Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Spotify embed widgets place a track, album, playlist or podcast player on your site via an iframe from open.spotify.com. Loading the player contacts Spotify servers, can set Spotify cookies and exposes the visitor IP address.
Spotify Widgets are embeddable iframe players that allow website owners to place a Spotify track, album, playlist or podcast episode directly on a page. The player is served from open.spotify.com and when it loads, the visitor browser makes a direct connection to Spotify servers, exposing the visitor IP address and allowing Spotify to set cookies.
When a Spotify Widget loads it can set several cookies including sp_t (a tracking identifier lasting one year), sp_landing (stores landing page data for one day), sp_dc (account routing cookie lasting one year used when the visitor is logged in to Spotify) and player preference cookies. The widget also exposes the visitor IP address, device information and playback events to Spotify regardless of login status.
Spotify Widgets trigger obligations under both the GDPR and the ePrivacy Directive. The ePrivacy Directive requires prior consent before storing or accessing cookies on a visitor device. Under GDPR, the transfer of IP addresses and personal data to Spotify constitutes processing that must have a lawful basis. Because the widget loads automatically on page render, consent must be obtained before the iframe is injected into the page.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is required before loading any Spotify Widget. The consent must be freely given, specific, informed and unambiguous. A compliant implementation replaces the iframe with a consent placeholder that only loads the Spotify player after the visitor actively accepts. Consent should be categorised under a media or functional cookies category in your consent management platform.
Spotify AB is headquartered in Sweden but operates on global cloud infrastructure including servers in the United States. Visitor data including IP addresses, device identifiers and playback events may be transferred to and processed in the United States. Spotify relies on standard contractual clauses and, where applicable, the EU US Data Privacy Framework as transfer mechanisms. You should document these transfers in your records of processing activities.
To use Spotify Widgets compliantly: gate the iframe behind a consent management platform and only inject it after the visitor opts in; display a clear placeholder explaining what will load; categorise the service in your cookie policy under media players; document the US data transfer and the transfer mechanism in your records; review Spotify data processing terms annually; and inform visitors that playback may be linked to their Spotify account if they are logged in.
Websites using Spotify Widgets must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA should be considered where Spotify Widgets are embedded on high traffic pages or pages targeting sensitive audiences. Key risks include transfer of visitor IP and playback data to Spotify infrastructure in the United States, linkage of playback to authenticated Spotify accounts, and the inability to offer a cookieless version. Document the legal basis, implement consent prior to loading the iframe and verify standard contractual clauses with Spotify.
Sample consent text
We would like to load a Spotify player to let you listen to music directly on this page. Spotify will receive your IP address and may set cookies to identify your device. If you are logged into Spotify, your playback may be linked to your account. Do you consent to loading the Spotify player?
Third-party domains contacted
open.spotify.comembed.spotify.comwww.spotify.com*.scdn.coCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| sp_t | Tracking | 1 year | Spotify tracking identifier that persists across sessions to identify the visitor device |
| sp_landing | Functional | 1 day | Stores the landing page URL data for Spotify analytics |
| sp_dc | Authentication | 1 year | Account routing cookie used when the visitor is logged in to Spotify to link playback to the account |
| sp_player_prefs | Functional | 1 year | Stores player preferences such as volume and playback settings |
Spotify Widgets uses cookies for user preferences — inform visitors with a consent banner.
The Spotify Widget can set sp_t (a tracking identifier lasting one year), sp_landing (stores landing page data for one day), sp_dc (account routing lasting one year, used when the visitor is logged in to Spotify) and player preference cookies. These cookies are deposited as soon as the iframe loads, before the visitor interacts with the player.
Yes. Consent must be obtained before the Spotify iframe is injected into the page. The widget contacts Spotify servers and can set cookies on page load, which triggers the ePrivacy Directive requirement for prior consent. Replace the iframe with a consent placeholder and only load the player after the visitor opts in.
The required legal basis is consent under Article 6(1)(a) GDPR for the processing of personal data, combined with Article 5(3) ePrivacy for the setting of cookies. Legitimate interest is not available because Spotify sets cookies for its own tracking purposes and the processing is not strictly necessary for the service.
Yes. Spotify AB is headquartered in Sweden but operates on global infrastructure including servers in the United States. Visitor IP addresses, device data and playback events may be transferred to the United States. Spotify relies on standard contractual clauses and the EU US Data Privacy Framework as transfer mechanisms.
A DPIA should be considered for high traffic sites or those targeting sensitive audiences. The key risk factors are the transfer of personal data to the United States, the inability to offer a cookieless version, and the potential linkage of playback to authenticated Spotify accounts. Document your assessment and the standard contractual clauses that cover the transfer.
Gate the iframe behind a consent management platform. Display a placeholder that describes what will load. Only inject the Spotify iframe after the visitor opts in. Categorise the service under media players in your cookie policy. Record the US data transfer and the transfer mechanism in your records of processing activities. Review Spotify data processing terms annually.
There is no official cookieless Spotify embed. Alternatives include linking to the Spotify track instead of embedding, hosting an audio file directly on your server, or using a server side proxy that removes direct visitor to Spotify connections. Any of these avoids the need for prior consent and eliminates the US data transfer.
Add Spotify to your cookie policy listing under the media players or functional cookies category. List the cookies sp_t, sp_landing and sp_dc with their durations and purposes. State that data may be transferred to the United States under standard contractual clauses and the EU US Data Privacy Framework. Note that consent is required before the player loads.