Live data from Hacker News

Spotify GDPR data export: user receives 250MB containing every interaction

twitter.com

31–40 of 137 posts

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#31
post #22

Earlier quoted context omitted.

If you think about it, now it makes sense why big names in smartphone industry like Apple and Samsung are removing P2 plugs from smartphones in favor of more powerful interfaces like Lighting/USB-C: so you can track more information about the user. Just imagine: you can track which kind of phone a user that likes to listen to Heavy Metal, for example, likes to use, or which phone is more popular at the moment. Based…

There's a much more mundane explanation - waterproofing. Lightning and USB-C connectors can both be made intrinsically waterproof up to IPx7, while the 3.5mm jack can't. Waterproofing is a key point of differentiation for recent flagship phones. An iPhone 7 will survive a dip in a toilet bowl or a pint of beer, but an iPhone 6 probably won't.

Plenty of phones where waterproof before. The lightning port is waterproof despite having many more pins than a simple phone jack.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#32
post #22

Earlier quoted context omitted.

If you think about it, now it makes sense why big names in smartphone industry like Apple and Samsung are removing P2 plugs from smartphones in favor of more powerful interfaces like Lighting/USB-C: so you can track more information about the user. Just imagine: you can track which kind of phone a user that likes to listen to Heavy Metal, for example, likes to use, or which phone is more popular at the moment. Based…

There's a much more mundane explanation - waterproofing. Lightning and USB-C connectors can both be made intrinsically waterproof up to IPx7, while the 3.5mm jack can't. Waterproofing is a key point of differentiation for recent flagship phones. An iPhone 7 will survive a dip in a toilet bowl or a pint of beer, but an iPhone 6 probably won't.

So all the other phone manufacturers selling IP68 phones with headphone jacks are lying?

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#33
post #7

Earlier quoted context omitted.

Interesting. Can they still sell it if it's owned by you? They are collecting and storing it, for sure. What limitations do they have from there? Also, how would the government patrol this without having access to all companies databases, servers, and policies?

They have to ask me if they can use it and for what purpose. And even better, they can’t condition the use of the site/product on me accepting that they sell it.

Is this actually happening, though?

I feel most sites don't comply with the latter half of your statement (conditioning based on acceptance).

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#34
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#35
post #29

Earlier quoted context omitted.

If I may intrude, I think they mean that revealing to you data that involves you and other people could invade the privacy of those other people.

Gotcha. Thank you, for some reason that wasn't immediately clicking in my brain.

For a bit more context, this was recently discussed a LOT with the Cambridge Analytica Facebook scandal.

The issue being that if you text me, and I give that to Facebook, does facebook have the right to ask me for permission to give it to a 4th party? Should facebook be required to give you that information if you don't have a facebook account and request it?

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#36
post #33
post #7

Earlier quoted context omitted.

They have to ask me if they can use it and for what purpose. And even better, they can’t condition the use of the site/product on me accepting that they sell it.

Is this actually happening, though? I feel most sites don't comply with the latter half of your statement (conditioning based on acceptance).

This is very true. Many sites and services seem to have deliberately misinterpreted the legal text. I hope a high profile target will be taken to court over this, to establish a cautionary precedent. It just hasn’t happened yet.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#38
post #19

Earlier quoted context omitted.

Further I don't think anyone understands Identity well enough to be able to provide transitively collected data without breaching confidence of similar third-parties. Would you be willing to unpack this statement a bit, please? I'm not quite sure I understand.

If I may intrude, I think they mean that revealing to you data that involves you and other people could invade the privacy of those other people.

This is one of the issues in personal data and privacy that I think we're going to have to acknowledge and confront some time very soon: often, data about an individual in isolation is less telling than data about that individual's relationships, but relationships always involve multiple parties. Right now, we've barely established a consensus on the ethical and legal principles of a relationship between a single data subject and a second party using data about them.

The big social networks have amassed their huge databases not only through information volunteered by individual members, but also by co-opting people who know those individuals (or just happened to be nearby) to provide more. For example, every time a social network's mobile app uploads an address book from someone I know when they install on their new phone, and consequently that social network knows my name and contact details, they have potentially violated my privacy with neither my knowledge nor consent. With the advent of ubiquitous devices with cameras, microphones, network connectivity, GPS and other sensors, and at the same time the developments in automatic recognition technologies based on photos, audio or video footage, the risks of exploiting network effects to gather data on unwilling subjects have increased dramatically.

I'm not sure it's reasonable to expect every person I've ever shared my contact details with or anyone who ever took a photo with me in the background to understand the implications of their devices and the software they run on them. In any case, there are going to be difficult ethical questions about balancing the rights and freedoms of multiple parties.

However, I am quite sure it's fair to require businesses on the scale of Facebook to understand the basic situation and at least not to retain or use personal data for any longer than is necessary. The GDPR and similar proposals starting to appear elsewhere are clearly trying to enshrine something like that principle in law, but everything I have seen so far suggests that the biggest data hoarders are paying lip service but still trying to get away with anything they can.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#39
post #34
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

That's the wrong analogy. The camera isn't some "security footage" in a random store, it's security footage from my own living room.

A better analogy is this: if i install a video camera in my home and pay a service to store and process that data (think nest cam), but that i'm paying monthly for, then that data should be mine. Stuff going on in my living room (aka my music listening habits) should be mine and i should have access to my habits and restrict others from using it if i want to.

Update: more importantly, without having access to data stored by any service, i can't make an informed decision as to whether the service is storing dubious information about myself that it shouldn't. Services can no longer hide the data they store about people.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#40
post #34
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

If the user didn't use Spotify, then the interaction data wouldn't exist.

It takes two. Perhaps if these companies had taken that tact (mutual ownership), then there'd have been no need for a law to specifically allow users to get the data created with their own effort.

Post reply on HN