children-data-minimization skill
Implements strict data minimization and retention limits for children''s personal data under GDPR Art. 5(1)(c), Recital 38, UK AADC Standard 8, and COPPA Section 312.7. Covers strict necessity testing, shorter retention periods, limited profiling, parental dashboard design, and automated deletion. Keywords: data minimization, children, retention, necessity test, parental dashboard.
Is the children-data-minimization skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the children-data-minimization skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open mkdir -p ~/.claude/skills cp -r /tmp/legal-skills-open/cross-jurisdiction/data-protection/skills/children-data-minimization ~/.claude/skills/children-data-minimization
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Children's Data Minimisation and Retention Limits
Overview
Data minimisation for children's data requires a stricter interpretation of GDPR Article 5(1)(c) ("adequate, relevant and limited to what is necessary") than the standard adult context. Recital 38 states that children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences, and safeguards concerned and their rights in relation to the processing of personal data. The UK AADC Standard 8 explicitly requires that services collect and retain "only the minimum amount of personal data needed to provide the elements of the service in which a child is actively and knowingly engaged." COPPA Section 312.7 prohibits conditioning a child's participation on the collection of more personal information than is reasonably necessary. This skill provides a comprehensive framework for applying these heightened standards.
Legal Framework
GDPR Article 5(1)(c) — Data Minimisation Principle
"Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed."
When applied to children's data, "necessary" is interpreted strictly. The EDPB has confirmed that the vulnerability of children as data subjects (WP248rev.01 Criterion 7) elevates the data minimisation obligation.
GDPR Article 5(1)(e) — Storage Limitation Principle
"Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed."
For children's data, retention periods should be shorter than for adult data given that: (a) the purposes of processing often have a shorter useful life for children (e.g., educational progress in a specific grade), (b) the risk of harm from data exposure increases with retention duration, and (c) the child may not have meaningfully consented to long-term retention.
GDPR Recital 38 — Specific Protection for Children
"Children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data. Such specific protection should, in particular, apply to the use of personal data of children for the purposes of marketing or creating personality or user profiles and the collection of personal data with regard to children when using services offered directly to children."
UK AADC Standard 8 — Data Minimisation
"Collect and retain only the minimum amount of personal data you need to provide the elements of your service in which a child is actively and knowingly engaged. Give children separate choices over which elements they wish to activate."
Key ICO interpretations:
- "Actively and knowingly engaged" means the child is intentionally using a specific feature, not passively generating data through background collection
- "Separate choices" means children must be able to use core service features without being forced to activate data-intensive optional features
- Background data collection (location, microphone, contacts, gyroscope) is prohibited unless the child actively triggers a feature requiring it
COPPA Section 312.7 — Data Minimisation
"An operator is prohibited from conditioning a child's participation in a game, the offering of a prize, or another activity on the child disclosing more personal information than is reasonably necessary to participate in such activity."
Strict Necessity Test
For each data element collected from a child, the controller must apply the Strict Necessity Test — a more demanding evaluation than the standard proportionality assessment used for adult data.
Test Questions
Application to Common Data Categories
Retention Period Framework
Children's data must be subject to shorter retention periods than adult data. The following framework establishes maximum retention periods for common categories.
Retention Schedule
End-of-Academic-Year Deletion
For educational platforms, the end of the academic year represents a natural data lifecycle milestone. BrightPath Learning implements the following end-of-year protocol:
- 30 days before academic year end: Parent receives notification that learning data will be archived
- End of academic year: Learning progress data is exported to a parent-downloadable report (PDF)
- 14 days after year end: If parent has not requested retention, granular activity data is deleted; only aggregate progress scores are retained for the next year's placement
- 60 days after year end: Aggregate scores deleted unless the child continues to the next year's service
Parental Dashboard Design
The parental dashboard is the primary mechanism for parental oversight and control over children's data. It must provide meaningful transparency and actionable controls.
Required Dashboard Features
BrightPath Learning — Dashboard Implementation
┌─────────────────────────────────────────────────────────┐
│ BrightPath Learning — Parent Dashboard │
│ Child: Alex (Age 11, France — threshold: 15) │
│ Account created: 2025-09-01 │
│ Next age review: 2026-09-01 (age 12) │
├─────────────────────────────────────────────────────────┤
│ │
│ DATA WE HOLD │
│ ┌──────────────────┬─────────────────┬──────────────┐ │
│ │ Category │ Purpose │ Status │ │
│ ├──────────────────┼─────────────────┼──────────────┤ │
│ │ First name │ Account ID │ Required │ │
│ │ Age band (10-12) │ Content level │ Required │ │
│ │ Learning scores │ Progress track │ ✓ Consented │ │
│ │ Game activity │ Recommendations │ ✗ Not active │ │
│ └──────────────────┴─────────────────┴──────────────┘ │
│ │
│ PRIVACY CONTROLS │
│ [✓] Share progress reports with me (parent) │
│ [ ] Allow content-based recommendations │
Automated Deletion Implementation
Technical Architecture
- Retention metadata: Every data record includes a retentioncategory field mapped to the retention schedule and an expiresat timestamp
- Deletion scheduler: A daily batch job identifies all records where expiresat < currenttimestamp and executes deletion
- Cascade deletion: Account deletion triggers cascade deletion across all related tables (activity logs, content, communications, consent records subject to their own retention schedule)
- Deletion verification: Post-deletion audit confirms that records are removed from primary storage, backup systems, and any caches
- Backup purge: Backups containing children's data are subject to a maximum 30-day retention cycle. Backup restoration procedures include a re-deletion step for expired children's data.
Deletion Logging
Every deletion event is logged for accountability:
{
"deletion_id": "DEL-2026-0047821",
"trigger": "automated_retention_expiry",
"data_category": "session_data",
"child_identifier": "child_bp_8f3a2d",
"records_deleted": 847,
"deletion_timestamp": "2026-03-14T02:00:00Z",
"deletion_scope": "primary_database, elasticsearch_index, redis_cache",
"backup_purge_scheduled": "2026-04-13T02:00:00Z",
"verified_by": "automated_verification_check"
}Common Compliance Failures
- Adult-equivalent retention: Applying the same retention periods to children's data as adult data, without justification for why shorter periods are not feasible
- Indefinite retention until deletion request: Retaining children's data indefinitely unless a parent specifically requests deletion violates Art. 5(1)(e) storage limitation
- Background data collection: Collecting device identifiers, location, accelerometer, or microphone data in the background without the child actively using a feature that requires it
- Contact list access: Requesting access to the child's device contact list for "find friends" features without strict necessity
- No parental dashboard: Failing to provide parents with a meaningful mechanism to view, control, and delete their child's data
- Backup retention gap: Deleting data from production systems but retaining it indefinitely in backups
Enforcement Precedents
- TikTok (DPC Ireland, 2023): EUR 345 million fine included findings on excessive data collection from children, including default public profiles exposing children's content to all users, violating Art. 5(1)(c) data minimisation.
- YouTube/Google (FTC, 2019): USD 170 million settlement for collecting persistent identifiers from child-directed channel viewers for advertising purposes — data not necessary for the service the child was using.
- Epic Games/Fortnite (FTC, 2022): USD 275 million for collecting personal information from children beyond what was necessary, including enabling real-time voice communications by default.
Integration Points
- GDPR Parental Consent: Parental consent scope should be limited to data collection justified by the necessity test — parents should not be asked to consent to unnecessary collection
- UK AADC Implementation: AADC Standard 8 is the primary operational standard for children's data minimisation in the UK
- Children's Profiling Limits: Data minimisation directly limits the data available for profiling, reinforcing AADC Standard 12 restrictions
- Children's Deletion Requests: The retention framework defines what data exists to be deleted and when automatic deletion occurs
- EdTech Privacy Assessment: Educational platforms must balance data minimisation with legitimate educational record-keeping needs
More skills from ThomasMoreAI/legal-skills-open
- A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
- A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
- Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
- Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
- Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
- Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
- Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
- Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
- Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
- Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
- Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
- Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway