Short answer
Replace every direct identifier with a typed, numbered placeholder and delete what nobody needs to screen. Name → [PERSON_1], phone → [PHONE_1], email → [EMAIL_1], address → [ADDRESS_1], LinkedIn and other links → [URL_1]; photo, date of birth, ID numbers and the references section go entirely. Then check where the contact block hides: page header and footer, hyperlink targets, file name, document properties.
Work on a copy, keep a one-line key ([PERSON_1] = the real
candidate) in your ATS, not in the chat, read the result once, and upload that. Word:
Find & Replace plus Inspect Document; Google Docs: Find and replace, then download
as .docx; a PDF you edit by hand gets converted first, a scan transcribed.
By hand, roughly
6–10 minutes a CV (our estimate). The result is pseudonymised, not anonymous — less
exposure, not none.
Which fields to replace — and which to delete outright
A CV carries two kinds of personal data: the direct identifiers in the contact block, and the career history that is the point of the document. Redaction swaps the first for placeholders and deletes what helps nobody screen; the career history stays. (Call it a resume if you like — the fields are identical.)
| Field | Do this | Where it hides |
|---|---|---|
| Full name | [PERSON_1] — same number wherever it appears; a referee becomes [PERSON_2] | Page header and footer, file name, “Author” property |
| Phone numbers | [PHONE_1], [PHONE_2]… | Often written twice in two formats (+44 7700 900123, 07700 900123) — both get one placeholder |
| Email address | [EMAIL_1] | Also the mailto: link behind the text — remove the link, not just the words |
| Postal address | [ADDRESS_1] (or cut to the city if the role needs one) | Contact block; sometimes only the footer |
| LinkedIn, portfolio, GitHub URLs | [URL_1], [URL_2]… | The link target behind “LinkedIn” can differ from the visible text; Markdown shows it in brackets |
| Date of birth, age | Delete the line; if a numeric date must stay, [DATE_1] | A “Personal details” block — delete nationality and marital status with it |
| ID, passport, NI, licence numbers | Delete the line; an Israeli ID you must keep a reference to → [ISRAELI_ID_1] | “Personal details” block; occasionally the footer |
| Photo | Delete the picture | Body, header or sidebar; nothing can redact inside an image |
| References | Delete the section | Referees' details are third parties' data you do not need to screen |
| Page header and footer | Open them and edit by eye | Name and phone repeat here on most templates; do not assume Replace All reached them |
| File name | Rename to a neutral code: candidate-a.docx |
AI tools display and store it |
| Document properties | Inspect Document → Remove All | Author, Last modified by, Company, Title |
| Comments and tracked changes | Accept or reject all; delete all comments | Reviewer names and deleted text stay in the file until you do |
Why these fields? They are personal data in its most direct form — the GDPR's definition names name, identification number, location data and online identifiers (Art. 4(1)) — and the minimisation principle says processing should be “limited to what is necessary” (Art. 5(1)(c); the UK ICO's guide to the principles). According to Israel's Privacy Protection Authority, Amendment 13 to the Protection of Privacy Law defines personal data just as broadly, and “minimise data you don't need” is among the basic steps the Authority suggests (PPA on Amendment 13). Screening needs the career history, not a phone number. This guide describes the rules; it is not legal advice.
The placeholder convention, with a before and after
Use typed, numbered placeholders in square brackets: [PERSON_1], [PHONE_1], [EMAIL_1], [ADDRESS_1], [URL_1], [DATE_1], [ISRAELI_ID_1]. Three rules make them work:
- The type says what was there. The model can still write “[PERSON_1] has six years of payroll experience — contact via [EMAIL_1]”.
- The number says which one. The same value gets the same number everywhere; a second, different phone number is [PHONE_2]. That is what lets you map the output back.
- The key stays with you. One line per CV — [PERSON_1] = the real candidate — in your ATS, never in the chat or the uploaded file.
Avoid blanks, “XXX” and “REDACTED” (they lose the type) and invented names (the model cannot tell they are fake; nor can a colleague). A fictional contact block, before and after — phone number and email domain are reserved example values, the address is made up, and everything below the contact block stays as it was:
| Before | After |
|---|---|
| Jordan Reyes | [PERSON_1] |
| +44 7700 900123 · jordan.reyes@example.com | [PHONE_1] · [EMAIL_1] |
| 14 Maple Street, Manchester M1 4AB | [ADDRESS_1] |
| Portfolio: https://www.example.com/jordan-reyes | Portfolio: [URL_1] |
| Date of birth: 03/05/1991 · photo · ID number | Lines deleted |
File: Jordan_Reyes_CV_2026.docx |
File: candidate-a.docx |
| Properties → Author: Jordan Reyes; 2 comments; tracked changes | Author blank; comments and revisions removed |
Word, Google Docs, plain text and PDF: what's different
- Word (.docx). Find & Replace does the swapping; Inspect Document clears properties, comments and revisions. Common misses: page header and footer, hyperlink targets, the Author property.
- Google Docs. Edit → Find and replace works on the text; there is no Inspect Document. For a file, File → Download → Microsoft Word (.docx) — a copy; the Doc keeps its version history. Clear comments and suggestions first: they can travel with the export.
-
Plain text and Markdown (.txt, .md). Nothing is hidden, but everything
is visible — link targets like
[LinkedIn](https://…), any front-matter block (name:,email:). Your editor's Replace (Ctrl+H) does it. -
PDF. A black rectangle drawn in a viewer does not remove the text under
it — text extraction brings it straight back; Adobe Acrobat Pro's Redact does remove it.
To edit one by hand, convert (File → Open in Word) or ask for the
.docx. Scans and photos convert to nothing useful — transcribe what you need into a text file. Sunda takes a text-layer PDF — the kind you can select text in — straight from the popup and writes a redacted PDF back; it refuses a scan rather than returning a blank one, and the file it writes keeps the words and the page breaks, not the layout, fonts or images.
The manual method, step by step
The complete steps for one CV. The clicks are Word's; Google Docs and text-editor equivalents are noted where they differ.
-
Get an editable file and work on a copy
PDF: converting is what makes it editable by hand, and the only way to keep the layout — File → Open → pick the PDF → OK on the conversion prompt, or ask for the
.docx. Google Doc: File → Download → Microsoft Word (.docx). Scan or photo: transcribe what you need into a text file; never upload the image. Save the copy ascandidate-a.docxnow; leave the original where your candidate data already lives. -
Strip the hyperlinks
Word: Ctrl+A, then Ctrl+Shift+F9 (Unlink fields) — the visible text stays, the link targets go; or right-click a link → Remove Hyperlink. Google Docs: click the link → Remove link. Text and Markdown: the target is already plain text; replace it in the next step.
-
Replace the contact block with Find & Replace
Word: Home → Replace (Ctrl+H). Find what:
Jordan Reyes; Replace with: [PERSON_1]; Replace All. Repeat for each phone number in every format it is written, the email, the address and each URL. Google Docs: Edit → Find and replace (Ctrl+H). Text editors: Ctrl+H. Same value, same placeholder, every time; the next distinct value takes the next number. -
Delete what nobody needs to screen
The photo (click it → Delete), date of birth or age, ID, passport and NI numbers, nationality, marital status, and the whole references section. If a numeric date or an Israeli ID must remain as a fact, write [DATE_1] or [ISRAELI_ID_1] rather than the value.
-
Open the page header and footer
Word: double-click the header area, or Insert → Header → Edit Header (likewise the footer). Google Docs: Insert → Headers & footers. Replace or delete what is there by eye; a second phone number in the footer is the most common miss.
-
Remove the hidden layer
Word: File → Info → Check for Issues → Inspect Document → Inspect, then Remove All for “Comments, Revisions and Versions” and “Document Properties and Personal Information” (it also flags headers, footers and hidden text). By hand: Review → Accept → Accept All Changes and Stop Tracking; Review → Delete → Delete All Comments in Document. Google Docs: resolve comments, then Tools → Review suggested edits → Accept all or Reject all before you download.
-
Read it once, top to bottom
Look for the value you did not know was there: a mobile number under a signature line, an email in a project description, a name in a running header, a referee's phone — what Replace All cannot see.
-
Save, keep the key, upload the copy, clean up
Save under the neutral name; add one line to the candidate's record — [PERSON_1] = Jordan Reyes. Upload the copy in an account or setting where your data is not used to improve models (see is it safe to put a CV into ChatGPT?). Afterwards delete the chat and, in ChatGPT, the file from your Library — deleting the chat does not delete the file (source: OpenAI's Chat and File Retention Policies).
What the manual method costs
- Per CV
- 6–10 minreplace, delete, header and footer, inspect, read-through
- At 15 CVs a day
- ≈ 2 hoursevery day, before any screening happens
- What leaks
- What Replace All can't seea link target, the footer, the Author field, the file name
Our estimates for a recruiter working carefully in Word; yours will differ. The shape won't: the cost is per CV, every time, and the misses live outside the body text.
What this doesn't solve
- Re-identification from the rest of the CV. A rare employer, an unusual sequence of roles or a niche skill set can still point at one person: pseudonymised, not anonymous — see pseudonymisation vs anonymisation.
- Your legal footing. Placeholders reduce what you disclose. They do not create a lawful basis, update your candidate privacy notice or sign a processor agreement. No tool makes you compliant with anything.
- Scans, layout — and Google Docs in the browser. Sunda reads Word (.docx), .txt, .md and text-layer PDF files. It refuses a PDF with no text in it — a scan or a photo — instead of handing back a blank page, there is no OCR, and it refuses a PDF whose text is Hebrew, Arabic or another non-Latin script: protect that one as .docx. A redacted PDF is a fresh document built from the text, so it keeps the words and the page breaks but not the layout — right for feeding an AI, wrong for forwarding to a client as it stands. Download a Google Doc as .docx first — the extension works on files, not on the Doc open in a tab.
-
Perfect detection. Rules catch emails, phone numbers in common formats,
URLs starting
http://,https://orwww.(a barelinkedin.com/in/nameis not caught), numeric dates, IBANs, card numbers and checksum-valid Israeli IDs. Names, addresses and written-out dates depend on the optional on-device model (about 900 MB, downloaded once; WebGPU, Chrome 138+) and will miss some. Employer names, job titles, universities and photos are deliberately left alone. Read the output before you share it. -
The rest of the checklist. Deleting the photo, clearing properties and
comments, and the read-through stay yours — and the output keeps the input's file name
plus
.redacted, so rename it yourself.
Questions recruiters ask
Should I also remove employer names, universities and job titles?
For a normal screen, usually not: they are how you judge experience. For a blind or fairness-oriented screen, remove universities, graduation years and anything that signals age, gender, ethnicity or religion, and consider replacing employers with sector and size. Either way, a distinctive sequence of employers and dates can identify a person on its own — redaction reduces exposure; it does not make the CV anonymous. See our guide on AI screening, bias and blind CVs.
Is a redacted CV anonymous under the GDPR or Israeli law?
No. Swapping identifiers for placeholders while you hold the key is pseudonymisation as the GDPR defines it (Art. 4(5)), and Recital 26 says pseudonymised data is still personal data. Israel's Protection of Privacy Law likewise defines personal data as any data about an identified or identifiable person. Pseudonymisation is still worth doing — Art. 32 names it as a security measure — but the usual rules keep applying to the redacted copy.
Is it safer to paste the text than to upload the file?
Pasting avoids the file-specific behaviour — in ChatGPT, uploaded files can be saved to your Library and are not removed when you delete the chat — and a Ctrl+A copy from the body of a Word document leaves the page header, footer and properties behind. But pasted text is still sent to and stored by the provider under its chat-retention rules, so redact before you paste, exactly as you would the file.