Blind CV Anonymisation for Recruiters: What It Removes, and What It Misses
Blind CVs are asked for more often every year, usually by clients formalising a fair-hiring process. The request sounds simple — remove the name and send it — and that is where most implementations go wrong. Identity leaks through a dozen fields nobody thinks to check, and a CV that is 90% anonymised is arguably worse than one that is not, because everyone involved believes the job is done. This guide covers what to remove, where automation reliably fails, and how to verify before sending.
What clients actually want from a blind CV
Blind recruitment exists to make the first sift turn on evidence rather than on inferences drawn from a name, an address or a graduation year. The research base is uncomfortable but consistent: identical CVs receive materially different callback rates when the name changes.
Note what that implies. The purpose is not secrecy — the client will meet the candidate. It is to delay identity until after a judgement about capability has been formed. That framing matters, because it tells you what to remove: not everything identifying, but everything that invites an assumption before the evidence is read.
The fields everyone remembers
These are handled by essentially every tool that claims anonymisation, and they are the easy part.
- Full name, and any header or footer repeating it
- Email address and phone number
- Home address, and often the town where it narrows too far
- Photograph, or the initials monogram some templates use in its place
- Date of birth and age
- Personal links: LinkedIn, portfolio sites, social profiles
The fields that leak identity anyway
This is where automated redaction quietly fails, and where a human check earns its keep. Every item below has survived a 'fully anonymised' export in the wild.
The pattern is consistent: redaction tools look for fields, but identity lives in prose. A name removed from the header is still sitting in the third bullet of the 2019 role, in the phrase 'as Sarah's deputy I ran the rota'.
- The candidate's name inside their own prose, especially in a profile written in the third person
- Possessive forms and inflections a simple find-and-replace misses
- Email addresses built from the name, where removing the name leaves a recognisable stub
- Graduation years, which approximate age precisely enough to defeat the purpose of removing a date of birth
- A named referee, or a referee's contact details
- Very small employers, where the company name identifies a person in a local market
- Gendered pronouns throughout a profile, if the client asked for gender-neutral screening
- Document metadata: the author field of the original file, which frequently still contains the candidate's name
- Voluntary or personal-interest sections naming a specific local club, congregation or society
Employer names are a judgement call, not a rule
Removing employers is where blind CVs most often become useless. Replacing 'Barclays' with 'a large UK bank' preserves the signal a client needs. Replacing every employer with 'Company A' strips the CV of the context that makes experience legible, and clients reject those submissions.
The workable approach is to generalise rather than delete: sector and scale, not the name. 'A FTSE 100 retailer', 'a 40-person regional practice'. The client can still judge relevance; they simply cannot look the candidate up mid-sift.
Agree this with the client before the first submission. Some want employers intact and only personal identifiers removed. Sending them a heavily redacted CV they did not ask for reads as carelessness.
Why pattern-based redaction is checked, not certified
It is worth being precise about what automated anonymisation can promise, because the category has a habit of implying more.
Pattern matching handles structured fields well: an email is recognisably an email. It handles prose probabilistically. A short or common name is genuinely ambiguous — a tool that redacts every instance of 'Mark' destroys 'marked the accounts' and 'market analysis'. So a well-built system errs toward retaining ambiguous cases and surfacing them, rather than silently guessing.
In ConnectIQ, redaction covers structured fields and prose, including name tokens inside sentences, name-bearing emails and links, employer mentions inside bullet text, and age or date-of-birth references. Confident matches are full-name sequences and name-bearing identifiers. Isolated, short or lowercase occurrences are retained and reported rather than destructively guessed, and a scan lists what remains so a person decides.
That is checked redaction. It is not a compliance certification, and no pattern-based tool can honestly offer one. Anyone claiming guaranteed anonymisation is describing a product that does not exist.
Verify before it leaves the building
A two-minute check catches nearly everything automation cannot.
The single most useful habit: read the anonymised CV as though you had never seen the original. If you can name the person, so can the client.
- Search the finished document for the candidate's first name, surname and any shortened form
- Read the profile paragraph in full — third-person profiles are the most common leak
- Check the referees section has not survived as 'available on request from Jane Okafor'
- Confirm graduation years are removed if dates of birth were
- Open the file properties and check the author field
- Confirm the header and footer, which are often generated separately from the body
Keep the identified version
Anonymisation should be a rendering choice, not a destructive edit. You will need the full CV again the moment the client wants to interview, and rebuilding it from a redacted copy is both wasteful and error-prone.
Anonymisation in ConnectIQ is applied at render time rather than stored, so the same approved document produces an identified or anonymised output as required. The redaction check runs against the exact document and settings being sent, and if it finds residual identifiers, a share link is not created until the warning is acknowledged.
Frequently asked questions
What should be removed from a blind CV?
Name, contact details, address, photograph, date of birth and personal links as a minimum. Beyond that, the items that actually leak identity: the name inside prose, name-derived email stubs, graduation years, named referees, document metadata and very small employers that identify a person locally.
Should employer names be removed?
Usually generalised rather than removed. 'A FTSE 100 retailer' keeps the signal a client needs; 'Company A' strips the CV of context and gets submissions rejected. Agree the level with the client before the first submission, because many only want personal identifiers gone.
Can anonymisation be fully automated?
The structured fields can. Prose cannot be guaranteed, because short and common names are genuinely ambiguous in ordinary sentences. A well-built tool redacts confident matches, retains ambiguous ones, and reports what remains so a person can decide — which is checked redaction, not certified compliance.
Do graduation dates need removing?
If you removed the date of birth, yes. A graduation year usually places someone within a two or three year band, which defeats the purpose. Keep the qualification and institution; drop the year.
Does anonymising mean re-creating the CV twice?
It should not. Anonymisation is a rendering choice applied to one approved document, so the identified and blind versions come from the same source and cannot drift apart. You will need the identified version again as soon as an interview is arranged.
Try it on a real CV
Turn a candidate's own CV into a branded client submission you can check before it leaves the building. No card required, and every AI change is shown as a diff you approve before sending.
ConnectIQ — branded CV formatting for recruitment teams. One free conversion, no card.