Certifications AIGP CIPP/E CIPP/US CIPM CIPT All certifications Career plan How it works Pricing Log in Start free
Study guide

The complete CIPT study guide

What the exam asks, in what order to study it, how long it takes, what it costs and where candidates lose marks.

AI-generated image - a professional with a folder outside a European institution, for the CIPP/E study guide
What it is

What is the CIPT?

The CIPT, the Certified Information Privacy Technologist, is the certification for people who build privacy into systems and products. It tests whether you can recognise a privacy risk in a design and choose the technique that answers it.

It is issued by the IAPP. There are no prerequisites: no degree and no minimum experience. You sit it online or at a test centre, in English.

Format and fees

90questions75 scored, 15 unscored
150minutesoptional 15-minute break
300of 500 to passscaled score
$550exam feeretake $375
12monthsto sit after you buy
20CPE creditsevery two years, plus the fee

Membership of the IAPP costs $295 a year and includes the maintenance fee; without membership that fee is $250 every two years.

Before you plan anything, find out what you already know. Free account, fifteen minutes.Free CIPT assessment
The body of knowledge

The five domains, and what each one asks

The IAPP publishes a body of knowledge for each certification: the list of competencies the exam is written from. The 22Academy course follows the current version concept by concept.

1

The privacy technologist's role in the context of the organisation

What a privacy technologist does and with whom: the work with legal, security and product teams, and how privacy differs from security.

Where people lose marks

Privacy and security. Encryption keeps outsiders away from data. It does not make a use of that data acceptable.

From the 22Academy bank · definition

Which term describes building a system so that the most privacy-protective setting applies without the user doing anything?

Twenty more like it, free
2

Data collection, use, dissemination and destruction

The privacy risks at each stage of the data life cycle: how data is collected, what it is used for, who it is shared with and how it is destroyed.

Where people lose marks

The harm. The exam describes a situation and asks which kind of privacy harm it is. Surveillance, aggregation, secondary use and exposure are not interchangeable.

From the 22Academy bank · two-statement true or false

Statement I: pseudonymised data falls outside data protection law because it no longer identifies anyone. Statement II: combining data from several sources can create a privacy risk that none of the sources carried alone. Which statement is correct?

Twenty more like it, free
Screenshot of the 22Academy course - accuracy per domain and module, with the weakest module marked as the one to focus on now
Screenshot from results in the course
Domain by domain

Law on one side, engineering on the other. Which is yours?

The exam sits between law and engineering. The course shows your accuracy per domain and per module, so you see which side needs the work, and points at the module to work on now.

3

Privacy risk management

Finding and weighing privacy risk in a system: risk models, threat modelling and privacy impact assessments.

Where people lose marks

The model. Each risk model asks a different question, and the exam names one and describes another.

From the 22Academy bank · scenario

A team is designing a new mobile app and wants to find the privacy threats before any code is written. Which technique should it use?

Twenty more like it, free
4

Privacy by design

Designing privacy in from the first sketch: the principles, the design strategies, and interfaces that inform people without steering them.

Where people lose marks

The strategy. Minimise, hide, separate and aggregate sound alike, and each means one specific thing.

From the 22Academy bank · best answer

A service needs to know only whether a user is over 18. Which design choice BEST applies data minimisation?

Twenty more like it, free
5

Privacy engineering and privacy governance

The techniques and the discipline around them: privacy-enhancing technologies, the objectives of privacy engineering, and governance through the development life cycle.

Where people lose marks

The technique. Anonymisation, pseudonymisation, k-anonymity and differential privacy give different guarantees, and the exam asks which one a description matches.

From the 22Academy bank · definition

Which technique adds calibrated statistical noise to results, so that the presence of any one person in a dataset cannot be inferred?

Twenty more like it, free

Not using your IAPP membership? Pay only the $250 maintenance fee and keep $340 every two years.

Start CIPT free
The rules

The techniques that keep coming back

Four groups of techniques run through the whole exam. Know what each one guarantees and what it does not.

Encryption

In transit, at rest and in use

What each form protects, and what it leaves exposed.

De-identification

Anonymisation and pseudonymisation

How they differ, and how data gets re-identified.

Differential privacy

Noise with a guarantee

Sharing results about a group without revealing any one person in it.

Threat modelling

Before the code is written

Walking through a design to find the privacy threats in it.

Worth knowing

The frameworks worth knowing

The exam draws on the frameworks and models that privacy engineers work with. Knowing what each one is for matters more than memorising it.

NIST Privacy Framework

A voluntary tool for managing privacy risk, built to sit next to the NIST Cybersecurity Framework.

NIST privacy engineering objectives

Predictability, manageability and disassociability: what a system should achieve for privacy.

Privacy by Design

The seven foundational principles, starting with proactive and not reactive.

Privacy design strategies

Minimise, hide, separate, aggregate, inform, control, enforce and demonstrate.

LINDDUN

A method for privacy threat modelling, named after the seven kinds of threat it looks for.

A taxonomy of privacy

Four groups of harmful activity: collection, processing, dissemination and invasion.

Decisions

Decisions worth knowing

These decisions settled how the law treats identifiers, cookies, plugins, security and pseudonymised data.

Breyer, Court of Justice of the EU, 2016

A dynamic IP address can be personal data for a website operator.

Planet49, Court of Justice of the EU, 2019

Pre-ticked boxes are not consent, and the cookie rules apply whether or not the data is personal.

Fashion ID, Court of Justice of the EU, 2019

A website that embeds a social plugin is a joint controller for the collection and transmission.

Schrems II, Court of Justice of the EU, 2020

Transfers need an assessment of the destination and, where needed, extra measures such as strong encryption.

FTC v. Wyndham, 2015

The FTC may treat poor data security as an unfair practice.

EDPS v SRB, Court of Justice of the EU, 2025

Whether pseudonymised data is personal data depends on whether the recipient can reasonably re-identify people.

Always current

When the rules change, your course changes with them.

Every explanation in the course is stored once and linked to its source. When a regulation, a guideline or a decision changes, we update it in one place and every lesson that uses it is correct from that moment.

AI-generated image - a hand adds a new volume to a row of law books, as the course is updated when the rules change
The questions

How the questions are built, and how to read them

Exam questions come in a small number of structures, and a candidate who knows the content can still lose marks on the structure. The course tags every question with its structure; the technique is one tap away on each one, and every test shows whether you lost the mark on the content or on the type of question.

Two-statement true or false
Judge each statement on its own before you look at the options.
Best, most, primary
Underline the qualifier. Several options are defensible; one is the most complete.
Except, least, not
Three options are right. You are looking for the one that is wrong.
Only if, unless, provided that
Restate the rule without the condition, then test whether the outcome could happen without it.
Scenario
Read the question first, then the scenario. The scenario carries deliberate noise.
Definitions
The trap is a neighbouring term with one word changed.
Screenshot of the 22Academy course - score per question type, showing which type costs you the most marks
Screenshot from results in the course

Buy the exam voucher when you are ready, not before. It expires a year after you buy it.

Free CIPT assessment
How long it takes

How long does it take to prepare?

The IAPP recommends at least 30 hours of study. People who already work in privacy or in engineering need less; people new to both need more. At three hours a day you can be ready in about a month.

Book the exam before you feel ready: a fixed date concentrates the effort. You have twelve months from purchase to sit it.

CIPT course€37 a week

Or €117 a month with a trial exam included.

Start the course

A four-week plan, at three hours a day

  1. Week 1The free assessment, domain 1 and the start of domain 2: the technologist's role and the data life cycle21 h
  2. Week 2Domains 2 and 3: risks per stage, risk models and threat modelling. First module tests21 h
  3. Week 3Domains 4 and 5: privacy by design, privacy-enhancing technologies and governance21 h
  4. Week 4Question structures, the trial exam and its analysis, work on the weak modules, then book the exam21 h

A guideline. The course builds your own plan from your assessment and the hours you have.

Resources

Resources, and what each one is worth

ResourcePriceWorth it?
CIPT body of knowledgeFreeEssential. Work through it competency by competency.
The IAPP textbookIAPP storeUseful for self-study; it can lag the current body of knowledge.
NIST Privacy FrameworkFreeShort, practical, and close to how the exam thinks about risk.
IAPP official trainingFrom $995A good introduction. It does not replace practice under time pressure.
IAPP practice examIAPP storeOne exam, useful for the house style of the questions.
22Academy CIPT course€37 a week or €117 a monthThe full course, the exam skills, the measurement and a trial exam. Stop when you are ready.
22Academy trial exam€42, or free with a monthly planFull length under real conditions, with analysis by domain and by question type.
Ten mistakes

Ten mistakes that cost candidates the exam

  1. Treating security as privacyA secure system can still use data in a way people never expected.
  2. Skipping the conceptsEngineers know the techniques and lose marks on notice, consent and purpose.
  3. Skipping the techniquesLawyers know the concepts and lose marks on how the techniques work.
  4. Mixing up the de-identification termsAnonymisation, pseudonymisation and aggregation are three different things.
  5. Naming the wrong harmThe exam asks which kind of privacy harm a situation shows.
  6. Reading the scenario firstThe scenario is written with noise in it. Read the question first.
  7. Missing the qualifierMost, best, primary and except change the logic of the whole question.
  8. Practice in the last week onlyTesting early is what finds the weak domains.
  9. Exam dumpsOften wrong, against the candidate agreement, and useless on scenarios.
  10. Sitting too earlyA retake costs $375. A trial exam costs €42 and tells you whether you are ready.

If you fail, fail cheap. Ten trial exams cost less than one retake.

Buy a trial exam
Jobs and pay

What jobs does CIPT lead to, and what do they pay?

The CIPT is the certification for anyone who builds or runs the systems that hold personal data. It leads to privacy engineering, and it strengthens roles that sit between technology and governance, such as the AI governance manager and the head of privacy.

Employers ask for it because it shows that you can turn a privacy requirement into a design. Pay rises with the scope of the role.

Each role page shows which certifications it takes, in which order, and how long it takes.

Which first

CIPT or another certification: which first?

CertificationWhat it coversTake it when
CIPTPrivacy in technologyYou build or run the systems
CIPP/EEuropean data protection lawYou want the legal foundation first
CIPP/USUnited States privacy law, federal and stateYou work with American data, clients or colleagues
CIPMRunning a privacy programmeYou run privacy rather than advise on it
AIGPAI governanceYour organisation builds or uses AI

Not sure? The career plan starts from the job you want.

Glossary

The terms the exam expects you to use precisely

Privacy by design
Building privacy into a system from the start instead of adding it later.
Privacy by default
The most protective setting applies without the user doing anything.
Data minimisation
Collecting and keeping only what the purpose needs.
Anonymisation
Removing the link to a person for good, so the data is no longer personal.
Pseudonymisation
Replacing identifiers so that data cannot be linked to a person without extra information kept apart.
Re-identification
Linking data that was de-identified back to a person.
k-anonymity
Each record is indistinguishable from at least k minus one others.
Differential privacy
Adding statistical noise so that results reveal nothing about any one person.
Homomorphic encryption
Computing on data while it stays encrypted.
Privacy-enhancing technology
A technique that reduces the personal data a system needs or exposes.
Threat modelling
A structured search for what can go wrong in a design.
Dark pattern
An interface that steers people into a choice they would not otherwise make.
Secondary use
Using data for a purpose other than the one it was collected for.
Aggregation
Combining pieces of data about a person into a fuller picture.
Data life cycle
Collection, use, disclosure, retention and destruction.
Access control
Deciding who may see or change which data, and enforcing it.

Know the terms. Now prove it.

Free account, fifteen minutes, your score per domain.

Exam day

Exam day, and after

Pace

About 1 minute 40 seconds a question. Flag and move on.

Eliminate first

Removing what is wrong is faster than hunting for what is right.

The qualifiers

Most, best, primary and except decide what is being asked.

The break

Optional, fifteen minutes. Taking it means submitting the first half for good.

Online or at a test centre: both work. If you sit online, do a full dry run the day before, and disconnect second screens and docking stations.

Passed? You keep the certification with 20 CPE credits in every two-year period, plus the maintenance fee or an IAPP membership that includes it.

Not this time? A retake costs $375, and your progress in the course is still there.

“This mock test will give you an exact reality check on your preparation.”

Parth, CIPT

Harder than the real thing, on purpose.

We believe a trial exam should hold a higher standard than the real one. Pass ours at the first attempt, sit the real exam within two weeks and fail it, and we refund what you paid for that trial exam.

Conditions
Questions

Questions people ask about the CIPT

Is the CIPT hard?

It is demanding rather than hard. It sits between law and engineering, and most candidates are at home on one side only. The questions reward precision about terms that sound alike, so candidates who practise on exam-style questions early do far better than those who only read.

Do I need to be an engineer?

No. There are no prerequisites, no degree and no minimum experience. The exam asks what a technique does and when to use it, not how to program it. Candidates come from engineering, security, product, compliance and law, and the course explains every concept in plain language.

Do I need the CIPP/E first?

No. The CIPT stands on its own. A CIPP certification gives you the law and the CIPT shows how to build it into systems, so the two fit together well, in either order.

How is 22Academy different from IAPP training?

The IAPP offers traditional classroom courses and e-learning in which the content is presented to you. We start from the fact that you already have access to all the content, so we focus on getting it into your head rather than throwing more of it at you. We test your knowledge constantly, because that is what makes it stick, and we explain every concept in the form and length that suits you. We also teach the exam skills: how the questions are built, what they are really asking and where the traps are. And we embrace AI for your study, because you use it already; we show you how to use it more effectively.

Do I need a trial exam if I have done practice questions?

Practice questions check your knowledge one item at a time. The trial exam checks whether you can answer ninety in a row under the clock, the way the real exam asks it. Its analysis shows whether you lose marks on the content or on the type of question, so you know exactly what to work on in the last days. It is the last check before you book.

Can I use my own AI app to prepare?

Yes, and we encourage it. An AI app is a good partner for rehearsing: it will quiz you, rephrase a concept or test you on a passage you give it. It is a poor judge of whether you are ready, because it cannot tell you what you failed to ask. The course gives you prompts that make your own app quiz you properly, and measures you with its own questions.

Is there a free option?

Yes. You can start your course for free and see whether the system suits you: the assessment and the first lesson are open without a card. When you want the rest, the course is €37 a week, or €117 a month with a trial exam included.

Can I stop at any time?

Yes. You pay for the weeks or months you study and cancel whenever you like; your access runs to the end of the period you paid for. If you come back within a year, your progress is still there.

Is 22Academy affiliated with the IAPP?

No. The IAPP owns the CIPT and sets the exam. 22Academy prepares candidates for it independently, and has done so since 2018.

More in the FAQ.

Bas Hennis, founder of 22Academy

Questions about your study?

How to plan around a job, when to book the exam, whether you are ready: connect and ask. Support is free!

info@22academy.com Connect

Start where you actually are

Free account, fifteen minutes, your score per domain.