Author: Rebecca Mattson, Director of Operations and Scholarship, Montague Law Library, Penn State Dickinson Law
Librarians have always been concerned with protecting patron privacy. It is a tenet of librarianship and part of the American Library Association’s Library Bill of Rights. As libraries have moved away from print resources in favor of electronic, it’s important to continue to keep patron data private and negotiate contracts with vendors that protect this information.
When a patron uses a library material or service, they should be protected so that their research remains confidential. Intellectual Freedom includes not only the right to receive information, but also the right to seek information without being scrutinized or tracked.
ALA’s Library Bill of Rights states that all people “possess a right to privacy and confidentiality in their library use” and that “libraries should advocate for, educate about, and protect people’s privacy, safeguarding all library use data, including personally identifiable information” (PII). PII is data that can be used to identify a person; this includes physical characteristics as well as sensitive information like a social security number. It also includes usernames or other account-identifying information. Confidentiality means that a library keeps a person’s PII private. Privacy means that a person can seek information without fear of judgment (ALA Privacy Interpretation). ALA’s Privacy Interpretation webpage states that patron PII should never be shared with vendors absent explicit permission or legal requirement. The Privacy Interpretation web page also states that vendor agreements should disallow the vendor from selling or distributing any collected data without the library’s permission.
There are several resources available for librarians who negotiate with vendors or who advise those who do.
AALL’s Principles & Practices for Licensing Electronic Resources, most recently approved in 2018, contains a section on usage tracking and privacy. It suggests that agreements require that information related to research activities connected to individual users remains confidential. Suggestions here include:
- Detailing the type of data collected for usage statistics and how it is accessed
- Disclosure of any routine collection of data by either party, respecting laws and policies regarding confidentiality and privacy
- Prohibiting collection of user-specific usage information
The ALA also has published an advocacy guide called Vendors and Privacy, available for free on the ALA website. This guide includes tips for librarians who negotiate vendor agreements and tips for librarians who can discuss privacy concerns with decisionmakers during acquisition.
The National Information Standards Organization (NISO) published Consensus Principles on User’s Digital Privacy in Library, Publisher, and Software-Provider Systems in 2015. The Privacy Principles provide guidance for best practices for librarians, vendors, and publishers. Some examples include transparency in data collection and privacy policies, secured data, anonymization of data, opt-out provisions and informed consent, and accountability.
The Association of Research Libraries (ARL) published an e-resource licensing guide in 2024. It contains a chapter on patron data privacy. The chapter provides an overview of the EU’s General Data Protection Regulation (GDPR) and US Law. The US does not have a comprehensive privacy law; it is largely left to the states. The chapter also offers model language to negotiate into your contracts.
SPARC also has modules on privacy, which include videos, podcasts, and readings about privacy in vendor contracts. This includes a checklist of questions to ask about vendor privacy policies.
The rapid adoption of AI technologies increases the need to be vigilant about patron privacy. EveryLibrary Institute recently released a report titled Library Patron Privacy in the Age of Artificial Intelligence. Many law library research platforms now include AI-enhanced research capabilities, and many institutions also rely on the library to provide access to non-research-based AI tools. This report details the privacy laws in all 50 states plus the District of Columbia and examines the implications of these laws on libraries.
The above resources are just a few starting points for librarians who are interested in learning more about patron privacy in licensing agreements. As AI and other emerging technologies continue to reshape how patrons interact with library services, the necessity for protecting user data will grow. By staying informed and advocating for strong privacy protections, librarians can continue to play a role in protecting intellectual freedom.

Leave a Reply