13 ms·
Spotify GDPR data export: user receives 250MB containing every interaction
- tedeh 8y agoWhat grand times we live in, where you can actually get this kind of data from the services that you use. Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation!
- pteredactyl 8y agoInteresting. Can they still sell it if it's owned by you? They are collecting and storing it, for sure. What limitations do they have from there? Also, how would the government patrol this without having access to all companies databases, servers, and policies?
- alkonaut 8y agoThey have to ask me if they can use it and for what purpose. And even better, they can’t condition the use of the site/product on me accepting that they sell it.
- pteredactyl 8y agoThat sounds good. How is it enforced? ( not being sarcastic )
- alkonaut 8y agoIt’s not (yet). The GDPR is still new and as far as I know there haven’t been many (or perhaps not any) legal processes.
- jdietrich 8y agoEvery EU country has a data regulator. These regulators have a range of enforcement options at their disposal, from politely asking a company to comply up to a fine of €20m or 4% of global revenues. You can see a list of previous enforcement action and adjudication decisions by the British Information Commissioner's Office at the link below. These are all under the old Data Protection Directive, which was broadly similar to GDPR but somewhat lacking in teeth. You'll see everything from a slap on the wrist to six-figure fines. https://ico.org.uk/action-weve-taken/enforcement/ https://ico.org.uk/action-weve-taken/enforcement/ https://icosearch.ico.org.uk/s/search.html?collection=ico-meta&profile=decisions&query https://icosearch.ico.org.uk/s/search.html?collection=ico-me...
- et-al 8y agoIs this actually happening, though? I feel most sites don't comply with the latter half of your statement (conditioning based on acceptance).
- alkonaut 8y agoThis is very true. Many sites and services seem to have deliberately misinterpreted the legal text. I hope a high profile target will be taken to court over this, to establish a cautionary precedent. It just hasn’t happened yet.
- simion314 8y ago>Also, how would the government patrol this without having access to all companies databases, servers, and policies? As in many other cases you assume the companies are not doing illegal stuff and you act when someone reports them. A developer that is asked to do something illegal like hiding something from the exported data can report it .
- zerotolerance 8y agoI don't think everyone agrees people have the right to claim ownership to all data exchanged in a multi-party interaction. Further I don't think anyone understands Identity well enough to be able to provide transitively collected data without breaching confidence of similar third-parties. Nothing is as simple as a quip can make it sound.
- iamdave 8y agoFurther I don't think anyone understands Identity well enough to be able to provide transitively collected data without breaching confidence of similar third-parties. Would you be willing to unpack this statement a bit, please? I'm not quite sure I understand.
- emiliobumachar 8y agoIf I may intrude, I think they mean that revealing to you data that involves you and other people could invade the privacy of those other people.
- iamdave 8y agoGotcha. Thank you, for some reason that wasn't immediately clicking in my brain.
- Klathmon 8y agoFor a bit more context, this was recently discussed a LOT with the Cambridge Analytica Facebook scandal. The issue being that if you text me, and I give that to Facebook, does facebook have the right to ask me for permission to give it to a 4th party? Should facebook be required to give you that information if you don't have a facebook account and request it?
- Silhouette 8y agoThis is one of the issues in personal data and privacy that I think we're going to have to acknowledge and confront some time very soon: often, data about an individual in isolation is less telling than data about that individual's relationships, but relationships always involve multiple parties. Right now, we've barely established a consensus on the ethical and legal principles of a relationship between a single data subject and a second party using data about them. The big social networks have amassed their huge databases not only through information volunteered by individual members, but also by co-opting people who know those individuals (or just happened to be nearby) to provide more. For example, every time a social network's mobile app uploads an address book from someone I know when they install on their new phone, and consequently that social network knows my name and contact details, they have potentially violated my privacy with neither my knowledge nor consent. With the advent of ubiquitous devices with cameras, microphones, network connectivity, GPS and other sensors, and at the same time the developments in automatic recognition technologies based on photos, audio or video footage, the risks of exploiting network effects to gather data on unwilling subjects have increased dramatically. I'm not sure it's reasonable to expect every person I've ever shared my contact details with or anyone who ever took a photo with me in the background to understand the implications of their devices and the software they run on them. In any case, there are going to be difficult ethical questions about balancing the rights and freedoms of multiple parties. However, I am quite sure it's fair to require businesses on the scale of Facebook to understand the basic situation and at least not to retain or use personal data for any longer than is necessary. The GDPR and similar proposals starting to appear elsewhere are clearly trying to enshrine something like that principle in law, but everything I have seen so far suggests that the biggest data hoarders are paying lip service but still trying to get away with anything they can.
- tensor 8y agoFrankly, I think a lot of this data isn't the users, but rather Spotify's. If Spotify didn't exist then the interaction data with it wouldn't exist. I don't see how it can possibly be "owned" only by the user here. Does a user "own" security footage in a store that they enter? Definitely not.
- heisenbergs 8y agoThat's the wrong analogy. The camera isn't some "security footage" in a random store, it's security footage from my own living room. A better analogy is this: if i install a video camera in my home and pay a service to store and process that data (think nest cam), but that i'm paying monthly for, then that data should be mine. Stuff going on in my living room (aka my music listening habits) should be mine and i should have access to my habits and restrict others from using it if i want to. Update: more importantly, without having access to data stored by any service, i can't make an informed decision as to whether the service is storing dubious information about myself that it shouldn't. Services can no longer hide the data they store about people.
- nickysielicki 8y agoNone of these analogies make any sense or have any relevance to the nature of what's going on when you use a service. Fundamentally you are sending requests from your computer to their computers, and their computers are sending things back to your computer in response. They have every right to log what activities their own computers are doing, and (in my mind) they have every right to claim sole ownership over the logs that they create. The fact that they have to legally release this kind of thing is really twisted, at least to me. If you want to have logs of your listening data --- if you want to have logs of what your computer is doing --- how about you log it yourself? If that's too much work for you, whose fault is that? Don't use it if you don't like it. Music services are a dime a dozen nowadays. The biggest reason that any given consumer stays with a given service has to do with recommendations and playlists and the profile that they've built on you. The fact that these companies now have to give that data back to consumers, which they could presumably feed into another (cheaper) service, disincentivizes companies from building better recommendation engines and down the line it ultimately makes for a worse experience for music listeners.
- detaro 8y agoIt's not actually "ownership": You have control over it, but you don't own it, and laws are careful to make that distinction. I emphasize this since at least in parts of the debate, people advocating for "data ownership" are advocating for weaker data protection laws, with the idea that rights derive from ownership of data means companies can gain ownership of data too, and you then do not have those rights. You have rights to your personal data, you do not need to own it to have those.
- yani 8y agoDo you remember how much negativity there was the few days before GDPR "doomsday". I kept saying that it is a beautiful thing but all I got ... I have requested my data from many services that I use and I learned a lot about myself by reviewing my data, searches, marketubg tags etc.
- maym86 8y agoThis is great. I wonder if the EU can write a law to allow us to see what adverts are being served to which audiences on platforms like Facebook and Google. More transparency please.
- mikeash 8y agoConfusing title. I thought there was some horrible bug that sent a 250MB file every time you clicked something! After reading the tweet I realize it’s saying the 250MB file contains every interaction.
- blaerk 8y agoIt's kind of weird (and worrying tbh) that the user doesn't get _all_ the data by default. Shouldn't all the data be sent upon request, is there a clause saying 'only after nagging the TRUE data will be sent?
- amarkov 8y agoThere's a sense in which summary views are the real data. If I asked Spotify to share my data, and they just sent me a 250 MB file of every interaction they've ever recorded, I would conclude they're trying to obfuscate which data they actually use and how they use it.
- patmcguire 8y agoYeah. If Netflix sends me every byte I've ever viewed, that's pretty useless.
- olejorgenb 8y agoThe default export only include the last 90 days so it's not just limited in details.
- glitchc 8y agoInstead of "with", please use "containing" in the title.
- aprao 8y agoAgreed. I couldn't understand why every single interaction would generate 250MB of data!
- brian_herman 8y agoMeh you are the product spotify is free!
- mikeash 8y agoSpotify has over 70 million paid subscribers.
- cuckcuckspruce 8y agoSo they're paying to be tracked. Nice gig if you can get it, Spotify!
- ballenf 8y agoThe pressure to collect any and all data to increase a company's valuation isn't lessened by charging your customers to use the service. That cliché is not really informative nor helpful in the fight for privacy and transparency.
- tjoff 8y agoYou assume there is a pressure to collect the data and that it has any positive effect on valuation.
- phyzome 8y agoNo, the new business model is that you're the product even if you're paying.
- valgaze 8y agoImpressive-- https://twitter.com/steipete/status/1025029133175336960 https://twitter.com/steipete/status/1025029133175336960 "They even store the brand of headphone I use. How do you even get that data, digging deep in CoreBluetooth?"
- m45t3r 8y agoIf you think about it, now it makes sense why big names in smartphone industry like Apple and Samsung are removing P2 plugs from smartphones in favor of more powerful interfaces like Lighting/USB-C: so you can track more information about the user. Just imagine: you can track which kind of phone a user that likes to listen to Heavy Metal, for example, likes to use, or which phone is more popular at the moment. Based on this you can develop phones that is more likely to sell or use specific marketing campaigns depending of the kind of music a person listen.
- jdietrich 8y agoThere's a much more mundane explanation - waterproofing. Lightning and USB-C connectors can both be made intrinsically waterproof up to IPx7, while the 3.5mm jack can't. Waterproofing is a key point of differentiation for recent flagship phones. An iPhone 7 will survive a dip in a toilet bowl or a pint of beer, but an iPhone 6 probably won't.
- steve19 8y agoPlenty of phones where waterproof before. The lightning port is waterproof despite having many more pins than a simple phone jack.
- detaro 8y agoSo all the other phone manufacturers selling IP68 phones with headphone jacks are lying?
- _r_o_y_ 8y agoI had a Xperia Z5 and every time water touched the headphone jack the phone would go crazy thinking that I was plugging and unplugging something repeatedly.
- idbehold 8y agoSeems like CSV would've been a better format than JSON for this type of data based on the screenshots.
- deleted 8y ago[deleted]
- mirimir 8y agoIndeed. Your typical data requester isn't going to know code for working with JSON. And converting JSON to CSV is a pain.
- oxymoron 8y agoTo be fair, GDPR stipulates only that it should be available in a common machine-readable format. It doesn’t require the most convenient format conceivable. Also, CSV can’t easily handle nested objects. If the data model is even slightly more complex than a plain table, it doesn’t make much sense. I’d also argue that even if the source data is stored in an RDMS without exotic data types, a JSON with a nested object representation is probably going to be more friendly even to non-developers than multiple files with opaque foreign keys linking back and forth.
- mirimir 8y agoSure, simple JSON you can view in browsers. But with CSV you can just use spreadsheets. Are there n00b-friendly apps based on R, Python, etc? And can't you always convert JSON to multiple CSV files?
- PeterisP 8y agoOnly if you accept a potentially unlimited number of CSV files/sheets. Many forms of data aren't really easily normalizable to a limited number of flat tables without losing information.
- 8y ago
- velcrovan 8y agoOK, I’ve been wondering if I could get this data. Now I want mine.
- wahlis 8y agoIf Spotify didn't give you all data with your first request I guess that they are in breach of GDPR?
- mgiannopoulos 8y agoYes, you would then have a basis to file complaint to your (within the EU) country’s data privacy authority
- callesgg 8y agoThe main issue as i see it is that he did not get data when he asked. He had to complain.
- rhcom2 8y agoHas anyone tried this request in the US? I'm assuming they would just tell you to politely shove it?
- Symbiote 8y agoThey are a Swedish company. The British regulator considers the rules to apply to all people, not just European citizens, so I think the Swedish would have the same opinion. In general, Europe has rights that apply to everyone, regardless of citizenship. This makes a difference when it comes to searches at the border, drone strikes, refugees and so on under the European Convention on Human Rights. This should become a selling point for EU businesses.
- deleted 8y ago[deleted]
- bhauer 8y agoRemember all of the data Winamp2 used to gather and send to third-party servers?
- starsinspace 8y agoIt's weird how perception on these things has shifted. So many practices are "normal" today which used to be clearly labeled "spyware" only 15 years ago. They successfully rebranded spyware, now it's called "telemetry", or similar. Anyone remember the huge privacy-related outrage when Windows XP came out, because it forced users to do challenge-response activation? How times have changed...
- Avamander 8y agoIt might just be that all those people have switched to free software and aren't being vocal because of that?
- kodablah 8y agoI don't but I suspect such a business model would flourish. Does anyone have a link to their hiring page?
- crtasm 8y agoDid it send anything? I don't know which way to interpret your question. I imagine some info was sent if you played those shoutcast(?) video streams listed in the media library, lots of cartoon channels from what I remember.
- bhauer 8y agoSorry, just a bit of silly sarcasm. It wasn't a data exfiltration and user surveillance system like modern music players.
- menacingly 8y agoI enjoy the mental exercise of finding where boundaries lie. For instance, if you simply observe the actions people take when they talk to you, that's obviously your observation. If you were to, say, journal it, it's still yours. It's a weird thing to do, but it's yours. If you used the journal to optimize yourself, perhaps to make conversation with you more enjoyable, again, that's weird, but perhaps also merely a paper version of what already goes on inside your head. What if talking to you were really enjoyable, so that while people could technically avoid it, they usually didn't want to? At what magnitude does the volume of people you're observing reach a scale where the people you're observing start to believe your observations are theirs?
- detaro 8y agotwo parts: purpose (e.g. GDPR excludes household activity, which a private journal of "everyone I talk to" would be if it's only for private use) and structure (with at least for GDPR a neatly kept notebook/ledger possibly already being organized enough to qualify). Although the observations are not "theirs" as in "their property", they merely gain rights against you to obtain information about them and copies, and rights to control your usage.
- tjoff 8y agoIt's a huge difference when a company does it rather than an individual (as in your example).
- menacingly 8y agoIt's a convenient difference, but I don't think it actually impacts anything. It's an indirect way to address the level of resources you have at your disposal, which is itself only important for the scale at which you can capture the data. In general, for the things people are OK with citizens doing but not OK with corporations doing, they mean an individual could not do it at a scale that bothers them. I'm specifically curious about what that scale is. Certainly for me, there exists a hypothetical scale at which an individual gathering and recording detailed observations of other people becomes a little unsettling. Perhaps not criminal, but it falls into a "wish it didn't happen" bucket.
- MikeKusold 8y agoI'd be interested in knowing if he is a paid subscriber or not. I understand that Spotify needs data to power Discover Weekly, but I'm not sure I'm comfortable with this amount of data.
- swiley 8y agoMan I was comfortable running spotify as the only non-free app on my Linux machines, now I'm not. It's back to ocp and mods/classical music/occasional purchased for me I guess... (except on my phone of course which is a lost cause)
- _4xjr 8y agoHere is a template for whoever else wants to request their data: https://www.dropbox.com/s/fx5yyrru1uvx6no/sarletter.txt?dl=0 https://www.dropbox.com/s/fx5yyrru1uvx6no/sarletter.txt?dl=0 Source (@mikarv on Twitter): https://twitter.com/mikarv/status/1012386696934182912?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1013539192805064704&ref_url=http%3A%2F%2Fdancemusicnw.com%2Fspotify-gdpr-data-exports-user-tracking%2F https://twitter.com/mikarv/status/1012386696934182912?ref_sr...
- zachruss92 8y agoWhile this is an extreme example, I'm not the least bit concerned about Spotify collecting this data. This data is likely used by Spotify to understand user behavior to improve user experience and improve their recommendation engine, or to simply understand how users interact with the app. I was delighted to find that Spotify sends you concert notifications of bands that I listened to the most. Personally, as long as they are not sharing this data with others without my permission they can collect this info. All of this is clearly stated in their privacy policy including the bit about Bluetooth) https://www.spotify.com/is/legal/privacy-policy-update/#s5 https://www.spotify.com/is/legal/privacy-policy-update/#s5.
- KenanSulayman 8y ago> "this enables us to access your GPS or Bluetooth to provide location-aware functionality" They only Bluetooth in the context of acquiring location data..
- a-dub 8y agoI have a friend that always used to joke that if Spotify ever failed and got sold off to private equity, they would shift to a business model where they mine for embarrassing music and behaviors and then extort people to keep quiet about it.
- draw_down 8y agoMP3s still do the trick.
- wiremine 8y ago> Having the law say your personal data is owned by you and not some company just because it's on their server may turn out to be a landmark in consumer friendly legislation! It's interesting to think where this goes in the future. Can I demand my purchase history from physical McDonalds restaurants at some point? Why limit it to internet-related interactions? (Or maybe this is already included in GDPR and I'm just not aware?)
- Symbiote 8y agoYou can already demand this data from McDonalds, if they retain it. You've been able to for about 20 years, in some form with the previous laws. (More commonly, you could demand the paper records your employer has about you.)
- MYEUHD 8y agoIf something is free, you are the product being sold...
- chiefalchemist 8y agoIs this data collected by Spotify, or __all__ data Spotify has for a user? That is, it's certainly possible for any given service to gather / aggregate data from sources other than itself.
- Sujan 8y agoHas someone started a list of GDPR data export requests and their results? I wonder what interesting information is out there...