Live data from Hacker News

Spotify GDPR data export: user receives 250MB containing every interaction

twitter.com

131–137 of 137 posts

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#131
post #129
post #34

Earlier quoted context omitted.

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

Damn - you bring up a good point. I wonder what a lawyer would say. Taking your thought one more step, what happens to the data the store creates thru a facial recognition system tied to the footage? Is that covered? I don’t know, but there are thousands of further permutations on his thought. Another reason I hate the GDPR (great intent, horrible execution).

I think the general point of decision is still about "personally identifiable information".

So my (IANAL) understanding is: If the data is somehow tied to your real life identity, it's protected. E.g., the headphone brand might be protected because it's uniquely associated with your user account which is uniquely tied to a real-life identity.

I guess, whether or not the facial recognition output is protected, might depend on whether you want to use it to identify the person behind it - e.g., if it's an identifier to a database, it might be protected. If it's an emotion score or eye tracking analysis, it might not be protected, unless it's associated with your identity by some other process.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#132
post #94
post #49

Earlier quoted context omitted.

I’m upvoting and agree in the realistic point you are making, but feel this isn’t the most popular point of view right now? I personally believe info just shouldn’t be captured period, beyond reasons for authentication protection purposes/identifying malicious/off pattern use of my login/auth token. We are releasing a new business/info mgmt product soon that has no GA/full story/user tracking whatsoever. It’s not cle…

One thing that people constantly praise Spotify for is the quality of their music recommendations. You can find so many testimonials of people saying that their "Discover Weekly" playlist suggested them songs which they felt they had been searching for their whole lives. Needless to say, such accurate recommendations of music, which even close personal friends have trouble doing, is based on building as complete of a…

> Needless to say, such accurate recommendations of music, which even close personal friends have trouble doing, is based on building as complete of a psychological profile of the user as possible.

And then an innovative "security contractor" or "data research agency" makes a backroom deal with Spotify and copies their database of complete psychological profiles. Win-win?

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#133
post #62

Remember all of the data Winamp2 used to gather and send to third-party servers?

It's weird how perception on these things has shifted. So many practices are "normal" today which used to be clearly labeled "spyware" only 15 years ago. They successfully rebranded spyware, now it's called "telemetry", or similar. Anyone remember the huge privacy-related outrage when Windows XP came out, because it forced users to do challenge-response activation? How times have changed...

It might just be that all those people have switched to free software and aren't being vocal because of that?

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#134
post #72

Man I was comfortable running spotify as the only non-free app on my Linux machines, now I'm not. It's back to ocp and mods/classical music/occasional purchased for me I guess... (except on my phone of course which is a lost cause)

Why are you uncomfortable with Spotify now?

Because it's a piece of proprietary software?

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#135
post #94
post #49

Earlier quoted context omitted.

I’m upvoting and agree in the realistic point you are making, but feel this isn’t the most popular point of view right now? I personally believe info just shouldn’t be captured period, beyond reasons for authentication protection purposes/identifying malicious/off pattern use of my login/auth token. We are releasing a new business/info mgmt product soon that has no GA/full story/user tracking whatsoever. It’s not cle…

One thing that people constantly praise Spotify for is the quality of their music recommendations. You can find so many testimonials of people saying that their "Discover Weekly" playlist suggested them songs which they felt they had been searching for their whole lives. Needless to say, such accurate recommendations of music, which even close personal friends have trouble doing, is based on building as complete of a…

At some level, I think one should have privacy concerns with baby monitors ... did your baby choose to opt-in?

(Three kids here, and no, we never used a baby monitor...)

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#136
post #94

Earlier quoted context omitted.

One thing that people constantly praise Spotify for is the quality of their music recommendations. You can find so many testimonials of people saying that their "Discover Weekly" playlist suggested them songs which they felt they had been searching for their whole lives. Needless to say, such accurate recommendations of music, which even close personal friends have trouble doing, is based on building as complete of a…

At some level, I think one should have privacy concerns with baby monitors ... did your baby choose to opt-in? (Three kids here, and no, we never used a baby monitor...)

I hope the sarcasm is flying over my head here...

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#137

Earlier quoted context omitted.

Whoa. You're right. This is kind of insanely low fee mandated. > The data controller may charge up to €6.35 for responding to such a request and must respond within 40 days. > This normally involves providing a copy of the footage in video format. ... Where stills are supplied, it would be necessary to supply a still for every second of the recording in which the requester's image appears in order to comply with the…

This is nothing new. The right to request CCTV footage of you has been about in the UK for 20 years. It's covered by the Data Protection Act 1998 . I remember some music video done this requested footage like 10 years ago https://www.youtube.com/watch?v=3LWpzHSOndk Stop trying to VC-fund everything single idea that pops into your head.

> Stop trying to VC-fund everything single idea that pops into your head.

Even if had suggested VC funding (I didn't), were an investor (I'm not), lived in the UK (I don't), and had experience with video automation (I don't), why would you care? The background info was helpful enough.

Post reply on HN