Short answer
A CV is personal data, so the GDPR applies in full the moment it goes into an AI tool. Nothing in the regulation bans AI in recruitment and nothing exempts it. Uploading a CV is “processing”, so the ordinary requirements attach: a lawful basis (Art. 6), a candidate notice that covers the tool (Art. 13), data minimisation (Art. 5), security with pseudonymisation named as a measure (Art. 32), a processor contract where the vendor works on your behalf (Art. 28), and an impact assessment where AI screening is systematic (Art. 35).
In practice the rules reward three things done before you upload: tell candidates, write down why, and send as little identifying data as the task needs. This guide describes the rules; it is not legal advice.
A CV is personal data — and that decides everything else
Article 4(1) defines personal data as any information relating to an identified or identifiable natural person — identifiable directly or indirectly by a name, an identification number, location data, an online identifier, or factors specific to their physical, economic, cultural or social identity. A CV is that definition written out, from the header to the last employer. There is no neutral paragraph in it.
That triggers the Article 5 principles — purpose limitation, data minimisation (“adequate, relevant and limited to what is necessary”), storage limitation, integrity and confidentiality — plus accountability (Art. 5(2)): the controller has to be able to demonstrate all of it, which is why “write it down” recurs below. The ICO's guide to the principles is the plainest official explanation.
CVs also carry special-category data by accident: a photo, a religious school, a union role, a disability-related gap. Article 9 prohibits processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health, sex life or sexual orientation, and genetic or biometric data, unless one of its exceptions applies. It travels with the upload unless you remove it.
Lawful basis and the candidate notice
Article 6 lists six lawful bases and requires one for every processing activity. Recruiters commonly rely on two, and neither is consent: steps taken at the request of the data subject prior to entering into a contract (Art. 6(1)(b)), and legitimate interests (Art. 6(1)(f)) — in the ICO's description a three-part test of interest, necessity and balance, which it recommends recording. Which fits your use of AI is a judgement about your process. Consent sits awkwardly: Recital 43 presumes it is not freely given where there is a clear imbalance between the parties, and a person who wants the job is in that position.
Article 13 is the one most often missed. When you collect data from the candidate it requires them to be told, at the time: the controller; the purposes and legal basis; the legitimate interests pursued; the recipients or categories of recipients; any transfer outside the EU/EEA; the retention period; their rights; and any automated decision-making including profiling. An AI vendor processing CVs on your behalf is a recipient. A notice written before you used AI tools is almost certainly silent on this.
Vendor contract, security, impact assessment, automated decisions
Processor contract. Where a vendor processes personal data on your behalf, Article 28 requires a binding contract: processing only on your documented instructions, confidentiality, security, control of sub-processors, help with requests and breaches, deletion or return at the end. Vendors publish such terms for business, enterprise and API tiers; whether they cover the plan you log into is answered by that plan's terms (training settings are a separate question — step 3). Most AI vendors are US companies, so the CV usually leaves the EEA; Chapter V permits that only under a transfer mechanism — an adequacy decision or appropriate safeguards such as standard contractual clauses — which the vendor's terms will name.
Security. Article 32 requires measures appropriate to the risk, and the first it names is “the pseudonymisation and encryption of personal data”. Article 4(5) defines pseudonymisation as processing so that the data can no longer be attributed to a person without additional information kept separately — placeholders in the document, the key somewhere else. Recital 26 is explicit that pseudonymised data is still personal data.
Impact assessment. Article 35 requires a DPIA where processing is likely to result in a high risk, and its first example is “a systematic and extensive evaluation of personal aspects … based on automated processing, including profiling” on which significant decisions are based. A tool that scores or ranks applicants is close to that wording; a one-off summary of one CV is further from it. Each supervisory authority publishes a list of operations that always need one (Art. 35(4)); the ICO's AI and data protection hub covers DPIAs for AI.
Automated decisions. Article 22 gives people the right not to be subject to a decision “based solely on automated processing, including profiling” with legal or similarly significant effects — Recital 71 names “e-recruiting practices without any human intervention” as its example. Where the decision is necessary for a contract (Art. 22(2)(a)) or based on the candidate's explicit consent (Art. 22(2)(c)), Article 22(3) still requires at least the right to human intervention, to express a point of view and to contest the decision; where it is authorised by Union or Member State law (Art. 22(2)(b)), that law itself has to lay down suitable safeguards. The Article 29 Working Party's guidelines on automated decision-making, endorsed by the EDPB (WP251rev.01), add that the human involvement has to be meaningful, not a rubber stamp.
The UK, the EU AI Act and Israel
UK GDPR. The UK kept the regulation's structure and article numbers, so the above reads across, with the ICO as regulator and its AI hub as the starting point; the Data (Use and Access) Act 2025 (section 80) rewrites the UK rules on automated decision-making. For the EU, the European Data Protection Board publishes the guidelines national authorities apply.
EU AI Act. Regulation (EU) 2024/1689 lists in Annex III, as high-risk, AI systems intended for “the recruitment or selection of natural persons … to analyse and filter job applications, and to evaluate candidates”, with obligations for providers and duties for deployers — human oversight, informing the people subject to the system — phasing in over 2026–2027 (check the Official Journal text for dates). Whether a general-purpose chatbot used ad hoc to summarise CVs is a “high-risk AI system” turns on the Act's definitions and Commission guidance; the GDPR applies regardless.
Israel. Amendment 13 to the Protection of Privacy Law, in force since 14 August 2025, defines personal data as any data relating to an identified or identifiable person and gives the Privacy Protection Authority administrative-fine powers — see the PPA's Amendment 13 pages.
Before you upload: the manual checklist
These steps cover the articles above without any tool. The first five are done once; the last three are per CV, every time.
-
Update the candidate privacy notice
Wherever candidates first see it — careers page, application acknowledgement, agency registration. Add the AI tools you use as a recipient or category of recipients, the purposes, the legal basis (and, for legitimate interests, what they are), the retention period, any transfer outside the EU/EEA, and whether any decision is automated — the Article 13 items.
-
Write down the lawful basis — one page is enough
Which Article 6 basis, for which activity, and why. For legitimate interests, the ICO's three parts: the interest, the necessity, the balance against the candidate's rights. Date it and file it; Article 5(2) is satisfied by evidence, not intention.
-
Read the terms of the plan you actually log into
Two separate questions: is there a processor agreement binding the vendor to your instructions for this plan (Art. 28), and does it use your content to improve models? As of August 2026 OpenAI states that ChatGPT Business, Enterprise, Edu and the API are not used for training by default (enterprise privacy page) and that consumer chats can be unless “Improve the model for everyone” is off (Data Controls FAQ); Anthropic's equivalent article covers Claude. No processor document for your plan is itself an answer.
-
Turn training off and use a disposable chat
ChatGPT: Settings → Data Controls → Improve the model for everyone off, or a Temporary Chat per CV. Claude: Settings → Privacy → model improvement off, or an Incognito chat. Gemini: review your Gemini Apps Activity settings.
-
Decide — and record — whether a DPIA is needed
Put your use against the Article 35(3)(a) wording and your authority's published list. One assessment may cover a set of similar operations, so one document can describe “AI-assisted screening” as a whole. If none is needed, keep the note saying why.
-
Minimise, then pseudonymise, per CV
Remove what the task does not need — photo, date of birth, ID number — then replace the identifiers with placeholders: name → [PERSON_1], phone → [PHONE_1], email → [EMAIL_1], address → [ADDRESS_1], links → [URL_1], using Find & Replace → Replace All; check header, footer, file name and document properties. Keep the key in your ATS, not in the chat. Field by field: how to redact a CV before using AI.
-
Keep a person in the decision
A human reads the summary or score and decides on more than the score, and your process notes say so — that is what “solely automated” in Article 22 turns on, and what the AI Act's human-oversight duty for deployers points at.
-
Apply the retention period and delete
Delete the chat and, in ChatGPT, the file from your Library — deleting the chat does not remove it (OpenAI's retention page). The period in your notice applies to the copies that ended up in AI tools too.
What the manual method costs
- Set-up, once
- 4–8 hoursnotice, basis record, vendor terms, DPIA screening
- Per CV, every time
- 6–10 minminimise, pseudonymise, check, delete afterwards
- The real cost
- Uncertaintynot knowing whether the step you skipped was the one that mattered
Our estimates for a small team doing this carefully without legal help; your numbers will differ. The set-up is bearable. The per-CV work is what quietly stops happening by Thursday, and the uncertainty is what you carry when it does.
What this doesn't solve
- Your legal footing. Placeholders reduce what you disclose. They do not create a lawful basis, update your notice, sign a processor agreement or write a DPIA. No tool makes you compliant with anything.
- Re-identification from the rest of the CV. A pseudonymised CV is still personal data (Recital 26): a unique employer sequence or a rare specialism can point at one person. See pseudonymisation vs anonymisation.
- The vendor's side. Replacing identifiers changes what you send, not what the vendor keeps or for how long. Training settings, Library files and the contract are still yours.
-
Scans, images and PDF layout. Sunda reads Word, text and text-layer
PDFs — the kind you can select text in. A scanned or photographed CV has no text layer,
so it is refused with a message rather than returned blank; there is no OCR. A PDF whose
text is Hebrew or another non-Latin script is refused too, and has to be protected as
.docx. And a redacted PDF is rebuilt from the text, so it keeps the words and the page breaks but not the layout, fonts, images or tables — right for feeding an AI, wrong for forwarding to a client as it stands. For a scan or a non-Latin PDF, step 6 above is the method. - Perfect detection. Emails, phone numbers, IBANs, card numbers, Israeli ID numbers and numeric dates are caught by rules; names and addresses depend on the optional on-device model and will miss some. Read the output before sharing it.
Questions recruiters ask
Do I need a candidate's consent to put their CV into an AI tool?
The GDPR does not single out consent: Article 6 lists six lawful bases. Recruiters commonly rely on steps taken at the candidate's request before a contract (Art. 6(1)(b)) or on legitimate interests (Art. 6(1)(f)); Recital 43 presumes consent is not freely given where there is a clear imbalance between the parties. Whichever basis applies, Article 13 says the candidate has to be told what it is. This guide describes the rules; it is not legal advice.
If I redact the CV first, does the GDPR still apply?
Yes. Replacing names, phones and emails with placeholders is pseudonymisation under Article 4(5): the data can still be attributed to the person with the key you keep, so under Recital 26 it remains personal data. The GDPR treats pseudonymisation as a safeguard (Article 32 names it as a security measure), not as an exit. Only data no longer linkable to a person by any reasonably likely means is anonymous, and a distinctive career history rarely gets there.
Is a DPIA required before I use ChatGPT to screen candidates?
Article 35 requires one where processing is likely to result in a high risk, and names as an example a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which significant decisions are based. Each supervisory authority also publishes a list of operations that always require one (Art. 35(4)). One assessment may cover a set of similar operations, so a single DPIA can describe your AI-assisted screening as a whole.
What does the EU AI Act change for recruiters?
Regulation (EU) 2024/1689 lists AI systems intended for the recruitment or selection of natural persons — including analysing and filtering applications and evaluating candidates — as high-risk in Annex III, with obligations for providers of those systems and duties for organisations deploying them, phasing in over 2026–2027. Whether a general-purpose chatbot used ad hoc to summarise CVs counts as such a system turns on the Act's definitions and Commission guidance; the GDPR applies either way.