CIPP/E vs CIPP/US vs AIGP: which IAPP certification should you take?
Short answer: take the certification closest to the law you actually work with. CIPP/E if your work touches EU or UK data protection (the GDPR). CIPP/US if you deal with United States privacy law. AIGP if your role involves AI governance, the EU AI Act, or responsible-AI programmes.
Starting from zero? Most people should do CIPP/E first - GDPR concepts (controllers, lawful bases, data-subject rights) are the vocabulary the whole privacy profession borrows - then add AIGP or CIPP/US depending on where your career points.
The three certifications side by side
| CIPP/E | CIPP/US | AIGP | |
|---|---|---|---|
| Full name | Certified Information Privacy Professional / Europe | Certified Information Privacy Professional / United States | Artificial Intelligence Governance Professional |
| Core subject | GDPR, ePrivacy, EU institutions, international transfers, enforcement | U.S. federal sectoral laws (FTC, HIPAA, GLBA, FCRA, FERPA), state laws, government access | AI risk, the EU AI Act, governance frameworks, the AI life cycle, responsible AI |
| Best for | DPOs, EU/UK counsel, compliance and privacy teams serving European markets | U.S. counsel, compliance officers, anyone whose clients or employer face U.S. privacy law | AI governance leads, risk managers, product and policy people building AI programmes |
| Character of the exam | One deep legal framework applied to scenarios | Many laws; breadth and keeping them apart is the challenge | Newer, framework-driven; vocabulary and life-cycle thinking |
| Free study guide | cippe.thesmios.com | cippu.thesmios.com | aigp.thesmios.com |
All three are administered by the IAPP; none has formal prerequisites. For current exam formats, fees and blueprints, always check the official pages at iapp.org.
Which should you take first?
Match the certification to your work, not to difficulty rankings. Having passed all three: CIPP/E gave me the conceptual base the other two kept reusing - risk-based thinking, roles and responsibilities, rights of individuals. AIGP felt like a natural second step because AI governance borrows privacy's toolkit (impact assessments, accountability, documentation). CIPP/US stands more on its own: it is a memorisation-heavy map of a genuinely fragmented legal landscape.
Is CIPP/E harder than CIPP/US?
They are hard in different ways. CIPP/E asks you to apply one coherent framework to subtle scenarios - the difficulty is depth. CIPP/US asks you to keep dozens of federal and state laws distinct - the difficulty is breadth. EU-background candidates usually find CIPP/US harder to memorise; US-background candidates usually find CIPP/E denser conceptually.
Do you need a CIPP before the AIGP?
No. The AIGP assumes no prior certification. Privacy knowledge helps because AI governance reuses privacy-style risk assessment, but AIGP-first is completely viable if AI governance is where your work already is.
How should you prepare?
The approach that worked for me across all three: active recall over re-reading. Short, structured notes per topic, then exam-style questions with explanations until the weak spots close. That is exactly how the free guides on this site are built - every topic in the body of knowledge as a concise note, with an optional exam-style question bank when you are ready to test yourself. One account works across all three guides.