Data Ethics, Privacy and Humans · worked example
A personal harm analysis of Spotify's privacy agreement — not a summary of what it says, but a reading of where the flows it authorizes could work against the person on the other end: you.
Spotify is, on its face, a music player. You open the relationship expecting one thing: it plays what you ask for and suggests more. The policy authorizes a great deal more than that — most of it defensible, some of it quietly consequential. Below are the specific places where the data flows it permits could cause you harm, each tagged with the lifecycle stage the risk lives in and how serious it is.
Before the harms, the raw material. Spotify collects your identity (“display name, email address, password, phone number, date of birth, gender, street address, country”), your behavior (“search queries, streaming history, playlists you create, your library, browsing history, account settings, interactions with other Spotify users”), your devices (“cookie data and IP addresses, device IDs… browser type, language, operating system”), and — the important one — its own inferences:
“inferences (i.e., our understanding) of your age, interests and preferences based on your usage of the Spotify Service”Section 3, Personal data we collect about you
If you use them: voice data and precise location (with permission). It does not store full card numbers.
What the policy allows: Spotify builds inferences about “your age, interests and preferences” from what you play, search, and save. What you listen to is not neutral — it can reveal mood, mental-health state, religion, politics, sexuality, pregnancy, recovery, grief.
Why it could harm you: attributes you never declared are guessed and attached to your account, then used to target you. You can't see the inferences, can't correct what you can't see, and the guesses can be wrong in ways that still follow you. This is the intimate core of the surveillance: not the data you gave, but the conclusions drawn from it.
What the policy allows: Spotify shares your User Data and Usage Data with advertising partners, and says so plainly:
“This is also known as interest based advertising, targeted advertising, or what some states may define as, ‘sharing or selling’ for purposes of cross-context behavioural advertising.”Section 2, Tailored advertising
Why it could harm you: for adults this is opt-out, not opt-in — it runs until you turn it off. Your real-time listening and profile leave Spotify for a network of ad partners, where they can be combined with data from elsewhere to track you across the web (“cross-context”). The company's own words concede this is what some laws call selling your data. The single highest-value thing you can do is in the actions list below.
What the policy allows:
“We disclose certain data, such as your IP address, to the podcast hosting platforms when you play a podcast.”Section 5, How we share your personal data
Why it could harm you: your IP address is a rough location and a persistent identifier. Podcasts are often about the most sensitive things — addiction, illness, faith, sexuality, politics. Each time you press play, a company you never chose learns that this IP listened to that topic, and can build its own record.
What the policy allows: search queries are “deleted after 90 days” (Section 6) — but streaming history is kept “for the life of an account.” The record only grows.
Why it could harm you: a permanent, ever-lengthening diary of what you listened to and when is a standing target — for a data breach, for a subpoena, for whoever eventually controls the account. The longer it lives, the more it can say about you, and the more moments in your life it can be made to testify about.
What the policy allows:
“We may process and share your personal data to comply with a request from courts, authorities, parties to litigation…”Section 5, How we share your personal data
Why it could harm you: combined with lifetime retention (#04) and inference (#01), this means your listening record and the profile built from it can be pulled into a legal process — including one you are not a party to — or a government request. Data that exists can be compelled; data that was deleted cannot.
What the policy allows: “If we were to sell or negotiate to sell any part of our business to a buyer or possible buyer” (Section 5), your data can move with it.
Why it could harm you: the company you decided to trust is not necessarily the company that ends up holding your data. A future owner inherits your profile under whatever policy they choose. (This is the 23andMe problem: consent given to one party, exercised by another.)
What the policy allows: “Spotify transfers personal data internationally with Spotify group companies, subcontractors and partners” (Section 7).
Why it could harm you: your data lands in jurisdictions with different protections and different government-access powers. Spotify names encryption and pseudonymization as safeguards — real, but partial. Where your data physically sits changes who can reach it.
What the policy allows: voice data (if you use voice features) and precise location (only “with explicit permission”) are collected.
Why it could harm you: these are among the most sensitive categories. If you tapped “allow” once, check whether it's still on — a permission granted in a moment persists until revoked.
Where the risks concentrate, named in the field's own vocabulary:
The heat is at the two ends: analysis (turning your behavior into a profile) and disclosure (moving that profile to others). Collection is the least of it.
The test
Context you entered: a music-listening relationship — you play songs, it recommends more.
Expected flow: your data used to deliver and improve the music you asked for.
Boundaries crossed: your behavior is analyzed into inferred, sensitive traits (#01); that profile is shared by default with advertising partners for cross-context tracking (#02); your IP goes to third-party podcast hosts (#03); the record is kept for the life of the account (#04) and remains reachable by courts, governments, and a future buyer (#05, #06).
None of these are what “play me some music” implies. That gap — between the flow you expected and the flows the policy authorizes — is where the harm lives.
Consequences
Free/cheaper music and more relevant ads, against cumulative profiling, data leaking to an ad-tech network, and exposure via breach or subpoena. The benefit is immediate and visible; the harm is diffuse and deferred.
Duty & rights
Agreeing to “listen to music” is not agreeing to be profiled and shared for cross-context advertising. Making it opt-out for adults treats consent as something you must claw back, not something you grant.
Virtue
What does a service become when it turns listening into an advertising asset by default? It normalizes surveillance as the price of culture, and trains users to expect it.
Justice
The burden falls hardest on those who never find the toggle — the less technical, the rushed, the young aging into defaults. Power is asymmetric: Spotify and its partners see the profile; you can't.
The policy grants real controls. In rough order of value:
Bottom line
Spotify's policy is not unusually predatory — it is a clear, well-drafted example of the ordinary bargain: intimate behavioral data, analyzed into a profile, shared by default for advertising, and retained for as long as you stay. The harm is not a scandal; it's the defaults. The most consequential decision Spotify made on your behalf — sharing your data for cross-context ads — is one you have to actively undo.