Swedish DPA fines Spotify $5.4M for ‘low level’ GDPR lapses

Spotify_web

Sweden’s data protection authority (DPA) levied a fine of 58 million Swedish krona (U.S. $5.4 million) against music streaming service Spotify following an audit on how the company handles customers’ rights to access their personal data.

The Swedish Authority for Privacy Protection acknowledged Spotify is compliant with General Data Protection Regulation (GDPR) rules about providing data access to users when requested but ran afoul of Article 15 of the privacy law by “not inform[ing] clearly enough about how this data is used,” the DPA said in a press release Tuesday.

In January 2019, privacy campaigner Max Schrems filed a complaint, along with two others, alleging Spotify breached Article 15 of the GDPR. The complaint was originally filed in Austria but routed to Sweden, where Spotify’s EU headquarters is located, in line with the GDPR’s one-stop shop mechanism.

lock iconTHIS IS MEMBERS-ONLY CONTENT. To continue reading, choose one of the options below.