This document proposes a formal privacy model and approach for privacy-preserving composition of Data as a Service (DaaS). Existing privacy models do not adequately address the new privacy concerns raised by DaaS. The proposed model defines privacy policies and requirements that can be verified for compatibility during DaaS composition. If services are incompatible, a negotiation mechanism is introduced to dynamically reconcile privacy capabilities so the composition is possible. The proposal is validated through a prototype implementation and experiments.