Speak Data Handling
jeremylongshore/tons-of-skills-marketplace
Handle student audio data, assessment records, and learning progress with GDPR/COPPA compliance.
Assesses children's data protection in educational technology.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills edtech-privacy-assessment --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/edtech-privacy-assessment .claude/skills/edtech-privacy-assessment && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "edtech-privacy-assessment" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/edtech-privacy-assessment into .claude/skills/edtech-privacy-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "edtech-privacy-assessment", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/edtech-privacy-assessmentType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills edtech-privacy-assessment --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/edtech-privacy-assessment .agents/skills/edtech-privacy-assessment && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "edtech-privacy-assessment" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/edtech-privacy-assessment into .agents/skills/edtech-privacy-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "edtech-privacy-assessment", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills edtech-privacy-assessment --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/edtech-privacy-assessment .cursor/skills/edtech-privacy-assessment && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "edtech-privacy-assessment" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/edtech-privacy-assessment into .cursor/skills/edtech-privacy-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "edtech-privacy-assessment", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/edtech-privacy-assessment--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills edtech-privacy-assessment --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/edtech-privacy-assessment .gemini/skills/edtech-privacy-assessment && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "edtech-privacy-assessment" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/edtech-privacy-assessment into .gemini/skills/edtech-privacy-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "edtech-privacy-assessment", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills edtech-privacy-assessmentInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/edtech-privacy-assessment .github/skills/edtech-privacy-assessment && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "edtech-privacy-assessment" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/edtech-privacy-assessment into .github/skills/edtech-privacy-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "edtech-privacy-assessment", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills edtech-privacy-assessment --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/edtech-privacy-assessment .opencode/skills/edtech-privacy-assessment && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "edtech-privacy-assessment" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/edtech-privacy-assessment into .opencode/skills/edtech-privacy-assessment/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "edtech-privacy-assessment", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
edtech-privacy-assessmentAssesses children's data protection in educational technology.
Edtech Privacy Assessment is an agent skill from mukul975/Privacy-Data-Protection-Skills. Assesses children's data protection in educational technology. Covers COPPA school exception under Section 312.5(c)(4), FERPA intersection, parental rights, teacher consent authority, data deletion at year-end, and Student Privacy Pledge compliance. Keywords: edtech, COPPA school exception, FERPA, student privacy, teacher consent, educational data.
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Education, covering Educational content and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Edtech Privacy Assessment loads about 4.8k tokens when it runs, and up to ~9.6k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 2,467 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,467 words, ~4,796 tokens.
.claude/skills/edtech-privacy-assessment/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Educational technology (EdTech) platforms that process children's personal data operate at the intersection of multiple privacy frameworks. In the United States, COPPA's school exception (16 CFR 312.5(c)(4)) allows schools to provide consent on behalf of parents for the collection of children's data in educational contexts, but only for school-authorised educational purposes. The Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. Section 1232g) governs education records maintained by educational agencies or institutions receiving federal funding. In the EU, GDPR applies with the heightened protections of Art. 8 (parental consent for children) and Recital 38 (specific protection for children). The UK AADC applies to EdTech services likely to be accessed by children. This skill provides a framework for conducting privacy assessments of EdTech platforms that navigate these overlapping requirements.
COPPA permits an operator to collect personal information from a child for the use and benefit of the school, and for no other commercial purpose, without obtaining verifiable parental consent directly, when:
Critical Limitations:
FERPA protects education records maintained by educational agencies or institutions that receive federal funding. EdTech platforms may receive education records as "school officials" under the school official exception.
Key Provisions:
| Scenario | FERPA Applies? | COPPA Applies? | Result |
|---|---|---|---|
| School-directed use of EdTech platform | Yes | Yes (school exception available) | School consents under COPPA; FERPA school official exception governs data handling |
| Student independently uses EdTech at home | No (not maintained by school) | Yes (full COPPA applies) | Operator must obtain verifiable parental consent directly |
| EdTech vendor receives education records from school | Yes | Yes (school exception) | FERPA and COPPA both apply; vendor must comply with both |
| EdTech vendor uses data for advertising | FERPA violation (non-educational use) | COPPA violation (exceeds school exception) | Both laws violated; school exception does not apply |
In the EU, the COPPA school exception does not exist. Schools using EdTech platforms must comply with:
The Student Privacy Pledge, administered by the Future of Privacy Forum (FPF) and the Software and Information Industry Association (SIIA), is a voluntary industry commitment. Signatories commit to:
Over 400 EdTech companies are signatories as of 2024.
| Question | Significance |
|---|---|
| Is the platform directed to children under 13? | COPPA applies fully; age gate and parental consent required |
| Is the platform used in a school context? | COPPA school exception may apply; FERPA may apply |
| Does the school direct students to use the platform? | Strengthens school exception applicability |
| Does the platform operate in the EU/UK? | GDPR/UK GDPR applies; AADC compliance required |
| Does the platform collect persistent identifiers? | COPPA personal information threshold met |
| Does the platform use collected data for non-educational purposes? | School exception does not apply to non-educational uses |
For each data element collected by the EdTech platform:
| Data Element | Collection Method | Educational Purpose | Non-Educational Use | Retention Period | Shared With |
|---|---|---|---|---|---|
| Student name | Account creation | Identify student in classroom | None | Academic year + 30 days | Teacher, parent |
| Email address | Login credential | Authentication | None | Account duration | None |
| Learning progress | Automated tracking | Adaptive content, grading | Product improvement (aggregated) | Academic year + 30 days | Teacher, parent |
| Assignment submissions | Student upload | Assessment, feedback | None | Academic year + 30 days | Teacher |
| Interaction logs | Automated | Feature usage analytics | Product improvement (aggregated) | 90 days | None (internal only) |
| Device identifiers | Automated | Session management | None | Session only | None |
| Jurisdiction | Lawful Basis | Conditions | Documentation Required |
|---|---|---|---|
| US (COPPA) | School exception consent | School has authorised use; data used only for educational purposes; operator does not use data commercially | Written agreement with school; operator's COPPA-compliant privacy policy |
| US (FERPA) | School official exception | Operator performs institutional service; under school's direct control; uses records only for authorised purposes | School's FERPA annual notification names operator as school official |
| EU (GDPR) | Art. 6(1)(e) Public task | School's educational mission qualifies as public task; processing necessary for that task | School's records of processing (Art. 30); DPA between school and vendor (Art. 28) |
| UK (GDPR + AADC) | Art. 6(1)(e) Public task or Art. 6(1)(f) Legitimate interests | Same as EU GDPR plus AADC compliance for all 15 standards | DPIA; AADC conformance assessment |
The agreement between the school and the EdTech vendor must address:
The end of the academic year is a critical data lifecycle event for EdTech platforms. The following protocol must be implemented:
60 Days Before Year End:
30 Days Before Year End:
Year End (Last Day of Academic Year):
30 Days After Year End:
60 Days After Year End:
BrightPath Learning Inc. operates an educational gaming platform deployed in schools and available for home use across the US, UK, and EU. The platform serves children aged 5-15.
Classification:
Dual-Track Compliance:
Data Practices Assessment:
| Practice | Status | Notes |
|---|---|---|
| Data used only for educational purposes | PASS | No advertising, no behavioural profiling, no commercial use |
| Student data not sold | PASS | Written policy prohibition; contractual commitment with schools |
| Behavioural advertising to students | N/A | Platform is ad-free; no advertising infrastructure |
| Data retention limited to academic year | PASS | Automatic deletion 30 days after year end; school can request earlier |
| Sub-processor list disclosed to schools | PASS | AWS (hosting), SendGrid (parent notifications); both under DPA |
| School agreement includes all required terms | PASS | Annual review; covers COPPA, FERPA, GDPR, security, deletion |
| Breach notification procedure | PASS | 24-hour notification to school; 72-hour to DPA (GDPR) |
| Parental access mechanism (home use) | PASS | Parental dashboard with data view, download, and deletion |
| Student Privacy Pledge signatory | YES | Signed 2024; annual compliance certification |
Several US states have enacted student privacy laws that impose additional requirements on EdTech vendors:
| State | Law | Key Requirements |
|---|---|---|
| California | Student Online Personal Information Protection Act (SOPIPA, 2014) | Prohibits using student data for non-educational advertising; prohibits selling student data; requires deletion when no longer needed |
| New York | Education Law Section 2-d (2014, amended 2020) | Requires data privacy and security plans; parental notification of third-party access; breach notification; data encryption |
| Colorado | Student Data Transparency and Security Act (2016) | Requires school contracts to specify data elements, purposes, and security; prohibits targeted advertising to students |
| Connecticut | Student Data Privacy Act (PA 16-189, 2016) | Prohibits using student data for targeted advertising; requires operator to delete data within 30 days of request |
| Illinois | Student Online Personal Protection Act (SOPPA, 2021) | Requires parental notification; prohibits targeted advertising, creating commercial profiles, selling student data; mandates data breach notification |
| Virginia | Student Data Governance Plan (2015) | Requires schools to adopt data governance plans; vendors must comply with school data governance policies |
| Texas | SCOPE Act (2017) | Prohibits using covered information for non-educational purposes; requires security standards; mandates deletion |
| Maryland | Student Data Privacy Act (2015) | Prohibits using student data for advertising; requires data security; mandates deletion at end of contract |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/edtech-privacy-assessment of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Edtech Privacy Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Edtech Privacy Assessment this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| Speak Data Handlingjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~651 | Automated safety check: Pass | MIT | |
| Privacy Data SecurityJoelLewis/finance_skills | 206 | — | ~11k | Automated safety check: Pass | MIT | |
| OpenMAIC Setup and ExtensionTHU-MAIC/OpenMAIC | 40k | — | ~1.7k | Automated safety check: Notes | MIT | |
| Codebase to Coursezarazhangrui/codebase-to-course | 5.7k | — | ~4.4k | Automated safety check: Pass | None | |
| AI Engineering Project Tutorrohitg00/ai-engineering-from-scratch | 66k | — | ~1.6k | Automated safety check: Pass | MIT |
jeremylongshore/tons-of-skills-marketplace
Handle student audio data, assessment records, and learning progress with GDPR/COPPA compliance.
JoelLewis/finance_skills
Design and operate privacy and data security programs for SEC-registered firms under Reg S-P, Reg S-ID, and SEC cybersecurity expectations.
THU-MAIC/OpenMAIC
Guides setup, classroom generation and secondary development for OpenMAIC, the multi-agent interactive classroom, one confirmed phase at a time.
zarazhangrui/codebase-to-course
Turns a codebase into an interactive single-page HTML course for non-technical learners, with scroll modules, animated diagrams, quizzes and plain-English code translations.
rohitg00/ai-engineering-from-scratch
Tutors a learner through one stage of a hands-on AI engineering project per session: lesson, prediction, code, grader run and reflection, with hints but never full solutions.
voidful/hung-yi-lee-skill
Explains machine learning, LLMs, AI agents and speech modeling in a Hung-Yi Lee-inspired teaching style, drawing on a knowledge base built from his lectures and research references.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Assesses children's data protection in educational technology. Edtech Privacy Assessment is an agent skill from mukul975/Privacy-Data-Protection-Skills. Assesses children's data protection in educational technology.
Edtech Privacy Assessment fits situations like: tasks that involve Educational content; tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a claude-code`. Or copy the skill folder (skills/privacy/edtech-privacy-assessment in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/edtech-privacy-assessment in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a codex`. Or copy the skill folder (skills/privacy/edtech-privacy-assessment in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/edtech-privacy-assessment in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/edtech-privacy-assessment, .gemini/skills/edtech-privacy-assessment, .github/skills/edtech-privacy-assessment and .opencode/skills/edtech-privacy-assessment in your project.
Going by SKILL.md and its folder, Edtech Privacy Assessment needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Edtech Privacy Assessment is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Edtech Privacy Assessment: Speak Data Handling (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Privacy Data Security (JoelLewis/finance_skills, 206 stars), OpenMAIC Setup and Extension (THU-MAIC/OpenMAIC, 40k stars) and Codebase to Course (zarazhangrui/codebase-to-course, 5.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.