CDPSE cheat sheet
A one-page reference for the ISACA CDPSE — Certified Data Privacy Solutions Engineer exam: the format, how the domains are weighted, and the glossary terms for this exam.
Exam at a glance
Vendor
ISACA
Level
Advanced
Questions
80
Time
150 min
Mock pass mark
70%
Domains
4
Practice Qs
147
Code
CDPSE
Domain weightings
How much of the exam each domain covers. Spend your study time in proportion — the heavier the domain, the more questions you'll see.
Key terms
- Privacy by Design
- Privacy by Design is the practice of embedding privacy protections into systems and processes from the outset rather than adding them later. CDPSE treats it, with privacy by default, as the core engineering principle of the credential.
- Privacy by Default
- Privacy by Default means the most privacy-protective settings apply automatically without the user having to act. CDPSE pairs it with privacy by design so systems minimize data use out of the box.
- Privacy Engineering
- Privacy Engineering is the discipline of building technical privacy controls into architecture, applications, and infrastructure. CDPSE's largest domain covers implementing privacy requirements in real systems.
- PETs
- Privacy-Enhancing Technologies (PETs) are techniques — such as encryption, differential privacy, and secure multiparty computation — that protect personal data while it is used. CDPSE covers applying PETs to enforce privacy in engineering.
- Personal Data
- Personal Data is any information relating to an identified or identifiable individual, the asset that privacy programs exist to protect. CDPSE frames governance, risk, and engineering decisions around how personal data is handled.
- PII
- Personally Identifiable Information (PII) is data that can identify a specific person on its own or combined with other data. CDPSE uses PII identification to scope privacy controls across the data lifecycle.
- Data Classification
- Data Classification labels data by sensitivity so that proportionate privacy and security controls can be applied. CDPSE uses classification as the basis for lifecycle handling, retention, and protection of personal data.
- Data Inventory
- A Data Inventory (data map) records what personal data an organization holds, where it flows, and who processes it. CDPSE uses data inventories and flow diagrams to understand and control the data lifecycle.
- Data Minimization
- Data Minimization is the principle of collecting and retaining only the personal data necessary for a stated purpose. CDPSE applies it across collection, use, and retention to reduce privacy risk.
- De-identification
- De-identification removes or obscures identifying elements to reduce the link between data and an individual. CDPSE covers it as a key data-lifecycle privacy control, distinguishing irreversible anonymization from reversible pseudonymization (which remains personal data).
- Anonymization
- Anonymization irreversibly transforms data so an individual can no longer be identified, taking it outside most privacy regulations. CDPSE contrasts it with pseudonymization, which is reversible with additional information.
- Pseudonymization
- Pseudonymization replaces identifying fields with pseudonyms so data can be re-identified only with separately held information. CDPSE treats it as a reversible privacy control that still leaves data as personal data.
- DPIA
- A Data Protection Impact Assessment (DPIA), also called a privacy impact assessment, evaluates the privacy risks of a processing activity before it begins. CDPSE uses DPIAs to identify and treat privacy risk in the risk-management domain.
- Privacy Risk
- Privacy Risk is the potential for harm to individuals or the organization from improper handling of personal data. CDPSE covers identifying, treating, monitoring, and reporting privacy risk alongside compliance.
- Consent Management
- Consent Management is the process and tooling for capturing, honoring, and revoking individuals' permissions for data processing. CDPSE covers it as a technical privacy control in the engineering domain.