Live data from Hacker News

Spotify GDPR data export: user receives 250MB containing every interaction

twitter.com

11–20 of 137 posts

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#11
post #7

Earlier quoted context omitted.

They have to ask me if they can use it and for what purpose. And even better, they can’t condition the use of the site/product on me accepting that they sell it.

That sounds good. How is it enforced? ( not being sarcastic )

It’s not (yet). The GDPR is still new and as far as I know there haven’t been many (or perhaps not any) legal processes.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#12
post #6

It's kind of weird (and worrying tbh) that the user doesn't get _all_ the data by default. Shouldn't all the data be sent upon request, is there a clause saying 'only after nagging the TRUE data will be sent?

There's a sense in which summary views are the real data. If I asked Spotify to share my data, and they just sent me a 250 MB file of every interaction they've ever recorded, I would conclude they're trying to obfuscate which data they actually use and how they use it.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#14
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

Interesting. Can they still sell it if it's owned by you? They are collecting and storing it, for sure. What limitations do they have from there? Also, how would the government patrol this without having access to all companies databases, servers, and policies?

>Also, how would the government patrol this without having access to all companies databases, servers, and policies?

As in many other cases you assume the companies are not doing illegal stuff and you act when someone reports them. A developer that is asked to do something illegal like hiding something from the exported data can report it .

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#17
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

I don't think everyone agrees people have the right to claim ownership to all data exchanged in a multi-party interaction. Further I don't think anyone understands Identity well enough to be able to provide transitively collected data without breaching confidence of similar third-parties.

Nothing is as simple as a quip can make it sound.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#19
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

I don't think everyone agrees people have the right to claim ownership to all data exchanged in a multi-party interaction. Further I don't think anyone understands Identity well enough to be able to provide transitively collected data without breaching confidence of similar third-parties. Nothing is as simple as a quip can make it sound.

Further I don't think anyone understands Identity well enough to be able to provide transitively collected data without breaching confidence of similar third-parties.

Would you be willing to unpack this statement a bit, please? I'm not quite sure I understand.

Post reply on HN