CDPSE certification exam
Computer-based professional knowledge assessment
- Type
- Written
- Delivery
- Both
Passing score: 450 ISACA scaled score
Exam sections
Privacy Governance
“Privacy Governance” addresses objectives, decision ownership, risk significance, fitness of supporting information, sequence of action, and judgments the evidence can sustain as part of CDPSE — Certified Data Privacy Solutions Engineer. Candidates need to assign the decision to the correct role, evaluate the available support, and respond at the proper point in the case, without accepting a result that the available evidence cannot support. It leads into “Privacy Risk Management And Compliance” in the published outline.
Question notes
Assessment of “Privacy Governance” rewards attention to context and verification because the best response should align with professional practice rather than the most immediately technical action. Common weakness: unverified inputs, unclear responsibility, judgment before analysis is complete, or an intervention focused on what is visible instead of the underlying risk. Acceptance evidence: a clear path from objective through risk, evidence, judgment, conclusion, and stakeholder communication. Use the stored weighting for relative study priority; it does not reveal how many questions will appear.
Preparation tips
For “Privacy Governance,” use an explain–perform–verify loop. Exercise: Review a flawed conclusion, identify the missing or unreliable evidence, and rewrite it so the final judgment is supportable. Explain how this evidence confirms the “Privacy Governance” result: a documented link from objective into risk, evidence, judgment, conclusion, and stakeholder communication. Also test for unverified inputs, unclear responsibility, judgment before analysis is complete, or an intervention focused on what is visible instead of the source of risk. Carry the final evidence forward to plan work in “Privacy Risk Management And Compliance”.
Privacy Risk Management And Compliance
“Privacy Risk Management And Compliance” tests whether a candidate understands objectives, decision ownership, risk significance, reliability of support, sequence of action, and defensible conclusions. That understanding must support an ability to assign the decision to the correct role, evaluate the available support, and respond at the proper point in the case. In the published sequence, it follows “Privacy Governance” and precedes “Data Life Cycle Management”.
Question notes
For “Privacy Risk Management And Compliance,” context matters: question context may require separating management ownership from independent assurance responsibility. Challenge the result with unverified inputs, unclear responsibility, judgment before analysis is complete, or a response aimed at the visible symptom rather than the underlying risk, then verify it using a clear path from objective through risk, evidence, judgment, conclusion, and stakeholder communication. The section record preserves blueprint emphasis without promising how many items will appear.
Preparation tips
Study “Privacy Risk Management And Compliance” through contrasting cases. Start with this exercise: Build an evidence matrix linking objective, risk, control, test, result, and conclusion; then challenge one weak source. Build the weaker case around unreliable support, unclear ownership, conclusions reached too early, or a response disconnected from the actual exposure. Separate the two results using traceability from objective to risk, evidence, judgment, conclusion, and stakeholder communication. Complete the exercise by tracing one consequence into “Data Life Cycle Management”.
Data Life Cycle Management
The assessment boundary for “Data Life Cycle Management” covers data shape, ownership, lifecycle, consistency, and later system effects of a change. The expected practical capability is to examine data at entry, during access and transformation, after updates, and at the end of its lifecycle. In the published sequence, it follows “Privacy Risk Management And Compliance” and precedes “Privacy Engineering”.
Question notes
Knowing the heading “Data Life Cycle Management” is not sufficient; a case may test whether the candidate gathers support before reaching or communicating a conclusion. The principal risk is hidden information loss, state that no longer reflects reality, ownership gaps, or lifecycle behavior treated as a given. The response should be supported by a recorded state comparison, provenance records, consistency checks, and results captured by a downstream consumer. The section's numeric emphasis is retained independently, with no inferred question quantity.
Preparation tips
Build preparation for “Data Life Cycle Management” around context, action, failure, and proof. Exercise: Create a valid data path and a deliberately inconsistent one, then use reconciliation evidence to explain the difference. The checklist must expose unnoticed corruption, obsolete state, ambiguous stewardship, or a mistaken assumption about data shape and disposition. Required proof: before-and-after state, documented lineage, comparison findings, and observations collected by a later process. Translate the evidence into a readiness check for “Privacy Engineering”.
Privacy Engineering
“Privacy Engineering” tests whether a candidate understands the concepts named by “Privacy Engineering” and the decisions, limitations, and effects that make the topic operationally meaningful. That understanding must support an ability to move through “Privacy Engineering” from context and decision to execution, communication, or confirmation as appropriate. It draws on work established in “Data Life Cycle Management”.
Question notes
Knowing the heading “Privacy Engineering” is not sufficient; the credential holder's accountability determines which action is appropriate at that point in the case. The principal risk is accepting work on “Privacy Engineering” without leaving enough support for an independent review of the decision and outcome. The response should be supported by a repeatable “Privacy Engineering” result, reasoning another practitioner can follow, and proof that the objective was satisfied. Use the dedicated weight field for published emphasis rather than deriving a question count from this note.
Preparation tips
For “Privacy Engineering,” use this drill: Practice “Privacy Engineering” under a deliberately different condition, then explain which logic survives the change. Negative test: a plausible “Privacy Engineering” response that fails once a reviewer inspects its assumptions, consequences, and evidence. Evidence to retain: an observable outcome for “Privacy Engineering,” the premise behind the response and verification that material limitations were respected. Explain how this work closes or exposes a risk originating in “Data Life Cycle Management”.
