Mmcp.market

children-profiling-limits skill

by ThomasMoreAI·ThomasMoreAI/legal-skills-open·79 stars·Apache-2.0

Implements profiling restrictions for children under GDPR Recital 71, Article 22, UK AADC Standard 12, and COPPA. Covers prohibition of behavioural advertising to children, recommendation algorithm limitations, nudge technique prohibition, and automated decision-making safeguards. Keywords: profiling, children, behavioural advertising, recommendation algorithm, AADC, automated decision.

A100/100content scan

Is the children-profiling-limits skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the children-profiling-limits skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open
mkdir -p ~/.claude/skills
cp -r /tmp/legal-skills-open/cross-jurisdiction/data-protection/skills/children-profiling-limits ~/.claude/skills/children-profiling-limits
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Children's Profiling Restrictions

Overview

Profiling of children is subject to heightened restrictions under multiple regulatory frameworks. GDPR Recital 71 states that automated decision-making including profiling "should not concern a child." The UK AADC Standard 12 requires profiling to be switched off by default for child users, with exceptions only where the controller can demonstrate a compelling reason and appropriate protective measures. The EU Digital Services Act (DSA) Article 28(2) explicitly prohibits online platforms from presenting targeted advertising based on profiling using the personal data of minors. COPPA prohibits the collection of persistent identifiers from children for behavioural advertising without verifiable parental consent. This skill establishes a comprehensive framework for lawful and ethical data processing that avoids prohibited profiling of children.

Legal Framework

GDPR Recital 71 — Children and Automated Decisions

"In any case, such processing should be subject to suitable safeguards, which should include specific information to the data subject and the right to obtain human intervention, to express his or her point of view, to obtain an explanation of the decision reached after such assessment and to challenge the decision. Such measure should not concern a child."

The EDPB interprets "should not concern a child" as a strong presumption against subjecting children to automated decision-making based on profiling that produces legal or similarly significant effects. While "should not" is weaker than "shall not," the EDPB guidance and DPA enforcement practice treat this as an effective prohibition unless exceptional circumstances apply.

GDPR Article 22 — Automated Individual Decision-Making

Art. 22(1): "The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."

For children, this prohibition is reinforced by Recital 71. Exceptions under Art. 22(2) (contract necessity, law, explicit consent) are interpreted narrowly for children:

  • Contract necessity (Art. 22(2)(a)): Rarely applicable to children; children's contracts are often voidable
  • Law (Art. 22(2)(b)): May apply for age verification or child safety obligations
  • Explicit consent (Art. 22(2)(c)): Must be parental consent under Art. 8 for children below the threshold; the child's explicit consent alone is insufficient

GDPR Article 4(4) — Definition of Profiling

"Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements."

UK AADC Standard 12 — Profiling

"Switch options which use profiling off by default (unless you can demonstrate a compelling reason for profiling to be on by default, taking account of the best interests of the child). Only allow profiling if you have appropriate measures in place to protect the child from any harmful effects (including but not limited to feeding the child content that is detrimental to their health or wellbeing)."

UK AADC Standard 13 — Nudge Techniques

"Do not use nudge techniques to lead or encourage children to provide unnecessary personal data or weaken or turn off their privacy protections."

EU Digital Services Act — Article 28(2)

"Providers of online platforms shall not present advertisements on their interface based on profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679, using personal data of the recipient of the service when they are aware with reasonable certainty that the recipient of the service is a minor."

COPPA — Persistent Identifiers

COPPA defines persistent identifiers as personal information when used for purposes other than support for internal operations. Using persistent identifiers to serve behavioural advertising to children requires verifiable parental consent.

Types of Profiling and Their Status for Children

Prohibited Profiling

Restricted Profiling (Permitted with Safeguards)

Permitted Processing (Not Profiling)

Recommendation Algorithm Safeguards

For services that implement content recommendation algorithms for children (where permitted), the following safeguards must be in place:

Content Diversity Injection

  • Recommendation algorithms must include a minimum diversity ratio (e.g., at least 30% of recommended content must be from categories the child has NOT previously engaged with)
  • This prevents filter bubbles and content rabbit holes that can be particularly harmful to children's development
  • The diversity injection must be documented and periodically reviewed

Time-Limitation Mechanisms

  • Recommendation-driven feeds must include natural stopping points (e.g., "You've been browsing for 20 minutes — time for a break!")
  • Autoplay must be disabled by default for children per UK AADC guidance (YouTube implemented this following ICO engagement)
  • Infinite scroll must be replaced with paginated content with clear endpoints

Content Safety Filters

  • All recommended content must pass through content safety filters before being presented to children
  • Filters must be age-tiered: stricter for younger children, proportionate for teenagers
  • Human review for edge cases where automated filtering confidence is low

Mental Health Circuit Breakers

  • If the recommendation algorithm detects engagement patterns associated with harmful content cycles (e.g., repeated engagement with content about self-harm, eating disorders, or extreme body image), the algorithm must:
  1. Stop recommending similar content
  2. Interject wellbeing resources or helpline information
  3. Alert the parent through the parental dashboard (without disclosing specific content details that might violate the child's confidence)

Nudge Technique Prohibition

Prohibited Nudge Techniques for Children

Required Design Patterns

BrightPath Learning Inc. — Profiling Compliance Implementation

Profiling Status Matrix

Algorithmic Impact Assessment

BrightPath conducts an annual Algorithmic Impact Assessment for its learning content recommendation system:

  1. Purpose test: Does the algorithm serve the child's educational interests? YES — adjusts content to appropriate difficulty level
  2. Necessity test: Could the educational purpose be achieved without profiling? NO — adaptive learning requires assessment of current skill level
  3. Proportionality test: Is the profiling limited to what is necessary? YES — only learning assessment scores are used; no behavioural data, no demographic data beyond age
  4. Harm assessment: Could the algorithm produce harmful effects? ASSESSED — risk of discouragement if difficulty increases too rapidly; mitigated by gradual progression and positive reinforcement design
  5. Bias audit: Does the algorithm produce different outcomes based on protected characteristics? TESTED — annual bias audit across age, gender, and language groups; no statistically significant disparities found
  6. Human oversight: Can a human override the algorithm? YES — parents can manually set content difficulty levels; teachers (in school deployments) can override

Enforcement Precedents

  • TikTok (DPC Ireland, 2023): EUR 345 million fine included findings that TikTok's "For You" algorithmic feed profiled children to serve content, with inadequate safeguards against harmful content amplification, violating GDPR Art. 5(1)(a), 5(1)(c), and 25.
  • Instagram (Meta, DPC Ireland, 2022): EUR 405 million fine for failing to restrict profiling and public exposure of children's data, including default public profiles for business accounts used by children aged 13-17.
  • YouTube (FTC, 2019): USD 170 million settlement for using persistent identifiers (cookies) to track children's viewing behaviour on child-directed channels and serve behaviourally targeted advertising.
  • TikTok (CNIL France, 2022): EUR 5 million fine for making it difficult for users, including children, to refuse tracking cookies — constituting a nudge technique that weakened privacy protections.
  • Fortnite/Epic Games (FTC, 2022): USD 275 million for design choices that exposed children to harmful interactions, with dark patterns facilitating in-app purchases by children.

Common Compliance Failures

  1. Profiling on by default: Activating recommendation algorithms, personalisation features, or content curation based on behavioural profiling without requiring explicit opt-in
  2. Behavioural advertising to known children: Serving targeted advertisements based on personal data profiles despite DSA Art. 28(2) prohibition
  3. No algorithmic impact assessment: Deploying algorithms that affect children without assessing their impact on children's rights, wellbeing, and development
  4. Nudge techniques in consent flows: Using dark patterns, confirmshaming, or asymmetric choice design to obtain consent for profiling features
  5. Cross-service tracking: Using persistent identifiers to track children across websites or services for profiling purposes
  6. No content diversity safeguards: Allowing recommendation algorithms to create filter bubbles or content rabbit holes without diversity injection or time limits

Integration Points

  • Children's Data Minimisation: Data minimisation directly limits the data available for profiling — less data collected means less material for profile construction
  • UK AADC Implementation: AADC Standards 5, 7, 12, and 13 collectively govern profiling, defaults, nudge techniques, and detrimental use
  • Children's Privacy Notice: The privacy notice must clearly explain what profiling occurs, its effects, and how the child/parent can object
  • GDPR Parental Consent: Parental consent is required for any profiling of children below the Art. 8 threshold
  • Age-Gating Services: The age gate result determines which profiling restrictions apply to the user account

More skills from ThomasMoreAI/legal-skills-open

  • A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
  • A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
  • Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
  • Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
  • Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
  • Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
  • Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
  • Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
  • Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
  • Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
  • Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
  • Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway

All agent skills → · MCP servers