Agent skill

Coppa Compliance

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Implements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312.

Apache-2.0Auto-check passedLegal & Compliance

Install Coppa Compliance

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill coppa-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills coppa-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/coppa-compliance .claude/skills/coppa-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
coppa-compliance
GitHub stars
301
Token cost
~4.8k tokens
SKILL.md length
2,460 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312.

  • Works in 6 steps: Direct notice to parents (Section… → Verifiable parental consent (Section… → Parental access (Section 312.6): Must… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Statutory and Regulatory…, Verifiable Parental Consent… and Direct Notice Requirements —…, plus 5 more sections
  • Runs Python scripts from its folder

What it does

Coppa Compliance is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312. Covers verifiable parental consent methods including signed forms, credit card verification, government ID, knowledge-based authentication, and video call. Includes FTC safe harbor programs and enforcement actions. Keywords: COPPA, FTC, children, parental consent, safe harbor, verifiable consent.

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the coppa-compliance skill to implement Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312”
  • “/coppa-compliance”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Direct notice to parents (Section 312.4): Before collecting, using, or disclosing personal information from a child, the operator must…
  2. Verifiable parental consent (Section 312.5): Must obtain verifiable parental consent before any collection, use, or disclosure, except for…
  3. Parental access (Section 312.6): Must provide parents with reasonable means to review the personal information collected from their child…
  4. Confidentiality, security, and integrity (Section 312.8): Must establish and maintain reasonable procedures to protect the…
  5. Data minimisation (Section 312.7): Must not condition a child's participation in an activity on providing more personal information than…
  6. Data retention (Section 312.10): Must retain personal information collected from a child only as long as reasonably necessary to fulfil…

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Coppa Compliance loads about 4.8k tokens when it runs, and up to ~9.3k if it reads all its reference files. Until then it costs about 102 tokens; SKILL.md has 2,460 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,460 words, ~4,765 tokens.

Download SKILL.mdSave it as .claude/skills/coppa-compliance/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
coppa-compliance
description
Implements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312. Covers verifiable parental consent methods including signed forms, credit card verification, government ID, knowledge-based authentication, and video call. Includes FTC safe harbor programs and enforcement actions. Keywords: COPPA, FTC, children, parental consent, safe harbor, verifiable consent.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
children-data-protection
metadata.tags
coppa, ftc, children-privacy, parental-consent, safe-harbor, verifiable-consent

COPPA Compliance — Children's Online Privacy Protection Act

Overview

The Children's Online Privacy Protection Act (COPPA), codified at 15 U.S.C. Sections 6501-6506 and implemented through the FTC's COPPA Rule at 16 CFR Part 312, regulates the online collection, use, and disclosure of personal information from children under 13 years of age. COPPA applies to operators of commercial websites and online services (including mobile apps) directed to children under 13, or operators with actual knowledge that they are collecting personal information from a child under 13. The FTC's 2013 amendments significantly expanded the scope to cover persistent identifiers used for behavioural advertising, photos, videos, audio recordings, and geolocation data. The FTC issued a Notice of Proposed Rulemaking (NPRM) in December 2023 proposing further amendments including restrictions on push notifications to children and expanded consent requirements for targeted advertising.

Statutory and Regulatory Framework

COPPA Statute — 15 U.S.C. Section 6502
  • Section 6502(a)(1): Unlawful for an operator of a website or online service directed to children, or having actual knowledge of collecting from a child under 13, to collect personal information in a manner that violates the FTC's regulations.
  • Section 6502(b)(1): FTC must issue regulations requiring operators to: (A) provide notice of information practices; (B) obtain verifiable parental consent; (C) allow parents to review information collected; (D) allow parents to refuse further collection/use; (E) limit collection to what is necessary for the activity.
  • Section 6502(b)(2): FTC shall apply regulations considering competitive impact, costs, and benefits, and potential effect on existing safe harbor programs.
COPPA Rule — 16 CFR Part 312
Section 312.2 — Key Definitions
  • Child: An individual under the age of 13
  • Operator: Any person who operates a website or online service and collects or maintains personal information from or about users, or on whose behalf such information is collected or maintained
  • Personal information: Individually identifiable information including: first and last name; home or physical address; online contact information (email); telephone number; Social Security number; persistent identifier that can be used to recognise a user over time and across different websites; photograph, video, or audio file containing a child's image or voice; geolocation information sufficient to identify street name and city; information concerning the child or parents collected and combined with any of the above
  • Website or online service directed to children: Determined by: subject matter, visual content, use of animated characters, child-oriented activities and incentives, music, age of models, presence of child celebrities, ads directed at children, competent evidence regarding the target audience
  • Support for internal operations: Activities necessary to maintain or analyse the functioning of the website or online service, including one-time collection and non-contact use, frequency capping, legal compliance, security, contextual advertising, personalising content (not for advertising)
Section 312.3 — Obligations of Operators
  1. Direct notice to parents (Section 312.4): Before collecting, using, or disclosing personal information from a child, the operator must provide clear and prominent notice on the website/service and directly to the parent
  2. Verifiable parental consent (Section 312.5): Must obtain verifiable parental consent before any collection, use, or disclosure, except for narrow exceptions
  3. Parental access (Section 312.6): Must provide parents with reasonable means to review the personal information collected from their child and to refuse to permit further collection or use
  4. Confidentiality, security, and integrity (Section 312.8): Must establish and maintain reasonable procedures to protect the confidentiality, security, and integrity of personal information collected from children
  5. Data minimisation (Section 312.7): Must not condition a child's participation in an activity on providing more personal information than is reasonably necessary
  6. Data retention (Section 312.10): Must retain personal information collected from a child only as long as reasonably necessary to fulfil the purpose for which it was collected

The FTC recognizes the following methods for obtaining verifiable parental consent. Controllers must select the appropriate method based on the sensitivity of data collected and how it will be used.

  • Parent prints, signs, and returns a consent form to the operator via postal mail, fax, or electronic scan
  • Form must identify the operator, list all information to be collected, describe uses and disclosures, and state that the parent can revoke consent
  • Suitable for initial high-assurance verification
  • Limitation: Slow turnaround, accessibility barriers for parents without printing capability
Method 2: Credit Card or Other Online Payment Transaction
  • Parent uses a credit card, debit card, or other online payment system that provides notification of each discrete transaction to the primary account holder
  • The transaction must be a bona fide purchase or donation, or a micro-transaction (e.g., USD 0.50) disclosed to the parent
  • Credit card verification alone (without a transaction) is insufficient; there must be an actual monetary transaction
  • Limitation: Excludes unbanked families; may deter participation
Method 3: Toll-Free Telephone Number or Video Conference
  • Parent calls a toll-free number staffed by trained personnel who verify the parent's identity through knowledge-based questions
  • Alternatively, parent connects through a video conference call where identity is confirmed visually
  • Operator must train staff on COPPA requirements and verification protocols
  • Limitation: Resource-intensive; staffing requirements for multi-language support
Method 4: Government-Issued ID with Comparison to Database
  • Parent submits a government-issued identification (driver's license, passport) which the operator checks against a database
  • The ID must be deleted promptly from the operator's records after verification is complete
  • Must comply with Section 312.5(b)(4) requirements for deletion of ID after verification
  • Limitation: Privacy concerns about collecting sensitive identity documents; storage risk
Method 5: Knowledge-Based Authentication
  • Operator uses a series of challenge questions drawn from a third-party database (e.g., TransUnion, Experian, LexisNexis) that only the parent would likely be able to answer
  • Questions must be dynamically generated and different for each verification attempt
  • Must meet threshold of difficulty that prevents a child from successfully answering
  • Limitation: Dependent on third-party data accuracy; may fail for parents with thin credit files
Method 6: Facial Recognition Technology (FTC-Approved Method, 2013)
  • Parent submits a photograph that is compared against a previously verified government-issued photo ID
  • The photograph and ID image must be deleted promptly after the comparison is complete
  • Currently an approved method under the FTC's COPPA Rule but raises significant privacy concerns
  • Limitation: Biometric data collection concerns; accuracy disparities across demographics
Method 7: Email Plus (Limited Use)
  • Parent receives an email from the operator containing a notice and a link or response mechanism
  • The operator sends a confirmatory email to the parent after a reasonable delay
  • This method is approved ONLY for internal uses of collected information — NOT when the operator will disclose personal information to third parties or make it publicly available
  • Limitation: Lowest assurance; child may access parent's email
Data Use ScenarioMinimum Consent MethodFTC Expectation
Internal use only (no disclosure)Email Plus (Method 7)Acceptable minimum
Sharing with third partiesMethod 1, 2, 3, 4, or 5Higher assurance required
Public posting of child's informationMethod 1, 2, 3, 4, or 5Highest assurance recommended
Behavioural advertisingMethod 1, 2, 3, 4, or 5FTC scrutinises closely
Collection of photos/videos/audioMethod 1, 2, 3, 4, or 5Must verify before publication

Direct Notice Requirements — Section 312.4

Notice on the Website or Online Service — Section 312.4(b)

The operator must post a clear and prominent link to an online notice of its information practices with respect to children on the home page and each area where personal information is collected from children. The notice must state:

  1. Name, physical address, email address, and telephone number of all operators collecting or maintaining personal information through the site/service (or one designated operator with hyperlink to list of all)
  2. Description of what information is collected and whether collected actively or passively
  3. How the operator uses (and may use) the information
  4. Whether personal information is disclosed to third parties; if so, the types of businesses, their general purposes, and whether they have agreed to maintain the confidentiality and security of the information
  5. That the parent can review and have deleted the child's personal information, and can refuse to permit further collection
  6. Procedures for the parent to exercise rights
Direct Notice to Parent — Section 312.4(c)

Before collecting personal information from a child, the operator must send a direct notice to the parent that includes:

  1. Statement that the operator has collected the parent's online contact information for the purpose of obtaining parental consent
  2. The information practices of the operator
  3. That if the parent does not respond within a reasonable time, the parent's online contact information will be deleted
  4. A link to the online notice
  5. The means by which the parent can provide consent

FTC Safe Harbor Programs — Section 312.11

Industry groups or other persons may apply to the FTC for approval of self-regulatory guidelines (safe harbor programs) that implement the protections of the COPPA Rule. Operators subject to an approved safe harbor program are deemed to be in compliance with Section 312.

Show full SKILL.md (987 more words)Show less
Currently Approved Safe Harbor Programs
ProgramAdministering OrganisationFocus Area
CARU (Children's Advertising Review Unit)BBB National ProgramsAdvertising and marketing directed to children
kidSAFE Seal ProgramkidSAFE, LLCWebsites and apps with child audiences
ESRB Privacy CertifiedEntertainment Software Rating BoardVideo games and interactive entertainment
Aristotle Integrity (formerly iKeepSafe COPPA Safe Harbor)Aristotle Inc.Cross-sector COPPA compliance
PRIVO (Privacy Vaults Online)PRIVO, Inc.Identity and consent management technology
TrustArc (formerly TRUSTe COPPA/Children's Privacy Program)TrustArc Inc.Cross-sector privacy certification
Safe Harbor Benefits
  • FTC will not bring enforcement action against an operator that is in compliance with an approved safe harbor program's guidelines
  • Safe harbor programs provide independent compliance review and monitoring
  • Programs offer dispute resolution mechanisms and consumer complaint handling
  • Membership signals compliance commitment to parents and regulators
Safe Harbor Obligations
  • Submit annual reports to the FTC on compliance activities
  • Provide effective enforcement mechanisms including consumer redress
  • Perform random, comprehensive compliance audits of members at least annually
  • Maintain publicly available list of members and compliance status

BrightPath Learning Inc. — COPPA Implementation

BrightPath Learning Inc. operates an educational gaming platform available to children in the United States. The platform includes interactive learning games, progress tracking, and parent communication features.

COPPA Compliance Architecture

Pre-Registration Flow:

  1. Landing page prominently links to the Children's Privacy Policy
  2. Registration form asks "Are you 13 or older?" with neutral yes/no options (no age pre-fill)
  3. User selecting "No" is routed to the parental consent flow
  4. User selecting "Yes" proceeds with standard registration (with age verification at Step 5)

Parental Consent Flow:

  1. Child enters parent's email address
  2. BrightPath sends direct notice to parent per Section 312.4(c) including full information practices disclosure
  3. Parent clicks the consent link within 72 hours (contact information deleted if no response)
  4. Parent completes credit card verification via USD 0.50 micro-transaction (refunded within 48 hours)
  5. Parent reviews and provides granular consent for each data use:
    • Account creation and educational content delivery (required for service)
    • Learning progress reports sent to parent (optional)
    • Anonymized aggregate analytics for platform improvement (optional)
  6. Confirmation email sent to parent with link to parental dashboard

Parental Dashboard Features:

  • View all personal information collected from the child
  • Download collected information in machine-readable format (JSON/CSV)
  • Delete specific data elements or the entire account
  • Modify consent preferences for each data use
  • Set usage time limits and content restrictions
  • Receive weekly activity summary reports

Data Minimisation Measures:

  • No persistent identifiers collected for advertising purposes
  • No geolocation data collected (GPS disabled; IP address truncated to /24)
  • No photographs, videos, or audio recordings stored beyond session
  • Profile avatar selected from pre-set options (no photo upload for children under 13)
  • Chat functionality disabled for accounts under 13; moderated text communication only through pre-approved messages
Annual COPPA Audit Checklist
#Audit ItemRegulatory ReferenceStatus
1Privacy policy posted and current312.4(b)Review quarterly
2Direct notice sent before collection312.4(c)Automated system verified
3Verifiable parental consent obtained312.5Credit card method validated
4Parental access mechanism functional312.6Dashboard tested monthly
5No excess data collection312.7Quarterly data mapping review
6Security measures adequate312.8Annual penetration test
7Retention limits enforced312.10Automated deletion verified
8Third-party disclosures documented312.4(b)(4)Vendor list updated quarterly
9Safe harbor membership current312.11kidSAFE renewal date tracked
10Staff training completedInternal policyAnnual COPPA training for all staff

FTC Enforcement Actions

  • Epic Games/Fortnite (FTC, 2022): USD 275 million penalty for collecting personal information from children under 13 without parental consent, enabling voice and text communications with strangers by default, and using dark patterns to induce purchases. Largest COPPA penalty in history.
  • Google/YouTube (FTC, 2019): USD 170 million settlement (USD 136 million FTC, USD 34 million New York AG) for collecting persistent identifiers from viewers of child-directed YouTube channels to serve targeted advertising without obtaining verifiable parental consent.
  • Musical.ly/TikTok (FTC, 2019): USD 5.7 million settlement for collecting names, email addresses, and other personal information from children under 13 without parental consent while knowing that a significant portion of users were children.
  • VTech Electronics (FTC, 2018): USD 650,000 settlement for collecting personal information from children including photos, chat logs, and audio recordings without parental consent, and failing to secure the data leading to a breach exposing 6.4 million children's records.
  • Unixiz Inc./Explore Talent (FTC, 2020): USD 2 million judgment for collecting personal information from children on a talent scouting website without posting a privacy policy, obtaining parental consent, or maintaining reasonable security.

Proposed 2024 COPPA Rule Amendments

The FTC's December 2023 Notice of Proposed Rulemaking proposes significant changes:

  1. Separate consent for targeted advertising: Operators must obtain separate, opt-in parental consent specifically for targeted advertising directed at children — consent for the service itself cannot be bundled with advertising consent
  2. Prohibition on push notification consent: Operators cannot condition access to the service on the parent's consent to send push notifications to the child
  3. Enhanced data security requirements: Operators must implement a written information security program with specific technical safeguards
  4. Expanded definition of personal information: Biometric identifiers added explicitly to the definition
  5. Limits on data retention: Operators must retain children's personal information only for as long as reasonably necessary for the specific purpose for which it was collected
  6. Safe harbor accountability: Enhanced FTC oversight of safe harbor programs including more detailed annual reporting requirements

Integration Points

  • GDPR Parental Consent: For services operating in both the US and EU, COPPA requirements (under-13 bright line) and GDPR Art. 8 requirements (13-16 depending on Member State) must both be satisfied
  • Age Verification Methods: COPPA requires age screening; the method must not incentivise false age claims
  • Children's Data Minimisation: COPPA Section 312.7 aligns with GDPR Art. 5(1)(c) data minimisation principle
  • EdTech Privacy Assessment: COPPA's school exception (Section 312.5(c)(4)) allows schools to consent on behalf of parents for educational technology used in the classroom
  • Children's Deletion Requests: COPPA Section 312.6 requires operators to delete children's information upon parental request

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/coppa-compliance of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Coppa Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Coppa Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Coppa Compliance this skillmukul975/Privacy-Data-Protection-Skills301—~4.8kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Coppa Compliance

What does Coppa Compliance do?

Implements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312. Coppa Compliance is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312.

When should I use Coppa Compliance?

Coppa Compliance fits situations like: tasks that involve Privacy and GDPR.

How do I install Coppa Compliance in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill coppa-compliance -a claude-code`. Or copy the skill folder (skills/privacy/coppa-compliance in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/coppa-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Coppa Compliance in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill coppa-compliance -a codex`. Or copy the skill folder (skills/privacy/coppa-compliance in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/coppa-compliance in your project. Codex loads it when a task matches its description.

Can I use Coppa Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill coppa-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/coppa-compliance, .gemini/skills/coppa-compliance, .github/skills/coppa-compliance and .opencode/skills/coppa-compliance in your project.

What does Coppa Compliance need to run?

Going by SKILL.md and its folder, Coppa Compliance needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Coppa Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Coppa Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Coppa Compliance use?

Coppa Compliance is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Coppa Compliance use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.5k tokens, read only when the agent opens those files.

What are the alternatives to Coppa Compliance?

Skills that share tags, products or a category with Coppa Compliance: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Coppa Compliance?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.