CAIC-DP-F · Foundation grade · Compliance
Certified AI Compliance Foundation — Data Protection
Data protection applied to AI: automated decision-making under GDPR Article 22, data protection impact assessments, and privacy by design in systems that learn from personal data.
- Reference
- CAIC-DP-F
- Level
- Foundation
- Examination
- 2 hours
- Delivery
- Remote, proctored
- Credential
- Valid 2 years
§ 1 — Intended candidates
Who this certification is for
The competency standard at the intersection of data-protection law and AI systems — the questions a privacy or compliance professional faces the moment personal data meets a model.
Who it is for. Privacy officers, data protection officers, and compliance and legal professionals responsible for AI that processes personal data.
- Prerequisites
- No formal prerequisites. Candidates are expected to have professional experience in a privacy, legal, compliance, or risk function.
- Status
- Open for registrationOpen for registration · Examinations from October 2026
This is the Foundation grade of the AI Compliance — Data Protection family — Practitioner and Fellow follow it.
§ 2 — Examination domains
What the examination covers
The examination is mapped to the GDPR and general data-protection law as they apply to AI systems. Weightings are indicative until each syllabus issues.
- 01
Data-protection foundations applied to AI25%
Lawful basis, minimisation, and purpose limitation applied to systems that learn from personal data.
- 02
Automated decision-making and profiling20%
GDPR Article 22 and its limits: when a decision is solely automated, and what meaningful human involvement requires.
- 03
Impact assessments for AI20%
When an AI deployment triggers a DPIA, scoping one that actually examines the model, and acting on what it finds.
- 04
Privacy by design and default20%
Privacy by design and default across the model lifecycle, from training data through deployment.
- 05
Rights, transparency, and transfers15%
Data-subject rights, transparency obligations, and cross-border transfer considerations.
Curriculum mapping indicates alignment of learning content with published frameworks. It does not constitute endorsement by, or certification under, any standards organisation or regulator.
§ 3 — Preparation
What preparation is anchored to
Anchored to the GDPR text and recognised regulatory guidance, adaptable to local regimes such as the Singapore PDPA in preparation. Candidates prepare independently against the published materials.
The Council certifies individuals — it sells no preparation of any kind, and how a candidate prepared is never visible to an assessor. How impartiality is protected.
§ 4 — How to certify
One route: the examination
Register through the candidate portal, verify your identity once, and sit. On a pass, the credential and its public register entry are issued.
The full rules — registration, identity verification, examination conduct, adjustments, retakes — are in the candidate handbook.
Fees and the pass standard are fixed in the scheme rules and confirmed ahead of the October 2026 examination window.
§ 5 — Assessment
How candidates are assessed
Examination centred on a supplied AI deployment processing personal data, requiring the applicable data-protection analysis and its consequences for the design.
Every script is marked twice — an AI assessor first and provisional, an independent human assessor second and final. The credential carries a unique identifier any employer can check on the public register.
§ 6 — Questions
Questions about this certification
- What are the prerequisites?
- No formal prerequisites. Candidates are expected to have professional experience in a privacy, legal, compliance, or risk function.
- When can I sit the examination?
- Registration is open now through the candidate portal; examination sittings run from the October 2026 window and are scheduled at booking.
- How is the examination marked?
- Every script is marked twice, in a fixed order: an AI assessor first, producing a provisional mark, and an independent human assessor second, whose determination is final on any divergence. No result is issued on automated marking alone, and no adverse decision — a fail, a suspension, a withdrawal — is ever made without a human assessor.
- How long is the credential valid?
- 2 years from the date of issue, recorded on the public register. The term and what follows it are set out in the revalidation policy.
Scheme-wide questions are answered on the FAQ and in the candidate handbook.
§ 7 — Further reading
Background reading
- What is AI assurance? A practitioner's definition
Producing credible, independently reviewable evidence that an AI system works as intended — and how that differs from governance and compliance.
- How to build an AI risk profile for a deployment
A seven-step method for producing a risk profile a sceptical reader can challenge, with the failure mode at each step and what the finished artefact contains.
§ 8 — Register
Register for this examination
Create a candidate account and register now; sittings are scheduled from the October 2026 examination window, and fees are confirmed ahead of it. The marking standard is identical however you prepared.
Register — candidate portal