Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Content selection, delivery, and reporting cookies are set by third-party social media services integrated into Spotify's site and are capable of tracking browser activity across other websites and building interest profiles that may influence content and messaging on those third-party sites.
This analysis describes what Spotify's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses that third-party social media cookies embedded in Spotify's web properties are capable of cross-site browser tracking and interest profiling, with downstream effects on content displayed on non-Spotify websites. This type of third-party cookie activity is among the most scrutinized practices under GDPR and ePrivacy Directive enforcement.
Under this provision, allowing content selection and delivery cookies permits third-party social media services to track browsing activity across websites and build interest profiles that may affect content displayed on other platforms. Users who disable these cookies may be unable to access social sharing tools on Spotify's site.
Cross-platform context
See how other platforms handle Content Selection, Delivery, and Reporting Cookies: Cross-Site Browser Tracking and similar clauses.
Compare across platforms →Monitoring
Spotify has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"These cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.Excerpt from Spotify's Platform Rules
1) REGULATORY LANDSCAPE: This provision engages GDPR requirements for lawful processing and transparency regarding third-party data controllers embedded in a site, the ePrivacy Directive's consent requirements for third-party cookies capable of cross-site tracking, and CPRA provisions regarding sharing personal information with third parties for cross-context behavioral advertising. Enforcement authorities include EU/EEA data protection authorities and the California Privacy Protection Agency. 2) GOVERNANCE EXPOSURE: High. Third-party social media cookies with cross-site tracking capabilities have been the subject of significant regulatory enforcement actions in the EU/EEA. The use of such cookies requires valid prior consent under ePrivacy Directive standards, and the identity and role of each social media service setting these cookies must be disclosed under GDPR transparency requirements. 3) JURISDICTION FLAGS: EU/EEA users face the highest regulatory exposure given ePrivacy Directive and GDPR requirements. California residents have CPRA opt-out rights for sharing with third parties for cross-context behavioral advertising. The involvement of third-party social media services as independent data controllers may require separate transparency disclosures in multiple jurisdictions. 4) CONTRACT AND VENDOR IMPLICATIONS: Spotify's integration of third-party social media cookies triggers GDPR obligations regarding the identification of joint controllers or independent third-party controllers. Legal teams should assess whether Spotify's disclosures accurately reflect the data controller relationships and whether appropriate contractual frameworks govern the embedded services. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should audit each social media service whose cookies are set through Spotify's site, verify that valid consent is obtained before these cookies are placed, and assess whether the consent interface accurately names all third-party cookie setters. The downstream impact on users' experiences on other websites should be documented as part of the data protection impact assessment.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision discloses that third-party social media cookies embedded in Spotify's web properties are capable of cross-site browser tracking and interest profiling, with downstream effects on content displayed on non-Spotify websites. This type of third-party cookie activity is among the most scrutinized practices under GDPR and ePrivacy Directive enforcement.
Under this provision, allowing content selection and delivery cookies permits third-party social media services to track browsing activity across websites and build interest profiles that may affect content displayed on other platforms. Users who disable these cookies may be unable to access social sharing tools on Spotify's site.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Spotify.