Over the past several years, libraries have been increasingly aware of threats posed to patron data privacy by the abundance of collection, storage, and sharing technologies used by vendor e-resource platforms. Compounding the problem is the vague, opaque, often confusing privacy language in vendor contracts, ranging from complex data processing addenda to linked privacy policies and third-party terms of use. Too often, this language serves to limit or nullify the data privacy protections that libraries try to implement. In response to these concerns, SPARC’s Privacy & Surveillance Contract Language Working Group is developing a range of practical tools to help libraries negotiate agreements that support the needs of users and protect their personal data. These tools include a negotiation guide for librarians focusing on privacy protections; a data privacy addendum with clear expectations for vendors on handling of library patron data (with vendor feedback from the pilot stage); as well as comprehensive reports on the data privacy practices of multinational vendors such as Elsevier and Springer. This session will give an overview of the group’s work in this area, with time for a robust Q&A about data privacy and surveillance in digital libraries.