, there is never a perfect time in life to take a certification test. So if you have decided to pursue this certification, you might as well get the test scheduled and give yourself a deadline and start studying.

The test is 90 multiple choice questions, each with four possible answers, and you have 2.5 hours to complete the test. Only 75 questions are scored, meaning that 15 of the questions (20%) are not scored. They are experimental or to gain insights for quality control for this and future tests. Each question you answer correctly is worth one point and there are no penalties for wrong answers. The Exam Blueprint lays out approximately how many questions you will see on the various topics. Some of the questions are scenario based, where you need to read a passage and then answer questions based on the facts presented. It is helpful to be able to spot the issues and determine what information is relevant for the questions, and what is not.

My other articles have tips on how to study and learn, and how to take an exam. In sum, put in honest continual effort long in advance, learn the materials well, relax, pass the test the first time, and then you will retain the knowledge to help you in your career.

Once you have earned your IAPP certification, you need to pay to maintain it. You can do this by being a member of IAPP for $275 annually, which will include the certification maintenance fee and provide many other benefits. If you are not an IAPP member, you will need to pay a certification maintenance fee of $250 for 2 years. Again, I recommend joining IAPP and maintaining your membership.

After earning your CIPP/US certification, you will also have to earn continuing professional education (CPE) credits and then remember to enter them into the IAPP portal regularly. CPEs need to be entered within three months, after which you cannot get credit for them, so stay on top of this.


The CIPP/US is an excellent certification from an excellent organization, and studying for it will give you an excellent foundation in law and privacy.

I have simplified things greatly and left out many details, and the IAPP is the main and final authority on their certification. Be sure to read the IAPP materials listed and linked to below, and consider that my list may not be complete or could become out of date. So check the IAPP website and read their materials. This article is a work-in progress, so please let me know of any feedback or suggestions.

I prepared a CIPP/US study course for the InfoSec Institute, a respected and leading online educational provider. I am excited for the learning opportunity this presents for me and those who will view the course. Of course I receive some payment for this, but I believe this has no influence upon my positive view of the CIPP/US certification. Rather, I believe my willingness to develop such a course demonstrates my existing favorable view.

Resources and Additional Reading

A copy of this article is hosted at my website, includes many references and links for additional reading, and may be updated more frequently. Please see https://johnbandler.com/cipp-us-certification/.

When my InfoSec Institute course goes live, I will also post a link to that here.

Page posted 8/1/2021. Updated 12/11/2021. Copyright John Bandler, all rights reserved.

Cybersecurity, cybercrime prevention, law, some more. Attorney, consultant, author, speaker. Find me at JohnBandler.com