Short answer
Replace every direct identifier in each CV with a typed, numbered placeholder, keep the key yourself, and scrub the job description too. Name → [PERSON_7], email → [EMAIL_7], phone → [PHONE_7], address → [ADDRESS_7], links → [URL_7]; photo, date of birth and ID number deleted. One number per candidate for the whole batch, kept in a key sheet that never enters the chat; one structured prompt asking for a five-bullet summary and a fit score per candidate; read the output, re-link through the key, delete the chat.
Because you keep a key — and because a career history is itself identifying — this is pseudonymisation, not anonymisation; the data stays personal data under the GDPR and under Israel's Protection of Privacy Law. It is the safeguard regulators recommend; it just doesn't take you outside the rules. See pseudonymisation vs anonymisation.
“Anonymise” is the wrong word — and it matters for the workflow
The GDPR defines pseudonymisation as processing personal data so it can no longer be attributed to a specific person without additional information that is kept separately and protected (Art. 4(5)). Anonymous information cannot be linked to a person by any means reasonably likely to be used — and only that falls outside the Regulation (Recital 26). The EU's data protection authorities spelled out the consequence in Opinion 05/2014 on anonymisation techniques: pseudonymisation is not a method of anonymisation; it merely reduces how easily a record can be linked to an identity.
A screening batch is pseudonymised on purpose: you need to know which candidate scored 9/10, so you keep a key. The honest goal is not “make the CVs anonymous” but “disclose the minimum, keep the key yourself, delete what you don't need”. The GDPR names pseudonymisation as a security measure (Art. 32(1)(a)) and data minimisation as a principle (Art. 5(1)(c)). In Israel, the Privacy Protection Authority's material on Amendment 13 defines personal data as any data about a person identified or identifiable with reasonable effort, directly or indirectly (PPA: Amendment 13, Hebrew) — on that definition, a CV with the name swapped out still qualifies. This guide describes the rules; it is not legal advice.
What to strip and what to keep, by screening task
A fit-to-JD screen needs the substance of the career; a blind or fairness-oriented screen removes more. Decide once per batch and apply the same rule to every CV.
| Field | Fit-to-JD screen | Blind / fairness screen |
|---|---|---|
| Name, email, phone, address, LinkedIn and portfolio links | Placeholder ([PERSON_n], [EMAIL_n] …) | Placeholder |
| Photo, date of birth, ID number, marital status | Delete | Delete |
| Employer names | Keep — they carry the signal you screen for | Replace with a numbered placeholder; keep sector and size in words |
| Job titles, duties, durations | Keep | Keep (durations rather than calendar years) |
| University or school name | Keep | Replace with a numbered placeholder; keep degree level and subject |
| Graduation year | Usually remove — it proxies age | Remove |
| Nationality, visa status, languages, religion, union roles | Remove unless the role requires it | Remove |
| Referees | Placeholder or delete | Delete |
Two things are easy to miss. First, the job description needs scrubbing too: “reports to Dana Cohen (dana@…)”, the client's name on a confidential search, an internal codename — none of it helps the model score a candidate, all of it is disclosure. Second, consistency across the batch: if candidate seven is [PERSON_7] in the header, the footer, the key sheet and the prompt, the model can say “[PERSON_7] is stronger on payments experience” and you can act on it. Numbering that restarts, or a referee who becomes [PERSON_7] on someone else's CV, is how scores land against the wrong person.
The batch workflow, by hand
Complete steps for a batch of 20, using Word, a spreadsheet and any AI tool. Nothing here costs money; all of it costs time.
-
Write the screening criteria before you open a single CV
From the JD, list five to eight must-haves and a few nice-to-haves in plain sentences — “3+ years owning a B2B sales quota”, not “sales experience”. This is what the model scores against; having it first stops you feeding in whole CVs “just in case”. Decide now: fit-to-JD screen or blind screen (table above)?
-
Scrub the job description
Copy the JD into a text file; remove the hiring manager's name and email, internal names, the client's name on a confidential search, and any salary or headcount detail you wouldn't send a candidate. Save it as
jd-scrubbed.txt. -
Make numbered working copies
One folder per batch; each CV saved as a copy named
01.docxto20.docx— never the original, never a file name with the candidate's name in it. PDFs: open in Word (File → Open; Word converts) or ask for a.docx. Scans: transcribe the parts you need; there is no shortcut for text inside a picture. -
Build the key sheet first
Four columns: file number, placeholder ([PERSON_1] … [PERSON_20]), real name, ATS link. Assigning numbers before you edit is what keeps them consistent. Store it where your candidate data already lives — ATS or drive — never in the AI tool.
-
Replace the identifiers in each CV
In Word, Home → Replace (Ctrl+H) → Replace All, so the same value gets the same placeholder everywhere — then check the header and footer by eye: name → [PERSON_7] (the key-sheet number), email → [EMAIL_7], phones → [PHONE_7], address → [ADDRESS_7], links → [URL_7]. Delete the photo, date of birth and any ID number. Referees get their own numbers ([PERSON_21] onwards), never a candidate's. Then File → Info → Inspect Document → remove Document Properties and Personal Information; resolve tracked changes and comments.
-
Apply the employer and school decision
Fit-to-JD screen: leave employer names. Blind screen: replace each employer with [EMPLOYER_n] and each school with [SCHOOL_n], keeping “mid-size logistics company” so the experience still reads. Do it identically on all 20 files.
-
Assemble one structured prompt
Instructions first, then the scrubbed JD and criteria, then the CVs, each under a heading carrying the candidate's placeholder. A prompt that works:
You are helping me screen candidates for the role below. Identifiers have been replaced with placeholders such as [PERSON_3] or [EMAIL_3]. Do not try to work out who anyone is; refer to each candidate only by their placeholder.
JOB DESCRIPTION (identifiers removed):
<paste jd-scrubbed.txt>
MUST-HAVES: 1. … 2. … 3. … NICE-TO-HAVES: 1. … 2. …
For each candidate give: (a) a 5-bullet summary of the experience relevant to this role; (b) a fit score from 1 to 10 against the must-haves, one sentence per must-have saying whether and where the CV meets it; (c) one question to ask at a screening call. Then rank all candidates from highest to lowest score. Do not infer or use age, gender, nationality, health, religion or family status from anything in the text.
### Candidate [PERSON_1]
<paste 01.docx text>
### Candidate [PERSON_2]
<paste 02.docx text>
… through [PERSON_20]Use a setting where the data isn't used to improve the model — ChatGPT Temporary Chat or a Business workspace, Claude Incognito or Claude for Work; see Is it safe to put a CV into ChatGPT?
-
Review the output before you act on it
Spot-check each summary against its CV — models do invent a certification or merge two candidates' histories — and check that no bullet leans on a signal you told it to ignore. Treat the score as a sort order for your reading, not a decision: the GDPR restricts decisions based solely on automated processing that significantly affect a person (Art. 22), and the EU AI Act lists AI that filters applications and evaluates candidates among its high-risk systems (Regulation (EU) 2024/1689, Annex III; obligations phase in).
-
Re-link through the key sheet
Copy each score and summary into your ATS against the real name, via the key sheet — and only there. Note the prompt version and date, so you can say later how the shortlist was made.
-
Delete the chat, the files and the surplus copies
Delete the conversation; in ChatGPT also remove uploaded files from your Library, which deleting the chat doesn't touch (OpenAI's retention policies). Delete the scrubbed copies; keep the key sheet only as long as the screen runs, in your ATS or drive, never in the AI tool.
What the manual method costs
- Per CV
- 6–10 mincopy, key-sheet row, replacements, header/footer, properties
- Per batch of 20
- ≈ 2½–3½ hoursplus JD scrub, prompt assembly, review and re-linking
- What leaks
- Numbering slipsa referee reused as a candidate's number, a footer phone, the file name
Our estimates for a careful recruiter in Word and a spreadsheet; yours will differ. The shape won't: the cost scales with the batch, the key sheet is the step people skip, and the misses hide in fields nobody reads.
What this doesn't solve
- Re-identification from the career history. “VP Engineering at a 40-person Haifa fintech, 2019–2024” names one person without a name. Placeholders reduce linkability; they do not make the CV anonymous — see pseudonymisation vs anonymisation.
- Bias. Removing names does not remove the signals a model can lean on: pronouns, graduation years, school names, language lists, career gaps. Telling it to ignore them helps; it is not proof. See AI screening, bias and blind CVs.
- Your legal footing. Placeholders reduce what you disclose. They do not create a lawful basis, update your candidate privacy notice, sign processor terms or replace an impact assessment (Art. 35). No tool makes you compliant with anything.
-
Scans, images and PDF layout. Sunda protects Word, text and
text-layer PDFs — the kind you can select text in. A protected PDF is rebuilt from
its text, so the words and the page breaks survive but the layout, fonts, columns
and images do not: right for feeding an AI, wrong for forwarding as it is. Scanned
or photographed PDFs are refused rather than returned blank, and so is a PDF written
in Hebrew, Arabic or another non-Latin script — protect those as
.docx. For anything Sunda refuses, steps 3 and 5 above are the method. On a protected site, a PDF you upload still passes through untouched; PDF protection is the popup's file flow only. - Perfect detection. Emails, phone numbers, ID and card numbers are caught reliably by rules. Names and addresses depend on the optional on-device model and will miss some; employer and school names are left to you. Read the output before it leaves your machine.
Questions recruiters ask
Is replacing names with placeholders the same as anonymising the CVs?
No. Under the GDPR, data that can still be attributed to a person with the help of separately kept information is pseudonymised (Article 4(5)); only data that cannot be linked to a person by any means reasonably likely to be used is anonymous (Recital 26). A screening batch with a key sheet is pseudonymised by design — you intend to re-link the scores. It remains personal data; the placeholders reduce what you disclose.
Should I remove employer names before AI screening?
For a fit-to-JD screen, usually keep them: the model reads “four years at a payments scale-up” very differently from “four years at [EMPLOYER_2]”, and that judgement is what you are asking for. For a blind or fairness-oriented screen, replace employers and schools with numbered placeholders and keep job titles, duties and durations. Decide once per batch and apply it to every CV, or the scores will not be comparable.
Can I screen a batch of 20 CVs in a single prompt?
In practice yes, if each CV is clearly delimited and labelled with its own placeholder, and the instructions come before the CVs. Long batches do degrade: if the summaries turn vague or the model starts mixing candidates, split into two batches of ten and keep the same numbering. The numbering is what lets you compare across batches and re-link afterwards.
Is an AI fit score an automated decision under the GDPR?
Article 22 of the GDPR concerns decisions based solely on automated processing with legal or similarly significant effects on the person. A score a recruiter reads, checks against the CV and can override is support for a human decision; a score that silently rejects candidates is closer to what Article 22 restricts. The EU AI Act also lists AI used to filter applications and evaluate candidates among its high-risk systems. The UK ICO publishes guidance on AI and recruitment; this guide describes the rules and is not legal advice.