FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Video
  4. Spotify Web API
S

Spotify Web API

PreferencesWebsite

Related services

Annoto

Annoto is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Annoto integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Annoto helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
B

Brightcove

Brightcove is a user preference and personalization service that helps websites deliver customized experiences based on individual visitor settings and choices. It manages preferences for content display, communication channels, and interaction styles. Brightcove integrates with website platforms to remember and apply user choices consistently across sessions. With privacy-compliant preference storage, Brightcove enhances satisfaction by ensuring tailored browsing experiences for every visitor.

Preferences
B

Bunny Stream

Bunny Stream is a video hosting and streaming platform that helps businesses deliver high-quality video content to their audiences. It provides adaptive bitrate streaming, customizable players, and content management tools. Bunny Stream supports live streaming, on-demand playback, and video analytics. With CDN-powered delivery and responsive embeds, Bunny Stream ensures smooth playback across all devices and network conditions for engaging video experiences.

Preferences

Caast.tv

Caast.tv is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Caast.tv supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Caast.tv ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

Captivate.fm

Captivate.fm is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Captivate.fm integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Captivate.fm helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
C

Cloudflare Stream

Cloudflare Stream is a video hosting and streaming platform that helps businesses deliver high-quality video content to their audiences. It provides adaptive bitrate streaming, customizable players, and content management tools. Cloudflare Stream supports live streaming, on-demand playback, and video analytics. With CDN-powered delivery and responsive embeds, Cloudflare Stream ensures smooth playback across all devices and network conditions for engaging video experiences.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Spotify Web API do?

The Spotify Web API and embedded player let websites stream music and display playlists directly on a page. When the player or API is loaded on a public page, it requests Spotify domains that set third party cookies such as sp_t, sp_dc, and sp_adid. These cookies measure usage, keep logged in sessions, and support advertising, so they are not strictly necessary. Their use requires prior consent under the GDPR and the ePrivacy Directive, and data may be processed on US infrastructure.

What the Spotify Web API is

The Spotify Web API is the developer interface that lets websites and applications read catalogue data, manage playlists, and control playback, while the Spotify embed is a ready made iframe player that streams tracks and albums on a page. Many sites use the embedded player to share songs or playlists, and others call the Web API to display rich music content. In both cases the visitor browser connects to Spotify domains, which set cookies and process technical data as the player loads.

What data and cookies it collects

When the embed loads, Spotify sets third party cookies such as sp_t for anonymous usage analytics, sp_landing to store the landing page, sp_dc for device and account continuity for logged in users, and sp_adid for advertising where applicable. Alongside these cookies, Spotify receives the visitor IP address, browser and device information, the referring page, and playback interactions. For users signed in to Spotify, this activity can be associated with their account, which makes the processing personal data under the GDPR.

GDPR and ePrivacy implications

Because these cookies are written to and read from the visitor device for analytics and advertising rather than strictly necessary functions, Article 5(3) of the ePrivacy Directive requires prior consent. The IP address and account linkage also make the data personal under the GDPR, so you need a lawful basis, clear information, and an entry in your record of processing activities. The embed should therefore never load before the visitor has accepted the relevant cookie category.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

Consent must be obtained before any Spotify domain is contacted, which means the player iframe and the Web API calls have to be blocked until the visitor actively opts in. A recommended pattern is a click to load placeholder that shows a static cover and a play button, loading the real embed only after consent is given. Pre ticked boxes, implied consent from scrolling, and cookie walls do not meet the standard, and consent must be as easy to withdraw as it was to give.

Data transfers and practical compliance steps

Spotify is based in Sweden but uses infrastructure and sub processors in the United States, so document the transfer under the Standard Contractual Clauses and reference Spotify supplementary measures. In practice, gate the embed and the API behind your consent management platform, use a click to load wrapper, and list the Spotify cookies and their durations in your cookie policy. Name Spotify as a recipient, disclose the US processing, and review periodically because cookie names and durations can change.

GDPR consent category

Preferences

Websites using Spotify Web API must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy Directive)
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive

DPIA considerations

The Spotify embed sets persistent third party cookies (sp_t, sp_dc) and an advertising identifier (sp_adid), links activity to Spotify accounts for logged in users, and sends IP addresses and device data to infrastructure that includes the United States. A DPIA should assess the scale of tracking through embedded players, the combination of analytics and advertising cookies, the international transfer to the US, and retention, together with mitigations such as click to load gating, consent control, and clear cookie disclosure.

Sample consent text

We use the Spotify player to let you listen to music on our site. When you allow it, Spotify places cookies on your device to keep your session, measure usage, and support advertising, and it may receive your IP address and device information. This content loads only after you accept the marketing category, and the data may be processed in the United States. You can withdraw your consent at any time through our cookie settings.

Technical details

Tracking methodEmbedded player and Web API with third party cookies
Server locationEuropean Union and United States (Spotify is based in Sweden with US infrastructure)
Data transferred outside the EUEmbedding the Spotify player or calling the Web API loads Spotify domains operated by Spotify AB and Spotify USA Inc. Although Spotify is headquartered in Sweden, it relies on infrastructure and sub processors in the United States, so personal data such as IP addresses and device identifiers can be transferred there. These transfers are governed by Standard Contractual Clauses and supplementary measures described in the Spotify privacy and data processing terms.

Third-party domains contacted

open.spotify.comembed.spotify.comembed-cdn.spotifycdn.comaudio-ak.spotifycdn.com

Cookies placed

NameTypeDurationPurpose
sp_tanalytics1 yearAnonymous usage analytics cookie set by Spotify to measure how the embedded player and content are used.
sp_landinganalyticsSessionStores the landing page so that Spotify can attribute the entry point of the visit. Short lived and used for measurement.
sp_dcmarketing1 yearMaintains device and account continuity for users who are logged in to Spotify, linking embedded activity to their account.
sp_adidmarketing1 yearAdvertising identifier set where applicable to support advertising and measurement across Spotify services.

Spotify Web API uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does the Spotify embed set?

The Spotify player sets third party cookies such as sp_t for anonymous usage analytics with a lifetime of about one year, sp_landing to remember the landing page for a short period, sp_dc for device and account continuity for logged in users for about one year, and sp_adid for advertising where applicable. The exact set depends on whether the visitor is signed in to Spotify.

Do I need consent to embed the Spotify player?

Yes. The cookies set by the embed are analytics and marketing cookies that are not strictly necessary, so under Article 5(3) of the ePrivacy Directive and the GDPR you must obtain prior, opt in consent before the player or the Web API contacts Spotify. The simplest compliant approach is a click to load placeholder.

What is the legal basis for the Spotify Web API?

The storage and reading of cookies relies on consent under the ePrivacy Directive, and the subsequent processing of personal data such as IP addresses relies on consent under Article 6(1)(a) of the GDPR. Legitimate interest is generally not available because consent is already required to set the cookies and load the embed.

Does the Spotify embed transfer data to the United States?

Yes. Although Spotify is headquartered in Sweden, it relies on infrastructure and sub processors in the United States, so IP addresses and device data can be transferred there. Document the transfer under the Standard Contractual Clauses and reference Spotify supplementary measures in your privacy notice.

Do I need a DPIA for the Spotify Web API?

A full DPIA is not always mandatory, but it is advisable when you embed Spotify across many pages or combine it with other tracking. Document the purposes, the cookies and their durations, the international transfer, and retention, and apply mitigations such as click to load gating and consent control.

How do I embed Spotify in a compliant way?

Block the player iframe and any Web API calls until the visitor accepts the marketing category in your consent management platform. Use a click to load wrapper that shows a static cover and loads the real embed only after consent, list the Spotify cookies in your cookie policy, and disclose the US processing.

Are there alternatives to embedding Spotify?

You can link out to Spotify instead of embedding, use a self hosted audio player for your own tracks, or choose a privacy friendly music widget that does not set tracking cookies. These options reduce or remove third party cookies and US transfers, at the cost of the native Spotify streaming experience.

How do I update my cookie policy for Spotify?

List each Spotify cookie such as sp_t, sp_dc, and sp_adid with its purpose and duration, name Spotify as a recipient, and disclose the transfer to the United States. Keep the entries in sync with a regular cookie scan because Spotify cookie names and durations can change over time.