AI tools can summarise a CV in seconds, compare experience with a job description or help identify relevant skills. That can be attractive when an employer receives hundreds of applications.
But copying candidate CVs into an AI tool is still personal data processing. Before doing it, employers need to understand what happens to that information.
What are you asking the AI to do?
There is a major difference between:
- Improving the wording of a generic recruitment email
- Summarising a candidate’s CV
- Comparing a CV with job criteria
- Ranking candidates
- Recommending who should be interviewed
- Automatically rejecting applicants
The closer the tool gets to making or determining the recruitment decision, the greater the legal and practical risk. Letting the system decide on its own takes you into automated rejection territory.
A CV contains personal data
Removing the filename does not anonymise a CV.
The document may contain:
- Name
- Email address
- Telephone number
- Employment history
- Education
- Location
- Photograph
- Professional memberships
- Other information that identifies the person
It may even contain sensitive information the candidate chose to include.
Treat the upload as a disclosure of personal data to a technology provider.
Check the AI provider first
Before using any AI service with candidate data, establish:
- Which product or account type you are using
- What contractual terms apply
- Whether submitted data is retained
- Whether it may be used for model training or improvement
- Where processing takes place
- Which subprocessors are involved
- What security measures are available
- Whether appropriate data processing terms are offered
- How deletion works
These answers can differ between consumer and business versions of the same AI service. The same questions apply to any AI tool that touches personal data, not only recruitment tools.
Minimise what you upload
If you only want help identifying skills, do you need to provide the candidate’s name, address, photograph and contact details?
Probably not.
Where possible, remove information that is unnecessary for the task.
Remember that pseudonymisation reduces risk but leaves the information as personal data, fully within the GDPR.
Don’t blindly trust the output
AI can make mistakes, misunderstand experience or generate conclusions that are not supported by the CV.
Recruitment decisions should not be based on an assumption that an AI-generated summary is accurate.
A human reviewer should be able to verify the relevant source information and challenge the output.
Ranking is different from summarising
Using AI to create a neutral summary can already involve GDPR obligations.
Using it to score, rank or reject candidates introduces additional concerns, including fairness, transparency, automated decision-making and potentially the high-risk AI system rules under the EU AI Act.
Do not treat these use cases as equivalent.
Create an internal AI rule
Employees should know whether they are allowed to paste candidate data into public or generative AI tools.
A simple AI acceptable use policy can define:
- Approved AI tools
- Permitted recruitment uses
- Information that may not be uploaded
- Required human review
- Security requirements
- Escalation for higher-risk uses
Without such a rule, hiring managers may create “shadow AI” processes without HR or management knowing.
Review the tool before the CV
The practical rule is simple: do not test an AI recruitment workflow with real candidate data before you have assessed the tool.
GDPRWise helps organisations map third parties and processing activities so new AI tools can be assessed as part of the existing GDPR compliance framework rather than introduced informally.
GDPRWise maps the providers and processing activities behind your recruitment, so an AI tool gets assessed before real candidate data reaches it.