1. Home
  2. IAPP
  3. CIPP/A Exam

CIPP/A Exam Topics and Questions

Let's Practice Free IAPP CIPP/A Questions Aligned with Official Exam Topics

Follows IAPP's official outline Updated 11 Sep, 2026 5 Topics
Reviewed by Robert Johnson, IAPP CIPP-A Certified Professional
Topic Content

You start with the conceptual ground: what privacy means in law, how it is defined across jurisdictions, and which international instruments shape the rules you will encounter later. This topic establishes the vocabulary and the lineage of principle-based frameworks. Most candidates underestimate how often exam items turn on the precise wording of a definition or the scope of a term like "personal data" versus "personally identifiable information." The cost here is assuming that similar-sounding concepts are interchangeable. – International frameworks...

See More

The question below asks you to match a definition to the jurisdiction that uses it, testing whether you can distinguish personal data from personally identifiable information in context.

Sample Questions for Topic 1 : Privacy Fundamentals
Q1

In Hong Kong's revised Breach Guidance Note of 2015, what course of action did the Commissioner recommend that companies take immediately after experiencing a breach?

Topic Content

Singapore's Personal Data Protection Act arrived in 2012, later than many regional statutes, and it reflects both APEC principles and a pragmatic approach to commercial data flows. The PDPA applies to private-sector organisations, with significant carve-outs for public agencies and specific activities. You will spend time on definitions, exemptions, and the obligations that attach to each stage of the data lifecycle. The Do Not Call Registry and the rules around business contact information are tested more heavily than their word...

See More

The scenario that follows tests whether you can identify when business contact information falls outside the PDPA's main consent requirements and when it does not.

Sample Questions for Topic 2 : Singapore Privacy Laws and Practices
Q2

Which of the following topics was NOT addressed in India's Information Technology Act 2000 (IT Act)?

Topic Content

Hong Kong's Personal Data (Privacy) Ordinance predates Singapore's PDPA and has a different structure. The six Data Protection Principles form the core, and the 2012 amendment introduced mandatory rules for direct marketing. Exemptions are extensive, and the Office of the Privacy Commissioner operates with a combination of complaint-driven enforcement and published guidance. The PDPO applies to both public and private sectors, but the scope of the exemptions often narrows that reach in practice. You need to know the DPPs in...

See More

The item below presents a data transfer scenario and asks whether Section 33 permits the transfer or whether additional steps are required.

Topic Content

India's Digital Personal Data Protection Act arrived in 2023, replacing the data protection provisions in the Information Technology Act. The DPDPA introduces a fiduciary model, grants enumerated rights to data principals, and establishes a Data Protection Board with enforcement powers. Children's data receives special treatment, and the rules issued under the DPDPA fill in operational detail on consent, security, breach notification and cross-border transfer. Exemptions are broad, especially for state agencies and public-interest processing. You must know the structure of...

See More

The scenario below asks whether a state agency's processing falls within the public-sector exemption or whether the DPDPA's consent requirements apply.

Topic Content

This topic pulls together the jurisdictions you have studied and asks you to compare their approaches to shared issues. Sensitive data, children's data, natural versus legal persons, breach notification, public registers, surveillance, data processing, export rules, intermediaries and extraterritorial reach all appear here. The outline also covers rights of the data subject and the scope of exemptions, particularly the domestic use carve-out and the treatment of publicly available information. The examiner expects you to move between jurisdictions fluently, recognising where...

See More

The question below presents a data export scenario involving two jurisdictions and asks whether the transfer satisfies both regimes or whether additional steps are required.

Ready to Start Practicing?

Access all questions and start your exam preparation journey

Upgrade to Full CIPP/A Exam Questions πŸš€
Exams Made Simple. Success Made Possible.