Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
The Spotify Web API and embedded player let websites stream music and display playlists directly on a page. When the player or API is loaded on a public page, it requests Spotify domains that set third party cookies such as sp_t, sp_dc, and sp_adid. These cookies measure usage, keep logged in sessions, and support advertising, so they are not strictly necessary. Their use requires prior consent under the GDPR and the ePrivacy Directive, and data may be processed on US infrastructure.
The Spotify Web API is the developer interface that lets websites and applications read catalogue data, manage playlists, and control playback, while the Spotify embed is a ready made iframe player that streams tracks and albums on a page. Many sites use the embedded player to share songs or playlists, and others call the Web API to display rich music content. In both cases the visitor browser connects to Spotify domains, which set cookies and process technical data as the player loads.
When the embed loads, Spotify sets third party cookies such as sp_t for anonymous usage analytics, sp_landing to store the landing page, sp_dc for device and account continuity for logged in users, and sp_adid for advertising where applicable. Alongside these cookies, Spotify receives the visitor IP address, browser and device information, the referring page, and playback interactions. For users signed in to Spotify, this activity can be associated with their account, which makes the processing personal data under the GDPR.
Because these cookies are written to and read from the visitor device for analytics and advertising rather than strictly necessary functions, Article 5(3) of the ePrivacy Directive requires prior consent. The IP address and account linkage also make the data personal under the GDPR, so you need a lawful basis, clear information, and an entry in your record of processing activities. The embed should therefore never load before the visitor has accepted the relevant cookie category.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent must be obtained before any Spotify domain is contacted, which means the player iframe and the Web API calls have to be blocked until the visitor actively opts in. A recommended pattern is a click to load placeholder that shows a static cover and a play button, loading the real embed only after consent is given. Pre ticked boxes, implied consent from scrolling, and cookie walls do not meet the standard, and consent must be as easy to withdraw as it was to give.
Spotify is based in Sweden but uses infrastructure and sub processors in the United States, so document the transfer under the Standard Contractual Clauses and reference Spotify supplementary measures. In practice, gate the embed and the API behind your consent management platform, use a click to load wrapper, and list the Spotify cookies and their durations in your cookie policy. Name Spotify as a recipient, disclose the US processing, and review periodically because cookie names and durations can change.
Websites using Spotify Web API must obtain user consent under GDPR regulations.
DPIA considerations
The Spotify embed sets persistent third party cookies (sp_t, sp_dc) and an advertising identifier (sp_adid), links activity to Spotify accounts for logged in users, and sends IP addresses and device data to infrastructure that includes the United States. A DPIA should assess the scale of tracking through embedded players, the combination of analytics and advertising cookies, the international transfer to the US, and retention, together with mitigations such as click to load gating, consent control, and clear cookie disclosure.
Sample consent text
We use the Spotify player to let you listen to music on our site. When you allow it, Spotify places cookies on your device to keep your session, measure usage, and support advertising, and it may receive your IP address and device information. This content loads only after you accept the marketing category, and the data may be processed in the United States. You can withdraw your consent at any time through our cookie settings.
Third-party domains contacted
open.spotify.comembed.spotify.comembed-cdn.spotifycdn.comaudio-ak.spotifycdn.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| sp_t | analytics | 1 year | Anonymous usage analytics cookie set by Spotify to measure how the embedded player and content are used. |
| sp_landing | analytics | Session | Stores the landing page so that Spotify can attribute the entry point of the visit. Short lived and used for measurement. |
| sp_dc | marketing | 1 year | Maintains device and account continuity for users who are logged in to Spotify, linking embedded activity to their account. |
| sp_adid | marketing | 1 year | Advertising identifier set where applicable to support advertising and measurement across Spotify services. |
Spotify Web API uses cookies for user preferences — inform visitors with a consent banner.
The Spotify player sets third party cookies such as sp_t for anonymous usage analytics with a lifetime of about one year, sp_landing to remember the landing page for a short period, sp_dc for device and account continuity for logged in users for about one year, and sp_adid for advertising where applicable. The exact set depends on whether the visitor is signed in to Spotify.
Yes. The cookies set by the embed are analytics and marketing cookies that are not strictly necessary, so under Article 5(3) of the ePrivacy Directive and the GDPR you must obtain prior, opt in consent before the player or the Web API contacts Spotify. The simplest compliant approach is a click to load placeholder.
The storage and reading of cookies relies on consent under the ePrivacy Directive, and the subsequent processing of personal data such as IP addresses relies on consent under Article 6(1)(a) of the GDPR. Legitimate interest is generally not available because consent is already required to set the cookies and load the embed.
Yes. Although Spotify is headquartered in Sweden, it relies on infrastructure and sub processors in the United States, so IP addresses and device data can be transferred there. Document the transfer under the Standard Contractual Clauses and reference Spotify supplementary measures in your privacy notice.
A full DPIA is not always mandatory, but it is advisable when you embed Spotify across many pages or combine it with other tracking. Document the purposes, the cookies and their durations, the international transfer, and retention, and apply mitigations such as click to load gating and consent control.
Block the player iframe and any Web API calls until the visitor accepts the marketing category in your consent management platform. Use a click to load wrapper that shows a static cover and loads the real embed only after consent, list the Spotify cookies in your cookie policy, and disclose the US processing.
You can link out to Spotify instead of embedding, use a self hosted audio player for your own tracks, or choose a privacy friendly music widget that does not set tracking cookies. These options reduce or remove third party cookies and US transfers, at the cost of the native Spotify streaming experience.
List each Spotify cookie such as sp_t, sp_dc, and sp_adid with its purpose and duration, name Spotify as a recipient, and disclose the transfer to the United States. Keep the entries in sync with a regular cookie scan because Spotify cookie names and durations can change over time.