Live data from Hacker News

Spotify GDPR data export: user receives 250MB containing every interaction

twitter.com

71–80 of 137 posts

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#71
post #65
post #58

Earlier quoted context omitted.

If I write down every song that I play through Spotify for a year. Does Spotify own that?

No, but that's you writing down every song. The alternative is them saving one of their interactions to their server. These aren't remotely comparable...

Party A records every interaction with Party B. Party B records every interaction with Party A.

Who owns what Party A recorded, and who owns what Party B recorded?

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#73
post #49

Earlier quoted context omitted.

I’m upvoting and agree in the realistic point you are making, but feel this isn’t the most popular point of view right now? I personally believe info just shouldn’t be captured period, beyond reasons for authentication protection purposes/identifying malicious/off pattern use of my login/auth token. We are releasing a new business/info mgmt product soon that has no GA/full story/user tracking whatsoever. It’s not cle…

> I personally believe > It’s not clear why everyone enables a floodgate of tracking just ‘cause. Have you worked in marketing, product development, or customer support? There are plenty of services that are used to help people generally do their jobs, identify problems, figure out what to build, improve the product, and to enable support folks to support customers. But yes, there are all sorts of other, third-party…

Yes, I have. It’s a tough argument/longer conversation I realize. I feel it’s getting out of hand overall. As technology/saas products make it easier to simply capture everything, including user actions/playback/screenshots, to the point that someone in marketing at X startup is watching my private usage of their app on their MacBook Air somewhere without really caring or realizing how intrusive they are being. I realize 99.9% don’t intend to abuse or don’t even realize the intrusion, there needs to be a reset where companies take a stand and find greater value in simply not engaging in this low hanging fruit.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#74
post #73

Earlier quoted context omitted.

> I personally believe > It’s not clear why everyone enables a floodgate of tracking just ‘cause. Have you worked in marketing, product development, or customer support? There are plenty of services that are used to help people generally do their jobs, identify problems, figure out what to build, improve the product, and to enable support folks to support customers. But yes, there are all sorts of other, third-party…

Yes, I have. It’s a tough argument/longer conversation I realize. I feel it’s getting out of hand overall. As technology/saas products make it easier to simply capture everything, including user actions/playback/screenshots, to the point that someone in marketing at X startup is watching my private usage of their app on their MacBook Air somewhere without really caring or realizing how intrusive they are being. I rea…

I wonder whether there's also a security compliance component here. For example, if you're SOC 2 compliant, does that preclude casual data review like that? If so, perhaps this will lead to greater demand for that kind of certification.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#75
post #62

Remember all of the data Winamp2 used to gather and send to third-party servers?

It's weird how perception on these things has shifted. So many practices are "normal" today which used to be clearly labeled "spyware" only 15 years ago. They successfully rebranded spyware, now it's called "telemetry", or similar.

Anyone remember the huge privacy-related outrage when Windows XP came out, because it forced users to do challenge-response activation? How times have changed...

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#78
post #65
post #58

Earlier quoted context omitted.

If I write down every song that I play through Spotify for a year. Does Spotify own that?

No, but that's you writing down every song. The alternative is them saving one of their interactions to their server. These aren't remotely comparable...

What makes them incomparable, in your view? The medium in which it's recorded? The ease with which it's recorded by Spotify? That the recording task is done in a different system than the client-server interaction? That Spotify has interactions with LOTS of people?

I get that they feel different, but every distinction I come up with feels like it either doesn't make sense applied uniformly. If I tracked songs in Excel, Spotify doesn't own that. If I automated tracking the songs I play, Spotify still doesn't own my recording. If I wrote down all my Spotify songs AND all my Skype messages AND all my texts, Spotify, Skype, and Verizon don't suddenly gain an ownership stake in what I've done.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#79
post #12

Earlier quoted context omitted.

There's a sense in which summary views are the real data. If I asked Spotify to share my data, and they just sent me a 250 MB file of every interaction they've ever recorded, I would conclude they're trying to obfuscate which data they actually use and how they use it.

Yeah. If Netflix sends me every byte I've ever viewed, that's pretty useless.

Exhaustive list of your data (sorted, redundant copies not included):

0x00

0x01

0x02

0x03

...

0xFE

0xFF

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#80
post #34
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

Try to use recognizable in-store footage of a person in a commercial advertisement without their consent and see what the lawyers say. It's not as clear-cut as you are making it out to be. You cannot just use photos or video of a person however you want without their consent.
Post reply on HN