Live data from Hacker News

Spotify GDPR data export: user receives 250MB containing every interaction

twitter.com

91–100 of 137 posts

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#91
post #12

Earlier quoted context omitted.

There's a sense in which summary views are the real data. If I asked Spotify to share my data, and they just sent me a 250 MB file of every interaction they've ever recorded, I would conclude they're trying to obfuscate which data they actually use and how they use it.

Yeah. If Netflix sends me every byte I've ever viewed, that's pretty useless.

[deleted]

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#92
post #27

Meh you are the product spotify is free!

The pressure to collect any and all data to increase a company's valuation isn't lessened by charging your customers to use the service. That cliché is not really informative nor helpful in the fight for privacy and transparency.

You assume there is a pressure to collect the data and that it has any positive effect on valuation.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#94
post #49
post #34

Earlier quoted context omitted.

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

I’m upvoting and agree in the realistic point you are making, but feel this isn’t the most popular point of view right now? I personally believe info just shouldn’t be captured period, beyond reasons for authentication protection purposes/identifying malicious/off pattern use of my login/auth token. We are releasing a new business/info mgmt product soon that has no GA/full story/user tracking whatsoever. It’s not cle…

One thing that people constantly praise Spotify for is the quality of their music recommendations. You can find so many testimonials of people saying that their "Discover Weekly" playlist suggested them songs which they felt they had been searching for their whole lives.

Needless to say, such accurate recommendations of music, which even close personal friends have trouble doing, is based on building as complete of a psychological profile of the user as possible. There wouldn't be any way to do it without gathering lots of information about your very personality.

Surveillance isn't always bad -- after all, what is a baby monitor?

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#95
post #71
post #65

Earlier quoted context omitted.

No, but that's you writing down every song. The alternative is them saving one of their interactions to their server. These aren't remotely comparable...

Party A records every interaction with Party B. Party B records every interaction with Party A. Who owns what Party A recorded, and who owns what Party B recorded?

When Party A is a multibillion dollar corporation and Party B is an individual, the arguments can not be parallelized.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#96
> Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

It's interesting to think where this goes in the future. Can I demand my purchase history from physical McDonalds restaurants at some point? Why limit it to internet-related interactions? (Or maybe this is already included in GDPR and I'm just not aware?)

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#97
post #22

Earlier quoted context omitted.

If you think about it, now it makes sense why big names in smartphone industry like Apple and Samsung are removing P2 plugs from smartphones in favor of more powerful interfaces like Lighting/USB-C: so you can track more information about the user. Just imagine: you can track which kind of phone a user that likes to listen to Heavy Metal, for example, likes to use, or which phone is more popular at the moment. Based…

There's a much more mundane explanation - waterproofing. Lightning and USB-C connectors can both be made intrinsically waterproof up to IPx7, while the 3.5mm jack can't. Waterproofing is a key point of differentiation for recent flagship phones. An iPhone 7 will survive a dip in a toilet bowl or a pint of beer, but an iPhone 6 probably won't.

Yeah, that must be it.

http://www.tradekorea.com/product/detail/P698873/IP67-waterp...

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#98
post #50

Earlier quoted context omitted.

Sure, simple JSON you can view in browsers. But with CSV you can just use spreadsheets. Are there n00b-friendly apps based on R, Python, etc? And can't you always convert JSON to multiple CSV files?

Only if you accept a potentially unlimited number of CSV files/sheets. Many forms of data aren't really easily normalizable to a limited number of flat tables without losing information.

OK, then. How would someone who's not technically sophisticated interpret such JSON?

I suppose that some service could handle it. But then there's another level of trust and GDPR compliance.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#99
post #34
post #2

What grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!

Frankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.

Personally I think that GDPR represents a rejection of the idea of "ownership" as it applies to data.

You will note that GDPR does not use "ownership" terminology anywhere. The closest it has is Data Controller, but GDPR makes that nowhere near the same as ownership.

GDPR establishes that data subjects are stakeholders in their data. It doesn't mean that they own the data, but it also doesn't mean that they don't own the data. They have rights to the data, which the Controller has to respect, while the Controller also has their own rights.

It's probably possible to model this situation as ownership (property law is complicated), but I think it's easier not to. Data is not owned, it is controlled and processed. Activities related to data are restricted.

Re: Spotify GDPR data export: user receives 250MB containing every interaction

#100
post #21

Earlier quoted context omitted.

I don't think everyone agrees people have the right to claim ownership to all data exchanged in a multi-party interaction. Further I don't think anyone understands Identity well enough to be able to provide transitively collected data without breaching confidence of similar third-parties. Nothing is as simple as a quip can make it sound.

>Further I don't think anyone understands Identity well enough to be able to provide transitively collected data without breaching confidence of similar third-parties. I'm obviously not a lawyer or anything but I think that this would be more compeling if Spotify was open source. "You don't want to share this? Well just remove the code then." Here not only can't I do that but I've been a paying customer of Spotify fo…

Everything is data. Anybody can remember anything they want. You didn't give them anything, they experience the same reality as you when you chose to interact with them. ... It takes two baby...
Post reply on HN