EXIN PDPP privacy and data protection professional exam banner showing that accredited training is mandatory before certification

EXIN PDPP Certification: The Exam You Cannot Simply Book

Most exam guides start with the booking page. For this one, start with the fact that there is no booking page you can reach on your own.

EXIN Privacy and Data Protection Professional, exam code PDPP, cannot be sat by a candidate who has simply read the syllabus and paid a fee. EXIN requires accredited training and the successful completion of a set of Practical Assignments before the credential can be awarded, which puts a gate in front of the exam that no amount of self-study clears. Once past it, the paper itself is 40 multiple choice questions in 120 minutes at a 65 percent pass mark, spread across five weighted domains in which a privacy information management system and a data protection impact assessment together account for 60 percent of everything asked.

Can You Self-Study for the EXIN PDPP Exam?

No. EXIN lists training as mandatory for PDPP and states the requirement for certification as accredited Privacy and Data Protection Professional training including successful completion of the Practical Assignments. A candidate cannot read the syllabus, book a slot and be certified. This separates PDPP from most privacy credentials, where training is recommended and optional.

The PDPP route: accredited training, practical tasks, a 40 question exam and the certificate at 65 percent

The Practical Assignments matter as much as the wording implies. They are assessed work carried out during the accredited course, not a warm-up quiz, and they sit alongside the exam rather than inside it. Passing the 40 question paper without completing them does not produce a certificate. That has two practical consequences: the real cost of the credential is the course plus the exam rather than the exam alone, and the timeline is set by the training provider’s calendar rather than by how quickly you can revise.

EXIN publishes the requirement plainly on its own PDPP certification page, and its general route to certification explains how the accredited path works across its portfolio. It is worth reading both before spending anything, because the sequence is training first, assignments second, exam third.

What this changes about preparation

If the course is compulsory, the question is not how to learn the material from scratch but how to arrive at the course already fluent in the parts it will move through quickly. The syllabus weightings answer that. Two domains carry most of the paper, and both are conceptual rather than procedural, so they reward reading done in advance far more than the lighter domains do.

What Are the EXIN PDPP Exam Details?

PDPP is 40 multiple choice questions in 120 minutes with a 65 percent pass mark, listed at 342 US dollars. EXIN classifies it as an advanced-level certification, worth four ECTS credits, delivered closed book with no electronic equipment permitted, and available in English, Portuguese and Chinese.

FieldValue
Exam nameEXIN Privacy and Data Protection Professional
Exam codePDPP
Questions40, multiple choice
Duration120 minutes
Passing score65%
Price$342 USD
LevelAdvanced
ECTS credits4
Open bookNo
TrainingMandatory, including Practical Assignments
LanguagesEnglish, Portuguese, Chinese
Published domains5, weighted, totalling 100%

Work the arithmetic before you work the syllabus. A 65 percent threshold on 40 questions means 26 correct answers, so 14 wrong is the whole allowance. That is a genuinely generous margin by certification standards, and it tells you something useful: EXIN is not trying to catch you out on obscure recall. The difficulty sits in applying the regulation to a described situation rather than in the pass mark.

Three minutes per question is also unusually relaxed for a 40 item paper. The time is there because several items give you a scenario and ask which of four responses is correct under the regulation, and reading the scenario properly takes longer than answering it. Calibrating against questions written in that shape is more useful than re-reading the objectives, which is what working through a set of PDPP sample questions is for.

How Are the Five PDPP Domains Weighted?

The privacy information management system carries 32.5 percent and the data protection impact assessment 27.5 percent, so those two domains alone are 60 percent of the paper. Roles of the controller, processor and DPO take 17.5 percent, breaches and notification 12.5 percent, and data protection policies just 10 percent.

DomainWeightSub-objectives and their weights
Privacy information management system (PIMS)32.5%PIMS basics 12.5%, benefits of a PIMS 10%, PIMS relationships 10%
Data protection impact assessment (DPIA)27.5%Criteria for a DPIA 15%, steps of a DPIA 12.5%
Roles of the controller, processor, and data protection officer (DPO)17.5%Roles of the controller and processor 10%, role and responsibilities of a DPO 7.5%
Data breaches, notification, and incident response12.5%GDPR requirements regarding personal data breaches 2.5%, requirements for notification 10%
Data protection policies10%Purpose of policies within an organization 5%, data protection by design and by default 5%

The distribution is lopsided in a way that is easy to misread. Data protection policies sounds like the foundational domain and is the one candidates expect to matter most, yet it is the smallest on the paper at 10 percent, split into two equal halves of 5 percent each. Meanwhile the single largest sub-objective anywhere on the blueprint is “criteria for a DPIA” at 15 percent, which is larger than the entire policies domain.

Read the weights as a statement about what EXIN thinks an advanced privacy professional does. Writing a policy is not it. Standing up and running a management system, and deciding when an assessment is legally required and then conducting it, are.

Why Does a Privacy Information Management System Take a Third of the Paper?

Because PDPP is built around ISO/IEC 27701 rather than around the regulation alone. The PIMS domain is 32.5 percent and its three sub-objectives cover the standard’s vocabulary, the case for implementing one, and how it relates to an information security management system. Candidates who prepare only from the GDPR text find this domain unfamiliar.

PIMS or ISMS comparison showing privacy of personal data built on 27701 against security of information built on 27001

The syllabus is specific about the terminology it expects. Internal and external issues, interested parties, the statement of applicability, the purpose of documentation, and the purpose of management reviews are all named individually. Anyone who has worked with an ISO management system will recognise every one of those as standard clause language; anyone who has not will need to learn it as vocabulary before it can be applied.

PIMS against ISMS, which the exam asks about directly

One sub-objective requires you to explain the difference between a privacy information management system and an information security management system, and another asks how the data protection principle of appropriate security arrangements relates to the standard. These are not throwaway comparison questions. The ISO/IEC 27701 standard is written as an extension to the security management standard rather than as a free-standing scheme, and the exam expects you to be able to say why that design decision was made.

The remaining PIMS content is practical governance: the objective of audits, how to determine what a management system must satisfy given local rules and contractual obligations, how the system and its audits demonstrate compliance, and how it helps in selecting suppliers. That last point is worth flagging because supplier selection is where privacy governance most often meets commercial reality, and it is explicitly examinable.

What Does PDPP Expect You to Know About a DPIA?

Two things, weighted separately. Criteria for a data protection impact assessment is 15 percent and covers when one is legally required and what it is meant to produce. Steps of a DPIA is 12.5 percent and requires you to describe the process and then actually perform one against a described situation.

The split is the useful signal. EXIN has decided that knowing when an assessment is triggered is worth more marks than knowing how to run one, which inverts how most people study the topic. Candidates tend to memorise a process diagram and then guess at the trigger conditions. The blueprint rewards the opposite.

The performance verb in the second sub-objective is “perform a DPIA in specific situations”, not “describe” or “list”. That phrasing carries through to the questions: expect to be handed a processing activity and asked what the assessment should conclude, rather than asked to name step four. A regulator’s own DPIA guidance is the closest thing to a worked model of that reasoning, and reading one before the course starts makes the objective concrete rather than abstract.

How Deep Does the Exam Go on Controller, Processor and DPO Roles?

Deeper than the definitions. The roles domain is 17.5 percent, split 10 percent for controller and processor and 7.5 percent for the data protection officer. The syllabus verb for the first two is “enact” their responsibilities, and for the relationship between them it asks you to explain how it works in a specific situation.

“Enact” is doing a lot of work in that sentence. It is not asking you to recite which party is which. It is asking what each one is obliged to do when something happens, and how the obligation shifts when a controller has engaged a processor. Most real disputes in data protection are exactly this question, which is presumably why it carries the larger share.

The DPO material is narrower than expected

Three objectives cover the DPO at 7.5 percent: when appointment is mandatory under the regulation, what the role does in practice, and how the DPO sits in relation to the supervisory authority. That last one is the least intuitive and the easiest to get wrong, because the DPO is simultaneously an employee of the organisation and its point of contact with the regulator, and the independence that follows from that is a defined property rather than a matter of good practice.

EXIN names the audience for this credential precisely, and the list explains the emphasis: data protection officers, privacy officers, legal and compliance officers, security officers, business continuity managers, data controllers, internal and external data protection auditors, and HR managers. Half of those roles sit on the controller side and half on the assurance side, so the exam has to test the relationship rather than one perspective on it.

What Does the Breach Notification Domain Actually Ask For?

Almost entirely notification, not detection. The domain is 12.5 percent overall, but the split inside it is 2.5 percent for assessing whether a breach has occurred under the regulation and 10 percent for the notification requirements that follow. Four times as many marks sit on what you do afterwards.

That 2.5 percent is the smallest weighting anywhere on the blueprint, which is a deliberate statement. Deciding whether an incident meets the regulatory definition of a personal data breach is treated as a single judgement you either can or cannot make. Everything else in the domain is procedural: notifying the supervisory authority, notifying the data subject, and describing the elements of the documentation obligation.

The documentation obligation is the part candidates most often skip, because it feels administrative next to the notification deadlines. It is examinable in its own right, and it is the mechanism by which an organisation demonstrates it handled a breach correctly even where no notification was required at all.

Should You Take Privacy and Data Protection Foundation First?

EXIN advises it rather than requires it. The official position is that because PDPP is an advanced-level certification, it is advisable to have passed EXIN Privacy and Data Protection Foundation beforehand. It is not listed among the certification requirements, so a candidate can go straight to the professional level if the accredited training provider accepts them.

Whether that is sensible depends on where your existing knowledge sits. Someone who already works to an ISO management system and has run an assessment will find the professional syllabus builds on familiar ground. Someone whose privacy knowledge is entirely regulatory, learned from reading the legislation, will hit the PIMS domain cold, and that domain is a third of the paper.

A more reliable self-test than the credential ladder: can you explain, without looking it up, what a statement of applicability is and why a privacy management system needs one? If not, the foundation level is the cheaper way to find that out. Our earlier guide to the PDPP exam covers the credential’s positioning in more detail.

How Should You Prepare for the PDPP Exam?

Work backwards from the weights, and do the reading before the mandatory course rather than after it. Six steps cover the ground in the order the blueprint rewards, and the first two alone address 60 percent of the questions.

  1. Learn the ISO/IEC 27701 vocabulary first, specifically internal and external issues, interested parties, the statement of applicability, documentation and management reviews, because the PIMS domain is 32.5 percent and every one of those terms is named in the objectives.
  2. Study DPIA trigger criteria before DPIA process, since the criteria sub-objective is 15 percent against 12.5 percent for the steps and is the single largest item on the blueprint.
  3. Practise performing an assessment against a described processing activity rather than reciting its stages, because the syllabus verb is perform rather than describe.
  4. Map the controller and processor obligations against each other in a real contract you have access to, so the relationship question becomes concrete rather than definitional.
  5. Learn the notification requirements in full and treat the documentation obligation as examinable, since notification carries 10 percent against 2.5 percent for recognising a breach in the first place.
  6. Book the accredited training and confirm with the provider how the Practical Assignments are scheduled and assessed, because those assignments are a certification requirement and not part of the 40 question paper.

Leave the policies domain until last. It is the smallest at 10 percent, it is the most intuitive if you have worked in a governed environment, and the seven principles of data protection by design and by default are quick to learn once the rest of the material has given them context.

One habit transfers well from other advanced security credentials: read every scenario twice before looking at the options, because in a paper of only 40 items a single misread situation costs 2.5 percent of the total. Candidates coming from an offensive security background will recognise the discipline from the EXIN Ethical Hacking Foundation exam, which is built the same way at a lower level.

Frequently Asked Questions

How many questions are on the EXIN PDPP exam?

40 multiple choice questions in 120 minutes, which works out at three minutes each. The generous timing exists because several items present a situation and ask which response the regulation requires.

What is the passing score for PDPP?

65 percent. On a 40 question paper that is 26 correct answers, leaving a margin of 14 wrong, which is comfortable by certification standards.

Is training mandatory for EXIN PDPP?

Yes. EXIN lists training as mandatory and gives the certification requirement as accredited Privacy and Data Protection Professional training including successful completion of the Practical Assignments. Self-study alone does not lead to the certificate.

How much does the PDPP exam cost?

342 US dollars for the exam. Because accredited training is compulsory, the total cost of the credential is the course fee plus the exam fee rather than the exam alone, and course pricing varies by provider.

Which PDPP domain carries the most weight?

The privacy information management system at 32.5 percent, followed by the data protection impact assessment at 27.5 percent. Together they are 60 percent of the paper.

Do I need EXIN Privacy and Data Protection Foundation before PDPP?

It is advised rather than required. EXIN recommends passing the foundation exam first because PDPP is an advanced-level certification, but it is not listed among the certification requirements.

Does PDPP cover ISO/IEC 27701?

Extensively. The largest domain is built on it, and the objectives name the standard’s own terminology, ask you to compare a privacy management system with a security management system, and ask how the security standard supports implementation.

What languages is the PDPP exam available in?

English, Portuguese and Chinese, according to EXIN’s certification page. Sample exams and preparation guides are published in a wider set of languages than the exam itself.

Is PDPP an open book exam?

No. EXIN states that the exam is not open book and that electronic equipment is not permitted, so every answer has to come from what you carry into the room.

How much of the exam is about data breaches?

12.5 percent, and it is weighted heavily toward what happens after the breach. Notification requirements carry 10 percent while recognising that a breach has occurred under the regulation carries only 2.5 percent.

Conclusion

Two facts should shape how you approach PDPP. Accredited training with completed Practical Assignments is a requirement rather than a recommendation, so the credential cannot be reached by self-study however well you know the regulation. And 60 percent of the paper sits in just two domains, neither of which is the one candidates expect.

Plan around both. Book the course early, because it sets your timeline rather than your revision does, and arrive at it already fluent in ISO/IEC 27701 vocabulary and in the criteria that trigger an assessment. Leave the policies domain until the end, treat the notification requirements as procedural knowledge to be learned exactly, and practise applying the regulation to described situations rather than reciting it. A 65 percent threshold on 40 questions is a fair target for anyone who has done that; it is a difficult one for anyone who has only read the legislation.

Rating: 0 / 5 (0 votes)