CIPP/US Study Guide (2026): Free Notes, Plan & Practice
Last reviewed: · By Victor Humenhuk (CIPP/US certified, 2026)
What this guide is
This is a complete, free study guide for the IAPP CIPP/US exam. I'm Victor Humenhuk, and I passed CIPP/US in 2026 (along with CIPP/E and AIGP), building these notes as I went. Everything you need to learn the body of knowledge is on this site at no cost: 307 plain-English topic notes organized into 14 chapter hubs, a cram sheet for final review, and 22 free practice questions. The full 722-question practice bank is a one-time $29 unlock when you want testing volume, and one account works across all my IAPP prep sites.
The page you're reading is the map. It tells you how the exam works, walks through every area of the body of knowledge with links to the relevant notes, and gives you a week-by-week plan that actually fits around a job. If you want the short version of my exam-day advice instead, start with how to pass the CIPP/US.
How the CIPP/US exam works
These are the facts as published by the IAPP at the time of writing:
| Questions | 90 questions, all multiple choice, some scenario-based |
|---|---|
| Time | 2.5 hours, with a 15-minute break offered |
| Passing score | 300 on a scale of 100-500 (the IAPP is explicit that 300 does not represent 60%) |
| Scoring | No penalty for wrong answers and no section minimums - only correctly answered scored questions count |
| Delivery | Computer-based, year-round: in person at Pearson VUE test centers or online via OnVUE remote proctoring |
| Results | Immediate on screen - pass/fail plus your scaled score |
| Prerequisites | None. Anyone can register and sit the exam |
Two things people always ask about. First, the IAPP does not publish pass rates - any percentage you see quoted online is a guess. Second, some questions on the exam are unscored; the IAPP's current published materials don't state the exact scored/unscored split, so check iapp.org if you want the latest detail. Practically it changes nothing: answer every question as if it counts.
The body of knowledge, area by area
Foundations of U.S. privacy law (Chapters 1-2). Where privacy law comes from: the fair information practices, the difference between the U.S. sectoral model and comprehensive regimes, and how the three branches of government, preemption, torts and consent decrees fit together. This is the lens the whole exam looks through. Start with Chapter 1 and Chapter 2, and make sure you're solid on the sectoral model, the FIPs and federal preemption.
Technology and information management (Chapters 3-4). The exam expects working knowledge of how the internet, cookies, tracking and encryption actually function, plus how a privacy program is run: data life cycles, notices, and impact assessments. See Chapter 3 and Chapter 4; the notes on HTTP cookies, encryption and PIAs and DPIAs are frequent question territory.
Regulators and enforcement (Chapter 5). The FTC is the closest thing the U.S. has to a national privacy regulator, and the exam tests its Section 5 powers hard. Work through Chapter 5, especially FTC Section 5 and its jurisdictional limits, deceptive practices and state attorneys general and UDAP statutes.
State comprehensive privacy laws and breach notification (Chapters 6-7). California's CCPA/CPRA and the wave of state laws that followed, plus the state-by-state breach notification framework that applies in all 50 states. Covered in Chapter 6 and Chapter 7 - key notes include California as first mover, opt-out rights and the common structure of state breach laws.
Sectoral laws: medical, financial, education (Chapters 8-10). HIPAA, HITECH, GINA; FCRA, FACTA, GLBA and the CFPB; FERPA, PPRA and edtech. This is the heaviest block of the exam by volume. Hubs: Chapter 8, Chapter 9 and Chapter 10. Anchor notes: HIPAA covered entities, FCRA permissible purpose and FERPA overview.
Telecommunications and marketing (Chapter 11). TCPA, the Telemarketing Sales Rule, Do Not Call, CAN-SPAM, CPNI and the VPPA - lots of small rules with precise numbers that reward flashcard-style revision. See Chapter 11, starting with the TCPA and robocalls, the Do Not Call Registry and CAN-SPAM.
Workplace privacy (Chapter 12). Background checks, monitoring, polygraphs and the employment life cycle. Work through Chapter 12, especially FCRA and background checks, the Wiretap Act and ECPA at work and polygraphs and the EPPA.
Government access, litigation and international (Chapters 13-14). The Fourth Amendment, e-discovery, FISA and national security letters, then the GDPR and EU-U.S. data transfers. Hubs: Chapter 13 and Chapter 14. Priority notes: Fourth Amendment limits, FISA Sections 702 and 215 and Schrems and the Data Privacy Framework.
A week-by-week study plan
Five weeks at roughly an hour a day was the rhythm that worked for me. The method matters more than the calendar: for every topic note, read it once, close the page, and try to say the key terms and rules out loud from memory before checking. That active-recall loop is what makes the material stick - passive re-reading does not.
- Week 1 - Foundations and technology. Work through Chapter 1, Chapter 2 and Chapter 3. Don't rush Chapter 2: preemption and private rights of action come back in almost every later chapter.
- Week 2 - Programs, regulators and state laws. Cover Chapter 4, Chapter 5, Chapter 6 and Chapter 7. At the end of the week, take the free practice questions cold to get a baseline.
- Week 3 - The sectoral heavyweights. HIPAA, financial privacy and education: Chapter 8, Chapter 9, Chapter 10. This is the densest week; build your own one-line summaries of who each law covers and who enforces it.
- Week 4 - Marketing, workplace, government and international. Finish the syllabus with Chapter 11, Chapter 12, Chapter 13 and Chapter 14.
- Week 5 - Questions and weak spots. Drill practice questions daily in the question bank, and after every session go back to the topic notes for anything you got wrong. Finish with the cram sheet the day before the exam.
If you're already a working privacy professional, you can compress this to three or four weeks by skimming familiar chapters and spending the saved time on questions. My honest take on how long different backgrounds need is in Is the CIPP/US exam hard?
Test yourself
Reading is half the job; retrieval is the other half. The exam is 90 multiple-choice questions, some of them scenario-based, and the only way to get fast at spotting what a question is really asking is to practice on realistic ones.
- Start free: the free practice page gives you 22 questions with explanations, no account or payment needed. It's enough to gauge where you stand.
- Then go deep: the full question bank has 722 questions - topic-by-topic practice sets plus full exam-style questions - each with an explanation tied back to the study notes. It's a one-time unlock with lifetime access, not a subscription, and the same account works across my CIPP/E and AIGP sites too.
A good benchmark before booking the real thing: consistently scoring comfortably above the level the questions feel hard at - in practice, if you're getting 80%+ on fresh questions you haven't seen before, you're ready.
Frequently asked questions
Is this study guide really free? Yes. All 307 topic notes, the chapter hubs, the cram sheet and 22 practice questions are free with no account required. The only paid thing on this site is the full 722-question practice bank, which is a one-time purchase with lifetime access.
How long does it take to prepare for the CIPP/US? In my judgement, four to six weeks of consistent daily study for most people, less if you already work in U.S. privacy. I've written a fuller breakdown by background in Is the CIPP/US exam hard?
Do I need a legal background? No, and there are no prerequisites to sit the exam. The material is legal in subject matter but the exam tests recognition and application, not legal drafting. Non-lawyers pass it all the time - the notes on this site are deliberately written in plain English for exactly that reason.
What score do I need to pass? 300 on a scale of 100-500. The IAPP states this does not simply mean 60% of questions correct - raw scores are converted to the common scale across exam forms. There's no penalty for guessing, so never leave a question blank.