Skip to main content

CDPSE Certified Data Privacy Solutions Engineer.

CDPSE is the ISACA technical-privacy credential. Three domains: privacy governance, privacy architecture, data lifecycle. The engineering-side companion to the policy-focused DPO/CDPO credentials. Strong fit for security teams owning privacy implementation and for architects working under the GDPR or the AI Act.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyCertifications & credentialsAll entries

The Cyber Academy take

CDPSE is the ISACA technical-privacy credential. Three domains: privacy governance, privacy architecture, data lifecycle. The engineering-side companion to the policy-focused DPO/CDPO credentials. Strong fit for security teams owning privacy implementation and for architects working under the GDPR or the AI Act.

What CDPSE is for

CDPSE is ISACA's answer to a gap that opened up once privacy stopped being a purely legal exercise. Drafting a privacy policy, mapping lawful bases, and answering data subject requests are the work of a Data Protection Officer. But none of that prevents a leaky API from exposing personal data, ensures pseudonymisation is applied correctly, or builds consent and retention logic into a system before it ships. CDPSE certifies the people who do that technical work: the engineers, architects, and security professionals who translate privacy obligations into running systems and controls.

That is the credential's defining stance. It is the engineering-side companion to the policy-focused DPO and CDPO credentials, not a competitor to them. A DPO decides what the organisation must do to comply; a CDPSE holder builds the controls that make compliance real and verifiable. In mature programmes the two roles sit on either side of the same table, which is why CDPSE is positioned as a bridge between privacy governance and the technology that implements it.

The three domains

CDPSE is built around three domains, and the proportions tell you where ISACA places the emphasis. The bulk of the exam sits in the architecture and lifecycle domains, because that is where engineering decisions actually get made.

  • Privacy governance. The connective tissue between legal requirements and technical execution: privacy programme structure, governance and management of privacy risk, and the policies and standards that engineering must build against. This is where a CDPSE holder reads what the DPO and legal team produced and turns it into design constraints.
  • Privacy architecture. Infrastructure, applications, and technologies through a privacy lens. This covers privacy by design and by default as an engineering discipline: data flow design, technical privacy controls, encryption and pseudonymisation, identity and access, and the privacy implications of architectural choices.
  • Data lifecycle. Personal data from collection through retention to destruction. Purpose limitation, data minimisation, quality, retention schedules, and secure disposal expressed as controls a system enforces rather than as clauses in a notice nobody reads.

Where CDPSE sits next to neighbouring credentials and standards

CDPSE is most useful when you read it against what it is not. The table below places it beside the credentials and standards practitioners most often confuse it with.

CDPSE compared to neighbouring privacy roles and standards
ReferencePrimary focusPosture
CDPSETechnical implementation of privacy in systemsEngineering and architecture, controls that run
DPO / CDPOLegal and policy compliance, accountabilityGovernance, interpretation, advisory
ISO 27701Privacy information management system (PIMS)Certifiable management system extending ISO 27001
GDPRThe legal obligations themselvesRegulation, the thing controls must satisfy

The fit is strongest for security teams that have inherited privacy implementation, and for architects designing under the GDPR or the AI Act, where data minimisation and purpose limitation have to be engineered into models and pipelines rather than promised in documentation. A CDPSE holder often becomes the person who can sit in a design review and say, concretely, how a feature will meet a privacy requirement. ISO 27701 frequently sits alongside the credential: the standard defines the privacy management system, and CDPSE-trained engineers are the ones who build the technical controls that system depends on.

CDPSE is an experience-based ISACA certification, which means it is aimed at people who already work in privacy, security, or IT rather than at beginners. Like other ISACA credentials it carries continuing professional education requirements to keep it current, reflecting how fast both the technology and the regulatory landscape move.

Frequently asked questions

01What is the difference between CDPSE and a DPO certification?

A DPO credential certifies legal and policy competence: interpreting regulation, managing accountability, advising the organisation. CDPSE certifies technical competence: building the controls and architecture that make those obligations real in running systems. They are complementary, not interchangeable.

02What are the three CDPSE domains?

Privacy governance, privacy architecture, and data lifecycle. The architecture and lifecycle domains carry the most weight, because that is where engineering and design decisions about personal data actually happen.

03Who should pursue CDPSE rather than ISO 27701 training?

CDPSE suits the individual engineer, architect, or security professional implementing privacy controls. ISO 27701 is a management system standard for the organisation. Many teams use both: ISO 27701 frames the privacy management system and CDPSE-trained people build the technical controls inside it.

04Is CDPSE suitable for beginners?

No. CDPSE is an experience-based ISACA certification aimed at practitioners already working in privacy, security, or IT. It assumes you can read a privacy requirement and turn it into a technical control.

05How does CDPSE relate to the GDPR and the AI Act?

Both regimes demand privacy by design and data minimisation as engineering outcomes, not just paperwork. CDPSE certifies the skills to deliver those outcomes in architecture and data pipelines, which is why it fits teams building under the GDPR or the AI Act.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.