Cornell had a student who suppressed their directory info through FERPA, which caused a single sign-on problem with a vendor. The vendor hadn't wanted to accept their limited attributes initially, but this is what let them renegotiate.

Seems like libraries could use FERPA initially to make the same argument?

#ERL25

They inform users when a vendor's privacy policy is potentially problematic, via notes in catalog and other places.

"This resource automatically establishes a user account including your name and university email address. Check the publisher's privacy statement for information about how they use this data."

#ERL25