ITZert stellt Ihnen die 310 Übungsfragen zur CIPP-E Prüfung in drei Formaten bereit: als druckbares PDF, als Desktop Test Engine für Windows und als Online Test Engine für alle gängigen Browser. So wählen Sie im Jahr 2026 genau die Lernform, die zu Ihrem Alltag passt.
IAPP CIPP-E Prüfungsübersicht:
| Zertifizierungsanbieter: | IAPP (International Association of Privacy Professionals) |
|---|---|
| Prüfungsname: | Prüfung zum Certified Information Privacy Professional/Europe (CIPP/E) |
| Prüfungsnummer: | CIPP/E |
| Anzahl der Fragen: | 90 |
| Mindestpunktzahl: | 300 (skalierte Punktzahl auf einer Skala von 100–500) |
| Verwandte Zertifizierungen: | CIPP/C CIPM CIPP/US CIPT |
| Prüfungsdauer: | 150 Minuten |
| Prüfungsgebühr: | USD 550 (Standardpreis, kann je nach Region und Mitgliedschaft variieren) |
| Verfügbare Sprachen: | Englisch |
| Prüfungsformat: | Szenariobasierte Fragen, Multiple-Choice-Fragen |
| Gültigkeitsdauer des Zertifikats: | 2 Jahre (Verlängerung durch Fortbildungspunkte im Bereich Datenschutz erforderlich) |
| Empfohlenes Training: | Lernmaterialien zur CIPP/E Offizielle Schulungen von IAPP |
| Prüfungsanmeldung: | Zertifizierungsseite von IAPP für die CIPP/E Prüfungsanmeldung bei Pearson VUE |
| Beispielfragen: | ![]() |
| Prüfungsmethode: | Durchgeführt in Testzentren von Pearson VUE sowie als online überwachte Prüfung. |
| Voraussetzungen: | Es gibt keine formellen Zulassungsvoraussetzungen; Vorkenntnisse im Bereich Datenschutz und Datenschutzkonzepte werden empfohlen. |
| Offizielle Syllabus-URL: | https://iapp.org/certify/cippe/ |
IAPP CIPP-E Prüfungsthemen:
| Abschnitt | Ziele |
|---|---|
| Thema 1: Grundlagen des EU-Datenschutzes | - Kernprinzipien der GDPR
|
| Thema 2: Datenschutzmanagement | - Rechenschaftspflicht und Maßnahmen zur Einhaltung der Vorschriften - Rollen und Verantwortlichkeiten
|
| Thema 3: Internationale Datenübermittlungen und Durchsetzung | - Aufsichtsbehörden und Durchsetzungsmaßnahmen - Mechanismen für grenzüberschreitende Datenübermittlungen
|
| Thema 4: Rechte der betroffenen Personen und Einhaltung der Vorschriften | - Meldepflicht bei Verletzungen des Schutzes personenbezogener Daten - Rechte der betroffenen Personen
|
| Thema 5: Regulatorischer Rahmen | - Datenschutz-Grundverordnung (GDPR)
|
Alles Wissenswerte zur IAPP-Prüfung CIPP-E – FAQ
Die CIPP-E Prüfung ist die offizielle Prüfung von IAPP für die Zertifizierung „Certified Information Privacy Professional/Europe (CIPP/E)" auf der Stufe Berufsebene. Sie steht zudem in Verbindung mit folgenden Zertifizierungen: CIPP/US, CIPP/C, CIPM, CIPT. Wer diese Prüfung ablegt, weist fundierte Kenntnisse im Themenfeld der IAPP Certified Information Privacy Professional/Europe (CIPP/E) nach. Mit den 310 Übungsfragen von ITZert bereiten Sie sich gezielt auf Inhalte und Fragetypen der Prüfung vor.
In der CIPP-E Prüfung bearbeiten Sie 90 Fragen innerhalb von 150 Minuten. Rechnet man das grob auf die einzelne Frage herunter, wird klar, warum ein festes Zeittempo entscheidend ist: Lassen Sie sich bei schwierigen Fragen nicht festbeißen, markieren Sie diese und kehren Sie am Ende zu ihnen zurück. Trainieren Sie dieses Zeitmanagement vorab mit dem Test Engine von ITZert im Zeitmodus, damit Sie am Prüfungstag nicht unter Druck geraten.
Zum Bestehen der CIPP-E Prüfung benötigen Sie 300 (skalierte Punktzahl auf einer Skala von 100–500); die offizielle Prüfungsgebühr liegt bei USD 550 (Standardpreis, kann je nach Region und Mitgliedschaft variieren). Bedenken Sie: Jeder Wiederholungsversuch muss erneut vollständig bezahlt werden. Buchen Sie Ihren Termin daher erst, wenn Sie die Übungstests von ITZert mehrfach in Folge sicher bestanden haben – so vermeiden Sie unnötige Kosten für einen zweiten Anlauf.
Es gibt keine formellen Zulassungsvoraussetzungen; Vorkenntnisse im Bereich Datenschutz und Datenschutzkonzepte werden empfohlen.
Da sich Zulassungsbedingungen ändern können, bestätigen Sie die aktuellen Angaben bitte zusätzlich auf der offiziellen Seite von IAPP.
Die Anmeldung zur CIPP-E Prüfung erfolgt über folgende offizielle Kanäle:
Die Prüfung selbst wird auf folgende Weise abgelegt: Durchgeführt in Testzentren von Pearson VUE sowie als online überwachte Prüfung..
Zur Vorbereitung auf die CIPP-E Prüfung empfiehlt IAPP offiziell folgende Trainings:
Als praktische Ergänzung zu diesen Kursen finden Sie bei ITZert 310 prüfungsnahe Übungsfragen, mit denen Sie das Gelernte unter realistischen Bedingungen anwenden und Ihren Wissensstand überprüfen.
Ja. Für die CIPP-E Unterlagen steht eine kostenlose PDF-Demo zum Herunterladen bereit – so prüfen Sie Qualität und Aufbau der Fragen in Ruhe, bevor Sie kaufen. Nach dem Kauf erhalten Sie außerdem 365 Tage lang kostenlose Updates; läuft dieser Zeitraum ab, verlängern Sie den Update-Service mit 50 % Rabatt.
Falls Sie die zugehörige Prüfung innerhalb von 60 Tagen nach dem Kauf nicht bestehen, können Sie eine vollständige Rückerstattung beantragen. Voraussetzungen: Der Name des Prüfungsteilnehmers muss mit dem Namen des Zahlers übereinstimmen, und Sie reichen innerhalb von 2 Tagen nach dem Prüfungstermin eine eingescannte Anmeldebestätigung (Enrollment Slip) sowie das offizielle Score Report als PDF ein – die Bearbeitung erfolgt innerhalb von 7 Tagen. Nicht erstattungsfähig sind Prüfungen, die innerhalb von 3 Tagen nach dem Kauf abgelegt wurden, lediglich heruntergeladene, aber nicht angetretene Prüfungen sowie kostenlose Materialien und abgelaufene Bestellungen.
Alternativ zur Rückerstattung können Sie einen Produktwechsel wählen: Sie erhalten kostenlos zwei gleichwertige Prüfungsunterlagen Ihrer Wahl und behalten den Update-Service für das ursprünglich gekaufte Produkt.
Die Lieferung erfolgt digital: Der Download steht sofort nach der Zahlung bereit, die Liefer-E-Mail erreicht Sie in der Regel innerhalb einer Minute. Sollten Sie nach 2 Stunden nichts erhalten haben, wenden Sie sich bitte an unseren Kundenservice. Eine Begrenzung der Installationen gibt es nicht – Sie nutzen die Software auf beliebig vielen Computern.
Die CIPP-E Prüfung gliedert sich in 5 Themenbereiche. Zu den wichtigsten zählen:
- Regulatorischer Rahmen
- Grundlagen des EU-Datenschutzes
- Internationale Datenübermittlungen und Durchsetzung
Die vollständige Aufstellung aller Bereiche samt Gewichtung finden Sie in der Prüfungsübersicht weiter oben auf dieser Seite.
IAPP Certified Information Privacy Professional/Europe (CIPP/E) CIPP-E Prüfungsfragen mit Lösungen
Which GDPR principle would a Spanish employer most likely depend upon to annually send the personal data of its employees to the national tax authority?
- A. The protection of the vital interest of the employees.
- B. The consent of the employees.
- C. The legitimate interest of the public administration.
- D. The legal obligation of the employer.
Antwort: D 🗳️
Erklärung: (Nur für ITZert-Mitglieder sichtbar)
SCENARIO
Please use the following to answer the next question:
Dynaroux Fashion ('Dynaroux') is a successful international online clothing retailer that employs approximately 650 people at its headquarters based in Dublin, Ireland. Ronan is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jonas, the CEO, tells Ronan that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Ronan tells the CEO that: (a) the potential risks of such activities means that Dynaroux needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Dynaroux may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jonas tells Ronan that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Dynaroux's business plan and associated processing activities.
Which of the following facts about Dynaroux would trigger a data protection impact assessment under the GDPR?
- A. The company employs approximately 650 people and will therefore be carrying out extensive processing activities.
- B. The company will be undertaking processing activities involving sensitive data categories such as financial and children's data.
- C. The company intends to shift their business model to rely more heavily on online shopping.
- D. The company plans to undertake profiling of its customers through analysis of their purchasing patterns.
Antwort: D 🗳️
Erklärung: (Nur für ITZert-Mitglieder sichtbar)
SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA. Today, it is a multi-billion- dollar candy company operating in every continent. All of the company's IT servers are located in Vermont.
This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone' s information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
The data transfer mechanism that Alice drafted violates the GDPR because the company did not first get approval from?
- A. The Data Protection Authority.
- B. The European Commission.
- C. The European Data Protection Board.
- D. The Court of Justice of the European Union.
Antwort: A 🗳️
Erklärung: (Nur für ITZert-Mitglieder sichtbar)
When does the European Data Protection Board (EDPB) recommend reevaluating whether a transfer tool is effectively providing a level of personal data protection that is in compliance with the European Union (EU) level?
- A. Every year.
- B. Every three (3) years.
- C. After a personal data breach.
- D. On an ongoing basis.
Antwort: D 🗳️
Erklärung: (Nur für ITZert-Mitglieder sichtbar)
Through a combination of hardware failure and human error, the decryption key for a bank's customer account transaction database has been lost. An investigation has determined that this was not the result of hacking or malfeasance, simply an unfortunate combination of circumstances. Which of the following accurately indicates the nature of this incident?
- A. A data breach has occurred because the loss of the key has resulted in the loss of confidentiality or integrity of the data.
- B. A data breach has not occurred because no data was exposed to any unauthorized individual.
- C. A data breach has not occurred because the loss was not the result of hacking.
- D. A data breach has occurred because the loss of the key has resulted in the data no longer being accessible.
Antwort: A 🗳️
Erklärung: (Nur für ITZert-Mitglieder sichtbar)




921 Kundenrezensionen


Käthe -
Ich habe heute meine CIPP-E Prüfung bestanden. Vielen Dank für ihre Anstrengungen. Ich bin sehr fröhlich, dass ich die Studienführung aus ITZert gekauft habe, denn sie ist ziemlich einfach zu verstehen. Vielen Dank.