SPOTIFY USA INC.
ent_019ed7ef33935a3d4c6be3cd57e6bde1
Disclosures
2
State AG · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SPOTIFY USA INC.
- Normalized
- spotify usa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 2138008WM218QBKRII94
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- spotify.com
- Corporate parent
- SPOTIFY TECHNOLOGY S.A.— per GLEIF relationship records
Disclosure history (2)newest first
- California State AGas victim2020-12-09
Spotify USA Inc. disclosed that a system vulnerability inadvertently exposed account registration information (email, password, display name, gender, date of birth) to certain business partners. The vulnerability existed from April 9, 2020, until discovery on November 12, 2020. Spotify contained the incident, reset passwords, and confirmed deletion of data by partners. No unauthorized use was detected.
- Illinois State AGas victim2020-01-01
SPOTIFY USA INC filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-517). The register records the breach as discovered on November 12, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.