The Energy Data Analysis Program (EDAP) was developed by the California Energy Commission (CEC) to support governmental entities in meeting state-mandated energy planning and reporting requirements. An action plan will be required to describe why the data is needed, what particular data set is needed, and how the data will further their energy planning goals.
What is EDAP?
The Energy Data Analysis Program (EDAP) is a California Energy Commission (CEC) initiative that facilitates secure analysis of confidential and other energy data housed by the CEC while maintaining confidentiality. Through EDAP, approved data analytics firms and similar organizations (referred to as Agents) may contract with participating entities to access and analyze this data on their behalf.
All results shared with participants must be anonymized, with limited exceptions, as approved by the CEC, ensuring that sensitive information remains protected.
Who is EDAP for?
EDAP supports local governments and other eligible entities that need detailed analysis of energy data to inform planning, policy development, or program design.
Because many entities face challenges accessing detailed energy data, EDAP offers a secure, compliant pathway for them to obtain analyses performed by CEC-approved Agents.
Eligible entities may include, on a nonexclusive basis:
- Municipal governments
- County governments
- Community Choice Aggregators (CCAs)
- Regional Energy Networks (RENs)
- Eligible tribal entities
- Joint powers authorities (JPAs)
- Other public entities authorized under EDAP
These groups often face challenges obtaining sufficiently detailed energy information. EDAP provides a secure and compliant structure for them to obtain vetted analysis performed by approved Agents.
What is the value of EDAP?
For Local Governments and Eligible Entities
EDAP enables participants to:
- Obtain analytical insights from an approved Agent’s analysis of confidential and other CEC-held energy data.
- Select their own contractor and define their own scope of work, provided the contractor is or becomes an Agent and the proposed work meets CEC requirements for protecting confidentiality.
For Approved Agents
EDAP offers a framework for qualified data analytics firms and similar organizations to:
- Contract with local governments and other eligible entities to conduct authorized analysis of confidential energy data for participating entities, under strict confidentiality rules.
- Provide anonymized analytical results that support local decision-making.
An EDAP Agent is a data analytics firm or similar organization appointed by the CEC to act as its nonexclusive agent for accessing and analyzing confidential and other energy data, such as interval meter data.
Agents operate under a formal Agency Agreement, which strictly defines their authority, responsibilities, and data-handling requirements.
Agents are not CEC contractors. Instead, local governments or other eligible entities contract them as authorized intermediaries capable of securely handling confidential information under stringent privacy, security, and operational standards.
Role of an EDAP Agent
Authorized Access to Confidential Energy Data
Agents are formally appointed by the CEC to access interval meter data and other protected information solely to perform analysis for participating entities.
Performing Data Analysis
Agents analyze confidential and non-confidential energy data according to the Action Plan submitted by the participating entity.
Agents may only perform activities within the scope of the approved plan.
Protecting Confidentiality and Anonymizing Results
Agents must:
- Comply with the Special Terms and Conditions for Confidential and Personal Information (Exhibit A).
- Ensure that all staff with data access sign and comply with the Nondisclosure Agreement (Exhibit B).
- Share only anonymized results with participating entities, as defined and approved in the project’s Action Plan, unless the CEC has approved sharing confidential results with an entity that already has legal authority to receive the confidential information.
Meeting Annual Vetting and Attestation Requirements
Agents must meet the CEC’s Agency Vetting Criteria and must re-attest every year.
Security and Reporting Obligations
Agents are required to:
- Maintain an Information Security Program Plan (ISPP) that meets state security standards.
- Encrypt all confidential information in transit and at rest.
- Report any potential or confirmed security incident to the CEC within 48 hours.
- Ensure staff receive annual security awareness training.
- Cooperate with any CEC audits or reviews.
- Agents may not bind the CEC and must not use CEC data beyond the approved scope of work.
Review of the Agency Vetting Criteria
Prospective Agents must first review the CEC’s Agency Vetting Criteria, which outline the organizational, technical, and security standards required to handle confidential CEC-held data.
These criteria include demonstrating the ability to securely manage interval meter data and comply with all confidentiality and data protection requirements. Applications must demonstrate that the applicant meets all vetting criteria.
Prepare Required Security and Data Protection Materials
Applicants must have a robust Information Security Program Plan (ISPP) that meets California administrative and privacy standards, including:
- Data encryption (in transit and at rest)
- 48-hour security incident reporting
- Annual security awareness training for all personnel with access to data
- Strict access controls and signed nondisclosure agreements
Submit an Application to the CEC
Applicants submit their materials through the EDAP application form.
Applications typically include:
- Documentation showing compliance with the Agency Vetting Criteria
- Security architecture or ISPP materials
- Descriptions of organizational and technical capabilities
- Contact information for operational, security, and legal personnel
Complete the Agency Agreement
Once the CEC verifies that an applicant meets the vetting criteria and security requirements, the applicant completes the Agency Agreement, which formally appoints the applicant as a nonexclusive Agent authorized to access CEC-held confidential data.
The Agreement outlines:
- Appointment and scope
- Confidentiality and data privacy obligations
- Security and reporting requirements
- Annual attestation commitments
Agent status becomes official once the agreement is fully signed.
Maintain Annual Attestation and Compliance
Approved Agents must:
- Attest annually
- Maintain all required security controls and training
- Comply with all confidentiality requirements in Exhibits A and B
- Cooperate with audits or reviews
Failure to do so may result in suspension or termination of Agent status.
Appear on the List of Approved Agents
Approved Agents will be listed publicly on the EDAP website, allowing local governments to confirm an Agent’s approved status before preparing their Action Plan.
Action Plans are required for any EDAP project. Local governments and eligible entities must submit an Action Plan before an Agent may access CEC-held confidential data.
Required Components of an Action Plan
- Project background and purpose
- Specific data needed, including justification for each data element
- Proposed analytical methods the Agent will use
- Expected results, including how confidentiality will be maintained and how outputs will be anonymized
Submitting an Action Plan
CEC staff review Action Plans to ensure:
- Only the minimum necessary data is being requested
- Methods comply with confidentiality and data handling requirements
- The request aligns with the participating entity’s stated goals
The CEC may approve the plan, request revisions, or reject it.
If revisions are requested, the local government and Agent must update the plan and resubmit it.
General Inquiries
- What is the Energy Data Analysis Program (EDAP)?
EDAP is a California Energy Commission initiative that enables local governments and other eligible entities to obtain secure, CEC-authorized analytical insights performed by approved data analytics firms and similar organizations (Agents). All results provided through EDAP must be anonymized, with limited exceptions, as approved by the CEC in the project’s Action Plan. - Who can participate in EDAP?
Participation is open to local governments and other eligible public entities, including but not limited to municipalities, counties, CCAs, RENs, JPAs, and eligible tribal entities. - Does EDAP give participating entities direct access to CEC-held energy data?
No. Participating entities do not receive direct access to confidential CEC-held data. Analyses are performed only by approved Agents operating under strict confidentiality requirements defined in the Agency Agreement. - Does the CEC perform analysis for EDAP participants?
No. The CEC does not conduct analyses for EDAP projects. Approved Agents perform all analytical work. The CEC vets Agents and reviews Action Plans and methodology reports for compliance with confidentiality requirements. - What do Agents gain by participating in EDAP?
Approved Agents are able to contract with local governments and eligible entities pursuing well-developed energy projects, giving them opportunities to apply their analytical expertise within a CEC-authorized framework.
Agent Questions
- How does an organization become an EDAP Agent?
Applicants must meet the CEC’s Agency Vetting Criteria, submit required security documentation, and complete the Agency Agreement. Once approved, the applicant is listed publicly as an EDAP Agent. - Does the CEC certify the quality of an Agent’s analysis?
No. The CEC does not endorse, certify, or recommend any Agent’s services. The CEC reviews Action Plans and methodology reports only to assess compliance with confidentiality requirements. - Are there fees associated with becoming an EDAP Agent?
No fees are charged by the CEC to become an EDAP Agent. Applicants are responsible for meeting all vetting, security, and compliance requirements. - Can Agents use the CEC logo or seal in marketing materials?
No. Use of the CEC seal or logo is prohibited without permission. EDAP participation may not be represented as CEC endorsement or approval of any product or service.
Local Government and Eligible Entity Questions
- What is an Action Plan?
An Action Plan outlines the project goals, data needs, analytical methods, and expected results for an EDAP project. It is required before an Agent may receive confidential data from the CEC. - How do I submit an Action Plan?
Action Plans are submitted through the EDAP intake form, available at the link provided on the EDAP website. The CEC reviews the plan for compliance with confidentiality and program requirements. - How long does Action Plan review take?
Review timelines may vary depending on project complexity and revisions needed. The CEC may approve the plan, request revisions, or reject it. - Can EDAP provide confidential results to a local government?
EDAP allows for release of confidential results in limited circumstances where the receiving entity already has legal authority to receive the confidential information. EDAP does not create any new authority for an entity to receive confidential information, and all information releases, anonymized or confidential, must be approved by the CEC as described in the project’s Action Plan.
Security or Compliance Questions
- What security requirements apply to EDAP Agents?
Agents must maintain an Information Security Program Plan (ISPP), encrypt all confidential data, complete annual training, and report any security incidents to the CEC within 48 hours. - Does the CEC audit or review Agents?
Yes. The CEC may conduct audits or request documentation to ensure ongoing compliance with confidentiality and security requirements. - Who do I contact for questions about EDAP?
Email the EDAP team at edap@energy.ca.gov.