- This topic has 1 reply, 2 voices, and was last updated 2 weeks, 1 day ago by
Cert Portal.
-
AuthorPosts
-
August 30, 2026 at 10:02 am #13054
Dear IIM Community,
As the regulatory and professional landscape for data protection continues to evolve, it is important that we periodically review whether our professional certification models remain practical, competitive and supportive of long-term career development.
The IIM Certified Data Protection Officer (IIM-CDPO) currently carries a 12-month validity period, with renewal requiring the applicable renewal fee and 20 CPD points.
While annual CPD requirements encourage continuous professional development, I believe the Institute of Information Management (IIM) could consider whether a **2- or 3-year certification cycle** would provide a more sustainable model for certified professionals while maintaining the Institute’s professional standards.
Why Consider a Longer Certification Cycle?
1. Greater Alignment with Established Professional Certification Models
Several established cybersecurity and information-security professional certifications operate on multi-year certification cycles supported by continuing professional education requirements. For example, CISSP and CISM operate on three-year certification cycles with ongoing CPE requirements.
A similar approach could position the IIM-CDPO as a longer-term professional credential while retaining continuous learning as a core requirement.
2. Continuous Professional Development Can Still Be Maintained
Moving from an annual renewal cycle does not necessarily mean reducing professional development requirements.
For example, under a three-year model, the existing annual CPD expectation could potentially be accumulated progressively over the certification period, subject to whatever structure IIM considers appropriate.
This would preserve the principle of continuous learning without requiring professionals to undergo a full renewal process every 12 months.
3. Reduced Administrative and Financial Burden
Annual renewal creates recurring administrative requirements for both certified professionals and the Institute, including CPD tracking, verification and certification renewal.
A longer certification cycle could reduce this administrative burden while allowing professionals to focus more attention on substantive privacy and compliance work.
4. Strengthening the Long-Term Value of the IIM-CDPO
The IIM-CDPO is increasingly relevant as organisations across Nigeria establish formal data-protection programmes and appoint qualified privacy professionals.
A 2- or 3-year certification cycle could potentially strengthen the perception of the credential as an established professional designation, particularly when combined with robust CPD requirements and appropriate professional conduct obligations.
A Possible Model
I would suggest that IIM consider either:
Option A — Three-Year Certification Cycle
* Three-year certificate validity;
* Continuing CPD requirements throughout the certification period;
* Periodic CPD reporting or verification;
* Renewal at the end of the three-year cycle.Option B — Two-Year Certification Cycle
* Two-year certificate validity;
* Proportionate CPD requirements;
* Renewal at the end of the two-year cycle.The final model, of course, should be determined by IIM based on its certification framework, professional standards and regulatory objectives.
The Broader Question
This is not a question of whether CPD should continue. It should.
The question is whether CPD and certification renewal need to operate on the same 12-month cycle.
As data-protection professionals, we are expected to advise organisations on sustainable governance frameworks, risk management and continuous improvement. It may therefore be worthwhile applying the same thinking to our own professional certification framework.
I would be interested in hearing the views of fellow IIM-CDPO holders, practitioners and IIM leadership:
Would a 2- or 3-year certification cycle provide a better balance between continuous professional development, certification assurance and administrative efficiency?
More importantly, what certification model would make the IIM-CDPO more competitive and recognised within Nigeria and internationally?
I believe this is a conversation worth having as the data-protection profession continues to mature.
Best regards,
Michael Ben Omorowa
Certified Data Protection Officer (IIM-CDPO)September 2, 2026 at 3:51 am #13129Dear Michael,
Thank you for your thoughtful contribution and for raising an important discussion regarding the validity and recertification cycle of the IIM Certified Data Protection Officer (IIM-CDPO®).
Your observations regarding other certification models and the potential administrative benefits of longer certification cycles are well noted. IIM continually reviews its certification framework to ensure that it remains relevant, credible and responsive to professional and regulatory developments.
It is, however, important to clarify that the annual recertification cycle for the IIM-CDPO® is deliberate and reflects the particular nature and purpose of this certification.
The IIM-CDPO® is one of IIM’s specialist professional certifications, with a significant focus on supporting professional competence and compliance within Nigeria’s data protection regulatory environment. The Nigeria Data Protection Act 2023 establishes ongoing accountability and compliance obligations, and applicable organisations are required to undertake annual compliance audit activities. A Data Protection Officer therefore operates in a compliance environment that calls for continuing professional currency, not competence demonstrated once every several years and left unverified in between.
For this reason, IIM considers the 12-month certification and recertification cycle appropriate for the IIM-CDPO®. Annual recertification provides an opportunity to verify Continuing Professional Development (CPD), maintain current professional standing, and ensure that certified professionals remain abreast of developments in data protection law, regulatory guidance, technology, AI, cybersecurity, enforcement and privacy governance.
It is also worth distinguishing the IIM-CDPO® from IIM’s broader professional certification portfolio. Other applicable IIM professional certifications generally operate on a three-year validity and renewal cycle. The annual model is therefore not IIM’s universal certification approach; it reflects the specialist, compliance-oriented character of the CDPO credential.
Importantly, the IIM-CDPO® pathway already provides for professional progression. A certified professional who successfully maintains the IIM-CDPO® through three consecutive annual recertification cycles, subject to the applicable requirements, becomes eligible to progress to IIM’s Master-level certification: the IIM Certified Data Privacy Professional (IIM-CDPP®).
The IIM-CDPP® recognises a higher level of sustained professional development, experience and commitment to the data privacy profession, and operates on a three-year renewal cycle.
The pathway can therefore be understood as:
IIM-CDPO® → Annual CPD & Recertification → Three Continuous Recertifications → Eligibility for IIM-CDPP® Master Certification → Three-Year Renewal Cycle
This structure intentionally combines annual competence assurance at the specialist CDPO level with longer-term professional recognition and progression at the Master Certification level.
We nevertheless appreciate your proposal. Constructive contributions such as this are valuable, because certification frameworks must continue to evolve alongside the profession. IIM will continue reviewing its certification and recertification policies against regulatory requirements, professional practice and relevant international conformity-assessment principles.
Thank you again for initiating this important professional discussion and for your continued commitment to the IIM-CDPO® community.
Best regards,
Lasisi Abiodun A. (AMAL)
For: Head of Certification
IIM Africa-
This reply was modified 2 weeks, 1 day ago by
Cert Portal.
-
This reply was modified 2 weeks, 1 day ago by
-
AuthorPosts
- You must be logged in to reply to this topic.

