Short answer
There is no “safe AI tool” for candidate data — only a safe way of using one. A tool is acceptable for CVs if it does not train on your inputs by default, lets you control and delete what it keeps, says where it processes data and will sign a data processing agreement, and gives one person admin control over who is in it. As of August 2026 it is the business tiers of the major assistants whose published terms address the first test; consumer accounts need settings changed; none undoes the fact that a third party now holds a copy.
The bigger lever sits before the tool: strip identifiers before CVs go in, write a one-page rule the whole team follows, keep the key where your candidate data already lives, and delete on a schedule. A small team can set that up in an afternoon.
Why “small team” changes the answer
An enterprise that adopts AI gets a security review, a signed data processing agreement, single sign-on and someone whose job includes deleting things. A small agency gets a Plus subscription on a personal card, a login shared between two consultants, and nobody who owns deletion. Same tools; the controls around them are missing.
The rules do not scale down. A CV is personal data from the first line to the last, so the GDPR's principles bind a three-person agency as they do a three-thousand-person one: data minimisation, storage limitation, integrity and confidentiality (Art. 5); a contract with any vendor processing candidate data on your behalf (Art. 28); and security measures appropriate to the risk, with pseudonymisation named as one (Art. 32) — the UK ICO keeps a hub on AI and data protection. In Israel, Amendment 13 to the Protection of Privacy Law (in force since 14 August 2025) defines personal data as any data relating to an identified or identifiable person, and the Privacy Protection Authority suggests basic steps for any organisation — map your databases, set an information-security procedure, minimise data you don't need, prepare a database-definitions document, check whether the data protection officer duty applies. This guide describes the rules; it is not legal advice.
Six checks before you let a tool near a CV
Apply these to whatever you already use; the right-hand column is what the vendors publish as of August 2026, and policies change.
| Check | Where the major tools stand (Aug 2026) |
|---|---|
| 1. Training off by default — by default, not a toggle each person must remember. | ChatGPT Business (formerly Team), Enterprise, Edu and the API: not trained on by default (OpenAI enterprise privacy). Claude for Work and the API: governed by commercial terms. Consumer plans need a setting: ChatGPT → “Improve the model for everyone” off in Settings → Data Controls, or a Temporary Chat (Data Controls FAQ); Claude → Privacy Settings, or an Incognito chat (Anthropic). Gemini: review Gemini Apps Activity. Microsoft 365 Copilot: your Microsoft 365 subscription terms — we don't summarise them. |
| 2. Retention you control — you can delete a chat and know when it is gone. | ChatGPT: chats kept until deleted, then permanently removed within 30 days; Temporary Chats within 30 days; Enterprise and Edu workspaces set retention (Retention Policies). |
| 3. File handling — uploads do not outlive the chat without you knowing. | ChatGPT: files uploaded in a chat go to your Library where available, and deleting the chat does not delete them; files in custom GPTs and projects stay until the GPT or project is deleted. Where possible, paste pseudonymised text instead of attaching a file. |
| 4. Admin and SSO — one owner sees who is in, adds and removes people; settings apply to all. | Business and Enterprise workspaces exist for this; OpenAI lists SAML SSO for enterprise plans. Shared logins and personal accounts fail by design: nobody can revoke a leaver or prove the setting is off for everyone. |
| 5. Where data is hosted — the vendor says where data is stored and processed. | Read the data-processing terms. For EU or UK candidates, the GDPR's rules on transfers outside the EEA (Chapter V) are what those clauses address. |
| 6. A DPA you can sign — for your plan, not only enterprise contracts. | Art. 28 requires the controller–processor relationship to be set out in a contract. Look on the vendor's legal pages for the business tier; if there is none, the plan was not designed for candidate data. |
Write the answers down with the date: that sheet is the first half of your policy.
The layer before the tool — the part that matters more
Every check above limits what the vendor does with a CV once it has one. The cheaper, stronger move is to make sure it never gets the identifying parts. Four habits, none needing a budget:
- Minimise what goes in. Name → [PERSON_1], phone → [PHONE_1], email → [EMAIL_1], address → [ADDRESS_1], links → [URL_1], before the CV goes anywhere. That is pseudonymisation as the GDPR defines it (Art. 4(5)) — still personal data (Recital 26), but the tool now holds a CV it cannot link to a person, and for screening the model loses nothing.
- One written rule. Not a policy — a sentence: “No identifiers in prompts or uploads.” Everyone can repeat it; a new starter learns it on day one.
- A shared key sheet. One line per CV mapping [PERSON_1] to the candidate, kept in the ATS or a restricted folder — never in the AI tool, a prompt or a chat title.
- A deletion habit. Chats and their files deleted weekly; one person checks the shared workspace monthly. Without it a workspace quietly accumulates a year of candidates.
The one-page team policy, written as steps
The complete manual method: do it once, print it, and it works with any tool.
-
Name an owner
One person owns the accounts, settings, key sheet and monthly check — in a five-person team, usually whoever owns the ATS. Write the name on the page.
-
Pick the plan and lock the settings
Preferably a business workspace: ChatGPT Business or Enterprise, Claude for Work, or the equivalent on your tool. On consumer accounts, write the exact settings: ChatGPT → Settings → Data Controls → Improve the model for everyone off, or a Temporary Chat per CV; Claude → Settings → Privacy → model improvement off, or an Incognito chat; Gemini → review Gemini Apps Activity. Record the plan and the date checked.
-
List what the tool may be used for
Summarising a pseudonymised CV, matching it to a job description, drafting interview questions or outreach from the placeholder version. Then what it may not: bulk exports from the candidate database, ID or passport scans, reference letters, anything mentioning health, family, religion or criminal history, photos.
-
List what must be stripped, and the placeholders
Name → [PERSON_1], phone → [PHONE_1], email → [EMAIL_1], postal address → [ADDRESS_1], LinkedIn and portfolio URLs → [URL_1]; date of birth, ID number and photo deleted outright. Same value, same placeholder throughout (Find & Replace → Replace All); a second email is [EMAIL_2]. Then the places people forget: header and footer, the file name (
candidate-a.docx, neverDana_Cohen_CV_redacted.docx) and the document properties (Word: File → Info → Inspect Document → Document Properties and Personal Information → Remove All). Employer names stay unless you run a blind screen. -
Decide where the key lives and who can see it
The mapping goes in the ATS record or a restricted folder your drive already protects. Name it, state who has access — usually everyone who screens, nobody else — and that it is never pasted into a tool.
-
Who deletes what, and when
Weekly: delete the chats and, in ChatGPT, the files from Library and any project — deleting the chat does not delete them. Monthly: the owner checks the workspace for anything older than the schedule. The day a colleague leaves: remove their access.
-
Tell candidates
Under the GDPR, candidates are entitled to information about how their data is processed, including the recipients or categories of recipients (Art. 13). If your candidate privacy notice says nothing about AI-assisted tools, ask whoever handles data protection for your business how to word it, starting from the regulators' own guidance: the ICO's guide to the principles, the EDPB, the PPA's Amendment 13 hub.
-
Sign it, date it, review it
Everyone who screens signs the page. The owner re-reads it quarterly and whenever a vendor changes its data policy — several did in 2025 and 2026.
What the manual method costs
- Set-up, once
- ≈ half a daychoose the plan, lock settings, write and sign the page
- Per CV, ongoing
- 5–8 minstripping by hand in Word: header, footer, file name, properties
- What slips
- The human bitsa login nobody revoked, a Library file nobody deleted, the footer
Our estimates for a small team working carefully; yours will differ. Set-up is cheap and happens once. The per-CV minutes are what erodes — on a twenty-CV day, about two hours before any screening — and where the rule quietly stops being followed.
What this doesn't solve
- Re-identification from the rest of the CV. A rare career path or a small employer can still point at one person. Pseudonymised is not anonymous — see pseudonymisation vs anonymisation.
- Your legal footing. Placeholders reduce what you disclose. They do not choose your lawful basis, write your privacy notice or sign a processor agreement. No tool makes you compliant with anything, including this one.
-
Scans, images and PDFs on Protected sites. The popup reads Word, text
and text-layer PDFs, and rebuilds a PDF as plain pages — the words, not the layout. A
scanned or photographed CV has no text layer, so it is refused, not silently passed;
there is no OCR. A PDF whose text is Hebrew, Arabic or another non-Latin script is
refused too — protect those as
.docx. And on a Protected site a PDF still passes through untouched, whatever the popup can do with it. Convert first, ask for the.docx, or use the manual steps. - Perfect detection. Emails, phones, IDs and card numbers are caught reliably by rules. Names and addresses depend on the optional on-device model and will miss some — and the upload guard on Protected sites does not use the model at all. Read the output before you share it.
- What people do on their own accounts. A rule and a workspace cover the tools you know about, not a colleague pasting a CV into a personal account on their phone. That is a conversation, not a setting.
Questions recruiters ask
Do we need ChatGPT Business, or can a small team use personal accounts?
Personal accounts can be made acceptable for pseudonymised CVs — turn off “Improve the model for everyone” under Settings → Data Controls, or use a Temporary Chat per CV — but they fail the admin test: nobody can remove a leaver, and one colleague who never changed the setting breaks the rule for the team. A business workspace — ChatGPT Business, which OpenAI says is not trained on by default, or Claude for Work, governed by commercial terms — gives one owner control over members and settings.
Is a Temporary Chat or an Incognito chat enough for a small team?
They are good defaults for an individual: ChatGPT Temporary Chats are not used for training, are not saved to your history and are deleted from OpenAI's systems within 30 days; Claude's Incognito chats are not used to improve Claude even when model improvement is on. They are not a team control — they rely on every person remembering every time, and the CV still sits on a third party's servers while the chat exists. Strip identifiers first regardless.
Does a small recruitment agency need a privacy officer under Israel's Amendment 13?
According to the Privacy Protection Authority, the duty applies to public bodies; to controllers whose main purpose is collecting personal data to pass on to others as a business, with data on more than 10,000 people; to controllers or holders whose core activities involve regular and systematic monitoring of people on a significant scale; and to certain data brokers and large sensitive databases. Whether a given agency is caught depends on what it does with the data — check the PPA's Amendment 13 guidance rather than assume either way.