News Stories
Sponsored by Earth Etch. Regulatory insight and compliance solutions for today’s energy markets.
PSC Staff Issues Preliminary Data Access Framework Proposal
On September 4, 2026 New York PSC Staff filed a preliminary proposal regarding potential modifications to the Commission’s Data Access Framework.
Note that Staff’s proposal is not yet final; Staff plans to gather stakeholder comments and hold a technical conference on implementation, costs, technical limitations, and alternatives before issuing a more comprehensive proposal for public comment and New York PSC action.
Among other things, Staff’s initial proposal recommends eliminating the Data Ready Certification (DRC) process and Data Access Matrix. Staff contends that the DRC may be too costly and complex.
As an alternative, Staff recommends strengthening the existing Data Security Agreement (DSA) and Security Agreement (SA) with consistent statewide requirements, including access reviews, multi-factor authentication, endpoint protection, encryption, background checks, and timely access revocation.
Staff also recommends limiting utility-specific discretion and preventing utilities from adding cybersecurity requirements beyond PSC approved standards. The proposal would use a risk-based, ongoing cybersecurity approach, allowing utilities to temporarily suspend data transfers when there is a material security risk while providing ESEs due-process protections and an opportunity to restore access after resolving the issue.
In terms of data availability and governance, Staff proposes a DAF Committee of utility and Staff representatives, supported by an Advisory Working Group of ESEs and other stakeholders should develop a statewide data dictionary and common use cases.
Staff also recommends stronger customer consent and education requirements, including clear explanations of what data is shared, why it is needed, how long and how often it will be accessed, whether it may be shared, and how customers can revoke consent, along with authorization confirmations, annual reminders, and account-based tools to manage authorizations where practicable.
New York proceeding to monitor the “business-to-business” process taking place between the joint utilities and eligible ESCOs in New York related to the utilities’ new requirement for suppliers and their agents/vendors to sign Data Security Agreements (DSA) and Vendor Risk Assessments (VRA) related to cybersecurity risk management.

