Certified Data Privacy Solutions Engineer Practice Exam — CDPSE:Certified Data Privacy Solutions Engineer

Exam information

I. Basic Exam Information

- Exam Name: ISACA Certified Data Privacy Solutions Engineer® (CDPSE®)

- Launch & Update Date: Officially launched in 2020; the latest exam outline was updated in 2025

- Exam Languages: Multiple language versions are available globally, including Simplified Chinese, Traditional Chinese and English, with unified language options worldwide.

- Registration Eligibility: There are no restrictions for exam registration, and all individuals may sign up for the exam. A formal CDPSE credential application is required upon passing the exam. Credential prerequisites:

 • Possess a minimum of 3 years of work experience related to data privacy governance, privacy architecture and/or data lifecycle management, with practical experience in at least one of the three CDPSE practice domains

 • Work experience shall be hands-on roles with direct participation in the design, implementation or maintenance of privacy solutions

 • Agree to and abide by the ISACA Code of Professional Ethics

 • Note: No experience exemptions are allowed for CDPSE; the full 3-year work experience requirement must be fulfilled

- Exam Fees: USD 575 for ISACA members; USD 760 for non-members. A USD 50 credential application fee is required after passing the exam.

- Exam Duration: 3.5 hours (210 minutes), covering all 120 exam questions.

- Exam Format: ISACA offers two standard exam modes worldwide: remote-proctored online exam (video proctoring via PSI) and in-person computer-based testing (CBT).

 Available exam modes by region:

 • Hong Kong: In-person CBT only

 • Taiwan: In-person CBT and online exam

 • Macau: In-person CBT only

 • Mainland China: In-person CBT arranged by ISACA-authorized partners

 • Overseas regions: Free to choose between remote proctoring and in-person CBT

- Exam Questions: 120 scenario-based multiple-choice questions. All questions are scored with no unscored pre-test items.

- Scoring Details:

 • A preliminary pass/fail result is provided immediately after the exam.

 • Official exam results will be sent via email within 10 working days.

 • Passing score: 450 points (total score: 800 points; scaled scoring range: 200 – 800).

- Exam Eligibility Validity: After successful registration, candidates must schedule and complete the exam within 12 months. Eligibility will expire if overdue, and re-registration and payment will be required.


II. Detailed Exam Content (Latest Exam Outline)

The CDPSE exam consists of three core practice domains with a total weight of 100%. It assesses the professional competencies and practical capabilities of data privacy solutions engineers.


1. Privacy Governance (34%): Privacy frameworks and standards (e.g. GDPR, CCPA, PIPL), formulation of privacy policies and procedures, Privacy Impact Assessment (PIA), responsibilities of Data Protection Officer (DPO), privacy training and awareness, compliance monitoring and reporting.

2. Privacy Architecture (36%): Implementation of Privacy by Design (PbD) principles, application of Privacy Enhancing Technologies (PETs), data classification and labeling, access control and identity management, technical controls for privacy compliance, third-party privacy risk management.

3. Data Lifecycle (30%): Compliance for data collection, security of data storage and transmission, restrictions on data processing and usage, controls for data sharing and disclosure, data retention and destruction policies, fulfillment of data subject rights (access, rectification, erasure and others).


Core Assessment Focus

Capabilities in designing data privacy governance systems, implementing privacy enhancing technologies, protecting data privacy throughout the entire data lifecycle, managing privacy compliance risks, cross-departmental collaboration and stakeholder communication.


III. Registration Process

1. Registration Process for Non-Mainland China Candidates

1. Visit the official ISACA website: https://www.isaca.org, create and log in to your MyISACA account.

2. Select the CDPSE exam for registration, and fill in personal information and work experience details.

3. Complete exam fee payment (USD 575 for members / USD 760 for non-members).

4. Upon successful payment, your 12-month exam eligibility period will take effect.

5. Schedule your exam time and location via PSI (remote proctoring or in-person CBT is optional).

6. Prepare valid identification documents and attend the exam at the scheduled time.


2. Registration Process for Mainland China Candidates

1. Register via the official ISACA China website: https://www.isaca.org.cn or ISACA-authorized partners such as ZhongShen Audit Online and Saihu Academy.

2. Submit personal information and work experience verification documents, and complete registration with assistance from authorized institutions.

3. Pay the exam fee (USD 575 for members / USD 760 for non-members). All registration formalities will be handled uniformly by the institution.

4. Upon successful registration, your 12-month exam eligibility period will take effect.

5. Follow the links or guidelines provided by the institution to schedule your exam time and test center on the PSI platform. In-person CBT is the primary option in Mainland China.

6. Present valid identification documents (ID card or passport) on exam day.


IV. Supplementary Notes

1. Credential Validity: The CDPSE credential is valid for 3 years. To maintain active status, holders must earn 120 Continuing Professional Education (CPE) credits within the validity period and pay annual maintenance fees (USD 45 for members / USD 85 for non-members).

2. Retake Policy: Candidates who fail the exam must wait 30 days before retaking it. A 90-day waiting period is required after two consecutive failures. Retake fees are identical to the initial exam fees.

3. Credential Application Period: You must submit the CDPSE credential application within 5 years upon passing the exam. Otherwise, you will need to retake the exam.

4. Differences from Other Privacy Credentials: CDPSE focuses on the design and implementation of technical data privacy solutions, ideal for IT, security and privacy engineers and architects. The CIPP suite (e.g. CIPP-CN) concentrates on privacy laws and compliance, suitable for legal and compliance professionals. CIPM targets privacy management systems, designed for privacy management practitioners.


Wish all candidates every success in the exam!


Sample questions

Certified Data Privacy Solutions Engineer · Q1
Question #1
What should be the PRIMARY consideration of a multinational organization deploying a user and entity behavior analytics (UEBA) tool to centralize the monitoring of anomalous employee behavior?
  • A.
    Cross-border data transfer
  • B.
    Support staff availability and skill set
  • C.
    User notification
  • D.
    Global public interest

Answer: A

Answer Analysis:
This question aligns with the CDPSE core domains of Privacy Governance and Data Lifecycle Management, which prioritize addressing legal and regulatory compliance risks as the first step for any global technology deployment processing personal data. A multinational organization deploying a centralized UEBA tool will need to collect, aggregate, and process employee personal data (including activity logs, access records, and behavioral patterns) from multiple jurisdictions into a single central repository, which inherently requires cross-border movement of personal data. Non-compliance with cross-border data transfer regulations across operating jurisdictions can result in severe regulatory penalties, legal liability, forced suspension of the tool, and reputational harm, making this the highest priority consideration before any operational or secondary control decisions are made. Option Analysis:
A. Cross-border data transfer: Correct. UEBA tools process high volumes of employee personal data that qualifies as PII or personal data under nearly all global privacy frameworks (including GDPR, CCPA, PDPA, and others). For a multinational deployment, centralizing this data requires adherence to cross-border transfer requirements such as adequacy decisions, standard contractual clauses, binding corporate rules, or other jurisdiction-approved transfer mechanisms. Failure to address this requirement first renders the entire deployment non-compliant, creating significant legal and regulatory risk that outweighs all other considerations, making this the primary priority.
B. Support staff availability and skill set: Incorrect. While trained staff are required for effective ongoing operation of the UEBA tool, this is an operational implementation consideration that is secondary to ensuring the deployment meets mandatory legal and privacy compliance requirements. Operational factors do not take precedence over compliance risk for multinational deployments under CDPSE frameworks.
C. User notification: Incorrect. User notification of monitoring is a required transparency control in many jurisdictions, but it is a downstream implementation step that is only valid if the underlying cross-border transfer and processing of the data is legally permitted. Even with proper user notification, non-compliant cross-border transfers will still expose the organization to significant regulatory risk, so this is not the primary consideration.
D. Global public interest: Incorrect. Global public interest is a broad, non-specific factor that is not a formal primary consideration for internal enterprise technology deployments under CDPSE domains. Organizations prioritize compliance with applicable regulatory requirements and defined enterprise risk postures over vague public interest considerations for internal monitoring tools. Key Concepts:
1. Cross-border data transfer compliance: A core CDPSE Privacy Governance concept that mandates organizations implement valid legal mechanisms for cross-border movement of personal data to meet jurisdictional regulatory requirements and avoid penalties, including fines up to 4% of global annual revenue under frameworks like GDPR.
2. Personal data scope of UEBA processing: A core CDPSE Data Lifecycle Management concept that recognizes employee behavioral and activity data processed by UEBA tools as personal data, triggering full privacy compliance obligations for collection, transfer, storage, and processing activities.
3. Jurisdictional alignment for global privacy deployments: A core CDPSE Privacy Architecture concept that requires organizations resolve conflicting cross-jurisdictional regulatory requirements for personal data processing as a first step before implementing any global privacy-impacting technology. References:
ISACA CDPSE Exam Preparation Resources, European Commission International Data Transfers Guidance, https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_en
Certified Data Privacy Solutions Engineer · Q2
Question #2
Which of the following should be the FIRST consideration when conducting a privacy impact assessment (PIA)?
  • A.
    The applicable privacy legislation
  • B.
    The quantity of information within the scope of the assessment
  • C.
    The systems in which privacy-related data is stored
  • D.
    The organizational security risk profile

Answer: A

Answer Analysis:
This question aligns with CDPSE Domain 1 (Privacy Governance) knowledge related to privacy impact assessment (PIA) execution fundamentals. The core purpose of a PIA is to identify, evaluate, and mitigate privacy risks associated with personal data processing, while ensuring alignment with mandatory legal obligations and data subject protection requirements. All PIA activities, including scoping, risk assessment, and control validation, rely on a predefined set of evaluation criteria, which are first established by applicable privacy legislation. Without first confirming what regulatory requirements apply to the organization and the processing activity being assessed, the PIA cannot correctly define its scope, identify relevant risks, or measure compliance with mandatory standards, making regulatory alignment the foundational first consideration for any PIA. Option Analysis:
A. Correct. Applicable privacy legislation establishes the mandatory requirements for personal data processing, data categorization, data subject rights, risk thresholds, and compliance standards that the entire PIA is designed to evaluate against. This is the foundational baseline for all subsequent PIA activities per CDPSE privacy governance best practices, so it is the first required consideration.
B. Incorrect. The quantity of information within the assessment scope is a factor evaluated later in the PIA process when calculating the severity of identified privacy risks. It cannot be a first consideration, as you cannot determine what information is relevant to the assessment until you first understand the legislative requirements that define which data types and processing activities are regulated.
C. Incorrect. Systems storing privacy-related data are identified during the PIA scoping phase, which occurs after applicable legislative requirements are established. Legislation dictates which data types and processing activities fall under regulatory oversight, so relevant systems cannot be identified until the applicable legal framework is confirmed first.
D. Incorrect. The organizational security risk profile is an input to risk evaluation during later PIA stages, but it is secondary to applicable privacy legislation. General security risk profiles rarely capture all privacy-specific regulatory requirements, so they cannot serve as the foundational first reference point for a PIA. Key Concepts:
1. PIA Regulatory Baseline: A core CDPSE principle is that all privacy assessments, including PIAs, must first align with applicable mandatory privacy legislation, as non-compliance carries the highest priority legal, financial, and reputational privacy risks for organizations. This baseline defines the entire evaluation framework for the PIA.
2. PIA Scoping Hierarchy: Per CDPSE Domain 2 (Privacy Architecture) and Domain 3 (Data Lifecycle) guidance, scoping of a PIA is dependent on first identifying regulatory requirements, which determine which processing activities, data assets, and systems are included in the assessment.
3. Privacy Risk Prioritization: CDPSE domain knowledge emphasizes that privacy risks are first measured against legal compliance requirements before other organizational risk factors, as regulatory penalties and legal liability are the primary drivers of formal PIA execution for most organizations. References:
ISACA CDPSE Review Manual, 1st Edition, ISACA Privacy Impact Assessments: A Practical Guide, https://www.isaca.org/resources/isaca-journal/issues/2021/volume-6/privacy-impact-assessments-a-practical-guide
Certified Data Privacy Solutions Engineer · Q3
Question #3
Which of the following BEST represents privacy threat modeling methodology?
  • A.
    Mitigating inherent risks and threats associated with privacy control weaknesses
  • B.
    Systematically eliciting and mitigating privacy threats in a software architecture
  • C.
    Reliably estimating a threat actor’s ability to exploit privacy vulnerabilities
  • D.
    Replicating privacy scenarios that reflect representative software usage

Answer: A

Answer Analysis:
The CDPSE certification covers three core domains: Privacy Governance, Privacy Architecture, and Data Lifecycle. Privacy threat modeling falls under the Privacy Architecture domain, and is defined as a comprehensive, structured methodology designed to identify, assess, prioritize, and mitigate privacy risks across all organizational assets, including systems, processes, third-party vendor ecosystems, and end-to-end data flows. The core objective of the methodology is to address exposure created by gaps or weaknesses in implemented privacy controls to reduce risk to acceptable levels aligned with organizational risk appetite and regulatory requirements. The suggested answer A is the most accurate and holistic representation of this methodology, as it captures the core end-to-end purpose of the process, rather than focusing on narrow sub-components or limited use cases. Option Analysis:
A. Correct. This option aligns with ISACA's official CDPSE definition of privacy threat modeling, which centers on identifying and mitigating inherent privacy risks and threats that arise from weaknesses in administrative, technical, and physical privacy controls across the full scope of organizational operations, not just limited technical environments. This comprehensive scope makes it the best representation of the full methodology.
B. Incorrect. While privacy threat modeling can be applied to software architectures as one use case, this option is excessively narrow. The methodology applies to all components of a privacy program, including processes, third-party data sharing, and physical data handling, not exclusively software architecture, so it does not represent the full methodology.
C. Incorrect. Estimating a threat actor's ability to exploit privacy vulnerabilities is only one small, partial step in the privacy threat modeling process, not the full methodology itself. The methodology also includes threat identification, risk prioritization, and mitigation implementation, so this description is incomplete.
D. Incorrect. Replicating representative software usage scenarios is a supporting technique used during the threat identification phase of privacy threat modeling, not the core methodology. It is a tactical activity used to surface potential threats, not a definition of the end-to-end process. Key Concepts:
1. Privacy Threat Modeling: A core Privacy Architecture domain concept defined as a structured, proactive process to identify, assess, and mitigate privacy risks across the entire data lifecycle to protect data subject rights and meet regulatory requirements.
2. Privacy Control Weaknesses: Gaps or deficiencies in implemented privacy controls (administrative, technical, physical) that create exposure to privacy threats, which are the primary focus of mitigation activities in privacy threat modeling.
3. Inherent Privacy Risk: The level of privacy risk that exists before mitigation controls are applied, which privacy threat modeling first quantifies to prioritize appropriate mitigation actions to reach acceptable residual risk levels. References:
ISACA CDPSE Exam Content Outline, ISACA Journal: Privacy Threat Modeling: A Proactive Approach to Data Protection, https://www.isaca.org/resources/isaca-journal/issues/2022/volume-1/privacy-threat-modeling-a-proactive-approach-to-data-protection
Certified Data Privacy Solutions Engineer · Q4
Question #4
An organization is creating a personal data processing register to document actions taken with personal data. Which of the following categories should document controls relating to periods of retention for personal data?
  • A.
    Data archiving
  • B.
    Data storage
  • C.
    Data acquisition
  • D.
    Data input

Answer: A

Answer Analysis:
This question aligns with the CDPSE Data Lifecycle domain, which covers end-to-end management of personal data including retention controls required for compliance with global privacy regulations such as GDPR, CCPA, and other regional privacy frameworks. A personal data processing register, also referred to as a Record of Processing Activities (ROPA), is a mandatory compliance document that captures all attributes of personal data processing, including formal controls for how long personal data is retained. Data archiving is the specific data lifecycle stage where formal controls for retention periods are defined, implemented, and documented to ensure data is only kept for as long as necessary to fulfill the original stated processing purpose, after which it is securely disposed of or anonymized. The correct answer directly addresses the requirement to document retention-related controls in the processing register as part of privacy compliance. Option Analysis:
A. Data archiving: Correct. Data archiving processes are purpose-built to manage inactive personal data for the remainder of its required retention period, and include formal, auditable controls for retention timelines, access restrictions, and secure disposal triggers. These controls must be explicitly recorded in the personal data processing register to demonstrate compliance with privacy regulations and organizational privacy policies.
B. Data storage: Incorrect. Data storage refers to the active holding of personal data to support ongoing operational processing. While storage implementations may include security and availability controls, they do not focus on the definition or enforcement of formal retention periods, which fall outside the scope of active storage management.
C. Data acquisition: Incorrect. Data acquisition covers the collection or gathering of personal data from data subjects or third-party sources. This stage focuses on controls for consent management, purpose specification, and data minimization at the point of collection, and does not include retention period controls.
D. Data input: Incorrect. Data input refers to the process of entering collected personal data into organizational processing systems. Controls for data input focus on accuracy, completeness, and validation of data being entered, and have no relation to retention period management. Key Concepts:
1. Records of Processing Activities (ROPA): A core compliance requirement under most global privacy frameworks, ROPA (the personal data processing register referenced in the question) mandates documentation of all personal data processing attributes, including retention periods for each category of personal data processed.
2. Personal Data Retention Policy: A foundational privacy control that defines the maximum period personal data may be retained for specific processing purposes, enforced through archiving and disposal processes to uphold the core privacy principles of purpose limitation and data minimization.
3. Data Lifecycle Management: A core CDPSE domain concept that covers end-to-end management of personal data from collection to secure disposal, with specific requirements to document and enforce retention controls during the archiving stage of the lifecycle. References:
ISACA CDPSE Official Exam Domains and Preparation Resources, EU General Data Protection Regulation (GDPR) Article 30: Records of processing activities, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679#d1e2978-1-1
Certified Data Privacy Solutions Engineer · Q5
Question #5
Data collected by a third-party vendor and provided back to the organization may not be protected according to the organization’s privacy notice. Which of the following is the BEST way to address this concern?
  • A.
    Review the privacy policy.
  • B.
    Obtain independent assurance of current practices.
  • C.
    Re-assess the information security requirements.
  • D.
    Validate contract compliance.

Answer: D

Answer Analysis:
This question falls under the CDPSE Governance (Domain 1) knowledge area, specifically third-party privacy risk management. The scenario identifies a risk that a third-party vendor handling data on the organization’s behalf is not adhering to the protections outlined in the organization’s public privacy notice. The best approach to address this concern is to validate contract compliance, as legally binding vendor contracts are required to explicitly embed all privacy obligations matching the organization’s privacy notice, including data protection controls, permitted use cases, and data handling requirements. Validating compliance directly confirms whether the vendor is meeting their agreed-upon obligations, and any identified gaps can be immediately addressed through contract enforcement, mandatory remediation, or contractual penalties. This approach directly mitigates the identified risk of misalignment between vendor practices and the organization’s public privacy commitments. Option Analysis:
A. Review the privacy policy. Incorrect. The concern explicitly states the vendor’s practices may not align with the existing privacy notice, so reviewing the internal privacy policy does not address the third party’s failure to adhere to already established requirements. This activity would only be relevant if the policy itself is found to be ambiguous or incomplete, which is not the core issue in the scenario.
B. Obtain independent assurance of current practices. Incorrect. Independent assurance is a periodic, supplementary control to verify vendor practices, but it is not the primary or most direct way to address the identified concern. Assurance activities are typically performed after confirming contractual obligations are clearly defined, and do not provide the enforceable mechanism to remediate gaps that contract validation offers.
C. Re-assess the information security requirements. Incorrect. The scenario does not indicate that the organization’s existing security or privacy requirements are insufficient to meet the privacy notice commitments. Re-assessing requirements is unnecessary unless contract validation first identifies that existing contract terms do not adequately reflect privacy notice obligations, making this a secondary rather than primary action.
D. Validate contract compliance. Correct. Vendor contracts for data processing are legally enforceable documents that must include all privacy obligations aligned with the organization’s public privacy notice. Validating compliance confirms whether the vendor is following these required terms, and any deviations can be addressed immediately through contractual remedies. This directly resolves the concern of vendor practices not aligning with the organization’s privacy notice, and is a core required control for third-party privacy management per CDPSE domains. Key Concepts:
1. Third-Party Privacy Contract Management: A core CDPSE Governance domain concept requiring all vendors processing personal data on an organization’s behalf to be bound by written contracts that explicitly incorporate the organization’s privacy commitments, including those outlined in public privacy notices, to ensure consistent processing and regulatory compliance.
2. Privacy Notice Adherence: A foundational privacy principle requiring all internal and third-party processing activities involving personal data to match the disclosures made to data subjects in the organization’s public privacy notice, to meet transparency obligations and reduce compliance and reputational risk.
3. Vendor Compliance Monitoring: An ongoing CDPSE control activity focused on verifying third parties adhere to agreed-upon privacy and data protection terms, which is required to identify and remediate gaps between vendor practices and organizational privacy requirements before they result in harm or non-compliance. References:
ISACA CDPSE Exam Content Outline, ISACA Third-Party Privacy Risk Management Guidance, https://www.isaca.org/resources/isaca-journal/issues/2021/volume-3/third-party-privacy-risk-management-a-practical-approach

FAQ

How many practice questions are available for Certified Data Privacy Solutions Engineer?

This question bank includes 374 Certified Data Privacy Solutions Engineer practice questions covering single and multiple choice, each with answers and explanations.

Are Certified Data Privacy Solutions Engineer practice questions available in Chinese and English?

Yes, Certified Data Privacy Solutions Engineer practice questions are provided in both Chinese and English.

Can I try Certified Data Privacy Solutions Engineer practice questions for free?

Yes. Free sample questions are available on this page, and the full question bank is available after signing up on Zhangxuetu.