GMP values its relationship with our customers and respects their concerns about privacy. This Policy describes the commitment GMP makes to securely manage the information we collect about our customers in order to provide services to them
Confidential Information Integrity and Security
a. GMP considers customer energy use data and personal identity information confidential information.
b. GMP will create, maintain and update measures to protect customer energy use data and personal identity information from inadvertent disclosure to and/or inadvertent accessibility by unauthorized third parties.
c. GMP will have sufficient controls in place so that customer energy use data is maintained securely within infrastructure owned or controlled by the utility.
d. GMP will take reasonable steps to maintain the accuracy of customer energy use data and personal identity information.
e. GMP will take reasonable steps to protect the identity of individual customers when aggregating customer energy use data.
f. GMP will keep customer information only for the time needed to complete business process, unless legal or regulatory mandates require different retention.
Customer Choice and Consent
a. Where appropriate, customers will be provided the option of directing GMP on the use of collected personal information.
b. GMP will clearly identify where customers have a choice to share data and provide a simple and easily accessible way for consumers to exercise their choice.
- Customer Access and Participation
a. GMP understands that customers may wish to access information about themselves held by GMP. GMP will take measures to provide this information to the customer in a timely and economical fashion.
b. GMP will provide a simple and clear process for the customer to contest and resolve data accuracy and completeness issues. The process will be easily accessible to customers and provide timely review, investigation, resolution, remedy and documentation of the issue.
c. GMP will provide a secure method of user authentication for online access to personally identifiable information.
- Disclosure to Third Parties
a. Customer personal identity information and personal energy use data shall not be sold, given, or in any fashion conveyed to third persons for any commercial purpose whatsoever without the written, express consent of the customer, except to the extent that such disclosures may be required by law.
b. From time to time GMP employs consultants who may need (in the course of performing their duties for GMP) to review customer-specific data. GMP will take reasonable steps to ensure that all such consultants maintain the confidentiality of such data.
- Disclosure of Customer Data to Statewide Energy-Efficiency Utility
a. Like other Vermont utilities, GMP is required to share the following information with Vermont's statewide energy efficiency utility, Vermont Energy Investment Corporation (VEIC) www.veic.org:
i. Customer-specific information (e.g. customer's address, phone number and utility account number)
ii. Usage data (customer's historic electric demand characteristics)
iii. Measure data (efficiency measures already provided to the customer by the local utility)
b. VEIC entered into an Order of Appointment with the Vermont Public Service Board to carry out the duties of an energy efficiency utility on December 20, 2010. In the Process and Administration of an Energy Efficiency Utility Order of Appointment of that same date, VEIC is required to keep all customer information confidential through the use of a Confidential Information Management System.
- Notice of Policy and Practices
a. GMP will provide adequate notice of its information practices before any personal information is collected from customers. These practices include but are not limited to:
i. GMP will identify itself as the data collecting entity. When GMP is not the entity, it will identify the entity and describe its relation to GMP;
ii. identify the uses to which the information will be put;
iii. identify any potential recipients of the information;
iv. the nature of the information collected and the means by which it is collected if it is not obvious;
v. whether the provision of the requested information is voluntary or required, and the consequences of refusal to provide the requested information;
b. GMP will share this policy and related policies with third party vendors where appropriate to ensure protection of personal identity information and energy use data.
d. GMP will update this policy as necessary and will provide notification to customers when changes are made.
- Company Self-Enforcement
a. GMP will regularly review its information practices for process improvement opportunities and compliance. When necessary GMP will take action in alignment with legal mandates and company policy.
b. GMP will review this policy every six months.