Privacy Policy
1. Privacy Notice
The Philadelphia Energy Authority (PEA) respects the privacy of its communities, partners, staff, and stakeholders. Protected personally identifiable information (PII) will not be disclosed as part of public messaging nor promotion. Neither shall protected PII be disclosed as part of a Right-to-Know Law request, pursuant to privacy exceptions afforded by the law. Data and personal information provided to PEA may be subject to disclosure in the event of subpoenas, warrants, legal orders, or law enforcement requests for data.
2. How Your Data is Used
The PEA website automatically collects certain technical and usage information when visitors browse the site. This may include information such as IP address, browser and device type, approximate geographic location, pages viewed, and information about how visitors interact with the website. The website uses cookies and similar technologies, including cookies associated with analytics and website functionality, to operate and improve the website and understand how visitors use it.
In addition to the automatically collected data described above, the PEA website may solicit the following personal information through its contact request forms:
i. Name, Email Address, Organization, Program/Public Bid of Interest, Phone Number
Provided information will be utilized for its intended use and follow-up on the contact request. PEA will not sell provided information for marketing purposes nor use it for machine learning or the training of AI models. If you believe that your data or Personally Identifiable Information has been improperly used or obtained by an unauthorized party, please contact PEA at info@philaenergy.org with the approximate date and a description of the suspected breach.
3. Security Controls
The PEA website provides security measures including network-level protections, a proprietary firewall, malicious traffic and bot blocking, automated security updates, vulnerability monitoring, data encryption in transit and at rest, regular website backups, as well as server-side security software. Additional security measures may be implemented as deemed necessary to safeguard data that is collected, managed, or retained by PEA.
Website and data hosting protocols utilize firewalls that identify and block malicious traffic and bots. Security protocols also prevent sensitive data from being publicly accessible, encrypting data at rest and in transit, and maintains a certified security environment.
4. External Link Disclaimer
PEA may utilize social media or other third-party websites to engage the broader community and keep residents informed on pertinent events or updates. Please be aware that PEA does not retain control over the security protocols of third-party sites nor any personal data collected via external sites.
Information and personal data provided or collected on third party platforms are not subject to the same protections and assurances herein provided. Any PII passively collected (i.e., not solicited) by the third-party website will not be transmitted or stored by PEA. Please use personal discretion when providing sensitive information either directly (e.g. via email) or through third-party sources.
5. Transparency in Government
To ensure transparency in government, the Pennsylvania Right-to-Know Law (RTKL) affords individuals the right to request certain information from government and quasi-governmental agencies. Certain PII is excluded from disclosure in this fashion and will not be shared in the event of a Right-to-Know request (see §6. Personally Identifiable Information). PEA maintains operational protocols to ensure both compliance with the RTKL as well as ensuring that protected and exempt personal data is safeguarded.
Per the Pennsylvania Right-to-Know Law, documents, electronic files, or other records created, received, or retained in connection with the Authority's official business is considered a public record except where exempt by law, e.g. personally identifiable information.
Records are retained for no less than three years per Federal and State record retention requirements.
6. Personally Identifiable Information (PII)
PEA takes reasonable steps, consistent with cyber security and internal control best practices, to ensure that PII is safeguarded. Sensitive information is requested only as necessary and through secure channels whenever possible.
While PEA documentation is subject to public records regulations, certain PII is exempt from general inquiry under the Right-to-Know Law. The following PII is exempt from Right-to-Know requests:
- Social Security numbers (in whole or in part)
- Driver’s license numbers
- Personal financial information
- Home, cellular or personal telephone numbers
- Personal e-mail addresses
- Employee number or other confidential personal identification number
Certain information may be subject to review and limited disclosure in certain instances, e.g. audit or legal proceedings. No PII will be disclosed or transferred to any other third-party entity outside the PEA, unless requested for and required by stated project implementation, audit or law enforcement purposes, or as required by statute.




