Live data from Hacker News

Spotify GDPR data export: user receives 250MB containing every interaction

twitter.com

101–110 of 137 posts

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#101

I enjoy the mental exercise of finding where boundaries lie. For instance, if you simply observe the actions people take when they talk to you, that's obviously your observation. If you were to, say, journal it, it's still yours. It's a weird thing to do, but it's yours. If you used the journal to optimize yourself, perhaps to make conversation with you more enjoyable, again, that's weird, but perhaps also merely a p…

It's a huge difference when a company does it rather than an individual (as in your example).

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#102

Earlier quoted context omitted.

Kind of: https://www.dataprotection.ie/docs/Data-Protection-CCTV/242.... You can make a subject access request for CCTV footage.

Whoa. You're right. This is kind of insanely low fee mandated. > The data controller may charge up to €6.35 for responding to such a request and must respond within 40 days. > This normally involves providing a copy of the footage in video format. ... Where stills are supplied, it would be necessary to supply a still for every second of the recording in which the requester's image appears in order to comply with the…

This is nothing new. The right to request CCTV footage of you has been about in the UK for 20 years. It's covered by the Data Protection Act 1998. I remember some music video done this requested footage like 10 years ago https://www.youtube.com/watch?v=3LWpzHSOndk

Stop trying to VC-fund everything single idea that pops into your head.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#103
post #95
post #71

Earlier quoted context omitted.

Party A records every interaction with Party B. Party B records every interaction with Party A. Who owns what Party A recorded, and who owns what Party B recorded?

When Party A is a multibillion dollar corporation and Party B is an individual, the arguments can not be parallelized.

What if party A is a small business and party B is a litigious user movement? We can substitute values for A and B all day. At what point can we parallelize the arguments? Modern laws aren't defining that line which, in some cases while trying to solve their immediate problems, have unintended effects on the non-targets.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#104
post #12
post #6

It's kind of weird (and worrying tbh) that the user doesn't get _all_ the data by default. Shouldn't all the data be sent upon request, is there a clause saying 'only after nagging the TRUE data will be sent?

There's a sense in which summary views are the real data. If I asked Spotify to share my data, and they just sent me a 250 MB file of every interaction they've ever recorded, I would conclude they're trying to obfuscate which data they actually use and how they use it.

The default export only include the last 90 days so it's not just limited in details.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#107
post #101

I enjoy the mental exercise of finding where boundaries lie. For instance, if you simply observe the actions people take when they talk to you, that's obviously your observation. If you were to, say, journal it, it's still yours. It's a weird thing to do, but it's yours. If you used the journal to optimize yourself, perhaps to make conversation with you more enjoyable, again, that's weird, but perhaps also merely a p…

It's a huge difference when a company does it rather than an individual (as in your example).

It's a convenient difference, but I don't think it actually impacts anything.

It's an indirect way to address the level of resources you have at your disposal, which is itself only important for the scale at which you can capture the data.

In general, for the things people are OK with citizens doing but not OK with corporations doing, they mean an individual could not do it at a scale that bothers them. I'm specifically curious about what that scale is.

Certainly for me, there exists a hypothetical scale at which an individual gathering and recording detailed observations of other people becomes a little unsettling. Perhaps not criminal, but it falls into a "wish it didn't happen" bucket.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#108
post #15

Impressive-- https://twitter.com/steipete/status/1025029133175336960 "They even store the brand of headphone I use. How do you even get that data, digging deep in CoreBluetooth?"

So all a device needs to do is play sound and they can retrieve you bluetooth make, model, and serial number. There's your replacement for the unique ID that Apple supposedly killed years ago. They just need to look at your bluetooth device identifier.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#110
post #65

Earlier quoted context omitted.

No, but that's you writing down every song. The alternative is them saving one of their interactions to their server. These aren't remotely comparable...

What makes them incomparable, in your view? The medium in which it's recorded? The ease with which it's recorded by Spotify? That the recording task is done in a different system than the client-server interaction? That Spotify has interactions with LOTS of people? I get that they feel different, but every distinction I come up with feels like it either doesn't make sense applied uniformly. If I tracked songs in Exce…

> If I wrote down all my Spotify songs AND all my Skype messages AND all my texts, Spotify, Skype, and Verizon don't suddenly gain an ownership stake in what I've done.

Bringing up actual communication content is where you start to get onto shaky ground, though, especially considering, for example, the existence of "2 party consent" for recording of communications in some US jurisdictions.

Although I believe that context is entirely for criminal, not civil matters, my point is that there's already a precedent, and a long-standing one predating "data", for the idea that all parties being recorded do, automatically, have a legal ("ownership" may not be the best word, as pointed out upthread) stake in that recording, regardless of which party did the recording or holds the record.

I suspect you used Skype and Verizon, specifically, because, as mere carriers of the communication, they're not really parties to the content that they carry. That doesn't really compare, though, since we're not talking about taping the Spotify songs themselves, and the "ownership" situation there is relatively much clearer, if only because the songs existed previously and aren't being created by the interaction itself.

Post reply on HN