Live data from Hacker News

Spotify GDPR data export: user receives 250MB containing every interaction

twitter.com

41–50 of 137 posts

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#41
post #28

Seems like CSV would've been a better format than JSON for this type of data based on the screenshots.

Indeed. Your typical data requester isn't going to know code for working with JSON. And converting JSON to CSV is a pain.

To be fair, GDPR stipulates only that it should be available in a common machine-readable format. It doesn’t require the most convenient format conceivable.

Also, CSV can’t easily handle nested objects. If the data model is even slightly more complex than a plain table, it doesn’t make much sense. I’d also argue that even if the source data is stored in an RDMS without exotic data types, a JSON with a nested object representation is probably going to be more friendly even to non-developers than multiple files with opaque foreign keys linking back and forth.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#42
post #34
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

A lot of countries have laws that allow you to have access to any information stored that relates to you, health, education, criminal justice, etc. I think this logical but ‘ownership’ seems a bit of a reach.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#43
post #22

Earlier quoted context omitted.

If you think about it, now it makes sense why big names in smartphone industry like Apple and Samsung are removing P2 plugs from smartphones in favor of more powerful interfaces like Lighting/USB-C: so you can track more information about the user. Just imagine: you can track which kind of phone a user that likes to listen to Heavy Metal, for example, likes to use, or which phone is more popular at the moment. Based…

There's a much more mundane explanation - waterproofing. Lightning and USB-C connectors can both be made intrinsically waterproof up to IPx7, while the 3.5mm jack can't. Waterproofing is a key point of differentiation for recent flagship phones. An iPhone 7 will survive a dip in a toilet bowl or a pint of beer, but an iPhone 6 probably won't.

You are wrong there.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#44
post #34

Earlier quoted context omitted.

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

That's the wrong analogy. The camera isn't some "security footage" in a random store, it's security footage from my own living room. A better analogy is this: if i install a video camera in my home and pay a service to store and process that data (think nest cam), but that i'm paying monthly for, then that data should be mine. Stuff going on in my living room (aka my music listening habits) should be mine and i shoul…

None of these analogies make any sense or have any relevance to the nature of what's going on when you use a service. Fundamentally you are sending requests from your computer to their computers, and their computers are sending things back to your computer in response. They have every right to log what activities their own computers are doing, and (in my mind) they have every right to claim sole ownership over the logs that they create.

The fact that they have to legally release this kind of thing is really twisted, at least to me. If you want to have logs of your listening data --- if you want to have logs of what your computer is doing --- how about you log it yourself? If that's too much work for you, whose fault is that? Don't use it if you don't like it.

Music services are a dime a dozen nowadays. The biggest reason that any given consumer stays with a given service has to do with recommendations and playlists and the profile that they've built on you. The fact that these companies now have to give that data back to consumers, which they could presumably feed into another (cheaper) service, disincentivizes companies from building better recommendation engines and down the line it ultimately makes for a worse experience for music listeners.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#45
post #12
post #6

It's kind of weird (and worrying tbh) that the user doesn't get _all_ the data by default. Shouldn't all the data be sent upon request, is there a clause saying 'only after nagging the TRUE data will be sent?

There's a sense in which summary views are the real data. If I asked Spotify to share my data, and they just sent me a 250 MB file of every interaction they've ever recorded, I would conclude they're trying to obfuscate which data they actually use and how they use it.

Yeah. If Netflix sends me every byte I've ever viewed, that's pretty useless.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#46
post #22

Earlier quoted context omitted.

If you think about it, now it makes sense why big names in smartphone industry like Apple and Samsung are removing P2 plugs from smartphones in favor of more powerful interfaces like Lighting/USB-C: so you can track more information about the user. Just imagine: you can track which kind of phone a user that likes to listen to Heavy Metal, for example, likes to use, or which phone is more popular at the moment. Based…

There's a much more mundane explanation - waterproofing. Lightning and USB-C connectors can both be made intrinsically waterproof up to IPx7, while the 3.5mm jack can't. Waterproofing is a key point of differentiation for recent flagship phones. An iPhone 7 will survive a dip in a toilet bowl or a pint of beer, but an iPhone 6 probably won't.

I don't see the difference in the connector and how that can determine how waterproof the phone is. In the end, lightning/usb-c and 3.5 are just sending electron via a connection, how would the format determine how waterproof you can make it?

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#47

Earlier quoted context omitted.

That's the wrong analogy. The camera isn't some "security footage" in a random store, it's security footage from my own living room. A better analogy is this: if i install a video camera in my home and pay a service to store and process that data (think nest cam), but that i'm paying monthly for, then that data should be mine. Stuff going on in my living room (aka my music listening habits) should be mine and i shoul…

None of these analogies make any sense or have any relevance to the nature of what's going on when you use a service. Fundamentally you are sending requests from your computer to their computers, and their computers are sending things back to your computer in response. They have every right to log what activities their own computers are doing, and (in my mind) they have every right to claim sole ownership over the lo…

With that logic you could argue that almost nothing should be regulated, as the "work" nowadays is always done by someone else, what is the different between this and a credit score?

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#48
post #34
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

> Does a user "own" security footage in a store that they enter? Definitely not.

Why not? Data is everywhere these days. You won't be able just quit e.g. social media in the future to avoid being tracked. One of your friends will tag you, your face will be indexed, your name will be correlated to your phone number, your phone number to your ip address and now they know everything you read anyway. If that isn't the future you want you can either come up with all sorts of rules for when and where you can and can't take pictures and collect data, which all the companies will try to avoid anyways. Or you can say that people own their own data and only reasonable usage is granted automatically.

Presumably reasonable usage of a security camera would be to, you know, ensure security. Maybe you can opt in to some consumer behavior survey. But they shouldn't just be able to sell the data to a data mining company for face recognition, location tracking and consumer intelligence.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#49
post #34
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

I’m upvoting and agree in the realistic point you are making, but feel this isn’t the most popular point of view right now? I personally believe info just shouldn’t be captured period, beyond reasons for authentication protection purposes/identifying malicious/off pattern use of my login/auth token. We are releasing a new business/info mgmt product soon that has no GA/full story/user tracking whatsoever. It’s not clear why everyone enables a floodgate of tracking just ‘cause. We are implementing better feedback/reporting channels instead.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#50
post #28

Earlier quoted context omitted.

Indeed. Your typical data requester isn't going to know code for working with JSON. And converting JSON to CSV is a pain.

To be fair, GDPR stipulates only that it should be available in a common machine-readable format. It doesn’t require the most convenient format conceivable. Also, CSV can’t easily handle nested objects. If the data model is even slightly more complex than a plain table, it doesn’t make much sense. I’d also argue that even if the source data is stored in an RDMS without exotic data types, a JSON with a nested object r…

Sure, simple JSON you can view in browsers.

But with CSV you can just use spreadsheets. Are there n00b-friendly apps based on R, Python, etc?

And can't you always convert JSON to multiple CSV files?

Post reply on HN