#13129

Dear Michael,

Thank you for your thoughtful contribution and for raising an important discussion regarding the validity and recertification cycle of the IIM Certified Data Protection Officer (IIM-CDPO®).

Your observations regarding other certification models and the potential administrative benefits of longer certification cycles are well noted. IIM continually reviews its certification framework to ensure that it remains relevant, credible and responsive to professional and regulatory developments.

It is, however, important to clarify that the annual recertification cycle for the IIM-CDPO® is deliberate and reflects the particular nature and purpose of this certification.

The IIM-CDPO® is one of IIM’s specialist professional certifications, with a significant focus on supporting professional competence and compliance within Nigeria’s data protection regulatory environment. The Nigeria Data Protection Act 2023 establishes ongoing accountability and compliance obligations, and applicable organisations are required to undertake annual compliance audit activities. A Data Protection Officer therefore operates in a compliance environment that calls for continuing professional currency, not competence demonstrated once every several years and left unverified in between.

For this reason, IIM considers the 12-month certification and recertification cycle appropriate for the IIM-CDPO®. Annual recertification provides an opportunity to verify Continuing Professional Development (CPD), maintain current professional standing, and ensure that certified professionals remain abreast of developments in data protection law, regulatory guidance, technology, AI, cybersecurity, enforcement and privacy governance.

It is also worth distinguishing the IIM-CDPO® from IIM’s broader professional certification portfolio. Other applicable IIM professional certifications generally operate on a three-year validity and renewal cycle. The annual model is therefore not IIM’s universal certification approach; it reflects the specialist, compliance-oriented character of the CDPO credential.

Importantly, the IIM-CDPO® pathway already provides for professional progression. A certified professional who successfully maintains the IIM-CDPO® through three consecutive annual recertification cycles, subject to the applicable requirements, becomes eligible to progress to IIM’s Master-level certification: the IIM Certified Data Privacy Professional (IIM-CDPP®).

The IIM-CDPP® recognises a higher level of sustained professional development, experience and commitment to the data privacy profession, and operates on a three-year renewal cycle.

The pathway can therefore be understood as:

IIM-CDPO® → Annual CPD & Recertification → Three Continuous Recertifications → Eligibility for IIM-CDPP® Master Certification → Three-Year Renewal Cycle

This structure intentionally combines annual competence assurance at the specialist CDPO level with longer-term professional recognition and progression at the Master Certification level.

We nevertheless appreciate your proposal. Constructive contributions such as this are valuable, because certification frameworks must continue to evolve alongside the profession. IIM will continue reviewing its certification and recertification policies against regulatory requirements, professional practice and relevant international conformity-assessment principles.

Thank you again for initiating this important professional discussion and for your continued commitment to the IIM-CDPO® community.

Best regards,

Lasisi Abiodun A. (AMAL)
For: Head of Certification
IIM Africa

  • This reply was modified 5 days, 17 hours ago by Cert Portal.