By Daniel de Almeida Afonso · Last updated: October 9, 2026
For most privacy professionals, the best data privacy certification is one of the IAPP credentials: CIPP for law, CIPM for program management, or CIPT for technology. Engineers can also consider ISACA's CDPSE. Businesses cannot earn a single "privacy certificate" in the same way, but they can adopt standards such as ISO/IEC 27001 and use approved GDPR certification schemes.
No law requires you to hold a data privacy certification. That leaves room for hype, often from the people who sell the exams. This guide explains what the main certifications cover, how they differ, and how to choose.
In this guide:
- What data privacy certifications are
- Certifications for professionals versus businesses
- The main professional certifications, compared
- How to get certified and stay certified
- Frequently asked questions
What are data privacy certifications?
A data privacy certification is a signal. It tells employers, clients, or regulators that you, or your organization, meet a defined standard of privacy knowledge or practice.
There are two separate kinds:
- Professional certifications test an individual's knowledge. They help someone implement a privacy program or qualify for a role.
- Organizational certifications assess a business's systems and controls. They are usually about security or privacy management, not about one person's skills.
No single certificate covers both. Pick the kind that matches your goal.
Why professionals get certified
Employers often list a privacy certification in job ads. Certification also gives you a structured way to learn, because exam preparation forces you to study the law and frameworks in depth.
Certified people can help a business in practical ways. They can:
- Map the organization's legal duties
- Write and maintain privacy policies and procedures
- Train employees
- Run the response when a data breach happens
Certification does not guarantee a job or a raise. Treat it as proof of knowledge, and pair it with real project experience. For the business side of the argument, see our guide to the benefits of GDPR certification.
The main certifications for privacy professionals
No privacy certificate holds "official" status. Each is issued by a private body. Its value depends on the issuer's reputation and the rigor of its exam, so check the issuer before you pay.
CIPP: Certified Information Privacy Professional (IAPP)
CIPP is the legal and regulatory credential from the International Association of Privacy Professionals (IAPP). It comes in regional versions:
- CIPP/A for Asia
- CIPP/C for Canada
- CIPP/E for Europe (the GDPR)
- CIPP/US for the United States
- CIPP/AU for Australia and CIPP/CN for China
The exam has 90 questions and lasts 2.5 hours. CIPP suits lawyers, compliance officers, and governance specialists. If you work with EU data, CIPP/E is the usual choice.
A common mistake is to say CIPP has "Associate, Professional, and Fellow" levels. It does not. The regions above are the real variants. "Fellow of Information Privacy" (FIP) is a separate IAPP designation for people who hold a CIPP plus either the CIPM or the CIPT.
CIPM: Certified Information Privacy Manager (IAPP)
CIPM focuses on running a privacy program day to day. It covers governance, operations, and how to build privacy requirements into business processes.
It is a single credential that is not tied to one country. Privacy officers, privacy managers, and legal and compliance leads often choose it. The exam has 90 questions and lasts 2.5 hours.
CIPT: Certified Information Privacy Technologist (IAPP)
CIPT is for people who build or secure systems. It covers privacy by design and how to put privacy controls into products and infrastructure.
It fits IT staff, security professionals, and engineers. The exam has 90 questions and lasts 2.5 hours. If you are on a technical team, our GDPR training course for IT professionals is a lighter starting point before a full CIPT.
CDPSE: Certified Data Privacy Solutions Engineer (ISACA)
CDPSE is aimed at engineers and architects who design privacy into technology. Its exam has 120 questions across four domains: privacy governance, privacy risk management and compliance, data life cycle management, and privacy engineering.
ISACA requires at least three years of cumulative work experience performing CDPSE tasks, gained within the 10 years before you apply. Older guides, including an earlier version of this one, quoted five years and an experience waiver for other certifications. ISACA's current page lists three years and mentions no waiver, so confirm the rules when you apply.
PECB Certified Data Protection Officer (CDPO)
PECB's DPO credential is built for people who already work in data protection and want to act as a Data Protection Officer under the GDPR. The requirements are:
- Pass the exam
- Five years of work experience, including two years in data protection
- 300 hours of data protection activities
- Agree to the PECB Code of Ethics
PECB also offers a training course that prepares you for the exam.
CDP: Certified in Data Protection (Identity Management Institute)
The CDP is issued by the Identity Management Institute (IMI). You must join IMI, meet a points-based eligibility rule, and pass an online exam. IMI describes it as 100 multiple-choice questions with a 70% pass mark. Its scope is broad: data protection across the data life cycle, tied to security standards and privacy laws.
IMI's own pages describe the program, and we could not find independent comparisons of its recognition. Check its standing with the employers you care about.
AIGP: AI Governance Professional (IAPP)
IAPP now also offers the AI Governance Professional (AIGP). It covers responsible AI, how AI affects people, and how current and emerging laws apply to AI. The exam has 100 questions and lasts 2.75 hours. Consider it if your work moves from privacy into AI oversight.
Comparing the core credentials
| Credential | Issuer | Best for | Exam and requirements |
|---|---|---|---|
| CIPP (regional) | IAPP | Law and compliance | 90 questions, 2.5 hours |
| CIPM | IAPP | Running a privacy program | 90 questions, 2.5 hours |
| CIPT | IAPP | Building privacy into technology | 90 questions, 2.5 hours |
| CDPSE | ISACA | Privacy engineering | 120 questions, 3 years' experience |
| AIGP | IAPP | AI governance | 100 questions, 2.75 hours |
IAPP's certification FAQ page lists no experience prerequisites for its exams. The CIPM, CIPP/E, CIPP/US, and CIPT credentials are accredited by ANAB under ISO/IEC 17024.
How to choose
- Choose CIPP (or CIPP/E for the GDPR) if your job is mainly law, policy, or compliance.
- Choose CIPM if you run or will run a privacy program and manage people and processes.
- Choose CIPT if you are an engineer or IT lead who builds systems that handle personal data.
- Choose CDPSE instead of CIPT if you have three or more years of hands-on privacy engineering and want an ISACA credential.
- Choose AIGP if you are adding AI governance to your remit.
Many DPO roles value a legal credential plus a management credential, such as CIPP/E and CIPM. Holding a CIPP with a CIPM or CIPT also qualifies you for the FIP designation.
Certifications for businesses
Businesses cannot buy a certificate that proves their privacy operations comply with the GDPR, the CCPA, or other laws worldwide. Compliance is something you demonstrate through documented practice, accountability, and cooperation with regulators.
There are still recognized options:
- ISO/IEC 27001 certifies an information security management system. It is about security, not privacy law.
- ISO/IEC 27701 extends that approach to privacy information management.
- GDPR Article 42 allows approved certification schemes. They are voluntary, and they do not by themselves prove compliance.
Some laws, including the GDPR, expect organizations to train their people. No official certificate covers that duty, so training records matter. Secure Privacy runs a data privacy training platform with short courses for employee awareness. It is not a replacement for the professional credentials above. For a free starting point, see the free GDPR certificate from Secure Privacy.
How to get certified and stay certified
The steps are similar across programs:
- Choose the credential that fits your role and goals.
- Check eligibility. IAPP's FAQ lists none, but ISACA and PECB require experience.
- Study the official body of knowledge, and consider a training course.
- Buy and schedule the exam. IAPP says you must complete it within one year of purchase.
- Maintain the credential.
Maintenance matters. IAPP certifications run in two-year terms. To keep one in good standing you need continuing privacy education (CPE) credits and either a maintenance fee or IAPP membership. IAPP's FAQ lists the maintenance fee as USD 250 per term, and its CPE policy sets the credit hours. We have not quoted exam prices, because they change and differ by membership. Check the issuer's current price list.
Practical tips:
- Start with the issuer's exam outline, then read the primary law, such as the GDPR text.
- Join a professional body for study groups and events.
- Ask your employer about paying for it, since many do.
Frequently asked questions
Which data privacy certification is best?
It depends on your role. CIPP suits legal and compliance work, CIPM suits program managers, and CIPT or CDPSE suit technical staff. The IAPP credentials are the most widely requested in job ads.
Is a data privacy certification required by law?
No. No law prescribes one for individuals. Some laws expect staff training, but no specific certificate satisfies that.
Can a company be "GDPR certified"?
Not in a general sense. The GDPR allows approved certification mechanisms, but they are voluntary and do not guarantee compliance. ISO/IEC 27001 and 27701 are standards you can be audited against.
How many questions are on the CIPP, CIPM, and CIPT exams?
Each has 90 questions and a 2.5-hour time limit, according to IAPP's FAQ.
Do IAPP certifications expire?
They run in two-year terms. You must earn CPE credits and pay the maintenance fee or hold IAPP membership.
Does CIPP have Associate, Professional, and Fellow levels?
No. CIPP has regional variants such as CIPP/E and CIPP/US. FIP is a separate designation.
What is the difference between CIPP and CIPM?
CIPP covers privacy law and regulation. CIPM covers how to run a privacy program in practice.


