The CDPO Exam Domains D1-D5: A Complete Content Map for Nigerian Candidates
    CDPO
    exam-domains
    study-plan
    Nigeria

    The CDPO Exam Domains D1-D5: A Complete Content Map for Nigerian Candidates

    The IIM CDPO exam is built around five published domains: Legal and Regulatory Frameworks (30%), Data Protection Principles and Compliance (25%), Risk Management and DPIA (20%), Incident Response a...

    Vantrel Editorial TeamAugust 13, 2026

    The IIM CDPO exam is built around five published domains: Legal and Regulatory Frameworks (30%), Data Protection Principles and Compliance (25%), Risk Management and DPIA (20%), Incident Response and Data Breaches (15%), and Governance, Policies and Ethics (10%). The weights matter because they tell you where the exam concentrates its marks.

    A five-domain syllabus can create a false sense of symmetry. Five boxes on a page look equal. The exam blueprint is not.

    One domain carries three times the weight of another. If you divide your study time equally because there are five headings, you are ignoring information the certification body has already given you.

    The useful way to read the CDPO blueprint is not as a list of topics. It is as a map of where your preparation should become deeper, where your scenario work should become harder, and where a weak domain can pull down an otherwise strong result.

    What are the five CDPO exam domains?

    IIM currently publishes the following Body of Knowledge for the CDPO exam:

    DomainOfficial domain namePublished weight
    D1Legal and Regulatory Frameworks30%
    D2Data Protection Principles and Compliance25%
    D3Risk Management and DPIA20%
    D4Incident Response and Data Breaches15%
    D5Governance, Policies and Ethics10%

    Those percentages total 100 percent and should shape the first version of your study plan.

    One caveat matters. IIM's public page gives the domain names and weights, but it does not publish a detailed line-by-line list of every examinable sub-objective. The topic mapping below therefore uses the official domain headings together with the NDPA 2023 and IIM's recommended study resources. Treat it as a preparation map, not as replacement wording for IIM's official blueprint.

    What does CDPO Domain 1 cover?

    D1: Legal and Regulatory Frameworks — 30 percent

    This is the largest domain.

    At a minimum, your preparation should be able to place Nigerian data protection obligations in their legal context and distinguish the core rules that govern processing. The Nigeria Data Protection Act 2023 is the obvious centre of gravity.

    Topics that belong naturally in this domain include:

    • the scope and objectives of the NDPA 2023;
    • the role and powers of the Nigeria Data Protection Commission;
    • lawful bases for processing;
    • consent requirements;
    • data subject rights;
    • controller and processor responsibilities;
    • the statutory role of the DPO;
    • cross-border transfer rules; and
    • the relationship between Nigerian law and relevant international privacy frameworks.

    IIM also lists the Malabo Convention and Convention 108+ among its recommended resources, while its CDPO materials state alignment with GDPR and ISO/IEC 27701.

    The exam risk in D1 is memorising legal labels without learning how they change an outcome.

    Knowing that "legal obligation" is a lawful basis is one thing. Recognising when it displaces consent in a real scenario is the competence the question is more likely to expose.

    What does CDPO Domain 2 cover?

    D2: Data Protection Principles and Compliance — 25 percent

    D2 is where the law becomes operating discipline.

    The NDPA's processing principles include fairness, lawfulness and transparency; purpose limitation; data minimisation; storage limitation; accuracy; security; accountability; and duty of care. Those principles should not sit in your notes as definitions only.

    You should be able to test a business process against them.

    Take a simple example. A company collects date of birth, home address, marital status and passport details to send a monthly email newsletter. Even before you ask which lawful basis applies, the data minimisation question should be obvious. Most of that information is unnecessary for the stated purpose.

    A strong D2 answer connects the principle to the facts quickly.

    Useful preparation areas include:

    • transparency and privacy notices;
    • purpose specification;
    • data minimisation;
    • retention and deletion logic;
    • accuracy controls;
    • accountability evidence;
    • processor governance and written agreements;
    • handling data subject requests; and
    • practical compliance records.

    The difference between D1 and D2 is not a hard wall. The exam can easily put both into one scenario. That is precisely why integrated practice matters.

    What does CDPO Domain 3 cover?

    D3: Risk Management and DPIA — 20 percent

    Section 28 of the NDPA requires a data privacy impact assessment where processing is likely to result in high risk to the rights and freedoms of a data subject because of its nature, scope, context and purposes.

    A DPIA is not a form completed after a product decision has already been made. The Act requires it before the high-risk processing takes place.

    For exam preparation, understand the logic of a DPIA:

    1. describe the proposed processing and its purpose;
    2. assess necessity and proportionality;
    3. identify risks to individuals;
    4. identify measures and safeguards to address those risks; and
    5. recognise when residual high risk requires consultation with the NDPC.

    The NDPC's GAID 2025 adds operational detail, including Schedule 4 guidance on DPIAs. That makes D3 especially suited to scenarios involving biometrics, large-scale monitoring, profiling, sensitive data, new technologies or processing where harm to individuals could be material.

    The wrong way to study D3 is to memorise a DPIA template without understanding the risk decision it is meant to support.

    What does CDPO Domain 4 cover?

    D4: Incident Response and Data Breaches — 15 percent

    This domain is narrower than D1 or D2, but it is highly scenario-friendly.

    Section 40 of the NDPA distinguishes the obligations of processors and controllers when a personal data breach occurs. A processor that becomes aware of a breach must notify the controller or engaging processor. A controller must notify the NDPC within 72 hours where the breach is likely to result in a risk to the rights and freedoms of individuals.

    Where the breach is likely to create a high risk for a data subject, communication to the affected person is also required.

    Preparation should therefore cover more than the phrase "72 hours."

    You need to be able to answer:

    • Who discovered the breach?
    • Is that party a controller or processor?
    • Who must be notified first?
    • Does the breach create a risk or a high risk?
    • What information should a notification contain?
    • What should the organisation do while facts are still developing?
    • What evidence should be retained after the incident?

    A timed scenario can bury those issues inside operational detail. Your job is to find the legal sequence.

    What does CDPO Domain 5 cover?

    D5: Governance, Policies and Ethics — 10 percent

    D5 carries the smallest published weight, but "smallest" does not mean optional.

    Data protection programmes fail when legal obligations are not assigned, documented, monitored or escalated. Governance is what turns a policy statement into accountable behaviour.

    Likely preparation areas include:

    • DPO independence and responsibilities;
    • privacy governance structures;
    • internal policies and standards;
    • roles and accountability;
    • oversight of processors and vendors;
    • training and awareness;
    • ethical use of personal data;
    • escalation and reporting; and
    • evidence that a compliance programme is functioning in practice.

    This is also where candidates with real professional experience often have an advantage, provided they do not assume their employer's process is automatically the legally correct one.

    The exam tests the framework, not your company's habits.

    How should you allocate study time across D1-D5?

    Start with the blueprint, then let your diagnostic result override the blueprint where necessary.

    If you had ten hours to allocate before taking any diagnostic, a purely weight-based starting point would be:

    • D1: 3 hours
    • D2: 2.5 hours
    • D3: 2 hours
    • D4: 1.5 hours
    • D5: 1 hour

    That is a starting allocation, not a permanent schedule.

    If your diagnostic shows that D5 is 18 points below your required level while D1 is already strong, continuing to spend three times as much time on D1 would be mechanically faithful to the blueprint and strategically wrong for you.

    The better rule is:

    use exam weight to set the baseline; use measured domain gaps to decide what happens next.

    That is how Vantrel's Signal Engine approaches question selection. The blueprint matters, but so does the candidate's actual performance inside it.

    Which CDPO domains are most important?

    By published exam weight, D1 and D2 are the two largest domains. Together they represent 55 percent of the blueprint.

    That makes them impossible to treat casually.

    But there is a second way a domain becomes important: your personal gap.

    A 10-percent domain can still be the difference between passing and failing if your performance in it is consistently poor. Conversely, a strong 30-percent domain gives you less marginal return if you keep revising material you already handle comfortably while another domain remains weak.

    This is why raw hours studied are a poor readiness metric.

    A candidate can study for 80 hours and remain underprepared if those hours are concentrated in familiar material.

    What should you read for the CDPO exam?

    IIM's current recommended resources include:

    • the Nigeria Data Protection Act 2023;
    • the NDPC Training Manual for Data Protection Officers;
    • the Malabo Convention;
    • Convention 108+; and
    • case studies and industry reports.

    IIM also states that the certification aligns with GDPR and ISO/IEC 27701.

    Do not interpret that list as an instruction to read every international instrument line by line before touching questions. The NDPA and Nigerian regulatory framework should anchor your preparation. Use the wider materials to understand principles, comparison points and international context.

    For a deeper statutory map, read The NDPA 2023 for the CDPO Exam.

    How do you know which domain is holding you back?

    You need domain-level data from questions that are difficult enough to expose your mistakes.

    A single overall score can hide the problem. A 76 percent mock result may contain one domain at 90 percent and another at 52 percent. The average looks reassuring. The underlying pattern is not.

    Vantrel's Vantage Score is designed to show readiness across the blueprint, while the domain view shows where the gap sits.

    That distinction matters because your next study session should be determined by the gap, not by which domain feels easiest to revisit.

    See the CDPO domain-level readiness view.

    Continue in this guide

    Frequently Asked Questions

    How many domains are in the IIM CDPO exam?

    There are five published domains: Legal and Regulatory Frameworks; Data Protection Principles and Compliance; Risk Management and DPIA; Incident Response and Data Breaches; and Governance, Policies and Ethics.

    Which CDPO domain has the highest weight?

    D1, Legal and Regulatory Frameworks, has the highest published weight at 30 percent.

    What percentage of the CDPO exam is D1 and D2 combined?

    D1 is 30 percent and D2 is 25 percent, so together they account for 55 percent of the published blueprint.

    Does IIM publish every subtopic tested inside D1-D5?

    The public certification page publishes the five domain names and their weights, but it does not provide a detailed public list of every exam objective. Candidates should use current IIM materials and the recommended sources for the official scope.

    Should I study every CDPO domain equally?

    No. Equal time ignores the published domain weights. Start with the blueprint, then adjust your study allocation using your own domain performance.

    Sources checked

    The domain names and weights above are based on IIM's public certification page as checked on 7 August 2026. Confirm the current blueprint before your sitting.

    Frequently Asked Questions

    How many domains are in the IIM CDPO exam?

    There are five published domains: Legal and Regulatory Frameworks; Data Protection Principles and Compliance; Risk Management and DPIA; Incident Response and Data Breaches; and Governance, Policies and Ethics.

    Which CDPO domain has the highest weight?

    D1, Legal and Regulatory Frameworks, has the highest published weight at 30 percent.

    What percentage of the CDPO exam is D1 and D2 combined?

    D1 is 30 percent and D2 is 25 percent, so together they account for 55 percent of the published blueprint.

    Does IIM publish every subtopic tested inside D1-D5?

    The public certification page publishes the five domain names and their weights, but it does not provide a detailed public list of every exam objective. Candidates should use current IIM materials and the recommended sources for the official scope.

    Should I study every CDPO domain equally?

    No. Equal time ignores the published domain weights. Start with the blueprint, then adjust your study allocation using your own domain performance.

    Keep building exam readiness

    If this article helped clarify the path, the next step is to turn insight into practice. Explore the platform, choose your exam track, and start preparing with structure.