3 ms·
So the other day Spotify decided to block API access to SongShift [1], which used their API to transfer playlists to other services. By doing that, they removed
by Confiks 6y ago
So the other day Spotify decided to block API access to SongShift [1], which used their API to transfer playlists to other services. By doing that, they removed a method which was valid under GDPR article 20 subsection 2 to transfer personal data directly from one controller to another. FreeYouMusic is using another process without cooperation or consent from Spotify, and doesn't include all personal data.
I've been exchanging emails with Spotify to demand that they re-enable the API or allow for some other method to transfer my personal data directly to another controller. So far they've just sent me boilerplate back telling me about their GDPR article 20 subsection 1 process. You can read the full conversation here [2].
I fully intend to file a complaint with the Dutch civil court if they don't allow me to exercise my rights under the law. It would be good to have some precedent here. As they've already shown it to be technically feasible (a requirement of the law), and enabling the process is literally a boolean away, I think such a complaint would have a high chance of success.
Additionally, in my opinion their GDPR article 20 subsection 1 process is currently also in violation, because they take up to 30 days (counting 2 now) before emailing you the ZIP with your personal data. This is arguably "undue delay" (which is prohibited under the GDPR). If it comes to a case, removing this delay will certainly be part of the demands.
[1] https://songshift.com/blog/spotify_transfers https://songshift.com/blog/spotify_transfers
[2] https://news.ycombinator.com/item?id=24764371 https://news.ycombinator.com/item?id=24764371