IAPP Certified Information Privacy Professional/Australia (2026) Practice Exams for IAPP
Prepare for your certification exam today and take a step towards certification success with our IAPP CIPP-AU practice exams. Designed for success, trusted by professionals worldwide.
Practice Exams For
IAPP Certified Information Privacy Professional/Australia
CIPP-AU Practice Exam Overview
Get a clear picture of what's included in your exam preparation, from detailed explanations and updated content to flexible practice options designed around the current certification requirements.
Exam Preparation Overview
Everything you need to know about your practice exam at a glance.
What is the IAPP CIPP/AU certification?
CIPP/AU stands for Certified Information Privacy Professional/Australia. It is a new certification from the International Association of Privacy Professionals (IAPP) that tests your knowledge of the legal and regulatory foundations of Australian privacy, and your ability to apply them in practice.
The exam is built around the Privacy Act 1988 and the Australian Privacy Principles (APPs). It also covers how that framework is changing as technology, cybersecurity, artificial intelligence, data governance and cross-border data flows raise new compliance questions. Ongoing Privacy Act reform and the Office of the Australian Information Commissioner (OAIC) expecting more from organisations, with wider enforcement powers, make solid privacy governance a core business skill.
The certification gives privacy professionals a shared standard for Australian practice: applying the rules in a practical, risk-aware way that supports responsible data handling and sound business decisions.
Why earn the CIPP/AU?
The credential is aimed at people who handle personal information in Australia, or advise those who do.
- A recognised industry standardCIPP/AU sits within the IAPP family of certifications, the benchmark many employers look for in privacy roles.
- Proof of Australian expertiseIt shows you understand a principles-based framework, and the state, territory and federal laws around it.
- Practical compliance skillsThe exam rewards applying the APPs to real situations, not just reciting them.
- A stronger leadership profilePrivacy accountability is rising across boards and executive teams. A certification makes your knowledge easy to verify.
CIPP/AU exam domains and question ranges
IAPP publishes a body of knowledge (BoK) listing exactly what can be assessed. It splits the exam into four domains and gives each a minimum and maximum number of questions.
Domain I: The regulatory context of Australian privacyFederal framework, government agencies, state and territory laws 14–18 questions
This domain covers the legislative framework behind Australian privacy, how it developed, what it applies to, and how it is applied to modern issues such as AI.
I.AThe federal legislative framework
- Structure of the Australian legal system and its role in privacy law
- How the Privacy Act 1988 (Cth) and the APPs developed
- Scope of the Privacy Act and its exemptions, such as media, small business and political parties
- Australia's approach to AI regulation through existing laws, plus guidance from the OAIC and the National AI Centre (NAIC)
I.BObligations of federal government agencies
- How agencies must comply with the Privacy Act and how their exemptions differ from other APP entities
- The Australian Government Agencies Privacy Code: privacy management plans, privacy officers and privacy impact assessments (PIAs)
- Identifying and prioritising privacy risk, and the roles of the Privacy Officer and Privacy Champion
I.CState and territory privacy laws
- Foundational laws in the ACT, NSW, NT, Queensland, Tasmania, Victoria and Western Australia
- Key similarities and differences between jurisdictions, and the role of each regulator
- How the Privacy Act interacts with state and territory laws
Domain II: The Australian Privacy Principles (APPs)The 13 core obligations and how to operationalise them 21–25 questions
The largest domain. It covers the core requirements for handling personal information, and the skills needed to build them into a working privacy program.
II.AKey considerations (APPs 1–2)
- Open and transparent management: compliant practices and systems, privacy by design, PIAs, and an accessible privacy policy
- Anonymity and pseudonymity, and when exceptions apply
II.BCollection of personal information (APPs 3–5)
- Collecting solicited information, with stricter rules for sensitive information and consent
- Handling unsolicited information, including destruction or de-identification
- Notifying individuals about collection: who you are, why you collect and who you disclose to
II.CDealing with personal information (APPs 6–9)
- Use and disclosure, including exceptions and de-identification before use
- Direct marketing and opt-outs, alongside the Do Not Call Register Act 2006 and Spam Act 2003
- Cross-border disclosure and making sure overseas recipients meet the APPs
- Government related identifiers and their exceptions
II.DIntegrity of personal information (APPs 10–11)
- Keeping information accurate, up to date, complete and relevant
- Technical and organisational security, destruction or de-identification, and the Notifiable Data Breaches (NDB) scheme
II.EAccess and correction (APPs 12–13)
- Handling access requests: response times, fees, grounds for refusal and written reasons
- Handling correction requests and refusals, including complaint pathways
Domain III: Australian privacy enforcementThe OAIC, regulator overlap, penalties and emerging issues 10–14 questions
This domain looks at the OAIC's role and powers, how it works alongside other regulators, and how the framework responds to new challenges.
III.ARoles of regulators
- OAIC functions and enforcement powers, and its regulatory escalation model
- The OAIC's annual regulatory priorities, such as privacy policies and cyber security
III.BRegulatory intersections
- Where jurisdiction overlaps between the OAIC, ACCC, eSafety Commissioner, ACMA and others
III.CInfringements and penalties
- How the OAIC handles infringements, the penalties that can follow and the role of case law
- When a statutory tort may arise from a serious invasion of privacy
III.DEvolving regulatory issues
- How regulation adapts to the NDB scheme, AI, digital IDs, open data and cyber security, including OAIC and ACSC guidance
Domain IV: Special cases involving personal informationHealth, finance, children, employment and surveillance 17–21 questions
Each sector brings its own risks. This domain covers how the Privacy Act and other laws work together in areas where personal information needs extra care.
IV.AHealth privacy
- How health information is defined, and the laws governing its collection, use and disclosure, including the My Health Records Act 2012 and state health privacy instruments
- Privacy implications of wearables, AI scribes and software as a medical device
- Inferential risk and secondary use, including workplace monitoring and health programs
IV.BFinancial privacy
- How the Privacy Act protects financial information, and which institutions it covers (banks, credit providers, insurers)
- The Consumer Data Right (CDR) and its link to financial information
IV.CChildren's privacy
- Obligations when collecting or handling children's personal information
- How the Online Safety Act 2021, the Children's Online Privacy Code, the Privacy Act and OAIC guidance fit together
IV.DEmployment privacy
- How private-sector employers handle personal information, and the employee records exemption
- Workplace surveillance rules, including state laws such as the NSW Workplace Surveillance Act
- Automated decision-making (ADM) and what policies must disclose about it
- The statutory tort of serious invasion of privacy in HR and employee monitoring
IV.ESurveillance
- Balancing individual privacy against national security and law enforcement needs
- Key surveillance and telecommunications legislation, including the Surveillance Devices Act 2004
- When collection is allowed or required, for example biometrics, ID scanning, drones and security cameras, plus the data breach risks involved
- The Surveillance Legislation Amendment (Identify and Disrupt) Act 2021 and its privacy concerns
The 13 Australian Privacy Principles at a glance
Domain II is the biggest part of the exam, so the APPs are the best place to start. This table is a study aid. Always check the wording of the Privacy Act and OAIC guidance for the detail.
| APP | Topic | Exam area | What it is about |
|---|---|---|---|
| APP 1 | Open and transparent management | II.A | Compliant practices and systems, privacy by design, PIAs and a clear, available privacy policy. |
| APP 2 | Anonymity and pseudonymity | II.A | Individuals can deal with an entity without identifying themselves, subject to exceptions. |
| APP 3 | Collection of solicited personal information | II.B | What you may collect and how, with stricter rules and consent requirements for sensitive information. |
| APP 4 | Dealing with unsolicited personal information | II.B | What to do with information you received but did not ask for, including destruction or de-identification. |
| APP 5 | Notification of collection | II.B | Telling individuals who you are, why you collect, and who you disclose to. |
| APP 6 | Use or disclosure | II.C | When information can be used or disclosed beyond the purpose it was collected for. |
| APP 7 | Direct marketing | II.C | Marketing rules and opt-outs, read alongside the Spam Act 2003 and Do Not Call Register Act 2006. |
| APP 8 | Cross-border disclosure | II.C | Steps to make sure overseas recipients handle information in line with the APPs, and the exceptions. |
| APP 9 | Government related identifiers | II.C | Limits on adopting, using or disclosing identifiers issued by government. |
| APP 10 | Quality of personal information | II.D | Keeping information accurate, up to date, complete and, when used or disclosed, relevant. |
| APP 11 | Security of personal information | II.D | Protecting information from misuse, interference, loss and unauthorised access, plus destruction or de-identification and the NDB scheme. |
| APP 12 | Access to personal information | II.E | Handling access requests, including timing, fees and written reasons for any refusal. |
| APP 13 | Correction of personal information | II.E | Correcting information on request, and giving written reasons and complaint options if you refuse. |
What kinds of questions to expect
IAPP writes its performance indicators with action verbs such as identify, evaluate, implement and define. Each verb maps to a level of Bloom's Taxonomy and signals how hard the matching questions will be. The more demanding the verb, the more you need to apply your knowledge to a situation, not just recall it.
IAPP's published sample questions from its other designations mostly sit in the Remember, Understand, Apply and Analyse levels. Remember and Understand questions have a single factual answer. Apply and Analyse questions still rest on facts, but ask you to choose the best answer for a scenario. The two examples below are our own illustrations of each style, not real exam questions.
Which Australian Privacy Principle deals with the cross-border disclosure of personal information?
Show answer
APP 8. It requires an entity to take steps so that an overseas recipient handles the information consistently with the APPs, subject to defined exceptions.
A retailer plans to store customer records with a cloud provider that hosts data overseas. Which APPs should the privacy team review first?
Show answer
APP 8 (cross-border disclosure) and APP 11 (security of personal information), and APP 1 if the privacy policy needs updating to reflect the arrangement. A PIA would help document the risks.
Laws and regulators named in the body of knowledge
A checklist of the legislation, codes and bodies that appear in the CIPP/AU syllabus. Use it to track what you have covered.
Core privacy framework
- Privacy Act 1988 (Cth)
- Australian Privacy Principles
- Australian Government Agencies Privacy Code
- Notifiable Data Breaches scheme
- Statutory tort for serious invasions of privacy
Health, finance and children
- My Health Records Act 2012
- State health privacy laws
- Consumer Data Right (CDR)
- Online Safety Act 2021
- Children's Online Privacy Code
Marketing and communications
- Spam Act 2003
- Do Not Call Register Act 2006
- Telecommunications Act 1997
- Telecommunications (Interception and Access) Act 1979
Surveillance and security
- Surveillance Devices Act 2004
- Intelligence Services Act 2001
- Surveillance Legislation Amendment (Identify and Disrupt) Act 2021
- NSW Workplace Surveillance Act
Regulators and bodies
- OAIC (Office of the Australian Information Commissioner)
- ACCC
- eSafety Commissioner
- ACMA
- ACSC (Australian Cyber Security Centre)
- NAIC (National AI Centre)
- State and territory privacy regulators
IAPP Australian Privacy training
IAPP's Australian Privacy training is the principal course for CIPP/AU. It covers the Privacy Act 1988, the APPs, state and territory laws, enforcement and special cases.
Why train
Australian privacy law is split across federal, state and territory rules. The course explains how they fit together, which helps if you are building compliance systems.
Who it suits
Anyone who needs in-depth knowledge of the Australian privacy landscape for compliance or privacy management work, including legal, risk, security, HR and product teams.
How it relates to the exam
IAPP presents the training as an essential resource for CIPP/AU candidates. Check the IAPP website for current requirements, pricing and schedules.
How to prepare for CIPP/AU
A suggested order of study, weighted towards the domains with the most questions.
- Read the body of knowledge firstDownload IAPP's official CIPP/AU BoK. Every exam question maps to one of its performance indicators, so use it as your checklist.
- Master the 13 APPsDomain II carries 21–25 questions, the most of any domain. Learn what each APP requires, its exceptions, and how the APPs interact (for example APP 6 with APP 7, and APP 8 with APP 11).
- Build the federal and state pictureMake a one-page comparison of the Privacy Act against each state and territory regime, noting who regulates what and where the exemptions sit.
- Learn who does whatKnow the OAIC's escalation model and powers, and where the ACCC, eSafety Commissioner, ACMA and ACSC overlap with it.
- Work through the special casesHealth, finance, children, employment and surveillance together carry 17–21 questions. Pay attention to AI scribes, automated decision-making and workplace monitoring, which are called out in the syllabus.
- Practise with scenariosMove beyond definitions. Answer questions that describe a situation and ask for the best response, then review why each wrong option fails.
- Check for syllabus updatesIAPP reviews the BoK every year and announces changes at least 90 days before they appear in the exam, so confirm you are studying the current version before your sitting.
CIPP/AU frequently asked questions
What does CIPP/AU stand for?
Certified Information Privacy Professional/Australia. It is an IAPP certification that validates your understanding of Australian privacy law, including the Privacy Act 1988 and the Australian Privacy Principles.
When can I take the CIPP/AU exam?
IAPP is offering the exam in person at the IAPP ANZ Summit in December. Online purchase is expected to become available in early 2027. Dates can change, so confirm on the IAPP website.
What topics does the CIPP/AU exam cover?
Four domains: the regulatory context of Australian privacy, the Australian Privacy Principles, privacy enforcement, and special cases involving personal information such as health, finance, children, employment and surveillance.
Which domain has the most questions?
Domain II, the Australian Privacy Principles, with a range of 21 to 25 questions. Domain IV has 17 to 21, Domain I has 14 to 18 and Domain III has 10 to 14.
What types of questions are on the exam?
IAPP's performance indicators use verbs that map to Bloom's Taxonomy. Expect fact-based questions that test recall and understanding, and scenario-based questions that ask you to apply or analyse your knowledge and choose the best answer.
Which laws should I study?
Start with the Privacy Act 1988 and the 13 APPs, then the Notifiable Data Breaches scheme, the Australian Government Agencies Privacy Code and state and territory privacy laws. Also cover sector and special-case laws such as the My Health Records Act 2012, the Consumer Data Right, the Online Safety Act 2021, the Spam Act 2003 and the surveillance and telecommunications legislation listed in the body of knowledge.
Do I need to take IAPP training before the exam?
IAPP describes its Australian Privacy training as the principal course for the certification, and an essential resource for candidates. Check IAPP's current certification requirements for the latest details.
How often does the CIPP/AU body of knowledge change?
IAPP reviews it every year and updates it if needed. Changes are reflected in annual exam updates and communicated to candidates at least 90 days before the new content appears in the exam.
Get ready for CIPP/AU
Work through the four domains, learn the 13 APPs, and practise scenario questions before your sitting.
Browse practice examsSuggested Study Plan for the CIPP-AU Exam
A clear routine makes your study time count. Use this plan to prepare for the IAPP IAPP Certified Information Privacy Professional/Australia exam:
- Read the official IAPP exam guide for CIPP-AU and note the topic weights
- Take a free CIPP-AU practice test without notes to find your starting score
- Read every answer explanation, even for questions you got right
- Go back to the domains where you scored lowest, then test those topics again
- Take full-length, timed tests until your scores are steady before you book the exam
Includes all practice questions, PDF + online test engine and 90 days of free updates
Is the CIPP-AU Exam Right for You?
The IAPP IAPP Certified Information Privacy Professional/Australia exam is taken by candidates at different stages of their careers. This preparation is a good fit if you:
- Are preparing for CIPP-AU for the first time and want to know what to expect
- Already work in this field and want a credential that proves your skills
- Need CIPP-AU for a new job, a promotion or an employer requirement
- Have taken the exam before and want to focus on the topics you missed
- Have finished studying and want to check your readiness before booking
Practice for CIPP-AU Anywhere, Anytime
Use the online test engine on your phone, tablet or computer, or download the PDF to study offline.
Access on Any Device
Open your practice tests from any browser, with nothing to install.
Unlimited Practice Attempts
Retake tests as often as you need to build confidence.
Progress Saved Automatically
Pick up where you left off on any of your devices.
CIPP-AU Exam Preparation FAQs
-
Our CIPP-AU questions are built around the current IAPP Certified Information Privacy Professional/Australia exam objectives. They follow the same topics, question formats and difficulty level you can expect in the real exam, so nothing on exam day feels unfamiliar.
-
You get two formats: a downloadable PDF for offline study and access to our online test engine for exam-style practice.
-
The PDF is your offline study guide. Download it and review the questions and explanations anytime, even without internet. The online test engine is on our website and works like the real exam: it has timed mock exams, instant scoring and results, so you can practice under exam conditions and track your progress.
-
Yes. Take a free practice test to see the question style, the explanations and the test engine before you get full access.
-
We update the questions whenever IAPP changes the exam objectives. Every purchase includes 90 days of free updates to both the PDF and the test engine, and the latest update date is shown in the Exam Overview on this page.
-
Yes. The online test engine lets you take full-length mock exams with a timer, or practice in untimed study mode. You get your score as soon as you finish.
-
Yes. The online test engine works in any browser on a phone, tablet or computer. The PDF can be downloaded to any device for offline reading.
-
You get 100% of your money back. If you don’t pass the CIPP-AU exam, contact our support team and we refund your purchase in full right away.
-
Our support team is available 24/7. Contact us through the support page on our site or email support@certs4all.com, and we'll help with anything before, during or after your purchase.