juicebox-data-handling
A guide to implementing GDPR-compliant data handling, encryption, and privacy controls for Juicebox recruitment datasets.
Install
mkdir -p .claude/skills/juicebox-data-handling && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/8634" && unzip -o skill.zip -d .claude/skills/juicebox-data-handling && rm skill.zipInstalls to .claude/skills/juicebox-data-handling
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Juicebox data privacy and GDPR.Key capabilities
- →Classify data types by sensitivity, retention, encryption.
- →Import people datasets from Juicebox API.
- →Export analysis results with contact info sanitized.
- →Validate profile data for required fields and format.
- →Track GDPR consent and support right-to-deletion.
- →Encrypt contact data at field level with per-tenant keys.
How it works
This skill defines data handling standards for Juicebox AI, classifying data by sensitivity and retention, and providing functions for importing, exporting, and validating profile data while ensuring compliance with privacy regulations.
Inputs & outputs
When to use juicebox-data-handling
- →Implement GDPR data deletion support
- →Apply field-level encryption to contact data
- →Manage candidate PII retention policies
- →Audit access controls for recruitment datasets
About this skill
Juicebox Data Handling
Overview
Juicebox AI processes people datasets for talent intelligence and analysis workflows. Data types include people search results, enriched profile records (employment history, skills, social links), analysis exports, and outreach logs. Profile data often contains personal information governed by GDPR, CCPA, and recruitment privacy regulations. All enrichment results must be handled with consent tracking, purpose limitation, and right-to-deletion support. Contact data requires field-level encryption and strict access controls to prevent unauthorized disclosure.
Data Classification
| Data Type | Sensitivity | Retention | Encryption |
|---|---|---|---|
| Search results | Low | Session only (ephemeral) | TLS in transit |
| Enriched profiles | High (PII) | Per data policy, max 1 year | AES-256 at rest |
| Contact data (email/phone) | High (PII) | Until candidate objects or deletion | Field-level encryption |
| Analysis exports | Medium | 90 days | AES-256 at rest |
| Outreach logs | Medium | 6 months | AES-256 at rest |
Data Import
interface JuiceboxProfile {
id: string; name: string; email?: string; phone?: string;
company: string; title: string; skills: string[];
source: string; enrichedAt: string;
}
async function importPeopleDataset(query: string, maxResults = 100): Promise<JuiceboxProfile[]> {
const profiles: JuiceboxProfile[] = [];
let offset = 0;
do {
const res = await fetch(`https://api.juicebox.ai/v1/search`, {
method: 'POST',
headers: { Authorization: `Bearer ${process.env.JUICEBOX_API_KEY}`, 'Content-Type': 'application/json' },
body: JSON.stringify({ query, limit: 50, offset }),
});
const data = await res.json();
if (!data.results?.length) break;
for (const p of data.results) {
if (!p.id || !p.name) throw new Error(`Invalid profile: missing required fields`);
profiles.push(p);
}
offset += 50;
} while (profiles.length < maxResults);
return profiles;
}
Data Export
async function exportAnalysisResults(profiles: JuiceboxProfile[], format: 'csv' | 'json') {
// Strip direct contact info from exports unless explicitly authorized
const sanitized = profiles.map(({ email, phone, ...rest }) => ({
...rest,
email: email ? '[CONSENT_REQUIRED]' : undefined,
phone: phone ? '[CONSENT_REQUIRED]' : undefined,
}));
if (format === 'csv') {
const header = Object.keys(sanitized[0]).join(',');
const rows = sanitized.map(r => Object.values(r).join(','));
return [header, ...rows].join('\n');
}
return JSON.stringify(sanitized, null, 2);
}
Data Validation
function validateProfile(p: JuiceboxProfile): string[] {
const errors: string[] = [];
if (!p.id) errors.push('Missing profile ID');
if (!p.name || p.name.length > 200) errors.push('Invalid or missing name');
if (p.email && !/^[\w.+-]+@[\w-]+\.[\w.]+$/.test(p.email)) errors.push('Invalid email format');
if (p.phone && !/^\+?[\d\s()-]{7,20}$/.test(p.phone)) errors.push('Invalid phone format');
if (!p.source) errors.push('Missing data source attribution');
if (p.enrichedAt && isNaN(Date.parse(p.enrichedAt))) errors.push('Invalid enrichment timestamp');
return errors;
}
Compliance
- GDPR consent tracked per profile: lawful basis recorded (consent, legitimate interest)
- Right-to-deletion: purge profile, enrichment data, and outreach logs within 30 days of request
- GDPR data subject access: export all stored data for a candidate on request
- CCPA opt-out: honor Do Not Sell signals for California residents
- Purpose limitation: enrichment data used only for stated recruitment/analysis purpose
- Contact data encrypted at field level with per-tenant keys
- Audit log for all profile access, export, and deletion events
- Data minimization: auto-purge enriched profiles older than retention window
Error Handling
| Issue | Cause | Fix |
|---|---|---|
| API 401 unauthorized | Expired or revoked API key | Rotate key in secret manager, update env |
| Duplicate profiles in import | Same person from multiple sources | Deduplicate by email hash before storage |
| GDPR deletion incomplete | Outreach logs not purged alongside profile | Cascade delete across all related tables |
| Export contains raw PII | Consent flag not checked before export | Add consent gate in exportAnalysisResults |
| Enrichment timeout | Upstream data provider slow | Implement 10s timeout with retry, fallback to cached |
Resources
- Juicebox Privacy Policy
- GDPR Data Subject Rights
Next Steps
See juicebox-security-basics.
When not to use it
- →When Juicebox API key is expired or revoked.
- →When outreach logs are not purged alongside profile deletion.
Limitations
- →Duplicate profiles may appear if from multiple sources.
- →GDPR deletion may be incomplete if outreach logs are not purged.
- →Export may contain raw PII if consent flag is not checked.
How it compares
This skill provides specific code examples and compliance checklists for Juicebox data, offering a structured approach to PII handling compared to general data privacy guidelines.
Compared to similar skills
juicebox-data-handling side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| juicebox-data-handling (this skill) | 0 | 25d | Review | Intermediate |
| gdpr-dsgvo-expert | 8 | 7mo | Review | Advanced |
| data-privacy-compliance | 4 | 7mo | No flags | Intermediate |
| ra-qm-skills | 1 | 2mo | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
gdpr-dsgvo-expert
davila7
Senior GDPR/DSGVO expert and internal/external auditor for data protection compliance. Provides EU GDPR and German DSGVO expertise, privacy impact assessments, data protection auditing, and compliance verification. Use for GDPR compliance assessments, privacy audits, data protection planning, and regulatory compliance verification.
data-privacy-compliance
davila7
Data privacy and regulatory compliance specialist for GDPR, CCPA, HIPAA, and international data protection laws. Use when implementing privacy controls, conducting data protection impact assessments, ensuring regulatory compliance, or managing data subject rights. Expert in consent management, data minimization, and privacy-by-design principles.
ra-qm-skills
alirezarezvani
12 production-ready regulatory affairs and quality management skills for HealthTech/MedTech: ISO 13485 QMS, MDR 2017/745, FDA 510(k)/PMA, ISO 27001 ISMS, GDPR/DSGVO compliance, risk management (ISO 14971), CAPA, document control, and internal auditing. Python tools included (all stdlib-only). Works with Claude Code, Codex CLI, and OpenClaw.
compliance-auditor
qa-aman
|
fda-medtech-compliance-auditor
TJSNDHU
Expert AI auditor for Medical Device (SaMD) compliance, IEC 62304, and 21 CFR Part 820. Reviews DHFs, technical files, and software validation.
ccpa-compliance
TerminalSkills
>-