He does, however have no say in the exact data transfer protocol used for the transfer. If Spotify wants to disable an api and shut down production resources, I don't see how a GDPR request can compel them otherwise. As long as they prepare all the data, and allow for the transfer, then they are complying with GDPR. Even if the API at some point existed, it doesn't mean they are required to maintain it.
The other side of this is that Spotify's answers were perhaps too earnest in detailing why. When arguing it is against their ToS, it doesn't really fly with GDPR anymore, because that implies they have everything in place, but they don't want to. They could have just said "we'll compile all the data and facilitate a transfer on your behalf", and the user really wouldn't have the slightest case.
So to sum up, my take is that both are wrong. Spotify in arguing its against their ToS (it doesn't fly). And the emailer arguing that they are entitled to Spotify enabling their api (they aren't).
That being said I am no lawyer and I don't know what I'm talking about.
If people think that GDPR grants consumers the right on which services exist and how data should represented etc, then I think they are misinformed.
Spotify could have answered with "That API is no longer available, but we will facilitate the transfer of an archived version of the data", and... I mean, what clause of GDPR does he have to complain or demand they do anything different?
Another think they can do is just try occasionally, and see if people give up.
I guess the law doesn't say "for free" ? So perhaps they could charge a fee for each API use...
It otherwise seems unreasonable to require data-holders (/"controllers") to pay the costs of this "direct transfer", esp. re building and maintaining an API.
They have in their possession an object which the user owns -- their data -- would we, in analogous cases, require stores to do anything other than "hand it back" ?
This seems quite an odd law.
EDIT: given downvotes, let me clarify: I like the law. It is useful. I just want to understand the moral/legal/economic logic.
This law imposes costs somewhere, and prevents some services being offered.
You can acquire it and store it, but you have to follow some procedures : - do not expose your employees to it - do not leak it in the environment
It then falls to the company to make the cost/benefit analysis : is this chemical important enough to our process to justify these hasles.
The data export also does not need to be a perfect API, dump a huge json and let third party handle changes.
Consider it a cost of collecting the data in the first place.
Eg., consider me uploading some image files for processing and then downloading them. The website keeps those images only insofar as I wish, and never analyses them or derives value from them beyond what I permit -- and suppose the default is to permit nothing.
Then it seems odd. Since this is more like taking my shoes to be repaired. It would be onerous to require repair shops to send them elsehwere.