Special Offer: Enjoy 20% Off Your Exam Prep with Coupon Code LEARN20.
Certs4all
IAPP Certification

IAPP Certified Information Privacy Professional/Australia (2026) Practice Exams for IAPP

Prepare for your certification exam today and take a step towards certification success with our IAPP CIPP-AU practice exams. Designed for success, trusted by professionals worldwide.

4.6 star rating 4.6 (396 Up Votes)

Practice Exams For

IAPP Certified Information Privacy Professional/Australia

Created by
Certs4All
Exam Code
CIPP-AU
Questions
100
Format
PDF + Test Engine
Updated
08-Oct-2026

CIPP-AU Practice Exam Overview

Get a clear picture of what's included in your exam preparation, from detailed explanations and updated content to flexible practice options designed around the current certification requirements.

Exam Preparation Overview

Everything you need to know about your practice exam at a glance.

Exam Code CIPP-AU
Exam Name IAPP Certified Information Privacy Professional/Australia
Practice Questions 100
Practice Format PDF + Online Test Engine
Answer Explanations Included
Last Updated 08-Oct-2026
Updated for current exam requirements
Detailed Answer Explanations
Current Exam Blueprint Alignment
90 Days Free Updates
PDF & Online Test Engine
Practice & Review

What is the IAPP CIPP/AU certification?

CIPP/AU stands for Certified Information Privacy Professional/Australia. It is a new certification from the International Association of Privacy Professionals (IAPP) that tests your knowledge of the legal and regulatory foundations of Australian privacy, and your ability to apply them in practice.

The exam is built around the Privacy Act 1988 and the Australian Privacy Principles (APPs). It also covers how that framework is changing as technology, cybersecurity, artificial intelligence, data governance and cross-border data flows raise new compliance questions. Ongoing Privacy Act reform and the Office of the Australian Information Commissioner (OAIC) expecting more from organisations, with wider enforcement powers, make solid privacy governance a core business skill.

The certification gives privacy professionals a shared standard for Australian practice: applying the rules in a practical, risk-aware way that supports responsible data handling and sound business decisions.

Exam availability: IAPP is offering the first CIPP/AU sittings in person at the IAPP ANZ Summit in December. Online purchase of the exam is expected to open in early 2027.

Why earn the CIPP/AU?

The credential is aimed at people who handle personal information in Australia, or advise those who do.

  • A recognised industry standardCIPP/AU sits within the IAPP family of certifications, the benchmark many employers look for in privacy roles.
  • Proof of Australian expertiseIt shows you understand a principles-based framework, and the state, territory and federal laws around it.
  • Practical compliance skillsThe exam rewards applying the APPs to real situations, not just reciting them.
  • A stronger leadership profilePrivacy accountability is rising across boards and executive teams. A certification makes your knowledge easy to verify.

CIPP/AU exam domains and question ranges

IAPP publishes a body of knowledge (BoK) listing exactly what can be assessed. It splits the exam into four domains and gives each a minimum and maximum number of questions.

Domain I: The regulatory context of Australian privacyFederal framework, government agencies, state and territory laws 14–18 questions

This domain covers the legislative framework behind Australian privacy, how it developed, what it applies to, and how it is applied to modern issues such as AI.

I.AThe federal legislative framework

  • Structure of the Australian legal system and its role in privacy law
  • How the Privacy Act 1988 (Cth) and the APPs developed
  • Scope of the Privacy Act and its exemptions, such as media, small business and political parties
  • Australia's approach to AI regulation through existing laws, plus guidance from the OAIC and the National AI Centre (NAIC)

I.BObligations of federal government agencies

  • How agencies must comply with the Privacy Act and how their exemptions differ from other APP entities
  • The Australian Government Agencies Privacy Code: privacy management plans, privacy officers and privacy impact assessments (PIAs)
  • Identifying and prioritising privacy risk, and the roles of the Privacy Officer and Privacy Champion

I.CState and territory privacy laws

  • Foundational laws in the ACT, NSW, NT, Queensland, Tasmania, Victoria and Western Australia
  • Key similarities and differences between jurisdictions, and the role of each regulator
  • How the Privacy Act interacts with state and territory laws
Domain II: The Australian Privacy Principles (APPs)The 13 core obligations and how to operationalise them 21–25 questions

The largest domain. It covers the core requirements for handling personal information, and the skills needed to build them into a working privacy program.

II.AKey considerations (APPs 1–2)

  • Open and transparent management: compliant practices and systems, privacy by design, PIAs, and an accessible privacy policy
  • Anonymity and pseudonymity, and when exceptions apply

II.BCollection of personal information (APPs 3–5)

  • Collecting solicited information, with stricter rules for sensitive information and consent
  • Handling unsolicited information, including destruction or de-identification
  • Notifying individuals about collection: who you are, why you collect and who you disclose to

II.CDealing with personal information (APPs 6–9)

  • Use and disclosure, including exceptions and de-identification before use
  • Direct marketing and opt-outs, alongside the Do Not Call Register Act 2006 and Spam Act 2003
  • Cross-border disclosure and making sure overseas recipients meet the APPs
  • Government related identifiers and their exceptions

II.DIntegrity of personal information (APPs 10–11)

  • Keeping information accurate, up to date, complete and relevant
  • Technical and organisational security, destruction or de-identification, and the Notifiable Data Breaches (NDB) scheme

II.EAccess and correction (APPs 12–13)

  • Handling access requests: response times, fees, grounds for refusal and written reasons
  • Handling correction requests and refusals, including complaint pathways
Domain III: Australian privacy enforcementThe OAIC, regulator overlap, penalties and emerging issues 10–14 questions

This domain looks at the OAIC's role and powers, how it works alongside other regulators, and how the framework responds to new challenges.

III.ARoles of regulators

  • OAIC functions and enforcement powers, and its regulatory escalation model
  • The OAIC's annual regulatory priorities, such as privacy policies and cyber security

III.BRegulatory intersections

  • Where jurisdiction overlaps between the OAIC, ACCC, eSafety Commissioner, ACMA and others

III.CInfringements and penalties

  • How the OAIC handles infringements, the penalties that can follow and the role of case law
  • When a statutory tort may arise from a serious invasion of privacy

III.DEvolving regulatory issues

  • How regulation adapts to the NDB scheme, AI, digital IDs, open data and cyber security, including OAIC and ACSC guidance
Domain IV: Special cases involving personal informationHealth, finance, children, employment and surveillance 17–21 questions

Each sector brings its own risks. This domain covers how the Privacy Act and other laws work together in areas where personal information needs extra care.

IV.AHealth privacy

  • How health information is defined, and the laws governing its collection, use and disclosure, including the My Health Records Act 2012 and state health privacy instruments
  • Privacy implications of wearables, AI scribes and software as a medical device
  • Inferential risk and secondary use, including workplace monitoring and health programs

IV.BFinancial privacy

  • How the Privacy Act protects financial information, and which institutions it covers (banks, credit providers, insurers)
  • The Consumer Data Right (CDR) and its link to financial information

IV.CChildren's privacy

  • Obligations when collecting or handling children's personal information
  • How the Online Safety Act 2021, the Children's Online Privacy Code, the Privacy Act and OAIC guidance fit together

IV.DEmployment privacy

  • How private-sector employers handle personal information, and the employee records exemption
  • Workplace surveillance rules, including state laws such as the NSW Workplace Surveillance Act
  • Automated decision-making (ADM) and what policies must disclose about it
  • The statutory tort of serious invasion of privacy in HR and employee monitoring

IV.ESurveillance

  • Balancing individual privacy against national security and law enforcement needs
  • Key surveillance and telecommunications legislation, including the Surveillance Devices Act 2004
  • When collection is allowed or required, for example biometrics, ID scanning, drones and security cameras, plus the data breach risks involved
  • The Surveillance Legislation Amendment (Identify and Disrupt) Act 2021 and its privacy concerns

The 13 Australian Privacy Principles at a glance

Domain II is the biggest part of the exam, so the APPs are the best place to start. This table is a study aid. Always check the wording of the Privacy Act and OAIC guidance for the detail.

APPTopicExam areaWhat it is about
APP 1Open and transparent managementII.ACompliant practices and systems, privacy by design, PIAs and a clear, available privacy policy.
APP 2Anonymity and pseudonymityII.AIndividuals can deal with an entity without identifying themselves, subject to exceptions.
APP 3Collection of solicited personal informationII.BWhat you may collect and how, with stricter rules and consent requirements for sensitive information.
APP 4Dealing with unsolicited personal informationII.BWhat to do with information you received but did not ask for, including destruction or de-identification.
APP 5Notification of collectionII.BTelling individuals who you are, why you collect, and who you disclose to.
APP 6Use or disclosureII.CWhen information can be used or disclosed beyond the purpose it was collected for.
APP 7Direct marketingII.CMarketing rules and opt-outs, read alongside the Spam Act 2003 and Do Not Call Register Act 2006.
APP 8Cross-border disclosureII.CSteps to make sure overseas recipients handle information in line with the APPs, and the exceptions.
APP 9Government related identifiersII.CLimits on adopting, using or disclosing identifiers issued by government.
APP 10Quality of personal informationII.DKeeping information accurate, up to date, complete and, when used or disclosed, relevant.
APP 11Security of personal informationII.DProtecting information from misuse, interference, loss and unauthorised access, plus destruction or de-identification and the NDB scheme.
APP 12Access to personal informationII.EHandling access requests, including timing, fees and written reasons for any refusal.
APP 13Correction of personal informationII.ECorrecting information on request, and giving written reasons and complaint options if you refuse.

What kinds of questions to expect

IAPP writes its performance indicators with action verbs such as identify, evaluate, implement and define. Each verb maps to a level of Bloom's Taxonomy and signals how hard the matching questions will be. The more demanding the verb, the more you need to apply your knowledge to a situation, not just recall it.

Create
Produce something newDesign, build, formulate, investigate.
Evaluate
Justify a decisionJudge, defend, weigh options, critique.
Analyse
Connect ideasIn IAPP sample questionsCompare, contrast, differentiate, examine.
Apply
Use knowledge in a new situationIn IAPP sample questionsImplement, solve, demonstrate, interpret.
Understand
Explain ideas and conceptsIn IAPP sample questionsDescribe, classify, identify, translate.
Remember
Recall facts and basic conceptsIn IAPP sample questionsDefine, list, state, memorise.

IAPP's published sample questions from its other designations mostly sit in the Remember, Understand, Apply and Analyse levels. Remember and Understand questions have a single factual answer. Apply and Analyse questions still rest on facts, but ask you to choose the best answer for a scenario. The two examples below are our own illustrations of each style, not real exam questions.


Recall style

Which Australian Privacy Principle deals with the cross-border disclosure of personal information?

Show answer

APP 8. It requires an entity to take steps so that an overseas recipient handles the information consistently with the APPs, subject to defined exceptions.

Scenario style

A retailer plans to store customer records with a cloud provider that hosts data overseas. Which APPs should the privacy team review first?

Show answer

APP 8 (cross-border disclosure) and APP 11 (security of personal information), and APP 1 if the privacy policy needs updating to reflect the arrangement. A PIA would help document the risks.

Laws and regulators named in the body of knowledge

A checklist of the legislation, codes and bodies that appear in the CIPP/AU syllabus. Use it to track what you have covered.

Core privacy framework

  • Privacy Act 1988 (Cth)
  • Australian Privacy Principles
  • Australian Government Agencies Privacy Code
  • Notifiable Data Breaches scheme
  • Statutory tort for serious invasions of privacy

Health, finance and children

  • My Health Records Act 2012
  • State health privacy laws
  • Consumer Data Right (CDR)
  • Online Safety Act 2021
  • Children's Online Privacy Code

Marketing and communications

  • Spam Act 2003
  • Do Not Call Register Act 2006
  • Telecommunications Act 1997
  • Telecommunications (Interception and Access) Act 1979

Surveillance and security

  • Surveillance Devices Act 2004
  • Intelligence Services Act 2001
  • Surveillance Legislation Amendment (Identify and Disrupt) Act 2021
  • NSW Workplace Surveillance Act

Regulators and bodies

  • OAIC (Office of the Australian Information Commissioner)
  • ACCC
  • eSafety Commissioner
  • ACMA
  • ACSC (Australian Cyber Security Centre)
  • NAIC (National AI Centre)
  • State and territory privacy regulators

IAPP Australian Privacy training

IAPP's Australian Privacy training is the principal course for CIPP/AU. It covers the Privacy Act 1988, the APPs, state and territory laws, enforcement and special cases.

Why train

Australian privacy law is split across federal, state and territory rules. The course explains how they fit together, which helps if you are building compliance systems.

Who it suits

Anyone who needs in-depth knowledge of the Australian privacy landscape for compliance or privacy management work, including legal, risk, security, HR and product teams.

How it relates to the exam

IAPP presents the training as an essential resource for CIPP/AU candidates. Check the IAPP website for current requirements, pricing and schedules.

How to prepare for CIPP/AU

A suggested order of study, weighted towards the domains with the most questions.

  1. Read the body of knowledge firstDownload IAPP's official CIPP/AU BoK. Every exam question maps to one of its performance indicators, so use it as your checklist.
  2. Master the 13 APPsDomain II carries 21–25 questions, the most of any domain. Learn what each APP requires, its exceptions, and how the APPs interact (for example APP 6 with APP 7, and APP 8 with APP 11).
  3. Build the federal and state pictureMake a one-page comparison of the Privacy Act against each state and territory regime, noting who regulates what and where the exemptions sit.
  4. Learn who does whatKnow the OAIC's escalation model and powers, and where the ACCC, eSafety Commissioner, ACMA and ACSC overlap with it.
  5. Work through the special casesHealth, finance, children, employment and surveillance together carry 17–21 questions. Pay attention to AI scribes, automated decision-making and workplace monitoring, which are called out in the syllabus.
  6. Practise with scenariosMove beyond definitions. Answer questions that describe a situation and ask for the best response, then review why each wrong option fails.
  7. Check for syllabus updatesIAPP reviews the BoK every year and announces changes at least 90 days before they appear in the exam, so confirm you are studying the current version before your sitting.

CIPP/AU frequently asked questions

What does CIPP/AU stand for?

Certified Information Privacy Professional/Australia. It is an IAPP certification that validates your understanding of Australian privacy law, including the Privacy Act 1988 and the Australian Privacy Principles.

When can I take the CIPP/AU exam?

IAPP is offering the exam in person at the IAPP ANZ Summit in December. Online purchase is expected to become available in early 2027. Dates can change, so confirm on the IAPP website.

What topics does the CIPP/AU exam cover?

Four domains: the regulatory context of Australian privacy, the Australian Privacy Principles, privacy enforcement, and special cases involving personal information such as health, finance, children, employment and surveillance.

Which domain has the most questions?

Domain II, the Australian Privacy Principles, with a range of 21 to 25 questions. Domain IV has 17 to 21, Domain I has 14 to 18 and Domain III has 10 to 14.

What types of questions are on the exam?

IAPP's performance indicators use verbs that map to Bloom's Taxonomy. Expect fact-based questions that test recall and understanding, and scenario-based questions that ask you to apply or analyse your knowledge and choose the best answer.

Which laws should I study?

Start with the Privacy Act 1988 and the 13 APPs, then the Notifiable Data Breaches scheme, the Australian Government Agencies Privacy Code and state and territory privacy laws. Also cover sector and special-case laws such as the My Health Records Act 2012, the Consumer Data Right, the Online Safety Act 2021, the Spam Act 2003 and the surveillance and telecommunications legislation listed in the body of knowledge.

Do I need to take IAPP training before the exam?

IAPP describes its Australian Privacy training as the principal course for the certification, and an essential resource for candidates. Check IAPP's current certification requirements for the latest details.

How often does the CIPP/AU body of knowledge change?

IAPP reviews it every year and updates it if needed. Changes are reflected in annual exam updates and communicated to candidates at least 90 days before the new content appears in the exam.

Get ready for CIPP/AU

Work through the four domains, learn the 13 APPs, and practise scenario questions before your sitting.

Browse practice exams

Suggested Study Plan for the CIPP-AU Exam

A clear routine makes your study time count. Use this plan to prepare for the IAPP IAPP Certified Information Privacy Professional/Australia exam:

  1. Read the official IAPP exam guide for CIPP-AU and note the topic weights
  2. Take a free CIPP-AU practice test without notes to find your starting score
  3. Read every answer explanation, even for questions you got right
  4. Go back to the domains where you scored lowest, then test those topics again
  5. Take full-length, timed tests until your scores are steady before you book the exam
Get Full CIPP-AU Access

Includes all practice questions, PDF + online test engine and 90 days of free updates

Is the CIPP-AU Exam Right for You?

The IAPP IAPP Certified Information Privacy Professional/Australia exam is taken by candidates at different stages of their careers. This preparation is a good fit if you:

  • Are preparing for CIPP-AU for the first time and want to know what to expect
  • Already work in this field and want a credential that proves your skills
  • Need CIPP-AU for a new job, a promotion or an employer requirement
  • Have taken the exam before and want to focus on the topics you missed
  • Have finished studying and want to check your readiness before booking
Study on Any Device

Practice for CIPP-AU Anywhere, Anytime

Use the online test engine on your phone, tablet or computer, or download the PDF to study offline.

Access on Any Device

Open your practice tests from any browser, with nothing to install.

Unlimited Practice Attempts

Retake tests as often as you need to build confidence.

Progress Saved Automatically

Pick up where you left off on any of your devices.

Try a Free Practice Test

CIPP-AU Exam Preparation FAQs

  • Our CIPP-AU questions are built around the current IAPP Certified Information Privacy Professional/Australia exam objectives. They follow the same topics, question formats and difficulty level you can expect in the real exam, so nothing on exam day feels unfamiliar.

  • You get two formats: a downloadable PDF for offline study and access to our online test engine for exam-style practice.

  • The PDF is your offline study guide. Download it and review the questions and explanations anytime, even without internet. The online test engine is on our website and works like the real exam: it has timed mock exams, instant scoring and results, so you can practice under exam conditions and track your progress.

  • Yes. Take a free practice test to see the question style, the explanations and the test engine before you get full access.

  • We update the questions whenever IAPP changes the exam objectives. Every purchase includes 90 days of free updates to both the PDF and the test engine, and the latest update date is shown in the Exam Overview on this page.

  • Yes. The online test engine lets you take full-length mock exams with a timer, or practice in untimed study mode. You get your score as soon as you finish.

  • Yes. The online test engine works in any browser on a phone, tablet or computer. The PDF can be downloaded to any device for offline reading.

  • You get 100% of your money back. If you don’t pass the CIPP-AU exam, contact our support team and we refund your purchase in full right away.

  • Our support team is available 24/7. Contact us through the support page on our site or email support@certs4all.com, and we'll help with anything before, during or after your purchase.