Regulatory Watch  /  Sweden  /  Fine
Moderate impactFineIn effect

Swedish Data Protection Authority fines Spotify €5 million for GDPR access violations

The Swedish Data Protection Authority (IMY) imposed a fine of 58 million Swedish crowns (≈ €5 million) on Spotify for not fully complying with users' right of access under the GDPR. The authority ordered Spotify to provide the complete set of personal data and related information under Article 58(2)(c) GDPR. The case followed a complaint by noyb and litigation against the IMY for delayed decision‑making.

Why it matters: The fine underscores enforcement of GDPR data‑access rights for major digital platforms.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Spotify fined € 5 Million for GDPR violation
noyb · primary source · Jun 13, 2023
Spotify fined € 5 Million for GDPR violation
noyb · Jun 13, 2023
Details
JurisdictionSweden
RegulatorSwedish Data Protection Authority (IMY)
LawGeneral Data Protection Regulation
StatusIn effect
PublishedJune 13, 2023
Effectivenot stated
Penalty58 Mln Swedish Crown (about € 5 Million)
OrganisationsSpotify
Topicsaccess, transparency
Datapersonal