Live data from Hacker News

Spotify GDPR data export: user receives 250MB containing every interaction

twitter.com

61–70 of 137 posts

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#61
post #49
post #34

Earlier quoted context omitted.

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

I’m upvoting and agree in the realistic point you are making, but feel this isn’t the most popular point of view right now? I personally believe info just shouldn’t be captured period, beyond reasons for authentication protection purposes/identifying malicious/off pattern use of my login/auth token. We are releasing a new business/info mgmt product soon that has no GA/full story/user tracking whatsoever. It’s not cle…

> I personally believe

> It’s not clear why everyone enables a floodgate of tracking just ‘cause.

Have you worked in marketing, product development, or customer support? There are plenty of services that are used to help people generally do their jobs, identify problems, figure out what to build, improve the product, and to enable support folks to support customers.

But yes, there are all sorts of other, third-party trackers and cookies that are not as directly relevant.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#63
post #34

Earlier quoted context omitted.

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

Kind of: https://www.dataprotection.ie/docs/Data-Protection-CCTV/242.... You can make a subject access request for CCTV footage.

Whoa. You're right. This is kind of insanely low fee mandated.

> The data controller may charge up to €6.35 for responding to such a request and must respond within 40 days.

> This normally involves providing a copy of the footage in video format. ... Where stills are supplied, it would be necessary to supply a still for every second of the recording in which the requester's image appears in order to comply with the obligation to supply a copy of all personal data held.

> Where images of parties other than the requesting data subject appear on the CCTV footage the onus lies on the data controller to pixelate or otherwise redact or darken out the images of those other parties before supplying a copy of the footage or stills from the footage to the requestor. Alternatively, the data controller may seek the consent of those other parties whose images appear in the footage to release an unedited copy containing their images to the requester

I wouldn't be surprised if some video workflow products pop up to help companies comply with requests like this. For example, select the target person on video, automatically pixelate the rest, stitch together and export all clips of the target, securely mail it and log the task completion, etc.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#64
post #37

If Spotify didn't give you all data with your first request I guess that they are in breach of GDPR?

Yes, you would then have a basis to file complaint to your (within the EU) country’s data privacy authority

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#65
post #58
post #40

Earlier quoted context omitted.

If the user didn't use Spotify, then the interaction data wouldn't exist. It takes two. Perhaps if these companies had taken that tact (mutual ownership), then there'd have been no need for a law to specifically allow users to get the data created with their own effort.

If I write down every song that I play through Spotify for a year. Does Spotify own that?

No, but that's you writing down every song. The alternative is them saving one of their interactions to their server. These aren't remotely comparable...

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#66
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

It's not actually "ownership": You have control over it, but you don't own it, and laws are careful to make that distinction. I emphasize this since at least in parts of the debate, people advocating for "data ownership" are advocating for weaker data protection laws, with the idea that rights derive from ownership of data means companies can gain ownership of data too, and you then do not have those rights.

You have rights to your personal data, you do not need to own it to have those.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#67
I enjoy the mental exercise of finding where boundaries lie.

For instance, if you simply observe the actions people take when they talk to you, that's obviously your observation. If you were to, say, journal it, it's still yours. It's a weird thing to do, but it's yours.

If you used the journal to optimize yourself, perhaps to make conversation with you more enjoyable, again, that's weird, but perhaps also merely a paper version of what already goes on inside your head.

What if talking to you were really enjoyable, so that while people could technically avoid it, they usually didn't want to?

At what magnitude does the volume of people you're observing reach a scale where the people you're observing start to believe your observations are theirs?

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#68

I enjoy the mental exercise of finding where boundaries lie. For instance, if you simply observe the actions people take when they talk to you, that's obviously your observation. If you were to, say, journal it, it's still yours. It's a weird thing to do, but it's yours. If you used the journal to optimize yourself, perhaps to make conversation with you more enjoyable, again, that's weird, but perhaps also merely a p…

two parts: purpose (e.g. GDPR excludes household activity, which a private journal of "everyone I talk to" would be if it's only for private use) and structure (with at least for GDPR a neatly kept notebook/ledger possibly already being organized enough to qualify). Although the observations are not "theirs" as in "their property", they merely gain rights against you to obtain information about them and copies, and rights to control your usage.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#69
post #34
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

Exactly.

Don't use logic though. Logic is cold and hateful. ;)

Post reply on HN