Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision discloses that Spotify stores or reads cookies, device identifiers, and associated technical information (including browser type, language, screen size, and supported technologies) on a user's device to enable persistent device recognition across app and website sessions.
This analysis describes what Spotify's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the technical mechanism underlying Spotify's data collection practices, including device fingerprinting-adjacent information. The breadth of technical parameters collected (screen size, supported technologies, browser information) may engage ePrivacy Directive requirements for consent to access information stored on a device, and GDPR requirements for lawful processing of device-linked personal data.
Interpretive note: Whether the combination of technical parameters constitutes device fingerprinting subject to stricter consent requirements under EU/EEA law is a matter of regulatory interpretation and may vary by jurisdiction.
Under this provision, Spotify may store and read identifiers and technical attributes on a user's device to recognize it across sessions and platforms. This mechanism supports the advertising and analytics purposes described elsewhere in the consent interface.
Cross-platform context
See how other platforms handle Device Identifier Storage and Recognition and similar clauses.
Compare across platforms →Monitoring
Spotify has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Cookies, device or similar online identifiers together with other information (e.g. browser type and information, language, screen size, supported technologies, etc.) can be stored or read on your device to recognise it each time it connects to an app or to a website, for one or several of the purposes presented here.Excerpt from Spotify's Platform Rules
1) REGULATORY LANDSCAPE: This provision directly engages ePrivacy Directive Article 5(3), which requires prior informed consent before storing or accessing information on a user's device. GDPR Article 6 lawful basis requirements apply to subsequent processing of device-linked personal data. The combination of device identifiers and technical attributes (screen size, browser type, supported technologies) may constitute personal data under GDPR if linkable to an individual. Relevant enforcement authorities include EU/EEA data protection authorities. 2) GOVERNANCE EXPOSURE: Medium. The enumeration of technical parameters including screen size and supported technologies alongside cookies and device identifiers raises questions about whether the combination constitutes device fingerprinting, which some EU/EEA regulators have treated as subject to the same consent requirements as cookies under the ePrivacy Directive. 3) JURISDICTION FLAGS: EU/EEA users have heightened exposure given ePrivacy Directive requirements. California residents may have rights regarding the collection of device identifiers under CPRA. The global application of this provision without jurisdiction-specific differentiation may require localized compliance assessments. 4) CONTRACT AND VENDOR IMPLICATIONS: If device identifier data is shared with third-party partners (as implied by the targeting cookies and advertising data sharing provisions), data processing agreements and transfer mechanisms must cover this data category. Procurement teams should confirm that all relevant data categories are enumerated in partner agreements. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether device fingerprinting-equivalent data collection is covered by the existing consent mechanism and whether the consent interface accurately characterizes the technical scope of data collection. A data mapping exercise should confirm which technical attributes are collected, stored, and shared, and under what legal basis.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes the technical mechanism underlying Spotify's data collection practices, including device fingerprinting-adjacent information. The breadth of technical parameters collected (screen size, supported technologies, browser information) may engage ePrivacy Directive requirements for consent to access information stored on a device, and GDPR requirements for lawful processing of device-linked personal data.
Under this provision, Spotify may store and read identifiers and technical attributes on a user's device to recognize it across sessions and platforms. This mechanism supports the advertising and analytics purposes described elsewhere in the consent interface.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Spotify.