While a specific Spotify class action lawsuit titled “Spotify Privacy Class Action Claims Audio Streaming Data Was Disclosed Improperly” has not been located in public records, Spotify has faced significant regulatory action for privacy violations. In June 2023, Sweden’s Internet and Privacy Authority (IMY) imposed a SEK 58 million (approximately $5.4 million) fine on Spotify for failing to provide clear information about how user personal data was processed and for providing vague responses to data access requests under GDPR Article 15. This regulatory enforcement action stemmed from a complaint filed in January 2019 by privacy activist Max Schrems and the noyb (None of Your Business) organization, followed by legal action filed in June 2022.
The Swedish fine represents one of the most significant privacy enforcement actions against a major music streaming platform and highlights the growing tension between streaming services’ data collection practices and user privacy rights. While this is not a traditional class action lawsuit in the U.S. sense, it demonstrates how regulators are holding Spotify accountable for transparency failures related to user data disclosure and processing.
Table of Contents
- What Was Spotify’s Actual Privacy Violation?
- GDPR Article 15 Data Access Rights Explained
- The Swedish Regulatory Action and Its Timeline
- How This Affects Spotify Users Globally
- Other Spotify Litigation and Privacy Concerns
- How to Check Your Spotify Data Access Rights
- What This Means for Other Streaming Services
What Was Spotify’s Actual Privacy Violation?
Spotify’s violation centered on its failure to comply with GDPR Article 15, which gives users the right to obtain confirmation of whether personal data is being processed and to receive a copy of that data in an understandable format. When users submitted formal requests for their personal data, Spotify either failed to clearly explain what data was collected or provided vague and incomplete responses. The Swedish authority found that Spotify’s transparency obligations were inadequate, particularly when users asked detailed questions about how their listening behavior, device information, and personal identifiers were being used.
The complaint was initially filed by Max Schrems, an Austrian privacy activist who founded noyb to challenge corporate privacy violations through GDPR enforcement. Schrems filed the complaint in January 2019, but it took until June 2022 for noyb to formally escalate the matter with legal action. The IMY (Internet and Privacy Authority) then investigated Spotify’s practices and determined the company had been systematically failing to meet transparency standards for over three years.
GDPR Article 15 Data Access Rights Explained
GDPR Article 15 is one of the regulation’s core provisions, giving individuals a “right of access” to their personal data. This means that any company processing personal data—including music streaming platforms—must provide users with a clear, written copy of all personal data held about them when requested. The data must be provided in a commonly used electronic format within 30 days. Additionally, the company must disclose the purposes for processing, the categories of data collected, who it’s shared with, and how long it will be retained. For Spotify specifically, this includes data like listening history, search queries, device information, location data, payment information, and any inferences the company has made about user preferences or demographics.
Many users are unaware they have this right, and Spotify’s vague responses prevented individuals from understanding the full scope of data collection. A user might request their data and receive only a list of songs played, without information about behavioral targeting or data sharing with third parties. The limitation of GDPR Article 15 is that it applies only to individuals in the European Union and countries with similar data protection laws. Spotify users in the United States, while having privacy rights under various state laws, do not have the same automatic data access rights as EU users. This geographic disparity means the Swedish fine only directly impacts Spotify’s European operations, though the company’s global privacy practices are increasingly coming under scrutiny.
The Swedish Regulatory Action and Its Timeline
The sequence of events reveals how privacy enforcement can move slowly but persistently. Max Schrems and noyb filed their initial complaint on January 18, 2019, after Schrems personally submitted data access requests to Spotify and received inadequate responses. The complaint sat with Swedish authorities for over three years before formal legal action was filed on June 22, 2022. Another year passed before the IMY issued its final decision in June 2023, imposing the SEK 58 million fine—approximately $5.4 million USD at the time.
The Swedish fine is significant in absolute terms but represents a modest penalty relative to Spotify’s revenue. In 2023, Spotify generated approximately $13.2 billion in annual revenue, meaning the fine amounted to roughly 0.04% of yearly income. This raises a critical limitation: European regulators can impose fines under GDPR’s penalty structure, but the fines are sometimes insufficient to change corporate behavior. Spotify could view this as a minor cost of doing business, similar to how tech companies calculate regulatory penalties as a line item rather than a genuine deterrent.
How This Affects Spotify Users Globally
For EU users, the Swedish regulatory action has practical implications. Spotify is now under increased scrutiny from the IMY and potentially other European data protection authorities. Users in the EU have strengthened leverage when submitting data access requests—Spotify must respond clearly and completely, or risk additional fines and enforcement action. A user in Germany or France can demand their personal data, and Spotify must provide a detailed accounting of what information is held, how it’s used, and who it’s shared with.
Outside the EU, the regulatory action serves as a warning rather than direct protection. U.S. users do not have an automatic GDPR Article 15 equivalent, though California residents benefit from the California Consumer Privacy Act (CCPA), which grants similar but narrower data access rights. Spotify users in other non-EU countries have limited legal mechanisms to compel data transparency, which means many are unaware of the extent of information Spotify collects and retains. Spotify’s global privacy practices have not fundamentally changed based on the Swedish fine alone—the company continues standard music streaming data collection in all markets.
Other Spotify Litigation and Privacy Concerns
Beyond the Swedish regulatory fine, Spotify faces additional legal challenges that relate to user data and fair treatment. In November 2025, a lawsuit was filed in the U.S. District Court for the Central District of California alleging that Spotify allowed fake bot streams to inflate artist play counts. The suit focuses specifically on Drake, whose catalog apparently contains approximately 37 billion streams, with substantial inauthentic activity detected between January 2022 and September 2025.
This litigation addresses data integrity rather than privacy disclosure directly, but it highlights Spotify’s inability to police its own platform and prevent manipulated user data. Separately, a 2025 lawsuit filed in New York federal court alleges that Spotify’s “Discovery Mode” operates as modern payola—undisclosed promotional arrangements where artists pay for playlist placement. Discovery Mode data is not transparent to regular users, who believe playlists are curated based on listening algorithms rather than financial relationships. This relates to privacy because user listening behavior is being influenced by non-disclosed financial relationships, and the data that shapes recommendations is partially driven by payments rather than user preference. A significant limitation of these lawsuits is that they address specific practices but do not necessarily challenge Spotify’s foundational data collection model.
How to Check Your Spotify Data Access Rights
Users who want to exercise data access rights can request their information directly from Spotify, though the process varies by country. In the EU, users can submit a data subject access request (DSAR) under GDPR Article 15. Spotify provides instructions on its privacy page for submitting formal requests. The company is required to respond within 30 days with all personal data it holds, including listening history, search queries, account information, and any algorithmic inferences about preferences or demographics.
For non-EU users, the process is less standardized. California residents can submit a request under CCPA, though they must identify themselves and verify their identity. Users in other U.S. states can attempt to submit requests, but Spotify may not be legally obligated to honor them with the same rigor as GDPR requests. After submitting a request, users often receive a downloadable file containing their data in JSON format, though the comprehensiveness of what’s included can vary significantly.
What This Means for Other Streaming Services
Spotify’s Swedish regulatory fine sets a precedent for how European authorities will evaluate other streaming and media platforms’ privacy practices. Apple Music, Amazon Music, and YouTube Music are likely to face similar scrutiny regarding GDPR Article 15 compliance. These services collect comparable user data—listening history, device information, demographic inferences, and behavioral targeting signals—yet may have comparable transparency gaps.
The IMY decision does not directly regulate competitors, but it establishes that Swedish and other European authorities view data access transparency as a fundamental obligation. The broader implication is that U.S.-based streaming services will increasingly face pressure to improve global privacy standards, even in markets without GDPR-equivalent laws. Spotify’s experience demonstrates that privacy violations carry reputational and financial costs, and that activists and civil society organizations can successfully challenge corporate data practices through regulatory channels. For consumers, this means data privacy is becoming a competitive differentiator—streaming services with superior data transparency may attract privacy-conscious users who are concerned about data disclosure practices.
You Might Also Like
- Disney Plus Privacy Class Action Claims Streaming Data Was Disclosed to Third Parties
- Venmo Privacy Class Action Claims User Transaction Data Was Shared Improperly
- Roku Privacy Class Action Claims Smart TV Viewing Data Was Shared Improperly
Open Settlements You Can Claim Now
Browse current class action settlements accepting claims — several require no proof of purchase:
