BLNDCVBack

GDPR

Anonymizing or pseudonymizing a CV: what the GDPR actually says

Published 26 July 2026 · Updated 26 July 2026 · Erwan André, DirtyLab

Removing the name, the photo and the contact details from a CV is pseudonymization, not anonymization within the meaning of the GDPR. The Regulation draws a sharp line between the two: anonymization is irreversible and takes the data outside the scope of the GDPR, whereas pseudonymization leaves personal data in place as long as the person remains "identifiable" by cross-referencing. A CV with the name erased still carries a career path, dates and unique descriptors: legally, it remains pseudonymized personal data, still governed by the GDPR. That is exactly the scope of a tool like BlindCV — robust pseudonymization, honest about its limits, not a legally guaranteed anonymization.

Anonymization and pseudonymization: what is the difference under the GDPR?

The difference is legal, not merely technical. The GDPR explicitly defines only pseudonymization, in article 4(5): "the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately". In other words, the data can still be linked back to a person, through a key held apart.

Anonymization, by contrast, is defined by France's data protection authority as "processing that uses a set of techniques so as to make it impossible, in practice, to identify the person by any means whatsoever, and to do so irreversibly" (CNIL, Anonymization of personal data). The consequence is significant: genuinely anonymized data is no longer personal data, and "data protection legislation no longer applies".

Pseudonymization offers no such exit from the GDPR. As the CNIL puts it, pseudonymization is "a reversible operation", and "data resulting from pseudonymization is therefore considered personal data and its processing remains fully subject to the obligations of the GDPR" (CNIL). Following the European Data Protection Board guidelines on pseudonymisation adopted on 17 January 2025, the position is unambiguous: pseudonymized data still relates to an identifiable natural person, and still constitutes personal data.

Is removing the name enough to anonymize a CV?

No. The decisive test is not whether the name is gone, but the risk of re-identification. Recital 26 of the GDPR states that, to determine whether a person is identifiable, account should be taken of "all the means reasonably likely to be used" by the controller or by a third party to identify the person, directly or indirectly.

The Court of Justice of the European Union set this standard in Breyer (C-582/14, 19 October 2016): data relating to an "identifiable" person remains personal as soon as means reasonably likely to be used exist to trace their identity. The CJEU confirmed a contextual approach in 2025 in EDPS v SRB (C-413/23 P, 4 September 2025): the same pseudonymized dataset can remain personal data for whoever holds the key, and lose that character for a recipient with no reasonable means of re-identifying the person.

On a CV, that is precisely the trap. Erasing "Erwan André" while keeping the sequence "engineer at Orange in Lille, 2018-2023, Centrale graduate" leaves a combination of indirect identifiers that is often unique: a recruiter, a former colleague or a search engine can join the dots. Replacing the employer with a generic descriptor ("large telecoms group") reduces the risk but does not remove it — which keeps us in pseudonymization, not the irreversible anonymization regulators require.

How long can a CV or an application be kept?

As long as a CV remains personal data, the principle of storage limitation (article 5 of the GDPR) applies. The CNIL recommends a specific maximum for unsuccessful applications: keeping a candidate's CV and cover letter to feed a "talent pool" is possible provided the retention period does not, in principle, exceed two years from the last contact with that candidate, and provided the candidate has been informed (CNIL, Recruitment and personal data).

Two conditions come with the deadline: the candidate must have been informed, and the clock runs from the last contact, not from the date the CV was received. A pseudonymized CV shared internally — for bias-free screening, say — is still subject to these limits: pseudonymization is a security measure, not an exemption from limited retention.

A genuinely anonymized file, conversely, falls outside these limits because it falls outside the GDPR — but anonymizing a document as rich as a CV is, in practice, very hard to guarantee.

Why a black box and forgotten metadata are not enough

The very definition of pseudonymization in article 4(5) of the GDPR requires effective "technical and organisational measures". Cosmetic masking does not meet that bar.

  • A black rectangle drawn on a PDF does not delete the text. In a PDF, the visual layer and the text layer are independent: putting a rectangle over a name hides it on screen, but the text remains selectable, copyable and extractable with a simple copy-paste or a script. The data was never removed.
  • Metadata gives the identity away. A PDF carries Author, Title and producing-software fields — where the candidate's name very often appears, even when it has been erased from the body of the document.

Robust pseudonymization therefore requires true redaction (actual removal of the content from the text layer, not a mask) and metadata scrubbing. That is BlindCV's technical approach: the sensitive text is genuinely deleted and then replaced, and the metadata is wiped. Let us stay precise on the legal side, though: this produces high-quality pseudonymization, robust against trivial extraction — not a legally guaranteed anonymization, since the residual career path can still, through cross-referencing, allow re-identification within the meaning of the Breyer case law.

Anonymization vs pseudonymization of a CV under the GDPR

CriterionAnonymizationPseudonymization
ReversibilityIrreversible: no way back to the identityReversible using additional information kept separately (art. 4(5) GDPR)
Legal statusNo longer personal data: outside the scope of the GDPRStill personal data, fully subject to the GDPR
Re-identification riskMust be nil in practice (no singling out, linkability or inference)Remains if reasonable means exist (CJEU Breyer / EDPS v SRB)
Example on a CVAggregated statistics that cannot be tied to an individualA CV with no name but with career path, dates and an employer descriptor
Retention periodNot governed by the GDPRLimited: 2 years after the last contact for a candidate (CNIL recommendation)
What BlindCV doesNot claimedTrue redaction + metadata scrub = robust pseudonymization

Frequently asked questions

Is a CV without a name anonymous data under the GDPR?

No, in almost every case. Removing the name does not remove the indirect identifiers (career path, dates, education, sector) whose combination is often unique. As long as re-identification is reasonably possible through cross-referencing, it is pseudonymization, and the CV remains personal data governed by the GDPR.

Do candidates still have to be informed if their CV is pseudonymized?

Yes. Pseudonymization is still processing of personal data: the transparency obligations and the need for a legal basis apply. The CJEU (EDPS v SRB, 2025) makes clear that identifiability is assessed from the standpoint of the controller collecting the data, which cannot escape transparency on the grounds that the data will be pseudonymized afterwards.

Can a pseudonymized CV be kept indefinitely?

No. A pseudonymized CV is still personal data subject to the storage-limitation principle. For an unsuccessful candidate, the CNIL recommends a period not exceeding, in principle, two years from the last contact, provided the candidate has been informed.

Is masking with a black box GDPR-compliant?

Not on its own. On a PDF, a rectangle placed over a name leaves the text intact in the document layer, so it can be extracted by copy-paste. Pseudonymization requires effective technical measures (art. 4(5) and art. 32 GDPR): actual deletion of the text and a metadata scrub, not a visual mask.

Does BlindCV legally anonymize a CV?

No, and we say so plainly. BlindCV performs robust pseudonymization — true redaction of the sensitive text, consistent replacements, metadata wiped — which withstands trivial extraction. It does not guarantee irreversible anonymization in the regulatory sense, because the residual career path may still allow re-identification through cross-referencing.

Sources

Read next: Hiring discrimination: the figures · CV anonymization tools compared

Anonymize a CV properly

True redaction, metadata wiped, zero storage. First CV free.

Try BlindCV