Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision authorizes Spotify to collect personal data associated with a user's browser or device and share it with third-party marketing partners for targeted advertising purposes, including sharing cookie data to deliver promotional messages on partner platforms.
This analysis describes what Spotify's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the legal basis and operational scope for Spotify's cross-platform advertising data sharing, authorizing disclosure of browser- and device-associated personal data to third-party partners. Compliance teams should evaluate this disclosure against GDPR legitimate interests or consent requirements and CPRA definitions of 'sharing' personal information for cross-context behavioral advertising.
Under this provision, Spotify may share cookie data and device-associated personal data with marketing partners who may use it to deliver targeted advertisements on their own platforms. The provision applies to users browsing Spotify's web properties regardless of account login status.
Cross-platform context
See how other platforms handle Tailored Advertising Data Sharing with Third-Party Partners and similar clauses.
Compare across platforms →Monitoring
Spotify has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Spotify may collect and share some of your personal data associated with this browser or device with some of our partners for certain purposes such as targeted advertising on their platforms. For example, we may share your cookie data with a marketing partner to inform you of one of our latest promotions while you are on their platform.Excerpt from Spotify's Platform Rules
1) REGULATORY LANDSCAPE: This provision engages GDPR requirements regarding consent for sharing personal data with third-party controllers, the ePrivacy Directive regarding cookie-based data collection, and CPRA provisions on sharing personal information for cross-context behavioral advertising. The FTC's guidelines on online behavioral advertising are also relevant. The relevant enforcement authorities include EU/EEA data protection authorities, the California Privacy Protection Agency, and the FTC. Where this provision relies on consent as a legal basis under GDPR, the validity of that consent depends on whether the consent mechanism meets GDPR Article 7 standards. 2) GOVERNANCE EXPOSURE: Medium. The provision authorizes sharing of personal data with an undefined set of partners for advertising purposes. The breadth of 'some of our partners' without enumeration may raise questions under GDPR transparency requirements regarding the identity of recipients. CPRA compliance teams should assess whether this constitutes 'sharing' personal information as defined under CPRA and whether the opt-out mechanism is operationally sufficient. 3) JURISDICTION FLAGS: EU/EEA users are subject to GDPR and ePrivacy Directive requirements, which may impose stricter consent standards than those applicable in other jurisdictions. California residents are subject to CPRA opt-out of sharing rights. The provision's global application without jurisdiction-specific differentiation (other than the opt-out toggle) may create heightened exposure in these regions. 4) CONTRACT AND VENDOR IMPLICATIONS: The reference to sharing data with 'partners' for advertising purposes triggers GDPR Article 28 data processing agreement requirements if those partners act as processors, or joint controller arrangements if they act as independent controllers. Procurement teams should verify that data-sharing agreements with advertising and marketing partners are in place and compliant with applicable law. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should audit the list of third-party partners receiving personal data under this provision, assess whether consent or another valid legal basis supports each transfer, and verify that data processing agreements or standard contractual clauses are in place for cross-border transfers. The adequacy of the consent mechanism for EU/EEA users and the sufficiency of the opt-out for California users warrant review.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes the legal basis and operational scope for Spotify's cross-platform advertising data sharing, authorizing disclosure of browser- and device-associated personal data to third-party partners. Compliance teams should evaluate this disclosure against GDPR legitimate interests or consent requirements and CPRA definitions of 'sharing' personal information for cross-context behavioral advertising.
Under this provision, Spotify may share cookie data and device-associated personal data with marketing partners who may use it to deliver targeted advertisements on their own platforms. The provision applies to users browsing Spotify's web properties regardless of account login status.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Spotify.