CIPP/US study guide
Use this CIPP/US study guide to learn the main U.S. privacy rules through free lessons, then test your recall with the diagnostic and practice questions. Use that published material to define coverage. Use this guide to practice recalling rules and applying them to facts.
How this CIPP/US study guide is organised
The free lessons follow the U.S. privacy environment, federal and state rules, sectoral privacy, workplace issues, civil discovery and government access. Each lesson is a study aid. The published blueprint remains the authoritative description of the exam.
Browse the free CIPP/US study guide Read the exam format and blueprint
The study method
- Map before memorising. Read the published outline and identify the relevant domain before studying detail.
- Retrieve, do not reread. Close the notes and state the entity, data, activity, jurisdiction and enforcer from memory.
- Compare overlapping rules. Practice HIPAA versus FERPA, federal versus state law, and notice duties versus private remedies.
- Use scenarios. Answer a question only after identifying the controlling facts.
- Space the return. Revisit weak topics after one day, one week and two weeks.
What to focus on first
| Priority | Study action | Proof of learning |
|---|---|---|
| Scope | Classify entities and records | You can explain why a statute applies |
| Rights and duties | Link collection, use, disclosure and security rules | You can identify the correct obligation |
| Enforcement | Separate agencies, state actors and private claims | You can reject a plausible wrong enforcer |
| Application | Complete mixed scenarios | You can reach an answer within time |
Use the guide with a plan
IAPP recommends at least 30 hours of study. Divide that time into short study and retrieval blocks. The CIPP/US study plan converts this method into a four-week schedule. Then take the practice exam to identify gaps.
Answer in brief
Use the published IAPP outline to set coverage, then use these free lessons to practice applying U.S. privacy rules to facts. Read the IAPP CIPP/US certification page.
Apply this decision
When reviewing an employer-data scenario, identify the employer, record, purpose, state and possible sectoral rule before studying the exception. Read the source context.
Common mistake
Memorising statute names without comparing scope, rights, duties and enforcement.
Related free lessons
Study U.S. privacy through legal triggers
A useful CIPP/US study guide helps you compare scope, rights, duties and enforcement across federal and state privacy rules.
Practical example
For an employment-data scenario, identify the employer, record, purpose, state and any sectoral rule before studying the exception.
Common mistake
Memorising statute names without comparing the actor, data, trigger and enforcement path that distinguish one rule from another.
Sources
Related lessons
Continue your CIPP/US preparation
Coverage checklist
Use this checklist to find gaps. Tick an area only when you can explain its main rules and apply them without notes.
0 of 5 areas checked.
Primary sources
- IAPP CIPP/US certification page and Body of Knowledge.
- IAPP guidance on preparation and the exam blueprint.
This independent guide is not legal advice and is not affiliated with IAPP.
Sources and study method
This independent study material uses the current published CIPP/US outline, active recall, spaced retrieval and scenario practice. Read the full method. Current sources. IAPP CIPP/US Body of Knowledge and Exam Blueprint, IAPP certification FAQs.
Frequently asked questions
What should I use as the source of truth for CIPP/US coverage?
Use the current IAPP CIPP/US Body of Knowledge and Exam Blueprint. IAPP says its exam is based on that document.
How much study time does IAPP suggest?
IAPP recommends a minimum of 30 hours of study time, while individual needs vary by prior experience and familiarity with U.S. privacy law.
Does this guide replace IAPP training or materials?
No. It is an independent study aid. No study resource can predict an exam result.