How to anonymise candidate CVs before sending them to clients

Anonymising a CV means removing anything that identifies the candidate before a client sees it: their name, email, phone number, postal address, photo, and links to personal profiles. You keep the parts a client needs to judge the work: job titles, employers, dates, locations at city level, and skills. Do it the same way every time, through a template or a tool, because a one-off redaction in Word misses things and you cannot un-send an email.

Agencies anonymise for two reasons that get mixed together and should not be. The GDPR one is simple: only share the personal data a client actually needs for the decision in front of them, which at shortlist stage is "can this person do the job," not "what is this person's name and phone number." The bias one is separate: a name signals gender, ethnicity and sometimes age before a client has read a single line of experience, and anonymising removes that signal from the part of the process where it costs the candidate the most.

What to remove, and why each one matters

Full name. The obvious one. Replace it with something stable across the documents you send for this candidate, a reference like "Candidate 14" or a generated code, so the client can refer back to the same person across a call and a follow-up email without you both re-identifying them by accident.

Email and phone number. These let a client skip your process and contact the candidate directly, which most agency agreements do not want to happen before a placement fee is settled, and GDPR gives you no reason to share them before that stage anyway.

Home address. Unlike a city or region, a street address identifies a specific household. It never belongs on a CV a client sees, anonymised or not.

Photo. Common on CVs from parts of Europe. A photo adds its own bias-triggering signal on top of a name, and it's the easiest thing to miss because it sits in a header or a sidebar a text-based redaction tool does not look at.

Personal profile links. A LinkedIn, GitHub or personal site URL usually has the real name in it, which defeats the point of removing the name from the document itself. Strip the link or replace it with "LinkedIn profile available on request."

What to keep, because the client needs it to say yes

Strip too much and you have handed the client a document they cannot evaluate. Keep:

Does anonymising a CV introduce new bias risk?

A little, in a direction worth knowing about. Writing style, project names, and the specific way someone describes their own work can still carry regional or educational signal even once the name is gone, so anonymisation reduces bias, it does not eliminate it. The honest claim is "removes the most obvious signal," not "makes screening neutral."

The part that actually breaks: identifiers hiding inside prose

Most anonymisation failures are not the name field. They are the sentence in a work-experience bullet that says "I led the QA team at my previous company, a 12-person startup founded by my university friend," which identifies the candidate to anyone who knows that startup, or the project description that names a client the candidate worked with under NDA.

A field-level redaction tool, including some "blind CV" browser extensions, only touches the structured fields: name, email, phone. It does not read the free text. If your anonymisation process stops at the header, you have solved the easy, visible part and left the part that actually causes the leak.

How do you catch identifiers buried in free text?

Two ways, and most agencies need both. A human reviewer reads the experience and summary sections before the CV goes out, specifically looking for company names, team sizes, and anything a client could use to identify the person with one search. Or the anonymisation step runs through a tool that scrubs name and contact patterns out of prose fields as well as structured ones, not just the header, which is the harder thing to build and the thing most "redact my CV" tools skip.

How Hireo handles this

Hireo's candidate CVs support a name display setting with four levels: the full name, first name with last initial, initials only, or a generated candidate ID in the form `HIR-XXXXXXXX`. A client review link that has never had this configured defaults to first name and last initial ("John D."), which anonymises the candidate without hiding the whole career history. It still fails closed on bad input: if a link's stored setting is present but doesn't match one of the four recognised values, Hireo falls back to the most anonymous mode, the generated ID, never to the real name.

On the client review page itself (the shortlist a client opens without creating an account), anonymisation goes further than the header. Past employers, dates and locations stay visible so the client can still assess the career history, but work-experience descriptions, education entries, screening answers, and the AI-generated match reasoning are all run through a scrub for name and contact patterns before they reach the client's screen. A CV downloaded from that same shortlist is a separate surface with a narrower scrub of its own (the header and company fields), so what holds on the review page isn't something to assume about the download too.

Contact-detail visibility is a setting of its own, separate from the name mode: one toggle controls whether contact details show at all on a link, and a recruiter can also hide contact info for a single candidate on a shortlist without changing it for the rest, through a per-candidate override in the client-review dialog.

How long does manual CV anonymisation take?

For one CV, a careful manual pass, header plus a read of the free text, takes real, noticeable time, and more of it the more prose the candidate wrote. That scales badly past a handful of candidates a week, which is the usual point an agency moves from a Word template to something that strips the structured fields and scrubs the prose automatically.

Is CV anonymisation legally required?

GDPR does not mandate anonymisation by name, but it does require data minimisation: you should only process and share the personal data necessary for the purpose at hand. At shortlist stage, a client's purpose is deciding whether to interview, which does not require a name, email or phone number. Anonymising at that stage is the practical way most agencies satisfy the principle without a case-by-case legal review of every shortlist. If you are an agency in a regulated sector, or placing candidates in the EU with clients outside it, check your specific data-processing agreement; this is the general shape, not legal advice for your contract.