ISACA CDPSE Training Course

Training course

This is a free, self-paced reading course for CDPSE: Certified Data Privacy Solutions Engineer — ISACA’s credential for the people who build privacy rather than interpret it. The exam is aimed at engineers, architects, and technical leads who turn privacy law and policy into working systems, and it tests that translation directly: designing privacy into pipelines and platforms, selecting controls and privacy-enhancing technologies, governing data across its life cycle, and assessing the privacy risk of what an organization actually runs. This course is written to be read straight through, in order, before you start drilling practice questions, so that a wrong answer becomes a gap you can name rather than a fact you memorize.

The course is organized as one module per official exam domain, in the order ISACA publishes them, and each module carries the domain’s published weight. That matters more on CDPSE than on most exams, because the outline effective June 2, 2025 was a restructure rather than a refresh: ISACA moved from three domains to four, split risk management and compliance into a domain of its own, and consolidated the technical material into a single Privacy Engineering domain that now carries 39% of the exam. Weighting the reading to the blueprint means the time you spend on privacy engineering matches the time the exam spends on it. Every module ends with its key terms and suggested further reading, so the course works as a reference after the first pass as well as a syllabus during it.

CDPSE Professional level 4 modules Domain-weighted Self-paced No signup

What the course covers

Privacy Governance

Module 1 · 20%

What counts as personal information and which principles, laws, and regulations govern it, then the organizational machinery that carries them: privacy documentation, roles and responsibilities, vendor and supply-chain management, incident management, and the duties around data subject rights and breach notification. The scenario work here is controller and processor roles, consent validity, cross-border transfers, notification clocks, and DSAR judgment calls.

Privacy Risk Management and Compliance

Module 2 · 18%

The assessment discipline — privacy risk management processes and policies, privacy impact assessments, and threats and vulnerabilities read through a privacy lens rather than a security one, which is where LINDDUN does work that STRIDE does not. Also risk response, the frameworks a program is built against such as the NIST Privacy Framework and ISO 27701, the evidence and artifacts that prove the program operates, and the metrics that show whether it is working.

Data Life Cycle Management

Module 3 · 23%

Data from purpose to destruction: inventory, dataflow diagrams, and classification; data quality; use limitation and whether a secondary use — analytics and AI training among them — is compatible with the purpose the data was collected for; minimization; disclosure and transfer; storage, retention, and archiving; and defensible destruction, from media sanitization under NIST SP 800-88 to cryptographic erasure where you do not control the media in a multi-tenant cloud.

Privacy Engineering

Module 4 · 39%

The exam’s center of gravity, and the longest module here by design. Infrastructure and platform technologies from legacy systems through cloud-native; devices, endpoints, and connectivity; privacy in the SDLC and in APIs; identity and access management, hardening, encryption and hashing, and monitoring and logging; and the privacy-specific control layer — consent tagging, tracking technologies, anonymization and pseudonymization, privacy-enhancing technologies, and AI and machine learning privacy considerations from training-data memorization through federated learning.

How to use it

Read a module, then take the matching portion of the CDPSE practice exam rather than waiting until you have finished everything. CDPSE questions are scenario-shaped: they hand you a system, a data flow, or a regulatory position and ask which control or decision fits. Reading a domain and immediately testing it exposes the difference between recognizing a term and being able to place it in a design, which is the difference the exam measures. Because Privacy Engineering carries 39%, treat module 4 as the one you return to — a strong governance score cannot carry a weak technical one.

If you want a quick read on where you stand before committing to the full course, the free CDPSE sample questions are a short, no-signup pass across the blueprint. For exam logistics — question count, timing, the 200–800 scaled score and 450 pass mark, and the experience requirement — see the CDPSE certification guide.

Course not found.

Frequently asked questions about the CDPSE training course

Is the CDPSE training course free?

Yes. The course is free to read and requires no signup or account. It is funded by the same practice-exam catalog it sits alongside.

How is the course structured?

One module per official CDPSE exam domain, in ISACA’s published order, with each module weighted to the domain’s published percentage. Privacy Engineering is 39% of the exam and is the longest module here for that reason. Within each module the material is broken into short lessons, followed by key terms and further reading.

Does this replace ISACA’s official training?

No. ISACA publishes the exam content outline, a review manual, and its own review courses, and those are the authoritative sources. This course is an independent study companion — written to be read quickly and to slot alongside practice questions — not a substitute for the official outline.

Do I need experience before starting?

Nothing stops you reading the course, but the credential itself is aimed at practitioners: the certification guide lists a three-year experience expectation, and the material assumes you are already comfortable with systems, data platforms, and security controls. It teaches how privacy reshapes those things, not the things themselves.

What should I do after finishing the course?

Move to the CDPSE practice exam and work until you are clearing the pass mark across all four domains rather than by leaning on the two you already know. Then verify your experience qualifications against ISACA’s current requirements and schedule the exam.

Is the course current with the latest CDPSE outline?

The course is built against the exam content outline effective June 2, 2025 — the four-domain structure with Privacy Engineering at 39%. If other study material you are using still shows three domains, it predates this outline. ISACA can revise the outline at any time; download the current version from isaca.org before you sit the exam.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISACA. CDPSE® and ISACA® are registered trademarks of ISACA. Use of these marks is solely to identify the certification for which these study materials are intended. The CDPSE exam content outline and its domain structure are the property of ISACA; candidates should download the official, current exam content outline directly from isaca.org.

All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISACA training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, scoring, and experience policies are set by ISACA and may change; always verify current details on isaca.org before scheduling your exam.