Agent skill

Edtech Privacy Assessment

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Assesses children's data protection in educational technology.

Apache-2.0Auto-check passedEducation

Install Edtech Privacy Assessment

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills edtech-privacy-assessment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/edtech-privacy-assessment .claude/skills/edtech-privacy-assessment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
edtech-privacy-assessment
GitHub stars
301
Token cost
~4.8k tokens
SKILL.md length
2,467 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Assesses children's data protection in educational technology.

  • Works in 4 steps: The school has authorised the collection… → The collection is solely for the… → The operator does not use the collected… → …
  • Tasks that involve Educational content
  • SKILL.md covers Overview, Regulatory Frameworks, EdTech Privacy Assessment… and BrightPath Learning Inc. —…, plus 4 more sections
  • Runs Python scripts from its folder

What it does

Edtech Privacy Assessment is an agent skill from mukul975/Privacy-Data-Protection-Skills. Assesses children's data protection in educational technology. Covers COPPA school exception under Section 312.5(c)(4), FERPA intersection, parental rights, teacher consent authority, data deletion at year-end, and Student Privacy Pledge compliance. Keywords: edtech, COPPA school exception, FERPA, student privacy, teacher consent, educational data.

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Education, covering Educational content and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Educational content
  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the edtech-privacy-assessment skill to assess children's data protection in educational technology”
  • “/edtech-privacy-assessment”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. The school has authorised the collection of personal information on behalf of the students
  2. The collection is solely for the school's use and benefit in the educational context
  3. The operator does not use the collected information for any commercial purpose unrelated to the educational context
  4. The operator does not disclose the information to non-school third parties

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Edtech Privacy Assessment loads about 4.8k tokens when it runs, and up to ~9.6k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 2,467 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,467 words, ~4,796 tokens.

Download SKILL.mdSave it as .claude/skills/edtech-privacy-assessment/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
edtech-privacy-assessment
description
Assesses children's data protection in educational technology. Covers COPPA school exception under Section 312.5(c)(4), FERPA intersection, parental rights, teacher consent authority, data deletion at year-end, and Student Privacy Pledge compliance. Keywords: edtech, COPPA school exception, FERPA, student privacy, teacher consent, educational data.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
children-data-protection
metadata.tags
edtech, coppa-school-exception, ferpa, student-privacy, teacher-consent, educational-data

EdTech Privacy Assessment — Children's Data in Educational Technology

Overview

Educational technology (EdTech) platforms that process children's personal data operate at the intersection of multiple privacy frameworks. In the United States, COPPA's school exception (16 CFR 312.5(c)(4)) allows schools to provide consent on behalf of parents for the collection of children's data in educational contexts, but only for school-authorised educational purposes. The Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. Section 1232g) governs education records maintained by educational agencies or institutions receiving federal funding. In the EU, GDPR applies with the heightened protections of Art. 8 (parental consent for children) and Recital 38 (specific protection for children). The UK AADC applies to EdTech services likely to be accessed by children. This skill provides a framework for conducting privacy assessments of EdTech platforms that navigate these overlapping requirements.

Regulatory Frameworks

COPPA School Exception — 16 CFR 312.5(c)(4)

COPPA permits an operator to collect personal information from a child for the use and benefit of the school, and for no other commercial purpose, without obtaining verifiable parental consent directly, when:

  1. The school has authorised the collection of personal information on behalf of the students
  2. The collection is solely for the school's use and benefit in the educational context
  3. The operator does not use the collected information for any commercial purpose unrelated to the educational context
  4. The operator does not disclose the information to non-school third parties

Critical Limitations:

  • The school acts as an agent of the parent; the school does not have unlimited authority
  • The school can only consent to the collection of information necessary for the school-authorised educational activity
  • If the operator wants to use the data for commercial purposes (including advertising), the operator must obtain verifiable parental consent directly from the parent
  • The FTC has stated that schools "should not be able to consent on behalf of the parent to the collection of information that is not needed for the educational purpose" (FTC COPPA FAQ J.2)
FERPA — 20 U.S.C. Section 1232g

FERPA protects education records maintained by educational agencies or institutions that receive federal funding. EdTech platforms may receive education records as "school officials" under the school official exception.

Key Provisions:

  • Education records: Records, files, documents, and other materials directly related to a student that are maintained by an educational agency or institution or by a person acting for such agency or institution
  • School official exception (34 CFR 99.31(a)(1)): An educational agency or institution may disclose education records to a contractor, consultant, volunteer, or other party to whom the agency has outsourced institutional services or functions, provided that: the party performs an institutional service or function; the party is under the direct control of the agency; the party uses the education records only for the purposes for which the disclosure was made; the party meets the criteria specified in the agency's FERPA annual notification
  • Legitimate educational interest: The school official must have a legitimate educational interest in the education records — meaning the official needs to review the record to fulfil their professional responsibility
  • Directory information exception (34 CFR 99.37): Schools may disclose directory information (name, address, telephone number, email, date and place of birth, honours, activities) without consent if parents have been notified and given the opportunity to opt out
FERPA vs. COPPA Interaction
ScenarioFERPA Applies?COPPA Applies?Result
School-directed use of EdTech platformYesYes (school exception available)School consents under COPPA; FERPA school official exception governs data handling
Student independently uses EdTech at homeNo (not maintained by school)Yes (full COPPA applies)Operator must obtain verifiable parental consent directly
EdTech vendor receives education records from schoolYesYes (school exception)FERPA and COPPA both apply; vendor must comply with both
EdTech vendor uses data for advertisingFERPA violation (non-educational use)COPPA violation (exceeds school exception)Both laws violated; school exception does not apply
GDPR Application to EdTech

In the EU, the COPPA school exception does not exist. Schools using EdTech platforms must comply with:

  • Art. 6 Lawful Basis: Schools may rely on Art. 6(1)(e) (public task) for processing necessary for educational purposes, or Art. 6(1)(f) (legitimate interests) where public task does not apply
  • Art. 8 Parental Consent: If the EdTech platform relies on consent as its lawful basis for processing children's data, parental consent is required for children below the applicable national threshold
  • Art. 28 Processor Agreement: If the school is the data controller and the EdTech vendor is the processor, a compliant Art. 28 data processing agreement must be in place
  • Controller Determination: The school is typically the controller for educational processing; the EdTech vendor is the processor. However, if the vendor processes data for its own purposes (product improvement, analytics, advertising), it becomes a controller or joint controller for those purposes
Student Privacy Pledge (FPF/SIIA)

The Student Privacy Pledge, administered by the Future of Privacy Forum (FPF) and the Software and Information Industry Association (SIIA), is a voluntary industry commitment. Signatories commit to:

  1. Not sell student personal information
  2. Not behaviourally target advertising to students using data from the educational context
  3. Not create advertising profiles of students
  4. Not change privacy policies without notice and choice
  5. Enforce strict limits on data retention and deletion
  6. Support access to and correction of student information by authorised parties
  7. Use student data only for authorised educational/school purposes or as directed by parent/student
  8. Maintain a comprehensive data security program
  9. Not disclose student information except for legitimate educational purposes
  10. Require downstream recipients to comply with these commitments

Over 400 EdTech companies are signatories as of 2024.

EdTech Privacy Assessment Framework

Assessment Phase 1: Platform Classification
QuestionSignificance
Is the platform directed to children under 13?COPPA applies fully; age gate and parental consent required
Is the platform used in a school context?COPPA school exception may apply; FERPA may apply
Does the school direct students to use the platform?Strengthens school exception applicability
Does the platform operate in the EU/UK?GDPR/UK GDPR applies; AADC compliance required
Does the platform collect persistent identifiers?COPPA personal information threshold met
Does the platform use collected data for non-educational purposes?School exception does not apply to non-educational uses
Assessment Phase 2: Data Mapping

For each data element collected by the EdTech platform:

Data ElementCollection MethodEducational PurposeNon-Educational UseRetention PeriodShared With
Student nameAccount creationIdentify student in classroomNoneAcademic year + 30 daysTeacher, parent
Email addressLogin credentialAuthenticationNoneAccount durationNone
Learning progressAutomated trackingAdaptive content, gradingProduct improvement (aggregated)Academic year + 30 daysTeacher, parent
Assignment submissionsStudent uploadAssessment, feedbackNoneAcademic year + 30 daysTeacher
Interaction logsAutomatedFeature usage analyticsProduct improvement (aggregated)90 daysNone (internal only)
Device identifiersAutomatedSession managementNoneSession onlyNone
JurisdictionLawful BasisConditionsDocumentation Required
US (COPPA)School exception consentSchool has authorised use; data used only for educational purposes; operator does not use data commerciallyWritten agreement with school; operator's COPPA-compliant privacy policy
US (FERPA)School official exceptionOperator performs institutional service; under school's direct control; uses records only for authorised purposesSchool's FERPA annual notification names operator as school official
EU (GDPR)Art. 6(1)(e) Public taskSchool's educational mission qualifies as public task; processing necessary for that taskSchool's records of processing (Art. 30); DPA between school and vendor (Art. 28)
UK (GDPR + AADC)Art. 6(1)(e) Public task or Art. 6(1)(f) Legitimate interestsSame as EU GDPR plus AADC compliance for all 15 standardsDPIA; AADC conformance assessment
Assessment Phase 4: Contractual Requirements

The agreement between the school and the EdTech vendor must address:

  1. Scope of data processing: Specific data elements, purposes, and retention periods
  2. Prohibition on commercial use: Vendor may not use student data for advertising, marketing, or non-educational product development
  3. Sub-processor restrictions: Vendor must disclose all sub-processors and ensure they comply with equivalent restrictions
  4. Data deletion obligations: Vendor must delete all student data at the school's request and at the end of the contract period
  5. End-of-year deletion: Vendor must delete or return all student data at the end of each academic year unless the school specifically authorises retention
  6. Security requirements: Specific technical and organisational security measures
  7. Breach notification: Vendor must notify the school within 24-72 hours of a data breach affecting student data
  8. Audit rights: School has the right to audit the vendor's compliance with the agreement
  9. FERPA compliance (US): Vendor acknowledged as school official; data used only for legitimate educational interests
  10. COPPA compliance (US): Vendor acknowledges school exception limitations; does not use data for non-educational commercial purposes
Show full SKILL.md (1,032 more words)Show less
Assessment Phase 5: End-of-Year Data Lifecycle

The end of the academic year is a critical data lifecycle event for EdTech platforms. The following protocol must be implemented:

60 Days Before Year End:

  1. Notify school administrators that the end-of-year data lifecycle process will begin
  2. Provide data export options: school can download all student data in standard formats (CSV, JSON, SIF)
  3. Confirm whether the school authorises retention of any data for the next academic year

30 Days Before Year End:

  1. Notify teachers that student data will be archived
  2. Generate end-of-year student progress reports for school records
  3. Export any student-created content (assignments, projects) to the school's designated storage

Year End (Last Day of Academic Year):

  1. Deactivate all student accounts associated with the ending year
  2. Archive student data to a deletion queue (not immediately deleted, to allow for last-minute school requests)

30 Days After Year End:

  1. Execute deletion of all student data in the deletion queue unless the school has authorised retention
  2. Deletion scope: primary database, search indices, analytics databases, caches, logs
  3. Generate deletion certificates for the school

60 Days After Year End:

  1. Purge archived backups containing deleted student data
  2. Provide final deletion confirmation to the school
  3. Retain only the deletion certificate and the school agreement (no student personal data)

BrightPath Learning Inc. — EdTech Privacy Assessment

Platform Profile

BrightPath Learning Inc. operates an educational gaming platform deployed in schools and available for home use across the US, UK, and EU. The platform serves children aged 5-15.

Assessment Results

Classification:

  • Directed to children under 13: YES
  • Used in school context: YES (deployed in 2,400 schools)
  • Also available for home (non-school) use: YES
  • Operates in US, UK, EU: YES

Dual-Track Compliance:

  • School deployments: COPPA school exception applies for school-directed use; FERPA school official exception applies; GDPR Art. 6(1)(e) public task in EU
  • Home use: Full COPPA applies (verifiable parental consent via credit card); GDPR Art. 8 parental consent required in EU

Data Practices Assessment:

PracticeStatusNotes
Data used only for educational purposesPASSNo advertising, no behavioural profiling, no commercial use
Student data not soldPASSWritten policy prohibition; contractual commitment with schools
Behavioural advertising to studentsN/APlatform is ad-free; no advertising infrastructure
Data retention limited to academic yearPASSAutomatic deletion 30 days after year end; school can request earlier
Sub-processor list disclosed to schoolsPASSAWS (hosting), SendGrid (parent notifications); both under DPA
School agreement includes all required termsPASSAnnual review; covers COPPA, FERPA, GDPR, security, deletion
Breach notification procedurePASS24-hour notification to school; 72-hour to DPA (GDPR)
Parental access mechanism (home use)PASSParental dashboard with data view, download, and deletion
Student Privacy Pledge signatoryYESSigned 2024; annual compliance certification

State Student Privacy Laws

Several US states have enacted student privacy laws that impose additional requirements on EdTech vendors:

StateLawKey Requirements
CaliforniaStudent Online Personal Information Protection Act (SOPIPA, 2014)Prohibits using student data for non-educational advertising; prohibits selling student data; requires deletion when no longer needed
New YorkEducation Law Section 2-d (2014, amended 2020)Requires data privacy and security plans; parental notification of third-party access; breach notification; data encryption
ColoradoStudent Data Transparency and Security Act (2016)Requires school contracts to specify data elements, purposes, and security; prohibits targeted advertising to students
ConnecticutStudent Data Privacy Act (PA 16-189, 2016)Prohibits using student data for targeted advertising; requires operator to delete data within 30 days of request
IllinoisStudent Online Personal Protection Act (SOPPA, 2021)Requires parental notification; prohibits targeted advertising, creating commercial profiles, selling student data; mandates data breach notification
VirginiaStudent Data Governance Plan (2015)Requires schools to adopt data governance plans; vendors must comply with school data governance policies
TexasSCOPE Act (2017)Prohibits using covered information for non-educational purposes; requires security standards; mandates deletion
MarylandStudent Data Privacy Act (2015)Prohibits using student data for advertising; requires data security; mandates deletion at end of contract

Common Compliance Failures

  1. Exceeding the school exception: Using data collected under the COPPA school exception for product improvement, advertising, or other commercial purposes without separate parental consent
  2. No end-of-year deletion: Retaining student data indefinitely after the educational purpose has expired
  3. Inadequate school agreements: Missing key contractual terms such as sub-processor disclosure, deletion obligations, audit rights, or breach notification timelines
  4. Treating all collection as school-authorised: When a student uses the EdTech platform at home for non-school purposes, the school exception does not apply — the operator must obtain direct parental consent
  5. FERPA non-compliance: Failing to ensure the vendor is designated as a school official or using education records for purposes beyond legitimate educational interest
  6. No separate consent for non-educational features: Bundling consent for educational features with optional features (gamification rewards, social features) that require separate consent

Enforcement Precedents

  • Edmodo (FTC, 2023): USD 6 million penalty for collecting and using children's personal information for advertising purposes while operating as a school-directed EdTech platform, exceeding the scope of the COPPA school exception.
  • Google/YouTube (FTC, 2019): USD 170 million included channels used in educational contexts where persistent identifiers were collected for advertising.
  • InBloom (State enforcement, 2014): Data aggregation platform for student records shut down after New York, Louisiana, and other states raised FERPA and privacy concerns about centralised storage of student data with inadequate security and access controls.
  • Chegg (FTC, 2023): FTC ordered Chegg to implement comprehensive data security program after four breaches exposed personal information of millions of students and employees.

Integration Points

  • COPPA Compliance: The school exception is a narrow carve-out from COPPA's general requirements; all other COPPA requirements (notice, security, data minimisation) still apply
  • Children's Data Minimisation: EdTech platforms must collect only data necessary for the educational purpose; data minimisation is both a COPPA and GDPR requirement
  • Children's Deletion Requests: Parents retain the right to request deletion of their child's data even in school-directed contexts; schools can also request deletion under FERPA
  • GDPR Parental Consent: In the EU, the school exception does not exist; schools must rely on Art. 6(1)(e) public task or obtain parental consent under Art. 8
  • Children's Privacy Notice: EdTech platforms must provide privacy notices to both the school (as decision-maker) and parents (as rights holders)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/edtech-privacy-assessment of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Edtech Privacy Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Edtech Privacy Assessment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Edtech Privacy Assessment this skillmukul975/Privacy-Data-Protection-Skills301—~4.8kAutomated safety check: PassApache-2.0
Speak Data Handlingjeremylongshore/tons-of-skills-marketplace2.8k—~651Automated safety check: PassMIT
Privacy Data SecurityJoelLewis/finance_skills206—~11kAutomated safety check: PassMIT
OpenMAIC Setup and ExtensionTHU-MAIC/OpenMAIC40k—~1.7kAutomated safety check: NotesMIT
Codebase to Coursezarazhangrui/codebase-to-course5.7k—~4.4kAutomated safety check: PassNone
AI Engineering Project Tutorrohitg00/ai-engineering-from-scratch66k—~1.6kAutomated safety check: PassMIT

Similar skills

  • Speak Data Handling

    jeremylongshore/tons-of-skills-marketplace

    Handle student audio data, assessment records, and learning progress with GDPR/COPPA compliance.

    2.8k GitHub stars~651 tokensUpdated today
    EducationAuto-check passed
  • Privacy Data Security

    JoelLewis/finance_skills

    Design and operate privacy and data security programs for SEC-registered firms under Reg S-P, Reg S-ID, and SEC cybersecurity expectations.

    206 GitHub stars~11k tokensUpdated 2 mo ago
    EducationAuto-check passed
  • Guides setup, classroom generation and secondary development for OpenMAIC, the multi-agent interactive classroom, one confirmed phase at a time.

    40k GitHub stars~1.7k tokensUpdated today
    EducationAuto-check: notes
  • Codebase to Course

    zarazhangrui/codebase-to-course

    Turns a codebase into an interactive single-page HTML course for non-technical learners, with scroll modules, animated diagrams, quizzes and plain-English code translations.

    5.7k GitHub stars~4.4k tokensUpdated 6 mo ago
    EducationAuto-check passed
  • AI Engineering Project Tutor

    rohitg00/ai-engineering-from-scratch

    Tutors a learner through one stage of a hands-on AI engineering project per session: lesson, prediction, code, grader run and reflection, with hints but never full solutions.

    66k GitHub stars~1.6k tokensUpdated today
    EducationAuto-check passed
  • Hung-Yi Lee Teaching Style

    voidful/hung-yi-lee-skill

    Explains machine learning, LLMs, AI agents and speech modeling in a Hung-Yi Lee-inspired teaching style, drawing on a knowledge base built from his lectures and research references.

    1.3k GitHub stars~13k tokensUpdated 2 mo ago
    EducationAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Edtech Privacy Assessment

What does Edtech Privacy Assessment do?

Assesses children's data protection in educational technology. Edtech Privacy Assessment is an agent skill from mukul975/Privacy-Data-Protection-Skills. Assesses children's data protection in educational technology.

When should I use Edtech Privacy Assessment?

Edtech Privacy Assessment fits situations like: tasks that involve Educational content; tasks that involve Privacy and GDPR.

How do I install Edtech Privacy Assessment in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a claude-code`. Or copy the skill folder (skills/privacy/edtech-privacy-assessment in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/edtech-privacy-assessment in your project. Claude Code loads it when a task matches its description.

How do I install Edtech Privacy Assessment in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a codex`. Or copy the skill folder (skills/privacy/edtech-privacy-assessment in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/edtech-privacy-assessment in your project. Codex loads it when a task matches its description.

Can I use Edtech Privacy Assessment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill edtech-privacy-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/edtech-privacy-assessment, .gemini/skills/edtech-privacy-assessment, .github/skills/edtech-privacy-assessment and .opencode/skills/edtech-privacy-assessment in your project.

What does Edtech Privacy Assessment need to run?

Going by SKILL.md and its folder, Edtech Privacy Assessment needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Edtech Privacy Assessment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Edtech Privacy Assessment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Edtech Privacy Assessment use?

Edtech Privacy Assessment is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Edtech Privacy Assessment use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.8k tokens, read only when the agent opens those files.

What are the alternatives to Edtech Privacy Assessment?

Skills that share tags, products or a category with Edtech Privacy Assessment: Speak Data Handling (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Privacy Data Security (JoelLewis/finance_skills, 206 stars), OpenMAIC Setup and Extension (THU-MAIC/OpenMAIC, 40k stars) and Codebase to Course (zarazhangrui/codebase-to-course, 5.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Edtech Privacy Assessment?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.