dc dotCreds
Reference guide

ISACA CDPSE Course Notes

Study ISACA CDPSE section notes, then jump straight into the guided course or related practice questions without losing your place.

Continue CourseStart PracticePDF downloads available in Pro.
Checking access

Checking Pro access...

Looking for your active Pro access before showing Course Notes. This usually takes just a moment.

Course Notes preview

Unlock Pro for the full per-exam reference guide.

Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.

Includes full Course Mode and Course Notes.

Section 1Privacy Governance (20%)Preview
More in this section
  • 11 more key points in Pro version
  • 4 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 57 more related questions in Pro version

Summary

Privacy Governance sets direction and Privacy Operations makes it work: identify personal information and obligations, define principles/policies/roles, govern vendors, handle incidents, and operationalize data-subject rights.

Key Points

  • Privacy risk is broader than cybersecurity risk; secure processing can still create privacy harm.

Common Mistakes

  • Assuming privacy governance equals regulatory compliance only.

Exam Tips

  • Purpose first.
Section 2Privacy Risk Management and Compliance (18%)Preview
More in this section
  • 10 more key points in Pro version
  • 4 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 24 more related questions in Pro version

Summary

Risk Management asks what privacy problems processing can cause; Compliance proves obligations and controls remain effective. Think PIAs, threats/vulnerabilities, risk response, frameworks, evidence, monitoring, and metrics.

Key Points

  • Privacy risk can result from authorized processing.

Common Mistakes

  • Treating a penetration test as a privacy impact assessment.

Exam Tips

  • Privacy risk starts with processing.
Section 3Data Life Cycle Management (23%)Preview
More in this section
  • 11 more key points in Pro version
  • 4 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 32 more related questions in Pro version

Summary

Data Life Cycle Management means know the data, control its use, preserve quality, minimize it, govern analytics/AI, control transfers, retain only as justified, and destroy it appropriately.

Key Points

  • Inventory = what/where/why/who; data-flow diagram = how data moves and changes.

Common Mistakes

  • Confusing processing purpose with a technical action.

Exam Tips

  • Map before control.
Section 4Privacy Engineering (39%)Preview
More in this section
  • 15 more key points in Pro version
  • 5 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 75 more related questions in Pro version

Summary

Privacy Engineering is the technical center of CDPSE: design privacy into infrastructure, cloud, endpoints, APIs and SDLC; implement security controls; and engineer consent, tracking, de-identification, PETs, and AI/ML privacy safeguards.

Key Points

  • NIST privacy engineering objectives: Predictability, Manageability, Disassociability.

Common Mistakes

  • Treating privacy as a database-only problem.

Exam Tips

  • P-M-D is core.