Blind Hiring
CV Redaction Software: What It Removes and Why Agencies Use It
CV redaction software removes identifying information from a candidate's resume before it is shared, producing a blind version judged on skills alone. Here is what it strips, where cheap tools leak identity, and how it fits a staffing agency's submission workflow.
Written by: Saply Team
CV redaction software automatically removes identifying information from a candidate’s CV before it is shared, producing a blind version that a client or hiring manager evaluates on skills and experience alone. It strips direct identifiers like name, photo, and contact details, and the better tools also handle the indirect identifiers (employer names, graduation years, home address) that quietly give a candidate away.
That is the definition. The reason agencies care is more practical: redaction sits at the exact point where a recruiter’s obligations to the candidate, the client, and the regulator all collide. Get it right and you submit faster with less risk. Get it wrong and you either leak personal data or waste an afternoon blacking out PDFs by hand.
What CV redaction software removes
Redaction is not one action, it is two. Removing the obvious identifiers is easy. Removing the ones a reader can still infer is where tools separate.
Direct identifiers are the fields that name the person outright: full name, photo, email, phone number, home address, date of birth, nationality, and links like a personal LinkedIn URL. Any redaction tool worth using removes these automatically.
Indirect identifiers are the harder half. A named employer, an unusual university, a precise graduation year, a hometown, or a niche certification can point straight back to one person even with the name gone. Redacting the name but leaving “Head of Growth at a 40-person Antwerp fintech, 2021 to 2024” defeats the purpose. Strong software recognises these by field and either masks them (“[employer]”) or generalises them (“a mid-size financial services firm”), while keeping the job title, responsibilities, dates, and skills the client actually needs to judge the candidate.
Redaction, anonymisation, or pseudonymisation
These three words get used interchangeably in marketing copy, and the difference is not academic. It decides whether the GDPR still applies to the file you just produced.
| What it means | Still personal data? | |
|---|---|---|
| Redaction | Identifiers removed or obscured in the document | Depends on whether re-identification is possible |
| Pseudonymisation | Identity replaced with a reference; a separate key can restore it | Yes, GDPR fully applies |
| Anonymisation | Identity cannot be recovered even with reasonable effort | No, falls outside GDPR scope |
Here is the catch most tools skip over. When your agency swaps “Sofia Andersson” for “Candidate 4471” but keeps the mapping in your ATS so you can reveal her later, that is pseudonymisation, not anonymisation. Under GDPR the redacted CV is still personal data, and the whole pipeline (storing it, forwarding it to a client, retaining it) still needs a lawful basis and a data processing agreement. Calling that output “anonymised” is a compliance mistake, because true anonymisation is a one-way door your recruiting workflow deliberately does not want to walk through.
Redaction supports two GDPR duties at once. Data minimisation (passing a client only the personal data necessary for the decision) is served directly by stripping identifiers before submission. That is the compliance case for redaction, separate from the fairness case below, and it holds even when the client never asked for a blind CV.
Why staffing agencies redact CVs
Two reasons, and it helps to keep them distinct because they answer to different people.
Compliance, owed to the candidate and the regulator. Every CV you hold is personal data almost line by line. Sending the full document to a client when the client only needs skills and experience is more data sharing than the placement requires. Redaction is the mechanism that lets you honour data minimisation without slowing the desk down.
Fairness, owed to the candidate and increasingly demanded by the client. A large body of correspondence studies (controlled experiments that send otherwise identical CVs with different names or photos) has repeatedly found that identity signals change callback rates independent of qualifications. Removing the name and photo does not fix bias on its own, but it removes the earliest and easiest point at which it enters. This is the same logic behind blind resume screening, and it is why more clients now ask suppliers to submit anonymised profiles as a matter of policy.
The honest caveat: redaction changes the first-screen decision, not the interview. Bias can re-enter the moment a face and a name appear later in the process. Treat redaction as one control in a fairer pipeline, not the whole solution. Our guide to blind recruitment covers where the rest of the leaks are.
What separates reliable redaction software from risky redaction
This is the part a demo rarely shows. Test these before you trust a tool with a real candidate.
- Metadata, not just visible text. A PDF carries author names, edit history, and embedded thumbnails in its metadata. A tool that blanks the visible name but leaves “Sofia Andersson” as the document author has not redacted anything a curious hiring manager cannot recover in two clicks.
- True removal, not a black box over text. The classic failure is drawing an opaque rectangle over a name in a PDF while the underlying text stays selectable and copyable underneath. Reliable software rebuilds the document so the removed data is genuinely gone, not merely hidden.
- Indirect identifiers by field. As above, if the tool only handles name, photo, and contact details, half the job is undone. Ask specifically how it treats employer names and rare qualifications.
- Language coverage. If your desks work in Dutch, French, and English, redaction that only recognises English identifiers will miss fields in the other two. Test one CV per language.
- Where processing happens. Redaction is itself a processing operation. For European agencies, whether the file leaves the EU during that step is one of the first questions a client’s data protection officer will ask. (Saply processes and stores everything in the EU; see the security overview.)
The single most common real-world leak is not a missed field, it is a reversible redaction. Before you rely on any tool, take one of its outputs, open the PDF, and try to select the text under a blacked-out area. If it highlights, the data is still there. That thirty second test has caught more failures than any feature checklist.
Where redaction fits in the submission workflow
Redaction is rarely a standalone task. It sits inside the pipeline that turns a raw CV into a client-ready submission, right after the software has understood the document well enough to know which field is which.
The order matters. Redaction depends on the parse step first understanding the document, because you cannot reliably remove “the name field” until the software knows which text is the name rather than a project title or a former manager’s reference. This is why redaction tends to be a capability inside a broader CV parsing and formatting workflow rather than a separate product you bolt on at the end.
In Saply, this is one continuous flow: the same engine that parses a CV also reformats it into your agency template and can strip identifiers on the way, so the recruiter uploads a raw file and gets back a blind, submission-ready CV without a separate redaction step. It syncs to your ATS the same way any other profile does. The point is not that redaction is hard to buy on its own, it is that a redacted CV a client cannot use still costs you the placement, so redaction earns its keep when it lands inside the workflow the desk already runs.
Frequently asked questions
Is CV redaction the same as CV anonymisation?
In everyday use, agencies use the terms interchangeably, and both describe producing a blind CV. Legally they differ: most recruitment redaction is pseudonymisation, because the agency keeps the ability to re-identify the candidate. True anonymisation means the identity can never be recovered, which is not what a recruiter wants, since you need to reveal the candidate once the client is interested.
Does redaction make a CV GDPR compliant on its own?
No. Redaction supports data minimisation, but a redacted CV is still personal data if you can re-link it, so you still need a lawful basis, a retention policy, and a data processing agreement with any vendor involved. Redaction is one part of GDPR compliance, not a substitute for it.
What is the most common mistake with redaction software?
Reversible redaction. Drawing a black box over a name in a PDF while the underlying text remains selectable leaves the data fully recoverable. Always test an output by trying to select or copy the text beneath a redacted area before trusting the tool.
Should indirect identifiers like employer names be removed too?
For genuine blind screening, yes. A distinctive employer, a rare university, or a precise graduation year can identify a candidate even without a name. Good software masks or generalises these while keeping the job title, dates, and skills a client needs to assess fit.
Can redaction be automated inside our ATS workflow?
Usually, yes. When redaction is part of a parsing and formatting engine, it can run automatically as a CV moves from upload to submission and sync the profile back to systems like Bullhorn or Vincere. This is more reliable than manual editing, which is where missed fields and reversible black boxes tend to come from.