Spotify · Spotify Privacy Policy

Facial Age Estimation and Biometric Age Check

High severity
Share 𝕏 Share in Share 🔒 PDF
Watch Spotify Get alerts when this provision or policy changes.
Watch — $9.99/mo

Why it matters (compliance & risk perspective)

Collecting facial imagery and identity documents constitutes biometric data collection under several US state laws, and the deletion guarantee applies to Spotify but may not bind the third-party processor — meaning your biometric data could be retained by a vendor Spotify does not fully control.

Consumer impact (what this means for users)

Spotify collects a wide range of personal data including your listening history, search queries, inferences about your interests and age, voice recordings, and — for age verification — photos of your face and identity documents. Targeted advertising using your data and data from third-party advertising partners is enabled by default for eligible users, meaning your listening behavior and demographic information are used to serve you personalized ads unless you actively opt out. You can opt out of tailored advertising by visiting spotify.com/account/privacy and toggling off 'Tailored Ads', or by clicking 'Your Privacy Choices' at the bottom of Spotify's website.

How other platforms handle this

Apple Medium

When you opt in to provide diagnostic and usage data, you consent to Apple's collection, use, and disclosure of this information as described in Apple's Privacy Policy. Apple may use this information to improve its products and services.

Pinterest Medium

Children under 13 are not allowed to use Pinterest. If you are based in a state or country with an older age requirement, you may only use the Services if you are at or over the age at which you can provide consent to data processing.

Stash Medium

We may collect information for purposes of identify verification, government-issued identification documents and self-portrait photographs ("Selfie"); and other information required by federal and industry laws and regulations.

See all platforms with this clause type →

This clause could change without notice.

Get alerted when Spotify updates this policy — with plain-language summaries and severity ratings.

Watch Spotify Need compliance memos? Professional →
View original clause language
Age Check Data is the data you provide if you use an Age Check powered by a third party provider on Spotify ('Age Check'). This includes: Facial age estimation: a photo of your face which is used to estimate your age; Identity document verification: photos of your face and ID which are used to confirm your age and to verify that the ID belongs to you. Where Age Check Data is collected, we will obtain your consent and provide notice of the third party policies that apply to the processing of such data. All Age Check Data is deleted immediately after the Age Check.

Applicable regulations

EU AI Act
European Union
BIPA
Illinois, USA
CCPA/CPRA
California, USA
COPPA
United States Federal
CAN-SPAM
United States Federal
DMA
European Union
FCRA
United States Federal
GDPR
European Union
GLBA
United States Federal
HIPAA
United States Federal
TCPA
United States Federal
UK GDPR
United Kingdom

Provision details

Document information
Document
Spotify Privacy Policy
Entity
Spotify
Document last updated
April 29, 2026
Tracking information
First tracked
March 6, 2026
Last verified
April 9, 2026
Record ID
CA-P-002173
Document ID
CA-D-00036
Evidence Provenance
Source URL
Wayback Machine
SHA-256
20e7378325f90f73de8e5f0d9b2d1ec4523f9cf07b406b492edd5753b96f24ad
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Spotify | Document: Spotify Privacy Policy | Record: CA-P-002173
Captured: 2026-03-06 20:27:52 UTC | SHA-256: 20e7378325f90f73…
URL: https://conductatlas.com/platform/spotify/spotify-privacy-policy/facial-age-estimation-and-biometric-age-check/
Accessed: May 4, 2026
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Don't miss changes to this clause.

Spotify has updated this policy before. Get alerted on the next change.

Watch Spotify

Frequently Asked Questions

What does Spotify's Facial Age Estimation and Biometric Age Check clause do?

Collecting facial imagery and identity documents constitutes biometric data collection under several US state laws, and the deletion guarantee applies to Spotify but may not bind the third-party processor — meaning your biometric data could be retained by a vendor Spotify does not fully control.

Is ConductAtlas affiliated with Spotify?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Spotify.