To use Spotify GDPR compliant you have to follow these instructions:
Services & integrations
The use of Spotify does not require consent. It can be carried out on one of the other applicable legal bases of Art. 6 GDPR.
An agreement according to Art. 26 GDPR must be concluded with Spotify AB. The essential points must be made available to the data subject, in particular who the data subject can contact to exercise their rights.
Privacy Statement for the Service Spotify
When accessing some sub-services of our website, additional personal services are processed. technical connection data of the server access (IP address, date, time, requested page, browser information)data for creating usage statistics. Delivery of content provided by third parties transmission of audio content. Your consent according to Art. 6 (1) a GDPR. Spotify AB, Regeringsgatan 19, SE-111 53 Stockholm, Sweden (https://www.spotify.com). is variable and ends when the processing purpose no longer applies.
In addition to the above information, the data protection information must also contain the mandatory information from Art. 13 or 14 GDPR: Name and contact details of the controller, if necessary the contact details of the data protection officer, the purposes for which the personal data are to be processed, the legitimate interests, if the processing is based on Article 6 (1) f GDPR, the duration of the processing, information on the rights of the data subjects including the right to lodge a complaint with a supervisory authority, the possibility of simply revoking consent given, and information as to whether the Provision of the data is required by law or contract or what the possible consequences of non-provision would be. In the event that the data is used for automated decision-making, including profiling, meaningful information about the logic involved and the scope and impact on the data subject must be provided. The processing of the data must also be documented in the list of processing activities in accordance with Art. 30 GDPR. The information required for this can already be found in the privacy statement, which can be created from the previous information.
Preconfigured services & integrations