Skip to content
Enforcement · Data Protection Authority of Sweden EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Spotify: Insufficient fulfilment of data subjects rights

The Swedish Data Protection Authority (DPA) has imposed a fine of EUR 4.9 million on the music streaming provider Spotify.

€4,900,000 Fine
Spotify
SWEDEN
Art. 12 GDPR Art. 15 GDPR

Full text

The Swedish Data Protection Authority (DPA) has imposed a fine of EUR 4.9 million on the music streaming provider Spotify. The DPA had launched an investigation after receiving a number of complaints and following a lawsuit filed against Spotify by the Austrian organization 'None of your Business'. In its investigation, the DPA found that Spotify had not sufficiently complied with data subject rights. Spotify failed, for example, to provide data subjects with sufficient information about the origin of their data or international transfers involving their data. Spotify also failed to provide information that was difficult to understand, such as information about technical processes, in the data subjects' native language; rather, such information was only available in English. Spotify has already taken measures to comply with the requirements for the handling of data subject requests. In addition, the DPA classified the identified deficiencies as not very serious.

Industry: Media, Telecoms and Broadcasting

How it connects

CJEU: Processing of beneficiary data not based on consent; individuals must be informed Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their… Nov 9, 2010 Consent Personal Data Right to Restriction
C-487/21 Österreichische Datenschutzbehörde v CRIF C-487/21 (Österreichische Datenschutzbehörde) CJEU Oct 26, 2023 Right of Access Right to Restriction Personal Data
CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69) Jun 29, 2010 Personal Data Legitimate Interest Right to Restriction
Guidelines 2/2018 derogations of Article 49 under Regulation 2016/679 Guidelines on derogations of Article 49 Guidelines ·EDPB May 25, 2018 Privacy Shield Lawful Basis Legitimate Interest
C-362/14 Schrems I Maximillian Schrems, an Austrian citizen, had been a Facebook user since 2008 Some of Mr. Schrems personal data had been transferred by Facebook Ireland to its servers belonging to Facebook Inc., located in the US. Personal data transferred by undertakings… C-362/14 - Schrems I ·CJEU Jun 10, 2015 International Transfer Personal Data Right of Access