abusesaffiliationarrow-downarrow-leftarrow-rightarrow-upattack-typeburgerchevron-downchevron-leftchevron-rightchevron-upClock iconclosedeletedevelopment-povertydiscriminationdollardownloademailenvironmentexternal-linkfacebookfiltergenderglobegroupshealthC4067174-3DD9-4B9E-AD64-284FDAAE6338@1xinformation-outlineinformationinstagraminvestment-trade-globalisationissueslabourlanguagesShapeCombined Shapeline, chart, up, arrow, graphLinkedInlocationmap-pinminusnewsorganisationotheroverviewpluspreviewArtboard 185profilerefreshIconnewssearchsecurityPathStock downStock steadyStock uptagticktooltiptwitteruniversalityweb

이 페이지는 한국어로 제공되지 않으며 English로 표시됩니다.

기사

13 6월 2023

저자:
Natasha Lomas, TechCrunch

Sweden: Spotify is fine over GDPR data access complaint

"Spotify fined in Sweden over GDPR data access complaint", 13 June 2023

Music streaming giant Spotify is facing a fine of around €5 million ($5.4M) in Sweden years after it was accused of breaching the data access rights of users in the European Union by not providing full information about personal data it processes in response to individual requests.

While the size of the fine is unlikely to grab many headlines, the fact it’s finally happened is notable as further evidence of the mountain European users have to climb to get their data protection rights upheld.

The finding of a breach of Article 15 of the General Data Protection Regulation (GDPR) comes more than four years after a complaint was lodged against Spotify by the privacy rights not-for-profit, noyb. The complaint, which was filed at the start of 2019, alleged Spotify failed to provide adequate detail in response to the complainant’s subject access request (SAR).

The complaint argued the music streaming platform failed to provide all personal data requested; did not provide information on the purposes of the processing; nor on recipients; and also did not provide information on international transfers, among other allegations.

While it was originally filed in Austria the GDPR’s one-stop-shop mechanism, which is supposed to streamline case handling where data-processing crosses national borders, meant the complaint got routed to Sweden where Spotify has its main EU establishment. (Another complaint over the same issue which was filed in the Netherlands was also joined to the case in Sweden.)

The complaint then languished undecided for several years as, according to noyb, the Swedish authority undertook a parallel ex officio investigation to which the complainants weren’t party — despite the GDPR stating data controllers must respond to access requests within a month.

noyb ended up taking the Swedish data protection authority (IMY) to court over the lack of a decision. And last year it successfully challenged IMY’s position that the complainant is not a party in procedures, with the Stockholm administrative court holding that complainants have the right to request a decision after six months.

While that litigation is still ongoing (in front of a higher court) the administrative court decision last November ordering IMY to process and investigate the complaint appears to have moved the DPA to issue a decision in the meanwhile.

noyb said today that IMY ordered Spotify to finally provide the full set of data. Although it’s reserving judgement on whether the authority has done everything it asked until it can scrutinize the decision.

We reached out to the Swedish authority with questions and it sent the below statement — confirming it identified a number of violations by Spotify pertaining to three complaints it investigated. It also described the case as “complex and comprehensive”, saying it not only looked at individual instances of how it handled data access requests but also assessed general procedures.

Spotify was also contacted for comment. A company spokesperson sent us this statement — confirming it intends to appeal:

Spotify offers all users comprehensive information about how personal data is processed. During their investigation, the Swedish DPA found only minor areas of our process they believe need improvement. However, we don’t agree with the decision and plan to file an appeal.

개인정보

이 웹사이트는 쿠키 및 기타 웹 저장 기술을 사용합니다. 아래에서 개인정보보호 옵션을 설정할 수 있습니다. 변경 사항은 즉시 적용됩니다.

웹 저장소 사용에 대한 자세한 내용은 다음을 참조하세요 데이터 사용 및 쿠키 정책

Strictly necessary storage

ON
OFF

Necessary storage enables core site functionality. This site cannot function without it, so it can only be disabled by changing settings in your browser.

분석 쿠키

ON
OFF

귀하가 우리 웹사이트를 방문하면 Google Analytics를 사용하여 귀하의 방문 정보를 수집합니다. 이 쿠키를 수락하면 저희가 귀하의 방문에 대한 자세한 내용을 이해하고, 정보 표시 방법을 개선할 수 있습니다. 모든 분석 정보는 익명이 보장되며 귀하를 식별하는데 사용하지 않습니다. Google은 모든 브라우저에 대해 Google Analytics 선택 해제 추가 기능을 제공합니다.

프로모션 쿠키

ON
OFF

우리는 소셜미디어와 검색 엔진을 포함한 제3자 플랫폼을 통해 기업과 인권에 대한 뉴스와 업데이트를 제공합니다. 이 쿠키는 이러한 프로모션의 성과를 이해하는데 도움이 됩니다.

이 사이트에 대한 개인정보 공개 범위 선택

이 사이트는 필요한 핵심 기능 이상으로 귀하의 경험을 향상시키기 위해 쿠키 및 기타 웹 저장 기술을 사용합니다.