For instance, just making it a rule that they are not allowed to lie to you about how things are being used -- we know that won't work because if they're willing to lie they are also willing to ignore contract violations.
Instead, put in a rule that says misuse of the system costs $X for each documented case. Now the vendor has a financial incentive to detect misuse, and the purchasers have a FINANCIAL incentive to curb misuse by their own employees.
It's not a magic fix, but it's the sort of thing that might help.
Make a neutral third party liable for the cost and then that third party which is mostly disinterested gets to calculate risk and compliance procedures.
The only way we're really going to get data handling under control is to give the victims of data abuse financial beneficiaries of liability through the courts and insurance companies.
This all ends in corporate feudalism, doesn't it?