Spotify's Data Sharing Defaults and Privacy Control Gaps
How Spotify defaults to maximum data collection and sharing, buries privacy controls in account settings, and requires external browser navigation to modify advertising preferences.
Unlock Full Privacy Intelligence
Get deep-dive reports on every company that touches your data. SeekerPro members see breach timelines, DSAR success rate...
Learn MoreAudit Your Site Free
Run a full privacy and compliance audit on any website in 60 seconds. NexusBro scans cookie consent, tracker behavior, a...
Learn MoreAutomate Privacy Compliance
Stop wasting hours on manual DSAR filings and cookie consent management. BliniBot handles the busywork so your team can ...
Learn MoreKey Findings
- #1New accounts default to maximum data collection and targeted advertising
- #2Privacy controls require navigating to external web browser, not available in app
- #3Tailored ads setting enabled by default requiring multiple steps to disable
- #4Mozilla flagged Spotify for collecting more data than necessary
- #5Terms permit use of listening data for AI and machine learning development
Investigation Details
According to privacy researchers, Spotify defaults new accounts to maximum data collection including targeted advertising, social sharing of listening activity, and data processing for personalization. Modifying these settings requires navigating to the Spotify Privacy Center through a web browser rather than the app itself. Spotify's 'tailored ads' setting, which controls whether the platform shares data with third-party advertisers, is enabled by default and requires multiple steps to disable. A 2023 review by the Mozilla Foundation's *Privacy Not Included project flagged Spotify for collecting more data than necessary and sharing it with a broad range of third parties. Spotify's terms also permit the use of listening data for AI and machine learning development purposes.
spotify has been the subject of increasing scrutiny over its consent manipulation practices. Privacy researchers and regulatory bodies across multiple jurisdictions have documented concerns about how the company handles user data, particularly regarding consent, transparency, and data minimization principles. The findings suggest a pattern of prioritizing business metrics over user privacy, a trend observed across the broader technology industry. Users affected by these practices have limited recourse without proactive intervention such as filing formal complaints with data protection authorities or submitting DSAR requests.
Regulatory responses have varied significantly. European data protection authorities have been more aggressive in enforcement under GDPR, while US enforcement remains fragmented across state-level privacy laws. The investigation highlights the need for stronger federal privacy legislation and more transparent corporate data practices. Affected users should consider reviewing their privacy settings, submitting data deletion requests, and exploring privacy-preserving alternatives recommended by independent researchers.
Related Scandals
Take Action
Protect Your Data Across Every Platform
Tools trusted by thousands of privacy-conscious users worldwide
No card charged today. Cancel anytime.
Frequently Asked Questions
What data does spotify collect?
Our investigation reveals spotify engages in consent manipulation. How Spotify defaults to maximum data collection and sharing, buries privacy controls in account settings, and requires external browser navigation to modify advertising preferences.
Is spotify's consent manipulation legal?
The legality of spotify's practices varies by jurisdiction. Under GDPR, companies must have a lawful basis for data processing. Under CCPA, California residents can opt out of data sales.
How can I protect myself from spotify?
You can submit a data subject access request (DSAR) to spotify, opt out of data collection through their privacy settings, or use privacy-preserving alternatives.