Opening the Black Box: Using Public Records to Analyze Privacy in Library Vendor Contracts

Document Type

Poster

Conference Title

Charleston Conference

Location

Charleston, SC

Conference Dates

November 2-6, 2026

Date of Presentation

11-5-2026

Abstract

Academic libraries are running on data, yet the contracts governing the usage of that data remain locked in a black box. Proprietary secrecy and non-disclosure baselines prevent institutions from auditing what vendors actually do with patron information - and block libraries from effectively benchmarking their contracts against industry standards.

We decided to crack the box open. After conducting a rigorous content analysis of 50 public higher education license agreements gathered via systematic open records requests, this session moves past policy theory to expose real-world contract patterns. We map out distinct structural trends across critical privacy variables, including data privacy addendums, selling/sharing user data, data retention lifecycles, downstream subprocessor sharing boundaries, and security breach notification windows.

Furthermore, we examine the systemic negotiation gap between standalone institutional agreements and aggregated consortial leverage, illustrating how larger systems successfully deploy state addenda to claw back user protections. Attendees will gain a transparent view of the current licensing landscape, a behind-the-scenes look at the logistics of a large FOIA public records campaign, and an actionable roadmap for striking invasive vendor boilerplate language.

Learning objectives

  • Spot high-risk contract language—including broad third-party data sharing, vague “usage data” definitions, and missing or unclear data retention terms.
  • Recognize how NDAs and confidentiality clauses limit transparency and reduce libraries’ collective negotiating power.
  • Understand how governance structures shape outcomes, with stronger privacy protections often emerging from consortial or state-level agreements.
  • Apply practical negotiation strategies, such as adding purpose limits on data use, requiring retention/deletion timelines, restricting downstream data sharing, and pushing back on unnecessary confidentiality clauses.

Share

COinS