E-1Application
5 passages
7.4.3.1 DSM PLAN DEVELOPMENT & REPORTING - DSM Plan development and reporting activities are an essential function of E1's Regulatory Affairs Team. - Through its Enabling Strategies, Regulatory Affairs manages all demand side management re...
AI summary The document outlines the development and reporting activities related to the DSM Plan by E1's Regulatory Affairs Team, including the creation of the 2026-2028 DSM Resource Plan, collaboration with NS Power and stakeholders, and submission of various reports and studies to the NSUARB.
9. REPORTING - E1 proposes to report on the implementation of the Settlement Plan through Quarterly Reports and Annual - Progress Reports (APR).
AI summary E1 proposes to report on the implementation of the Settlement Plan using Quarterly Reports and Annual Progress Reports (APR).
1. The Parties agree that for the purpose of this Agreement "Confidential Information" means all information, regardless of the form in which it is communicated or maintained and prepared by the Disclosing Party, and is disclosed directly...
AI summary The document defines 'Confidential Information' as any information disclosed by the Disclosing Party to the Recipient, including reports, analyses, contracts, and other sensitive data, which may be filed with the Nova Scotia Utility and Review Board in confidence. It includes explanations and access details provided by either party and marked as confidential.
Permitted Disclosures - 6. The Recipient shall be permitted to disclose relevant aspects of the Confidential Information to its employees and professional advisors to the extent that such disclosure is reasonably necessary for the performa...
AI summary This section outlines the permitted disclosures of confidential information by the Recipient to its employees and professional advisors, requiring them to sign a confidentiality undertaking. It also allows disclosure under legal obligations or court orders, with prior notice to the Disclosing Party and steps to protect commercially sensitive information.
SHARING OF DATA AND INFORMATION 20 24. - EfficiencyOne shall work co-operatively with NSPI to provide NSPI with information and data from time to time in order to assist NSPI with planning and load forecasting as may be reasonably required...
AI summary EfficiencyOne is required to share data and information with NSPI for planning and load forecasting, consistent with past practices. In case of disputes, NSPI may apply to the UARB for access to the requested information.
E-12E1(NSUARB) RIR-1 to RIR-41
23 passages
s between E1 and NS Power (2023-2025 DSM Plan) E1 Responses to Nova Scotia Utility and Review Board (NSUARB) Information Requests NON-CONFIDENTIAL
AI summary EfficiencyOne (E1) provided responses to Nova Scotia Utility and Review Board (NSUARB) information requests regarding the 2023-2025 Demand Side Management (DSM) Plan with Nova Scotia Power. The proceeding involves regulatory processes related to information disclosure and DSM planning.
een E1 and NS Power (2023-2025 DSM Plan) E1 Responses to Nova Scotia Utility and Review Board (NSUARB) Information Requests NON-CONFIDENTIAL
AI summary E1 is responding to information requests from the Nova Scotia Utility and Review Board (NSUARB) regarding the 2023-2025 Demand Side Management (DSM) Plan. The document is part of a regulatory proceeding and contains non-confidential responses.
Remediation Summary The following table outlines the status of each observation and PIO, organized by risk level as noted in our follow-up review. Please refer to Appendix A for the risk classification level criteria used for each observat...
AI summary The document provides a remediation summary outlining the status of various observations and PIOs, organized by risk level. Several high and moderate risk items have been remediated, with some requiring additional actions or resulting in new PIOs.
Moderate Partially remediated 3.6 Segregation of duties for website developers Moderate Remediated + new PIO 3.7 Compliance monitoring for agents Low Remediated + new PIO 3.8 Security of service account credentials with access to the corpo...
AI summary The document outlines various risk ratings and remediation statuses for different process improvement opportunities, focusing on segregation of duties, compliance monitoring, security of credentials, and redaction of personal information. Some issues are partially remediated, while others remain unremediated.
ology system management and protection PIO Remediated PIO-3 Alignment to upcoming privacy breach notification requirements PIO Remediated PIO-4 No consent withdrawal procedure PIO Not remediated PIO-5 Use of multiple ticketing systems with...
AI summary The document outlines various privacy information officer (PIO) issues, including alignment with privacy breach notification requirements, lack of consent withdrawal procedures, use of multiple ticketing systems, unapproved software, outdated documentation, and insufficient safeguards in the privacy policy.
diately manner where access upon termination of was terminated two personnel. business days after departure. Management agrees with the new moderate gap and recommendations identified by KPMG. Moving forward EfficiencyOne will be conductin...
AI summary Management agrees with KPMG's recommendations regarding account and access control reviews, which will be conducted quarterly starting in Q2, 2022. The document also references the termination of access two business days after personnel departure.
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe 3.4 Information security EfficiencyOne operates using a mix of formal and R...
AI summary EfficiencyOne's information security policies are a mix of formal and informal IT policies, which include a well-defined privacy policy but do not cover all domains of information security and are not consistently applied across the IT environment. The residual risk is medium, and recommendations include obtaining annual acknowledgments for the Privacy Policy.
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe 3.6 Segregation of While EfficiencyOne controls the flow of changes to Reme...
AI summary The review identified a medium risk issue regarding the lack of segregation of duties and monitoring for developers with access to both production and non-production environments at EfficiencyOne. The finding was remediated, but recommendations include establishing a monthly change review as part of continual improvement efforts.
EfficiencyOne's websites and ensure that they followed the change management process. Management acknowledges KPMG's new PIO. EfficiencyOne is currently refining its existing change and approval process to include a retroactive review Mana...
AI summary EfficiencyOne is refining its change and approval process to include a retroactive review of website change evidence relative to what had been approved, following KPMG's new PIO appointment.
surance of or monitor the their understanding and EfficiencyOne should compliance of agents against these agreed-to commitment to consider promoting contractual requirements for the handling and compliance with privacy best practices to se...
AI summary The text discusses the need for EfficiencyOne to ensure compliance of agents with contractual requirements related to the handling and security of personal information (PI), including adherence to PIPEDA. It notes that some agent websites, such as those related to energy assessments, did not include privacy best practices or proper redirections.
ed, including but not limited to, having a clear privacy policy, using website certificates, not using customer information for undisclosed use-cases. © 2022 KPMG LLP, an Ontario limited liability partnership and a member firm of the KPMG...
AI summary The text outlines requirements for privacy practices, including having a clear privacy policy, using website certificates, and not using customer information for undisclosed purposes. It also includes a copyright notice from KPMG LLP.
rporate data warehouse with access to PI corporate data through an embedded Excel macro. warehouse Management response N/A Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk lev...
AI summary This chunk discusses a finding related to the redaction of social insurance numbers in EfficiencyOne's corporate data warehouse. The concern is that the current method does not fully render the numbers irrecoverable, although physical security safeguards are in place for paper forms.
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe PIO-1 Potential for While we have not identified a specific instance Not re...
AI summary The review identifies a potential risk that EfficiencyOne may retain personal information (PI) longer than necessary, particularly if a data subject withdraws consent. There is no formal records retention and destruction schedule in place, and recommendations include establishing such a schedule and consulting with Nova Scotia Power.
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe PIO-2 Lack of coordination During the course of our fieldwork, we noted tha...
AI summary The review identified a lack of coordination between the IT and Marketing departments at EfficiencyOne, leading to fragmented operations and control processes. The issue has been remediated, and no further action is recommended.
rol processes exists between the two. EfficiencyOne should consider implementing a more holistic structure that provides management with a single view of their IT environment and footprint, including maintaining regular communications on p...
AI summary The document suggests that EfficiencyOne should implement a more holistic IT management structure to provide a unified view of their IT environment and maintain regular communication on changes and security requirements.
Detailed follow-up review findings Residual Suggested ID # Original finding Original Finding Description Status Remaining gaps Recommendations risk level timeframe PIO-4 No consent EfficiencyOne does not have a defined procedure Not remedi...
AI summary EfficiencyOne lacks a defined procedure for handling consent withdrawal requests, despite no known instances of such requests. The recommendation is for EfficiencyOne to seek a formal legal opinion to justify declining requests to delete personal information.
ne should consider centralizing all ticketing systems and ensure sufficient visibility of all changes occurring across its IT environment. Management response N/A © 2022 KPMG LLP, an Ontario limited liability partnership and a member firm...
AI summary The text suggests centralizing all ticketing systems and ensuring visibility of changes across the IT environment, though no specific response from management is provided. The document is filed with the Nova Scotia Utility and Review Board.
restrictions placed on installing unauthorized software such as the TOR browser. Management response N/A © 2022 KPMG LLP, an Ontario limited liability partnership and a member firm of the KPMG global organization of independent member firm...
AI summary The text discusses restrictions on the installation of unauthorized software, such as the TOR browser, and includes a management response of 'N/A'. The document is filed with the Nova Scotia Utility and Review Board and is part of a larger document by KPMG LLP.
through a configuration management database (CMDB). EfficiencyOne should consider implementing a CMDB to track assets, their configurations and their interrelationships, and maintain up-to-date technical documentation to assist with both I...
AI summary The text suggests implementing a configuration management database (CMDB) to track assets, configurations, and interrelationships, as well as maintain up-to-date technical documentation for IT operations and security incident response. There is no management response provided.
nauthorized access, disclosure, use, or modification." which does not describe in general terms what safeguards will be applied (GAPP 8.1.1). EfficiencyOne should consider updating this information to describe in general terms the safeguar...
AI summary The text highlights a concern regarding the lack of detailed safeguards and policy framework described in EfficiencyOne's information protection practices, as per GAPP 8.1.1. It suggests that EfficiencyOne should update its information to better describe the measures in place to protect personal information.
, 2022 NSUARB IR-17, Attachment 3, Page 33 of 343 D.P.U. 21-120 through D.P.U. 21-129 Page 20 First, as noted above, in a Three-Year Plan filing (or any regulatory filing), it is imperative that the filing contain all required information,...
AI summary The text discusses issues with the submission of Three-Year Plan filings, highlighting missing information, incomplete testimony, and failure to follow directives from the Department. Multiple rounds of discovery were required to obtain necessary data, and service territory-specific information was not adequately provided.
ng of beneficial data/information and the minimization of administrative costs. D.P.U. 20-150-A at 12 n.9. The Department further directed the Program Administrators to include testimony in the Three-Year Plan filings describing a formal,...
AI summary The Department of Public Utilities (DPU) directed Program Administrators to provide a formal process for handling Council data requests, but they submitted a draft proposal that had not been reviewed by the Council. The formal proposal was submitted over five weeks after the close of the record and only eleven days before the Department was required to issue an Order, preventing adequate review.
to disclose personal information about customers including name, address, and usage data, without the customers’ permission. See New 155 General Laws c. 164, App. § 2-3(c) provides: No person shall disclose the name of a customer or the co...
AI summary The document discusses the requirement for Program Administrators to obtain affirmative customer consent before disclosing personal information, such as name, address, and usage data, from energy audit reports. This is mandated by General Laws c. 164, App. § 2-3(c), which limits disclosure to specific entities unless the customer waives confidentiality.
E-12-(i)NSUARB IR-17 Attachment 2_ACEEE’s Entire State Database - Excel
11 passages
ome Programs with WAP Services Level of coordination is unclear from publicly available data. Last updated: June 2017 ","Alabama does not have self-direct or opt-out provisions for large customers. Last updated: July 2017 ","Alabama Power...
AI summary Alabama Power and Alabama Gas use Rate RSE for cost recovery, allowing revenue adjustments based on return calculations. The Alabama Public Service Commission (APSC) concluded that existing IRP programs and rate structures meet federal energy efficiency requirements, avoiding new policies. No third-party access policies exist for customer energy data.
state has one research center focused on energy efficiency. ","Financial Incentive information for Alaska is provided by the Database of State Incentives for Renewables and Efficiency (DSIRE Alaska). Last Updated: July 2017 ","We were unab...
AI summary The text references Alaska's energy efficiency policies, including Senate Bill 220 requiring public building retrofits and ASHRAE compliance, DSIRE's role in providing financial incentives, and a statute mandating utility data disclosure for residential buildings. It also notes gaps in equity metrics and workforce development in energy plans.
13) allocates incentive earnings among four major categories: Energy Efficiency Resource Savings; Ex Ante Review Process Performance; Codes and Standards Advocacy Programs; and Non-Resource Program: Incentives for energy efficiency resourc...
AI summary The text outlines the allocation of incentive earnings across four categories, including caps on energy efficiency incentives and management fees for utility involvement in codes and standards programs. It also discusses the ESPI mechanism and the Commission's approval of third-party access to energy data through the EDRP and Energy Data Access Committee.
ities, after informing the Commission, to provide energy data to state and federal government entities that need data to fulfill statutory obligations and request such data pursuant to this decision. Pursuant to California’s landmark legis...
AI summary This text outlines California's energy data availability requirements under AB802, which mandates utilities to provide energy consumption data to building owners upon request. Utilities must respond within four weeks and maintain data portals and catalogs, with updates filed quarterly. The CPUC oversees the process, ensuring compliance with confidentiality agreements.
Report: Supplement 2; Evaluation, page 1). More information on large customer self-direct programs can be found in the ACEEE report, Follow the Leaders: Improving Large Customer Self-Direct Programs. Last reviewed: July 2019 ","Idaho Power...
AI summary The document discusses Idaho Power's Fixed-Cost Adjustment (FCA) mechanism, which was implemented in 2007 and made permanent in 2013. It also mentions that Idaho does not offer energy efficiency performance incentives to its investor-owned utilities and that customer energy usage data is not released without customer consent.
se utilities are using formula rates that adjust every year based on actual costs and actual sales in the previous years. The formula rate is in effect until December 31, 2022 per 220 ILCS 5/16-108.5. Illinois Public Act 99-0906 was passed...
AI summary The text discusses formula rates in Illinois that adjust annually based on actual costs and sales, with an expiration date of December 31, 2022. It also outlines the Illinois Public Act 99-0906, which introduced shareholder incentives for energy efficiency, effective January 1, 2018. The Commission has established guidelines for third-party access to energy data, referencing multiple dockets and sections of the Illinois Public Utilities Act.
e able to access data through a secure electronic system. Illinois does not require the provision of energy use data in aggregated form to owners of multi-tenant buildings or to public agencies. While not required by statute or Commission...
AI summary Illinois does not mandate the provision of aggregated energy use data to multi-tenant building owners or public agencies, though ComEd provides such data through tools like the Energy Usage Data System. The Commission has adopted a 15/15 Rule for anonymized data release and ordered utilities to consider the Open Data Access Framework. Illinois also allocates significant funding to transportation efficiency and has complete streets legislation.
Utilities but did not come to a consensus on a recommendation for an energy savings goal. Last updated: July 2019 ","There are no self-direct or opt-out provisions available to utilities in Maryland. Last updated: July 2018 ","The Public S...
AI summary The text discusses energy efficiency and data policies in Maryland, including the absence of self-direct or opt-out provisions for utilities, the approval of revenue-per-customer decoupling for certain utilities, and the prohibition on disclosing energy use data without customer consent. It also notes the lack of standardized systems for energy use data access.
U-16302, U-16303, U-16736, U-17281, U-17601). The Commission also approved a performance incentive for SEMCO Gas (U-17362) and Indiana Michigan Power Company (U-17353) for program years 2014 and 2015. PA 295 (2008) contained two provisions...
AI summary The Commission approved performance incentives for several utilities, including SEMCO Gas and Indiana Michigan Power Company, for program years 2014 and 2015. PA 295 (2008) allowed utilities to capitalize energy efficiency program costs and earn performance incentives for exceeding annual energy savings targets. The MPSC updated its administrative rules in 2017 regarding data privacy and accessibility.
os. E008/GR-13-316; G007,G011/GR-10-977; and G004/GR-15-879). In addition, the Minnesota Commission approved full revenue decoupling for one electric utility, Xcel Energy (Docket No. E002/GR-13-868.) Minnesota has had a shared benefit ince...
AI summary Minnesota has implemented a shared benefit incentive program for utilities, with varying thresholds and caps based on energy savings. There is no policy requiring utilities to release individual energy use data, though guidelines exist for third-party access and aggregate data disclosure.
y 7, 2015 in Docket No. E-22, Sub 464) that provides for program cost recovery, up to 36 months of net lost revenues, and a program performance incentive (8% for DSM programs and 13% for EE programs). In the natural gas sector, Piedmont Na...
AI summary The text discusses revenue decoupling mechanisms in the natural gas sector in North Carolina, including provisions for program cost recovery and performance incentives. It also addresses the lack of provisions requiring utilities to release customer data to third parties without consent and the Commission's request for more information on data dissemination.