Provision record
Spotify · Spotify Platform Rules · View original document ↗

Device Identifier Storage and Recognition

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Spotify changes these terms. Follow Spotify →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Spotify Monitor emails you the same day this changes. The archive stays free.
Follow Spotify →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

This provision discloses that Spotify stores or reads cookies, device identifiers, and associated technical information (including browser type, language, screen size, and supported technologies) on a user's device to enable persistent device recognition across app and website sessions.

This analysis describes what Spotify's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the technical mechanism underlying Spotify's data collection practices, including device fingerprinting-adjacent information. The breadth of technical parameters collected (screen size, supported technologies, browser information) may engage ePrivacy Directive requirements for consent to access information stored on a device, and GDPR requirements for lawful processing of device-linked personal data.

Interpretive note: Whether the combination of technical parameters constitutes device fingerprinting subject to stricter consent requirements under EU/EEA law is a matter of regulatory interpretation and may vary by jurisdiction.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this provision, Spotify may store and read identifiers and technical attributes on a user's device to recognize it across sessions and platforms. This mechanism supports the advertising and analytics purposes described elsewhere in the consent interface.

Cross-platform context

See how other platforms handle Device Identifier Storage and Recognition and similar clauses.

Compare across platforms →

Monitoring

Spotify has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Spotify → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Cookies, device or similar online identifiers together with other information (e.g. browser type and information, language, screen size, supported technologies, etc.) can be stored or read on your device to recognise it each time it connects to an app or to a website, for one or several of the purposes presented here.

Excerpt from Spotify's Platform Rules

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision directly engages ePrivacy Directive Article 5(3), which requires prior informed consent before storing or accessing information on a user's device. GDPR Article 6 lawful basis requirements apply to subsequent processing of device-linked personal data. The combination of device identifiers and technical attributes (screen size, browser type, supported technologies) may constitute personal data under GDPR if linkable to an individual. Relevant enforcement authorities include EU/EEA data protection authorities. 2) GOVERNANCE EXPOSURE: Medium. The enumeration of technical parameters including screen size and supported technologies alongside cookies and device identifiers raises questions about whether the combination constitutes device fingerprinting, which some EU/EEA regulators have treated as subject to the same consent requirements as cookies under the ePrivacy Directive. 3) JURISDICTION FLAGS: EU/EEA users have heightened exposure given ePrivacy Directive requirements. California residents may have rights regarding the collection of device identifiers under CPRA. The global application of this provision without jurisdiction-specific differentiation may require localized compliance assessments. 4) CONTRACT AND VENDOR IMPLICATIONS: If device identifier data is shared with third-party partners (as implied by the targeting cookies and advertising data sharing provisions), data processing agreements and transfer mechanisms must cover this data category. Procurement teams should confirm that all relevant data categories are enumerated in partner agreements. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether device fingerprinting-equivalent data collection is covered by the existing consent mechanism and whether the consent interface accurately characterizes the technical scope of data collection. A data mapping exercise should confirm which technical attributes are collected, stored, and shared, and under what legal basis.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has authority over undisclosed or deceptive data collection practices including device tracking under the FTC Act.
    File a complaint →

Provision details

Document information
Document
Spotify Platform Rules
Entity
Spotify
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
July 9, 2026
Record ID
CA-P-013585
Document ID
CA-D-00037
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
5587b8143de1ac408c3820b663d53fe08a9cf3b4a16bf8d9900ea12b4954a66d
Analysis generated
May 8, 2026 00:16 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Spotify
Document: Spotify Platform Rules
Record ID: CA-P-013585
Captured: 2026-05-08 00:16:42 UTC
SHA-256: 5587b8143de1ac40…
URL: https://conductatlas.com/platform/spotify/spotify-platform-rules/provision/CA-P-013585/device-identifier-storage-and-recognition/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Spotify's Device Identifier Storage and Recognition clause do?

This provision establishes the technical mechanism underlying Spotify's data collection practices, including device fingerprinting-adjacent information. The breadth of technical parameters collected (screen size, supported technologies, browser information) may engage ePrivacy Directive requirements for consent to access information stored on a device, and GDPR requirements for lawful processing of device-linked personal data.

How does this clause affect you?

Under this provision, Spotify may store and read identifiers and technical attributes on a user's device to recognize it across sessions and platforms. This mechanism supports the advertising and analytics purposes described elsewhere in the consent interface.

Is ConductAtlas affiliated with Spotify?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Spotify.