generated: '2026-07-27' method: searched source: https://www.oeb.ca/ontarios-energy-sector/open-data note: >- Standards conformance for the Ontario Energy Board, asserted from the OEB's own published pages, the Ontario instruments that bind it, and live anonymous probes on 2026-07-27. Each entry carries its evidence. Two things are worth separating up front. As a DATA PUBLISHER the OEB conforms to Ontario's open-government instruments and to nothing else - no API standard, no discovery standard, no error standard. As a REGULATOR it is the body that made NAESB REQ.21 ESPI (Green Button) compulsory for the utilities it supervises and that publishes the register proving implementation - so its most significant standards conformance is exercised on other organisations, not on itself. standards: - id: open-government-licence-ontario conforms: true evidence: >- Every Open Data dataset page states the data is published under the Open Government Licence - Ontario (https://www.ontario.ca/page/open-government-licence-ontario), and the licence is linked from the programme landing page. Attribution required; commercial reuse permitted. - id: ontario-digital-and-data-directive-2021 conforms: true evidence: >- The OEB's 2022-09-29 transition letter places the Open Data programme under Ontario's Digital and Data Directive (2021), the provincial instrument requiring open publication by default. - id: open-data-anonymous-access conforms: true evidence: >- 33 dataset files fetched with HTTP 200 anonymously on 2026-07-27 - no registration, no key, no terms click-through, no rate-limit gate. Verified per file in openapi/ontario-energy-board-open-data-openapi.yml. - id: naesb-req21-espi conforms: not-applicable role: regulator version: '3.3' evidence: >- The OEB holds no customer meter, usage or billing data and operates no ESPI endpoint, so the standard does not bind it as a data holder. It is the body that made ESPI v3.3 compulsory in Ontario through O. Reg. 633/21 and the amended Retail Settlement Code, ran the consultation (EB-2021-0183) and publishes the implementation status register naming 54 confirmed distributors and 6 extensions (https://www.oeb.ca/sites/default/files/Green-Button-implementation-status-summary.pdf, HTTP 200, 399,394 bytes, verified 2026-07-27). - id: green-button-download-my-data conforms: not-applicable role: regulator evidence: Mandated by the OEB for Ontario's rate-regulated utilities; not implemented by the OEB, which holds no consumption data. - id: green-button-connect-my-data conforms: not-applicable role: regulator evidence: As above. The OAuth-protected CMD surfaces in Ontario belong to the utilities - see all/hydro-one/ and all/toronto-hydro/. - id: xml conforms: true evidence: >- The dominant Open Data format; 27 of 33 verified files are served as text/xml. The OEB publishes a guide for importing that XML into Excel (Open-Data-Guide-XML-Excel-20221215.pdf, HTTP 200). - id: ooxml-spreadsheetml conforms: true evidence: >- Rate data keys, historical RPP prices and RRR all-accounts analyses are served as application/vnd.openxmlformats-officedocument.spreadsheetml.sheet. - id: gis-shapefile-bundle conforms: true evidence: >- Electricity and natural gas distributor service-territory boundaries are published as ZIP archives for use in GIS applications (2.0 MB and 13.2 MB, both HTTP 200 on 2026-07-27). - id: tls-1-3 conforms: true evidence: TLSv1.3 negotiated on both www.oeb.ca and www.rds.oeb.ca; see security/ontario-energy-board-domain-security.yml. - id: hsts-preload conforms: true evidence: 'Strict-Transport-Security: max-age=31536000; includeSubDomains; preload on both hosts.' - id: content-security-policy conforms: true evidence: >- www.oeb.ca serves a detailed enforcing CSP with a report-uri (https://oebca.report-uri.com/r/d/csp/enforce); www.rds.oeb.ca restricts frame-ancestors to *.oeb.ca. Also present on both: X-Content-Type-Options nosniff, X-Frame-Options SAMEORIGIN, Referrer-Policy, Permissions-Policy. - id: dmarc conforms: true evidence: 'oeb.ca publishes SPF and DMARC with policy p=quarantine; probed 2026-07-27.' - id: dnssec conforms: false evidence: No DNSSEC on oeb.ca. - id: caa conforms: false evidence: No CAA records on oeb.ca. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger definition exists on any OEB host. /openapi.json, /swagger.json and /api-docs return HTTP 404 on www.oeb.ca, www.rds.oeb.ca and the Azure APIM host referenced in the site CSP. The two OpenAPI documents in this repo were generated by API Evangelist from live probes and are explicitly marked x-published-by-provider false. - id: rfc9457-problem-details conforms: false evidence: >- The RDS error envelope is a Content Manager ServiceStack ResponseStatus object served as application/json, and rejected queries return HTTP 200 rather than 4xx. See errors/ontario-energy-board-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns HTTP 404 on both www.oeb.ca and www.rds.oeb.ca. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns HTTP 404 on both hosts. - id: oauth2 conforms: false evidence: No OAuth surface. /.well-known/oauth-authorization-server returns HTTP 404 on both hosts; neither surface authenticates at all. - id: openid-connect conforms: false evidence: /.well-known/openid-configuration returns HTTP 404 on both hosts. - id: llms-txt conforms: false evidence: /llms.txt returns HTTP 404 on both hosts. The llms.txt in this repo is generated by API Evangelist. - id: mcp conforms: false evidence: No Model Context Protocol server is published or discoverable. - id: asyncapi conforms: false evidence: No event, webhook, streaming or subscription surface exists on either host. - id: json-api conforms: false evidence: The RDS JSON is a vendor ServiceAPIModel payload, not JSON:API. - id: odata conforms: false - id: ckan-dcat conforms: false evidence: >- The OEB runs its own Drupal dataset pages rather than a CKAN/DCAT catalogue, so there is no package_search or DCAT feed for OEB Open Data. Two OEB-derived boundary datasets do appear on Ontario's CKAN catalogue (data.ontario.ca), published there by the Ministry of Energy rather than by the OEB. - id: idempotency-key conforms: not-applicable evidence: Both surfaces are strictly read-only; there is no write operation for an idempotency key to protect. regulatory: - id: ontario-reg-633-21 name: O. Reg. 633/21 (Energy Data), Electricity Act, 1998 url: https://www.ontario.ca/laws/regulation/210633 applies: false applies_evidence: >- The OEB is not a rate-regulated utility and holds no customer energy data, so it is not an obligated party. It is the regulator named in the instrument. oeb_role: >- Ran the consultation (EB-2021-0183), amended the Retail Settlement Code, collects quarterly implementation progress reports and publishes the implementation status register. regulator_pages: - https://www.oeb.ca/green-button - https://www.oeb.ca/consultations-and-projects/policy-initiatives-and-consultations/green-button-implementation - id: ontario-energy-board-act-1998 name: Ontario Energy Board Act, 1998 applies: true applies_evidence: The OEB's own constituting statute; the source of its licensing, rate-setting and RRR reporting powers, which are what the open datasets contain. - id: ontario-digital-and-data-directive-2021 name: Ontario's Digital and Data Directive (2021) url: https://www.ontario.ca/page/ontarios-digital-and-data-directive-2021 applies: true applies_evidence: Named by the OEB itself as the basis of the Open Data programme. certifications: [] compliance_program_published: false compliance_program_note: >- The OEB publishes no trust centre, no SOC 2 / ISO 27001 / PCI attestation, no penetration-test summary and no vulnerability disclosure policy. probe-security-programs found no bug bounty and no trust centre; /.well-known/security.txt is a 404. As a provincial regulator it is subject to Ontario's public-sector accountability regime rather than to commercial certification, and it makes no certification claim of its own. No `Compliance` and no `TrustCenter` pointer is emitted. related: - authentication/ontario-energy-board-authentication.yml - conventions/ontario-energy-board-conventions.yml - lifecycle/ontario-energy-board-lifecycle.yml - security/ontario-energy-board-domain-security.yml - well-known/ontario-energy-board-well-known.yml