CDPSE · ● Active · Professional · ISACA
Exam facts
| Field | Value |
|---|---|
| Cost | USD $575 (ISACA member) / $760 (non-member); $50 application fee upon certification |
| Duration | 3.5 hours (210 minutes) |
| Questions | 120 multiple choice |
| Passing | 450 / 800 scaled score |
| Format | Multiple choice |
| Delivery | Pearson VUE testing centers and OnVUE (remote proctored) |
| Languages | English, Chinese Simplified, Chinese Traditional, Japanese, Korean, Spanish |
| Valid | 3 years |
| Renewal | Continuing Professional Education (CPE) credits; annual maintenance fee $45 (member) / $85 (non-member) |
| Prerequisites | 3 years cumulative experience in technical privacy by design implementation, control, or security work within the past 10 years. Experience must span at least two CDPSE job practice domains. No waivers or substitutions; early exam allowed but certification withheld until experience requirement met. |
| Released | 2021 |
| Retiring | N/A |
Vendor source — ISACA CDPSE Credentialing ↗ Official exam guide — CDPSE Get Certified ↗ Exam objectives — CDPSE Exam Content Outline ↗
About
The Certified Data Privacy Solutions Engineer (CDPSE) is ISACA's professional-level certification for technical privacy professionals who design, build, and operate privacy-enhancing systems. Launched in 2021, CDPSE validates the ability to implement privacy controls, design privacy-by-design architectures, manage data throughout its lifecycle with privacy safeguards, and address regulatory compliance through technical solutions. Unlike privacy management certifications (CIPP/E, CIPM) that focus on policy and compliance strategy, CDPSE emphasizes technical implementation — including privacy-enhancing technologies (PETs), encryption, anonymization, consent management systems, and identity/access controls. CDPSE holders typically work as Privacy Engineers, Privacy Solutions Architects, Privacy Technology Leaders, and Chief Privacy Officers with engineering focus in regulated industries (finance, healthcare, tech, manufacturing).
Domain context — Privacy / Engineering
Technical privacy implementation and architecture — designing systems with privacy by design, implementing privacy-enhancing technologies, managing data lifecycles with privacy controls, and ensuring regulatory compliance (GDPR, CCPA, PIPL, LGPD) through technical solutions.
Read full deep dive — ISACA Ecosystem →
Topics covered
CDPSE covers three job practice domains, weighted by exam emphasis (total 120 questions):
- Privacy Governance (34%) — Privacy laws and standards (GDPR, CCPA, PIPL, LGPD), privacy policies and procedures, privacy risk management, data classification, privacy program development, governance frameworks, privacy impact assessments.
- Privacy Architecture (36%) — Technical privacy by design principles, privacy-enhancing technologies (PETs), data flow mapping, data minimization strategies, anonymization and pseudonymization techniques, encryption and key management, consent management systems, identity and access management for privacy, enterprise privacy architecture design.
- Data Lifecycle (30%) — Data collection, processing, use, retention, and deletion controls, third-party data management and vendor risk, data subject rights fulfillment (technical implementation), data breach response and incident management (technical), cross-border data transfer mechanisms (technical implementation of Standard Contractual Clauses, Binding Corporate Rules).
Source: ISACA CDPSE Exam Content Outline ↗
Common skills at Privacy / Engineering · Professional
Shared competencies for privacy engineering and technical privacy roles at professional level — not specific to CDPSE.
- Privacy by design (PbD) principles and SDLC integration
- Privacy-enhancing technologies (PETs): differential privacy, homomorphic encryption, secure multi-party computation
- Data classification and sensitivity labeling
- Encryption and key management (symmetric, asymmetric, key rotation)
- Anonymization and pseudonymization techniques (k-anonymity, l-diversity, t-closeness)
- Identity and access management (IAM) with privacy focus
- Data minimization and purpose limitation implementation
- Consent management systems (CMS) and preference management
- Cross-border data transfer mechanisms (SCCs, BCRs, Standard Contractual Clauses)
- Privacy impact assessments (PIA) and data protection impact assessments (DPIA)
- Regulatory compliance architecture (GDPR, CCPA, PIPL, LGPD technical requirements)
- Data breach response and incident management (technical controls)
- Privacy audit and control evaluation
Recommended courses at Privacy / Engineering · Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISACA Official | CDPSE Online Review Course | $600–$800 (member) / $900–$1,100 (non-member) | ↗ |
| InfoSecTrain | CDPSE Certification Training | $150–$300 | ↗ |
| Learning Tree | CDPSE Training Course | $200–$400 | ↗ |
| CBT Nuggets | CDPSE Certification Course | $300–$600/yr | ↗ |
| Pluralsight | Privacy Engineering Path | $300–$500/yr | ↗ |
| Udemy | CDPSE Exam Prep Courses (Multiple instructors) | $15–$100 | ↗ |
| Data Privacy Academy | CDPSE by ISACA | $200–$500 | ↗ |
Course-selection rule: CDPSE courses must emphasize technical privacy implementation, privacy-enhancing technologies, and regulatory compliance mechanisms (GDPR SCCs, CCPA technical requirements, PIPL technical controls) — avoid policy-only or management-focused content.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISACA Official | CDPSE Practice Questions (QAE) | $100–$150 (1,000+ questions) | ↗ |
| Infosec Institute | CDPSE Practice Exam Bank | $50–$100 | ↗ |
| Whizlabs | CDPSE Practice Exams | $50–$80 | ↗ |
| Udemy | CDPSE Practice Exam Questions (Multiple instructors) | $15–$100 | ↗ |
Practice rule: The ISACA Official Questions and Explanations (QAE) database is the most accurate predictor of exam performance and should be prioritized for final review.
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| CDPSE Certified Data Privacy Solutions Engineer Study Guide | Multiple authors | ISACA | 2024 | — | ↗ |
| Data Privacy Engineering: Designing Privacy Protection in Enterprise Systems | Demchenko, Amulyam, Ferretti | Springer | 2023 | 978-3031285936 | ↗ |
| Privacy by Design: A Practical Guide | Cavoukian, Borrett | Privacy by Design | 2018 | — | ↗ |
| GDPR Compliance by Design | Blume | Springer | 2022 | 978-3662652220 | ↗ |
Book rule: ISACA's official CDPSE study materials are the canonical reference. Supplement with privacy engineering texts that emphasize technical implementation over policy/compliance management.
Typical job titles at Privacy / Engineering · Professional
Privacy Engineer · Privacy Solutions Architect · Privacy Technology Lead · Chief Privacy Officer (technical focus) · Solutions Engineer (Privacy) · DPO Technical Advisor · Data Privacy Architect · Security Engineer (Privacy focus) · Privacy Compliance Engineer · Privacy Program Manager (technical)
(Job titles drawn from current job-board postings that list CDPSE as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $105,000 – $165,000+ for Privacy Engineer / Solutions Architect roles; average $129,716–$150,000+ | ZipRecruiter ↗ · PayScale ↗ · InfoSec Institute ↗ |
| ZAR | R420,000 – R750,000+ annually (Privacy Engineer / Solutions Architect roles in South Africa) | Pnet ↗ · CareerJunction ↗ |
| GBP | £65,000 – £100,000+ for Privacy Engineer / Solutions Architect roles in UK | IT Jobs Watch ↗ · Hays ↗ |
| EUR | €74,000 – €115,000+ (Germany/Netherlands Privacy Engineering & Architecture roles) | LinkedIn Salary EU ↗ · PayScale EU ↗ |
| AUD | A$135,000 – A$202,000+ for Privacy Engineer / Architect roles in Australia | Seek ↗ · PayScale AU ↗ |
Salary note: CDPSE compensation is role and experience-dependent; junior Privacy Engineers start lower, while Solutions Architects and Privacy Technology Leads (especially in tech, finance, and healthcare) command premium salaries. Roles in regulated industries (finance, healthcare, pharmaceuticals) and tech sector (Google, Meta, Apple) typically offer higher compensation than other sectors.
Skills validated
- Technical Privacy Architecture — Design privacy-preserving systems, implement privacy by design, evaluate technical privacy controls
- Privacy-Enhancing Technologies (PETs) — Understand and implement encryption, anonymization, differential privacy, secure multiparty computation
- Regulatory Compliance Implementation — Translate GDPR, CCPA, PIPL, LGPD requirements into technical solutions and controls
- Data Lifecycle Management — Implement technical controls across data collection, processing, storage, sharing, and deletion phases
- Consent & Preference Management — Design and implement consent capture and preference management systems
- Identity & Access Management (Privacy Focus) — Control data access with privacy-preserving principles
- Privacy Impact Assessment (PIA/DPIA) — Assess privacy risks and recommend technical mitigations
- Third-Party Risk Management — Evaluate and manage privacy risks from vendors, processors, and data sharing partners
- Data Breach & Incident Response — Respond to privacy incidents with technical remediation and evidence preservation
- Cross-Border Data Transfer — Implement Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and other transfer mechanisms
Key study areas
Privacy Governance Focus
- Privacy laws: GDPR Articles 32–34 (technical and organizational measures), CCPA Section 1798.100+ (consumer rights technical implementation), PIPL Articles 37–38 (security measures), LGPD Articles 46–50 (technical safeguards)
- Privacy program maturity models and risk management frameworks
- Privacy policies and procedures (technical controls section)
- Privacy impact assessments (DPIA) — identifying privacy risks and selecting controls
Privacy Architecture Focus
- Privacy by design (PbD) principles: data minimization, purpose limitation, storage limitation, integrity and confidentiality
- Privacy-enhancing technologies: encryption (end-to-end, field-level), tokenization, masking, differential privacy, secure multiparty computation, homomorphic encryption
- Identity and access management (IAM) with privacy controls: role-based access control (RBAC), attribute-based access control (ABAC), just-in-time provisioning, zero-trust architecture
- Data flow mapping and privacy data discovery
- Consent and preference management systems (CMS): cookie consent, preference centers, marketing preference management
- Privacy-focused API design and microservices architecture
- Privacy controls in cloud, hybrid, and on-premises environments
Data Lifecycle Management Focus
- Data collection: minimization, consent capture, purpose specification, collection limitation
- Data processing and use: purpose limitation, legitimate interest assessment, lawful basis documentation
- Data retention: retention policies, data aging, deletion triggers, archive strategies
- Data sharing and transfers: processors, third parties, cross-border transfer mechanisms (SCCs, BCRs), data subject rights fulfillment (access, deletion, portability — technical implementation)
- Data subject rights: right to access (data exports), right to deletion (technical erasure), right to data portability (technical export formats)
- Data breach response: incident detection, evidence preservation, notification workflow, remediation
Prerequisite validation
Before sitting the CDPSE exam, ensure you have documented:
- 3 years of cumulative experience in technical privacy implementation, control, or security work (within the past 10 years)
- Experience spanning at least 2 of the 3 job practice domains:
- Privacy Governance implementation
- Privacy Architecture design or review
- Data Lifecycle management with privacy controls
- No experience substitutions or waivers (unlike CISA, CISM, CRISC which allow degree/cert substitutions)
You may sit the exam before completing 3 years; however, certification is withheld until experience is documented and verified.
Related ISACA certifications
- CISA (Certified Information Systems Auditor) — IT audit, control, and governance; complements CDPSE with audit and risk assessment skills
- CISM (Certified Information Security Manager) — Information security management and governance; overlaps on risk management and compliance
- CRISC (Certified in Risk and Information Systems Control) — Risk assessment and control design; covers broader IT risk (CDPSE focuses on privacy-specific technical controls)
Next steps
- Verify your experience — Document 3+ years in technical privacy roles across 2+ CDPSE domains
- Select study materials — Use ISACA official review course + practice exams
- Schedule exam — Register via ISACA at Pearson VUE (in-center or OnVUE remote)
- Maintain certification — Renew every 3 years via CPE credits or recertification exam
- Explore specializations — Combine with CISA/CISM for broader GRC expertise, or pursue vendor-specific privacy certifications (AWS Privacy, Google Cloud Privacy, Azure Privacy)
Last verified: 2026-05-02 via ISACA official sources and current job market data.