Having ChatGPT sort through a stack of CVs is tempting, and many recruiters already do it. But two problems arise at once. First the GDPR: a CV is full of personal data (name, age, address, phone, sometimes a photo) that then goes to a third-party service. Then discrimination: if the AI sees the name, the assumed gender, the age or the origin, it can reproduce bias, exactly what a pre-screening is meant to avoid. Data protection authorities watch AI in recruitment closely. The good practice is to anonymize CVs before the pre-screening, so the AI judges on skills, not identity.
You mask what can bias screening (name, age, location) ; you keep the skills and experience, the only relevant criteria.
The double risk: personal data and bias
A CV sent raw to an AI carries two stacked risks. On the personal data side, you expose the identity and contacts of candidates who never asked for it, outside your control. On the fairness side, the name, photo, age or address steer the sorting, even involuntarily. Removing these before the AI handles both at once.
What to remove from a CV before the AI
- Name and first name: the strongest signal of origin and gender bias.
- Age and date of birth: to avoid age-based sorting.
- Photo: to be removed, including when the CV is a scan.
- Address and contacts: so you do not sort on where someone lives.
- Indirect clues: nationality, graduation year that reveals age, and so on.
The method, without changing your process
- 1. Pseudonymize each CV: identity, contacts, age and photo become neutral tokens.
- 2. Pre-screen with the AI on the masked version: it ranks on skills and expérience, not identity.
- 3. Re-identify the shortlisted candidates locally, to contact them. The key stays with you.
The framing: data protection and fairness
Regulators stress that AI in recruitment must stay fair, transparent and non-discriminatory, and that a décision should not be fully automated without human involvement. Pre-screening anonymized CVs reduces candidate data exposure and makes the sorting more explainable. It is not compliance on its own, but it is a concrete step in the right direction.
The limits to keep in mind
- The AI does not decide for you. Pre-screening assists, the human decides. A fully automated décision about people is regulated.
- Detection is not perfect. No tool catches 100% of cases, a review is still useful.
- Scanned CVs. A CV as an image contains text and a photo: you must OCR it and remove the photo, otherwise the leak goes through the image.
Pseudonymization or anonymization?
For recruitment you usually want to re-identify shortlisted candidates after the pre-screening: that is pseudonymization (réversible, tokens such as PERSONNE_1, key kept on your side). Anonymization is irréversible, useful only if you never need to recover the identity. Better to know which one you are doing.
Safe-Doc pseudonymizes CVs and HR files before the AI, also removes the photo from scanned CVs, and lets you re-identify shortlisted candidates locally. Processing in the European Union then purged, key under your control. For sector détails, see the Safe-Doc for HR page.
Test on a stack of CVs, réversible pseudonymization, skills-focused screening.