Live data from Hacker News

Spotify GDPR data export: user receives 250MB containing every interaction

twitter.com

81–90 of 137 posts

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#81
post #71
post #65

Earlier quoted context omitted.

No, but that's you writing down every song. The alternative is them saving one of their interactions to their server. These aren't remotely comparable...

Party A records every interaction with Party B. Party B records every interaction with Party A. Who owns what Party A recorded, and who owns what Party B recorded?

That's why "ownership" is a bad model for this, and (to my knowledge) not really used in any privacy laws. They are not about who owns records, it's about who has which rights to them. Under GDPR, you do not own data about you a company has, but you have rights related to it.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#82
post #34

Earlier quoted context omitted.

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

Try to use recognizable in-store footage of a person in a commercial advertisement without their consent and see what the lawyers say. It's not as clear-cut as you are making it out to be. You cannot just use photos or video of a person however you want without their consent.

Spotify is not making commercial advertisements showing all the raw data they have collected on you. Instead, they are probably doing things like aggregating data on their users and looking for trends.

It's more like watching security footage (or having machines watch it and let you know what they've observed) and then making decisions with that information.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#83
post #34

Earlier quoted context omitted.

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

Try to use recognizable in-store footage of a person in a commercial advertisement without their consent and see what the lawyers say. It's not as clear-cut as you are making it out to be. You cannot just use photos or video of a person however you want without their consent.

That's because footage of them uses their image/likeness. If I used an amalgamation of all my customers it would be fine.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#84
post #56
post #22

Earlier quoted context omitted.

If you think about it, now it makes sense why big names in smartphone industry like Apple and Samsung are removing P2 plugs from smartphones in favor of more powerful interfaces like Lighting/USB-C: so you can track more information about the user. Just imagine: you can track which kind of phone a user that likes to listen to Heavy Metal, for example, likes to use, or which phone is more popular at the moment. Based…

There is a lot of conjecture happening here. I'm sure it doesn't hurt to know data about headphones but I'm having doubts that's the primary motivator.

Yeah, I am not saying this is happening right now (however this log from Spotify is alarming).

However, considering that they will have this option is sufficient to someone in the industry to abuse it, and after someone start to use this information, everyone will to remain competitive.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#85
While this is an extreme example, I'm not the least bit concerned about Spotify collecting this data. This data is likely used by Spotify to understand user behavior to improve user experience and improve their recommendation engine, or to simply understand how users interact with the app. I was delighted to find that Spotify sends you concert notifications of bands that I listened to the most. Personally, as long as they are not sharing this data with others without my permission they can collect this info. All of this is clearly stated in their privacy policy including the bit about Bluetooth) https://www.spotify.com/is/legal/privacy-policy-update/#s5.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#86
post #50

Earlier quoted context omitted.

To be fair, GDPR stipulates only that it should be available in a common machine-readable format. It doesn’t require the most convenient format conceivable. Also, CSV can’t easily handle nested objects. If the data model is even slightly more complex than a plain table, it doesn’t make much sense. I’d also argue that even if the source data is stored in an RDMS without exotic data types, a JSON with a nested object r…

Sure, simple JSON you can view in browsers. But with CSV you can just use spreadsheets. Are there n00b-friendly apps based on R, Python, etc? And can't you always convert JSON to multiple CSV files?

Only if you accept a potentially unlimited number of CSV files/sheets. Many forms of data aren't really easily normalizable to a limited number of flat tables without losing information.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#88
post #72

Man I was comfortable running spotify as the only non-free app on my Linux machines, now I'm not. It's back to ocp and mods/classical music/occasional purchased for me I guess... (except on my phone of course which is a lost cause)

Why are you uncomfortable with Spotify now?

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#89
post #34
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

> If Spotify didn't exist then the interaction data with it wouldn't exist.

Likewise, if you didn't exist, then the interaction data wouldn't exist either. I agree that the ownership is more complex in this case and is hard to attribute solely to one party. One party provides a system where interactions can take place, another party provides the interactions. Who owns the interactions? Clearly both parties are required for them to exist.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#90
post #71
post #65

Earlier quoted context omitted.

No, but that's you writing down every song. The alternative is them saving one of their interactions to their server. These aren't remotely comparable...

Party A records every interaction with Party B. Party B records every interaction with Party A. Who owns what Party A recorded, and who owns what Party B recorded?

Are you suggesting that the user should track their interactions themselves if they want to own a copy?
Post reply on HN