Edtech Privacy Assessment logo

Edtech Privacy Assessment

Community
mukul975
edtech-privacy-assessment

Assesses children's data protection in educational technology. Covers COPPA school exception under Section 312.5(c)(4), FERPA intersection, parental rights, teacher consent authority, data deletion at year-end, and Student Privacy Pledge compliance. Keywords: edtech, COPPA school exception, FERPA, student privacy, teacher consent, educational data.

Overview

Publishermukul975
RepositoryPrivacy-Data-Protection-Skills
Skill nameedtech-privacy-assessment
Stars
279
Forks
59
Bundled files
4
LicenseApache-2.0
Links
  • Markdown instructions

    A SKILL.md file the model loads on demand, so it only costs tokens when a request actually matches.

  • Works with any LLM

    AI skills are plain Markdown, not provider-specific code, so this works with GPT, Claude, Gemini, Grok, or a local model.

  • 4 bundled files

    Scripts, templates, and references the model can read while it works. Files are read-only and never executed.

  • Open source

    Published by mukul975 on GitHub. Read the source before you install it.

Installation

Install the Edtech Privacy Assessment AI skill in TypingMind to use it with any LLM, or drop it into another agent that reads SKILL.md.

1

Install in TypingMind

TypingMind installs a skill straight from its GitHub folder — it reads SKILL.md, bundles the resource files, and stores the result locally.

  1. Open the app and go to Plugins → Skills.
  2. Choose "Install from GitHub".
  3. Paste the skill folder URL below and confirm.
  4. Enable the skill in any chat where you want it available.
Plugins → Skills → Add skill → From GitHub URL, then paste the folder URL and press Continue.
2

Install in another agent

Any agent that reads the Agent Skills format can use this skill — copy the folder into that agent's skills directory.

Claude Code — .claude/skills
git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git /tmp/Privacy-Data-Protection-Skills
mkdir -p .claude/skills
cp -r /tmp/Privacy-Data-Protection-Skills/plugins/children-privacy-skills/skills/edtech-privacy-assessment .claude/skills/edtech-privacy-assessment
Restart Claude Code after copying so it picks up the new skill.

Use it in TypingMind

Enable Edtech Privacy Assessment in any TypingMind chat and the model takes it from there. Its name and description sit in the system prompt, and the moment a request matches, the model loads the full instructions itself — you never invoke it by hand, and it costs no tokens until it is actually used.

The model loads Edtech Privacy Assessment on its own as soon as a request matches it.

Works with any AI model

AI skills are plain Markdown instructions rather than provider-specific code, so Edtech Privacy Assessment is not tied to the model it was written for. Install it once in TypingMind and use it with GPT-5, Claude, Gemini, Grok, DeepSeek, Mistral, Llama, or a local model you run yourself — all on your own API keys.

  • Loaded only when it is needed

    The system prompt carries just the name and description. The instructions are fetched on the first matching request, so an idle skill costs nothing.

  • Switch models mid-chat

    Because the skill is instructions rather than code, changing model does not break it — the next model reads the same SKILL.md.

Skill instructions

This is the SKILL.md content the model loads. Read it before installing — a skill is instructions your model will follow.

EdTech Privacy Assessment — Children's Data in Educational Technology

Overview

Educational technology (EdTech) platforms that process children's personal data operate at the intersection of multiple privacy frameworks. In the United States, COPPA's school exception (16 CFR 312.5(c)(4)) allows schools to provide consent on behalf of parents for the collection of children's data in educational contexts, but only for school-authorised educational purposes. The Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. Section 1232g) governs education records maintained by educational agencies or institutions receiving federal funding. In the EU, GDPR applies with the heightened protections of Art. 8 (parental consent for children) and Recital 38 (specific protection for children). The UK AADC applies to EdTech services likely to be accessed by children. This skill provides a framework for conducting privacy assessments of EdTech platforms that navigate these overlapping requirements.

Regulatory Frameworks

COPPA School Exception — 16 CFR 312.5(c)(4)

COPPA permits an operator to collect personal information from a child for the use and benefit of the school, and for no other commercial purpose, without obtaining verifiable parental consent directly, when:

  1. The school has authorised the collection of personal information on behalf of the students
  2. The collection is solely for the school's use and benefit in the educational context
  3. The operator does not use the collected information for any commercial purpose unrelated to the educational context
  4. The operator does not disclose the information to non-school third parties

Critical Limitations:

  • The school acts as an agent of the parent; the school does not have unlimited authority
  • The school can only consent to the collection of information necessary for the school-authorised educational activity
  • If the operator wants to use the data for commercial purposes (including advertising), the operator must obtain verifiable parental consent directly from the parent
  • The FTC has stated that schools "should not be able to consent on behalf of the parent to the collection of information that is not needed for the educational purpose" (FTC COPPA FAQ J.2)

FERPA — 20 U.S.C. Section 1232g

FERPA protects education records maintained by educational agencies or institutions that receive federal funding. EdTech platforms may receive education records as "school officials" under the school official exception.

Key Provisions:

  • Education records: Records, files, documents, and other materials directly related to a student that are maintained by an educational agency or institution or by a person acting for such agency or institution
  • School official exception (34 CFR 99.31(a)(1)): An educational agency or institution may disclose education records to a contractor, consultant, volunteer, or other party to whom the agency has outsourced institutional services or functions, provided that: the party performs an institutional service or function; the party is under the direct control of the agency; the party uses the education records only for the purposes for which the disclosure was made; the party meets the criteria specified in the agency's FERPA annual notification
  • Legitimate educational interest: The school official must have a legitimate educational interest in the education records — meaning the official needs to review the record to fulfil their professional responsibility
  • Directory information exception (34 CFR 99.37): Schools may disclose directory information (name, address, telephone number, email, date and place of birth, honours, activities) without consent if parents have been notified and given the opportunity to opt out

FERPA vs. COPPA Interaction

ScenarioFERPA Applies?COPPA Applies?Result
School-directed use of EdTech platformYesYes (school exception available)School consents under COPPA; FERPA school official exception governs data handling
Student independently uses EdTech at homeNo (not maintained by school)Yes (full COPPA applies)Operator must obtain verifiable parental consent directly
EdTech vendor receives education records from schoolYesYes (school exception)FERPA and COPPA both apply; vendor must comply with both
EdTech vendor uses data for advertisingFERPA violation (non-educational use)COPPA violation (exceeds school exception)Both laws violated; school exception does not apply

GDPR Application to EdTech

In the EU, the COPPA school exception does not exist. Schools using EdTech platforms must comply with:

  • Art. 6 Lawful Basis: Schools may rely on Art. 6(1)(e) (public task) for processing necessary for educational purposes, or Art. 6(1)(f) (legitimate interests) where public task does not apply
  • Art. 8 Parental Consent: If the EdTech platform relies on consent as its lawful basis for processing children's data, parental consent is required for children below the applicable national threshold
  • Art. 28 Processor Agreement: If the school is the data controller and the EdTech vendor is the processor, a compliant Art. 28 data processing agreement must be in place
  • Controller Determination: The school is typically the controller for educational processing; the EdTech vendor is the processor. However, if the vendor processes data for its own purposes (product improvement, analytics, advertising), it becomes a controller or joint controller for those purposes

Student Privacy Pledge (FPF/SIIA)

The Student Privacy Pledge, administered by the Future of Privacy Forum (FPF) and the Software and Information Industry Association (SIIA), is a voluntary industry commitment. Signatories commit to:

  1. Not sell student personal information
  2. Not behaviourally target advertising to students using data from the educational context
  3. Not create advertising profiles of students
  4. Not change privacy policies without notice and choice
  5. Enforce strict limits on data retention and deletion
  6. Support access to and correction of student information by authorised parties
  7. Use student data only for authorised educational/school purposes or as directed by parent/student
  8. Maintain a comprehensive data security program
  9. Not disclose student information except for legitimate educational purposes
  10. Require downstream recipients to comply with these commitments

Over 400 EdTech companies are signatories as of 2024.

EdTech Privacy Assessment Framework

Assessment Phase 1: Platform Classification

QuestionSignificance
Is the platform directed to children under 13?COPPA applies fully; age gate and parental consent required
Is the platform used in a school context?COPPA school exception may apply; FERPA may apply
Does the school direct students to use the platform?Strengthens school exception applicability
Does the platform operate in the EU/UK?GDPR/UK GDPR applies; AADC compliance required
Does the platform collect persistent identifiers?COPPA personal information threshold met
Does the platform use collected data for non-educational purposes?School exception does not apply to non-educational uses

Assessment Phase 2: Data Mapping

For each data element collected by the EdTech platform:

Data ElementCollection MethodEducational PurposeNon-Educational UseRetention PeriodShared With
Student nameAccount creationIdentify student in classroomNoneAcademic year + 30 daysTeacher, parent
Email addressLogin credentialAuthenticationNoneAccount durationNone
Learning progressAutomated trackingAdaptive content, gradingProduct improvement (aggregated)Academic year + 30 daysTeacher, parent
Assignment submissionsStudent uploadAssessment, feedbackNoneAcademic year + 30 daysTeacher
Interaction logsAutomatedFeature usage analyticsProduct improvement (aggregated)90 daysNone (internal only)
Device identifiersAutomatedSession managementNoneSession onlyNone

Assessment Phase 3: Legal Basis Evaluation

JurisdictionLawful BasisConditionsDocumentation Required
US (COPPA)School exception consentSchool has authorised use; data used only for educational purposes; operator does not use data commerciallyWritten agreement with school; operator's COPPA-compliant privacy policy
US (FERPA)School official exceptionOperator performs institutional service; under school's direct control; uses records only for authorised purposesSchool's FERPA annual notification names operator as school official
EU (GDPR)Art. 6(1)(e) Public taskSchool's educational mission qualifies as public task; processing necessary for that taskSchool's records of processing (Art. 30); DPA between school and vendor (Art. 28)
UK (GDPR + AADC)Art. 6(1)(e) Public task or Art. 6(1)(f) Legitimate interestsSame as EU GDPR plus AADC compliance for all 15 standardsDPIA; AADC conformance assessment

Assessment Phase 4: Contractual Requirements

The agreement between the school and the EdTech vendor must address:

  1. Scope of data processing: Specific data elements, purposes, and retention periods
  2. Prohibition on commercial use: Vendor may not use student data for advertising, marketing, or non-educational product development
  3. Sub-processor restrictions: Vendor must disclose all sub-processors and ensure they comply with equivalent restrictions
  4. Data deletion obligations: Vendor must delete all student data at the school's request and at the end of the contract period
  5. End-of-year deletion: Vendor must delete or return all student data at the end of each academic year unless the school specifically authorises retention
  6. Security requirements: Specific technical and organisational security measures
  7. Breach notification: Vendor must notify the school within 24-72 hours of a data breach affecting student data
  8. Audit rights: School has the right to audit the vendor's compliance with the agreement
  9. FERPA compliance (US): Vendor acknowledged as school official; data used only for legitimate educational interests
  10. COPPA compliance (US): Vendor acknowledges school exception limitations; does not use data for non-educational commercial purposes

Assessment Phase 5: End-of-Year Data Lifecycle

The end of the academic year is a critical data lifecycle event for EdTech platforms. The following protocol must be implemented:

60 Days Before Year End:

  1. Notify school administrators that the end-of-year data lifecycle process will begin
  2. Provide data export options: school can download all student data in standard formats (CSV, JSON, SIF)
  3. Confirm whether the school authorises retention of any data for the next academic year

30 Days Before Year End:

  1. Notify teachers that student data will be archived
  2. Generate end-of-year student progress reports for school records
  3. Export any student-created content (assignments, projects) to the school's designated storage

Year End (Last Day of Academic Year):

  1. Deactivate all student accounts associated with the ending year
  2. Archive student data to a deletion queue (not immediately deleted, to allow for last-minute school requests)

30 Days After Year End:

  1. Execute deletion of all student data in the deletion queue unless the school has authorised retention
  2. Deletion scope: primary database, search indices, analytics databases, caches, logs
  3. Generate deletion certificates for the school

60 Days After Year End:

  1. Purge archived backups containing deleted student data
  2. Provide final deletion confirmation to the school
  3. Retain only the deletion certificate and the school agreement (no student personal data)

BrightPath Learning Inc. — EdTech Privacy Assessment

Platform Profile

BrightPath Learning Inc. operates an educational gaming platform deployed in schools and available for home use across the US, UK, and EU. The platform serves children aged 5-15.

Assessment Results

Classification:

  • Directed to children under 13: YES
  • Used in school context: YES (deployed in 2,400 schools)
  • Also available for home (non-school) use: YES
  • Operates in US, UK, EU: YES

Dual-Track Compliance:

  • School deployments: COPPA school exception applies for school-directed use; FERPA school official exception applies; GDPR Art. 6(1)(e) public task in EU
  • Home use: Full COPPA applies (verifiable parental consent via credit card); GDPR Art. 8 parental consent required in EU

Data Practices Assessment:

PracticeStatusNotes
Data used only for educational purposesPASSNo advertising, no behavioural profiling, no commercial use
Student data not soldPASSWritten policy prohibition; contractual commitment with schools
Behavioural advertising to studentsN/APlatform is ad-free; no advertising infrastructure
Data retention limited to academic yearPASSAutomatic deletion 30 days after year end; school can request earlier
Sub-processor list disclosed to schoolsPASSAWS (hosting), SendGrid (parent notifications); both under DPA
School agreement includes all required termsPASSAnnual review; covers COPPA, FERPA, GDPR, security, deletion
Breach notification procedurePASS24-hour notification to school; 72-hour to DPA (GDPR)
Parental access mechanism (home use)PASSParental dashboard with data view, download, and deletion
Student Privacy Pledge signatoryYESSigned 2024; annual compliance certification

State Student Privacy Laws

Several US states have enacted student privacy laws that impose additional requirements on EdTech vendors:

StateLawKey Requirements
CaliforniaStudent Online Personal Information Protection Act (SOPIPA, 2014)Prohibits using student data for non-educational advertising; prohibits selling student data; requires deletion when no longer needed
New YorkEducation Law Section 2-d (2014, amended 2020)Requires data privacy and security plans; parental notification of third-party access; breach notification; data encryption
ColoradoStudent Data Transparency and Security Act (2016)Requires school contracts to specify data elements, purposes, and security; prohibits targeted advertising to students
ConnecticutStudent Data Privacy Act (PA 16-189, 2016)Prohibits using student data for targeted advertising; requires operator to delete data within 30 days of request
IllinoisStudent Online Personal Protection Act (SOPPA, 2021)Requires parental notification; prohibits targeted advertising, creating commercial profiles, selling student data; mandates data breach notification
VirginiaStudent Data Governance Plan (2015)Requires schools to adopt data governance plans; vendors must comply with school data governance policies
TexasSCOPE Act (2017)Prohibits using covered information for non-educational purposes; requires security standards; mandates deletion
MarylandStudent Data Privacy Act (2015)Prohibits using student data for advertising; requires data security; mandates deletion at end of contract

Common Compliance Failures

  1. Exceeding the school exception: Using data collected under the COPPA school exception for product improvement, advertising, or other commercial purposes without separate parental consent
  2. No end-of-year deletion: Retaining student data indefinitely after the educational purpose has expired
  3. Inadequate school agreements: Missing key contractual terms such as sub-processor disclosure, deletion obligations, audit rights, or breach notification timelines
  4. Treating all collection as school-authorised: When a student uses the EdTech platform at home for non-school purposes, the school exception does not apply — the operator must obtain direct parental consent
  5. FERPA non-compliance: Failing to ensure the vendor is designated as a school official or using education records for purposes beyond legitimate educational interest
  6. No separate consent for non-educational features: Bundling consent for educational features with optional features (gamification rewards, social features) that require separate consent

Enforcement Precedents

  • Edmodo (FTC, 2023): USD 6 million penalty for collecting and using children's personal information for advertising purposes while operating as a school-directed EdTech platform, exceeding the scope of the COPPA school exception.
  • Google/YouTube (FTC, 2019): USD 170 million included channels used in educational contexts where persistent identifiers were collected for advertising.
  • InBloom (State enforcement, 2014): Data aggregation platform for student records shut down after New York, Louisiana, and other states raised FERPA and privacy concerns about centralised storage of student data with inadequate security and access controls.
  • Chegg (FTC, 2023): FTC ordered Chegg to implement comprehensive data security program after four breaches exposed personal information of millions of students and employees.

Integration Points

  • COPPA Compliance: The school exception is a narrow carve-out from COPPA's general requirements; all other COPPA requirements (notice, security, data minimisation) still apply
  • Children's Data Minimisation: EdTech platforms must collect only data necessary for the educational purpose; data minimisation is both a COPPA and GDPR requirement
  • Children's Deletion Requests: Parents retain the right to request deletion of their child's data even in school-directed contexts; schools can also request deletion under FERPA
  • GDPR Parental Consent: In the EU, the school exception does not exist; schools must rely on Art. 6(1)(e) public task or obtain parental consent under Art. 8
  • Children's Privacy Notice: EdTech platforms must provide privacy notices to both the school (as decision-maker) and parents (as rights holders)

Bundled files

The model reads these on demand while the skill is loaded. They are exposed as readable files and are never executed.

Frequently asked questions

What does the Edtech Privacy Assessment AI skill do?

Assesses children's data protection in educational technology. Covers COPPA school exception under Section 312.5(c)(4), FERPA intersection, parental rights, teacher consent authority, data deletion at year-end, and Student Privacy Pledge compliance. Keywords: edtech, COPPA school exception, FERPA, student privacy, teacher consent, educational data.

Why use Edtech Privacy Assessment on TypingMind?

Because you install it once and use it with any model. Edtech Privacy Assessment is plain Markdown rather than provider-specific code, so the same skill runs on GPT-5, Claude, Gemini, Grok, or a local model — and you can switch model mid-chat without it breaking. TypingMind runs on your own API keys, so you pay providers directly instead of a per-seat subscription, and your skills and chats stay in your own storage.

How do I install Edtech Privacy Assessment in TypingMind?

Open Plugins → Skills → Install from GitHub in TypingMind and paste https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/plugins/children-privacy-skills/skills/edtech-privacy-assessment. TypingMind reads its SKILL.md and bundles its files and installs it as a skill you can enable per chat.

Which AI models can use Edtech Privacy Assessment?

Any model you connect in TypingMind. AI skills are plain Markdown instructions rather than provider-specific code, so GPT, Claude, Gemini, Grok, and local models can all load this skill when a request matches it.

How many AI models can I use with Edtech Privacy Assessment?

As many as you like. As long as a model supports skills, you can use Edtech Privacy Assessment with it — GPT, Claude, Gemini, Grok, DeepSeek, Mistral, Llama and more — all on TypingMind with your own API keys.

Is the Edtech Privacy Assessment AI skill free?

Yes. It is published on GitHub by mukul975 under the Apache-2.0 license. You only pay your own AI provider for the tokens you use.

What are AI skills?

An AI skill is a reusable instruction bundle that teaches an AI model how to do one specific task. It follows the open Agent Skills format: a SKILL.md file with a name and description, plus any scripts, templates or reference files the model may need. The model reads the instructions only when your request matches the skill, so an installed skill costs nothing until it is used.

How are AI skills different from plugins or MCP servers?

A plugin or MCP server gives a model new tools to call — code that runs somewhere and returns a result. An AI skill gives the model knowledge and process instead: how to approach a task, which steps to follow, what good output looks like. Skills are plain Markdown, so they need no server, no API key and no runtime, and they work with any model.

View all

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇