Spotify · Spotify Privacy Policy · View original document ↗

Facial Age Estimation and Identity Document Collection

High severity Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Spotify Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Spotify may collect a photo of your face and a photo of your ID document to verify your age through a third-party provider. Spotify says this data is deleted immediately after the check.

This analysis describes what Spotify's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The provision establishes the operational scope and retention parameters for biometric and identity document data processed through Spotify's age verification mechanism. By restricting retention to the duration of the verification process and requiring prior consent and third-party notice, the clause defines the conditions under which sensitive personal data may be collected and processed.

Clause Stability Stable

0
Changes
3
Months Monitored
Apr 9, 2026
First Seen
Apr 10, 2026
Last Seen
This clause type exists across 967 other provisions on other platforms.

Consumer impact (what this means for users)

If you use the Age Check feature, a photo of your face and potentially your government ID will be processed by a third-party provider — this is highly sensitive biometric-adjacent data, and while Spotify states it is deleted immediately, the third-party provider's processing is governed by their own policies.

How other platforms handle this

Paramount+ Medium

"By clicking 'Next', you are indicating that you have read and agree to the TERMS OF USE AND PRIVACY POLICY"

OpenAI Medium

We automatically collect certain information from your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Service, we collect information about the individual web pages or products th...

Microsoft Azure Medium

Location data. Data about your device's location, which can be either precise or imprecise. For example, we collect location data using Global Navigation Satellite System (GNSS) (e.g., GPS) and data about nearby cell towers and Wi-Fi hotspots. Location can also be inferred from a device's IP address...

See all platforms with this clause type →

Monitoring

Spotify has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Age Check Data is the data you provide if you use an Age Check powered by a third party provider on Spotify ('Age Check'). This includes: Facial age estimation: a photo of your face which is used to estimate your age. Identity document verification: photos of your face and ID which are used to confirm your age and to verify that the ID belongs to you. Where Age Check Data is collected, we will obtain your consent and provide notice of the third party policies that apply to the processing of such data. All Age Check Data is deleted immediately after the Age Check.

— Excerpt from Spotify's Spotify Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1) REGULATORY FRAMEWORK: This provision potentially implicates Illinois BIPA (740 ILCS 14/1 et seq.) which requires informed written consent before collecting biometric identifiers including facial geometry; Texas CUBI (Tex. Bus. & Com. Code §503.001) which prohibits capturing biometric identifiers without informed consent; the Washington My Health MY Data Act (SB 1155) as it relates to biometric health data; CCPA/CPRA sensitive personal information provisions (Cal. Civ. Code §1798.121) which classify biometric information as sensitive and require a separate opt-in or right to limit use; and COPPA (15 U.S.C. §6501) for any minor users who undergo age verification. The FTC and state AGs have enforcement authority. Illinois BIPA is privately enforceable with statutory damages of $1,000–$5,000 per violation. 2)

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has enforcement authority over unfair or deceptive practices related to biometric data collection and children's privacy under COPPA.
    File a complaint →
  • State AG
    State AGs in Illinois (BIPA enforcement), Texas (CUBI), and California (CPRA sensitive personal information) have enforcement authority over biometric and facial data collection practices.
    File a complaint →

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
COPPA
United States Federal
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Spotify Privacy Policy
Entity
Spotify
Document last updated
May 5, 2026
Tracking information
First tracked
March 6, 2026
Last verified
April 9, 2026
Record ID
CA-P-002608
Document ID
CA-D-00036
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
20e7378325f90f73de8e5f0d9b2d1ec4523f9cf07b406b492edd5753b96f24ad
Analysis generated
March 6, 2026 20:27 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Spotify
Document: Spotify Privacy Policy
Record ID: CA-P-002608
Captured: 2026-03-06 20:27:52 UTC
SHA-256: 20e7378325f90f73…
URL: https://conductatlas.com/platform/spotify/spotify-privacy-policy/facial-age-estimation-and-identity-document-collection/
Accessed: June 16, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Spotify's Facial Age Estimation and Identity Document Collection clause do?

The provision establishes the operational scope and retention parameters for biometric and identity document data processed through Spotify's age verification mechanism. By restricting retention to the duration of the verification process and requiring prior consent and third-party notice, the clause defines the conditions under which sensitive personal data may be collected and processed.

How does this clause affect you?

If you use the Age Check feature, a photo of your face and potentially your government ID will be processed by a third-party provider — this is highly sensitive biometric-adjacent data, and while Spotify states it is deleted immediately, the third-party provider's processing is governed by their own policies.

Is ConductAtlas affiliated with Spotify?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Spotify.