Privacy
Privacy Certifications Explained: CIPP, CIPM, and CIPT
The IAPP's three credentials answer three different questions — what the law requires, how to run a program, and how to build privacy into systems. Here is which one fits your work, and in what order.

Two people with the same job title, "privacy analyst," can do almost entirely different work. One spends the day interpreting whether a new data-sharing arrangement is lawful and how retention rules apply. The other spends it wiring consent logic into a signup flow and arguing with engineers about log minimization. Both are privacy professionals; a single certification would serve them badly. The IAPP built three credentials precisely because the field splits this way, and choosing among them starts with being honest about which of those two people you are.
The three are CIPP, CIPM, and CIPT, all issued by the International Association of Privacy Professionals (IAPP). They are not a difficulty ladder. They are three different lenses on the same discipline: the law, the program, and the system.
CIPP: what the law requires
The Certified Information Privacy Professional (CIPP) is the law-and-policy credential, and it is region-specific by design. You sit for a particular concentration — CIPP/E for European law centered on the GDPR, CIPP/US for the United States framework, and others for further jurisdictions. The exam tests your grasp of what the applicable regime actually demands: the legal bases for processing, individual rights, cross-border transfer rules, and how the concepts fit together.
This is the credential for people whose work is interpretation. If your day involves reading a regulation and deciding what it means for a real situation, CIPP is your foundation. It rewards precision about distinctions that matter and that people routinely get wrong. Under the GDPR, for example, whether an organization is a controller or a processor turns on who determines the purposes and means of the processing, not on the sensitivity or type of data involved. CIPP training drills exactly this kind of distinction, because getting it wrong in practice misassigns legal accountability.
CIPP tells you what must be true. It does not, on its own, tell you how to make it true across an organization. That is a different credential.
CIPM: how to run the program
The Certified Information Privacy Manager (CIPM) is the operational credential. It is jurisdiction-neutral and concerned with building and running a privacy program: governance structures, the privacy operational lifecycle, risk assessment, incident response, metrics, and vendor management.
CIPM is for the person accountable for whether privacy actually happens, not just whether it is understood. If your work is standing up a program, coordinating across legal, security, and product, and being able to demonstrate compliance rather than merely assert it, this is the credential that maps to your job. It covers the machinery — for instance, when a data protection impact assessment (DPIA) is required, which under the GDPR is when processing is likely to result in a high risk to individuals, and how to run one as a repeatable process rather than a one-off document.
Where CIPP asks what the rules are, CIPM asks how you operationalize them at scale and prove it later.
CIPT: how to build it into systems
The Certified Information Privacy Technologist (CIPT) is the technical credential, aimed at people who build and secure the systems that process personal data. It covers privacy-by-design, data-lifecycle controls, de-identification techniques, and the privacy implications of specific technologies.
CIPT fits engineers, architects, security professionals, and privacy specialists who work close to systems. This is where the difference between a management-system framework and an attestation report matters, and where practitioners often blur it: ISO/IEC 27001 is a certifiable information-security management-system standard, while SOC 2 is an AICPA attestation report on controls, not a framework an organization is certified against. A CIPT-minded professional is expected to understand what each actually provides and where privacy controls sit relative to them.
CIPT translates legal and program requirements into technical reality. It is the answer to "we agreed data minimization applies — now what does that mean in the schema?"
Sequencing them
There is no mandated order, but the sensible path follows your role rather than a checklist. Start with the credential closest to the work you already do: CIPP if you interpret law, CIPM if you run programs, CIPT if you build systems. Depth in your own lane beats a shallow spread across all three.
For most people, a natural second step is CIPP plus CIPM. That pairing — what the law requires and how to operationalize it — covers the core of most privacy roles and is common enough that many employers treat it as the working standard. Add CIPT when your responsibilities pull you toward engineering decisions.
Certifications signal competence; they do not create it. The value comes from doing the work each one describes. Pick the lens that matches your job now, earn it properly, and add the next when your role, not a credential collection, actually calls for it.