GDPR compliant CV tool

What makes a CV tool GDPR compliant?

CVumi team ยท September 7, 2026

GDPR compliant is a badge tools award themselves. Here is what the regulation actually demands, the six questions that separate a real answer from a marketing line, and why the safest copy of your CV is the one that never left your device.

Almost every CV builder claims to be GDPR compliant. Very few explain what they mean, and the phrase has no certification behind it. There is no badge, no audit, no registry. A company writes it on the pricing page because nobody stops them.

That does not make the regulation useless. It gives you a specific set of things to check, and once you know them you can tell a real answer from a marketing line in about five minutes. Here is what actually applies when a tool handles your CV.

Why a CV is a hard case

The GDPR governs personal data, and a CV is close to a worst case: your name, home address, phone number, email, employment history, education, and often a photograph and date of birth, all in one structured file.

Some CVs also carry what Article 9 calls special categories of data, which get stricter protection. A career break explained by illness, volunteering for a religious organisation, a role at a trade union, membership of a disability network. None of that is unusual on a real CV, and all of it raises the bar for whoever stores the file.

So a CV builder is not handling casual data. It is handling a dossier, and the obligations scale accordingly.

What the regulation actually requires

Five obligations matter for this kind of tool.

A lawful basis. The company needs a specific legal reason to process your data. For a paid tool that is usually performance of a contract for the service itself, and consent for anything extra such as marketing. "We collect data to improve our services" is not a lawful basis, it is a sentence.

Data minimisation. Collect what is needed, not what might be useful later. A CV builder that asks for your date of birth when no template uses it has already failed this one.

Storage limitation. Data is kept only as long as the purpose requires. A tool that still holds the CV you wrote four years ago, on an account you abandoned, is not meeting this.

Your rights, workably. Access, rectification, erasure, portability and objection, answered within a month and without an obstacle course. A deletion flow that requires emailing support and waiting is technically compliant and practically hostile.

Controlled transfers. If data leaves the EU or EEA, appropriate safeguards must be in place, typically Standard Contractual Clauses. This is where most AI tools get complicated, because the model provider is frequently in the United States.

Compliance is about who else holds your data. The obligations follow the copies.
Compliance is about who else holds your data. The obligations follow the copies.

The AI layer doubles the question

This is the part specific to AI CV tools, and it catches people out.

When a cloud builder sends your CV to a language model, two companies are now processing your data: the builder and the model provider. Each has its own policy, its own retention window, its own jurisdiction and its own security record. A perfectly compliant builder sitting on top of a model provider that trains on submitted content has still moved your CV somewhere you did not evaluate.

So the question is never "is this tool GDPR compliant". It is "who are all the parties that touch my file, and what does each of them do with it".

Six questions that get you a real answer

Ask these of any tool. The answers should be findable in the privacy policy in a few minutes. If they are not, that is itself the answer.

The limit of the right to erasure

People treat Article 17, the right to erasure, as a reset button. It is a genuine and useful right, and it is weaker than it sounds.

A deletion request reaches the copies a company controls. Backups age out on their own schedule. Data already shared with sub-processors follows their timelines. The regulation lists cases where the right does not apply at all, including legal obligations to retain records. And erasure cannot reach a copy that was scraped, leaked or breached before you asked.

Deletion after the fact is a repair. It is always weaker than never sending the file.

Why local processing changes the shape of the problem

There is a category of tool the compliance question barely applies to, because there is no third party to be compliant.

If the software runs on your computer and your documents stay in a folder you chose, no company is processing your personal data. There is no controller other than you, no retention policy to read, no sub-processor list, no transfer mechanism, and nothing to request erasure of. The GDPR is not satisfied so much as sidestepped: it governs what organisations do with your data, and no organisation received it.

CVumi is built this way. It is a desktop app for Windows and macOS. Your master profile, your generated documents and your application history live on your own machine. When an AI step runs, the request goes from your computer to the model provider under your own API key, so the API terms apply and no CVumi database sits in the middle holding a copy. The only personal data CVumi's operator ever receives is the email address attached to your purchase, handled by the payment provider.

It is a one-time payment: 69 EUR for a standard licence with three device activations, or 34 EUR with a student email.

Cloud CV builderLocal app with your own key
Companies processing your CVThe builder plus its model providerNone
Retention policy to evaluateTwo, one per companyNone for your documents
Transfer safeguards neededUsually yesOnly for the model call you initiate
What erasure has to reachServers, backups, sub-processorsYour own folder
Who you have to trustTwo companies and their securityYour own device

The honest summary

GDPR compliance is not a badge, it is a set of answerable questions. A cloud CV builder can answer them well, and the good ones do. Ask the six questions above and you will quickly see which category a tool falls into.

But the regulation exists because organisations holding your personal data is inherently risky. The lowest-risk arrangement is not the best-drafted privacy policy. It is the arrangement where no organisation holds the file at all.

For the practical version of that, see how to keep your career documents fully private, and for how the tools compare, the best privacy-friendly AI CV builders in 2026.

← All articles