This provision discloses that Spotify stores or reads cookies, device identifiers, and associated technical information (including browser type, language, screen size, and supported technologies) on a user's device to enable persistent device recognition across app and website sessions.
This analysis describes what Spotify's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the technical mechanism underlying Spotify's data collection practices, including device fingerprinting-adjacent information. The breadth of technical parameters collected (screen size, supported technologies, browser information) may engage ePrivacy Directive requirements for consent to access information stored on a device, and GDPR requirements for lawful processing of device-linked personal data.
Interpretive note: Whether the combination of technical parameters constitutes device fingerprinting subject to stricter consent requirements under EU/EEA law is a matter of regulatory interpretation and may vary by jurisdiction.
Under this provision, Spotify may store and read identifiers and technical attributes on a user's device to recognize it across sessions and platforms. This mechanism supports the advertising and analytics purposes described elsewhere in the consent interface.
Cross-platform context
See how other platforms handle Device Identifier Storage and Recognition and similar clauses.
Compare across platforms →"Cookies, device or similar online identifiers together with other information (e.g. browser type and information, language, screen size, supported technologies, etc.) can be stored or read on your device to recognise it each time it connects to an app or to a website, for one or several of the purposes presented here.Excerpt from Spotify's Platform Rules
1) REGULATORY LANDSCAPE: This provision directly engages ePrivacy Directive Article 5(3), which requires prior informed consent before storing or accessing information on a user's device.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the technical mechanism underlying Spotify's data collection practices, including device fingerprinting-adjacent information. The breadth of technical parameters collected (screen size, supported technologies, browser information) may engage ePrivacy Directive requirements for consent to access information stored on a device, and GDPR requirements for lawful processing of device-linked personal data.
Under this provision, Spotify may store and read identifiers and technical attributes on a user's device to recognize it across sessions and platforms. This mechanism supports the advertising and analytics purposes described elsewhere in the consent interface.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Spotify.