Your data, your rights: privacy and security

35 min 4 outcomes Quiz + privacy analysis

By the end of this module you will be able to:

  • Explain three overlapping privacy frameworks: UK GDPR, the DUA Act 2025, and the DAPF tiered consent model
  • Describe what 48 half-hourly readings reveal about occupants and how lawful basis, consent and Smart Data purposes differ
  • Outline the DCC PKI-E four-tier certificate hierarchy and the NIS/CAF cybersecurity framework
  • Describe the RECCo Consumer Consent Solution delivery timeline and what it replaces

9.1 UK GDPR and energy data

The UK General Data Protection Regulation (), implemented through the Data Protection Act 2018, applies to all personal data processed in the energy sector. For smart meter data, the key provisions are:

processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);

UK GDPR, Article 5(1)(a)

This is the first principle of UK GDPR data processing. In the energy sector it means that smart meter data collection must have a valid lawful basis (Article 6), that consumers must be informed about how their data is used, and that processing must not be deceptive or harmful.

Lawful basis for processing

Article 6(1) requires a for processing personal data. The energy sector uses several bases: consent (the customer agrees to their data being used for a specific purpose), contract (processing is necessary to fulfil the supply contract), legal obligation(processing is required by law, such as BSC settlement obligations), andlegitimate interests (processing is necessary for the data controller's legitimate interests, balanced against the individual's rights).

The choice of lawful basis matters enormously. Consent can be withdrawn, creating operational complexity. Contract is limited to what is strictly necessary for supply. Legal obligation only applies where specific legislation mandates the processing. Legitimate interests requires a balancing test that must be documented and can be challenged. The added “recognised legitimate interests”, a seventh basis in force since 5 February 2026, which simplifies some of these decisions for the specified public-interest purposes it covers and none outside them.

Data minimisation

Article 5(1)(c) requires that personal data be adequate, relevant, and limited to what is necessary for the purpose. This principle directly challenges the industry's desire for ever more granular data. Is half-hourly data necessary for settlement, or would daily data suffice? Is individual-level data necessary for network planning, or would aggregated data at the substation level be adequate? These are not technical questions - they are governance questions with no universally agreed answers.

Right to erasure and portability

Article 17 gives individuals the right to have their personal data deleted. Article 20 gives them the right to receive their data in a portable format and to transmit it to another controller. Both rights create practical challenges in the energy sector. Settlement data cannot simply be deleted because it is needed for reconciliation runs that currently complete over 14 months and are reducing to four months under MHHS. Portability requires standardised data formats that not all suppliers have implemented.

The right to erasure is particularly complex because energy data serves multiple purposes with different retention requirements. The same half-hourly reading may be needed for billing (retained until the bill is paid and the dispute period expires), settlement (retained through the settlement run timetable), network planning (retained indefinitely in aggregated form), and regulatory compliance (retained as Ofgem directs). Deleting the data for one purpose while retaining it for another requires sophisticated data management capabilities that many suppliers lack.

Four UK GDPR Article 6 lawful bases for processing energy data

Data can only be used within the limit paired with its basis, so the choice made at collection fixes what can be done later: consent can be withdrawn, contract reaches only the supply purpose, legal obligation only the mandated scope, legitimate interests can be objected to.

Four lawful bases. The right choice limits what can be done later. Source: UK GDPR Article 6, Data Protection Act 2018, ICO Energy Guidance.

Four UK GDPR Article 6 lawful bases for processing energy data A two-by-two grid of four lawful basis cards labelled A, B, C and F (Article 6 paragraphs). Each card has a brand-red letter block on the left, then the basis name, the conditions under which it applies, the risk on withdrawal or challenge, and a worked example from energy data. Contract and legal obligation are emphasised because they bear the bulk of regulated processing. A Art 6(1) Consent WHEN IT APPLIES Subject chose, opt-in, recorded RISK Withdrawable; loss of processing right EXAMPLE Sharing half-hourly data with a third-party tariff agent B Art 6(1) Contract WHEN IT APPLIES Necessary to fulfil the supply contract RISK Only covers the supply purpose itself EXAMPLE Reading the cumulative register to issue a bill C Art 6(1) Legal obligation WHEN IT APPLIES Specific legislation mandates the processing RISK Limited to the mandated scope EXAMPLE BSC settlement collection of half-hourly volumes F Art 6(1) Legitimate interests WHEN IT APPLIES Documented balancing test passes RISK Subject can object; ICO can challenge EXAMPLE Network planning aggregates that benefit the wider system
Check your understanding

Why is the right to erasure under UK GDPR Article 17 particularly complex for smart meter data?

9.2 The DUA Act, Smart Data and lawful basis

Data (Use and Access) Act 2025

The DUA Act received Royal Assent on 19 June 2025 and introduces two provisions with significant implications for energy data privacy. First, the framework gives the Secretary of State power to create regulated data-sharing schemes. The July 2025 government response defines Smart Data in energy as secure sharing of customer data at the customer's request with authorised third parties. This is a customer-authorised data-sharing route, not a blanket route for every settlement, planning or operational use of meter data.

Second, the Act added “recognised legitimate interests”, in force since 5 February 2026, as a lawful basis for processing personal data. The ICO says recognised legitimate interest is one of the seven UK GDPR lawful bases and applies only to specified public-interest purposes in Annex 1 of the UK GDPR. The practical lesson for energy teams is narrow but important: do not assume that all smart-meter processing moves to one no-consent basis. Billing, settlement, network planning, fraud prevention, consumer-authorised sharing and product analytics each need their own purpose, lawful basis, minimisation test and access control.

processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

UK GDPR, Article 6(1)(f)

This is the ordinary legitimate-interests test. Recognised legitimate interest is different: the purpose must be specified in Annex 1. The course therefore treats each energy use case separately rather than implying that one lawful basis covers all half-hourly data processing.

DAPF tiered consent model

The Data Access and Privacy Framework () was developed alongside the smart meter rollout to define consent requirements for different levels of data granularity. It establishes a tiered approach:

Monthly data, no consent required. Monthly consumption totals are considered necessary for billing and settlement. No additional consent is needed because the data is collected under the contract and legal obligation lawful bases. The granularity is too low to reveal behavioural patterns.

Half-hourly data for settlement, purpose-specific basis required.This is the most important tier for MHHS. Half-hourly data is personal data when it relates to an identifiable household, so collection and use must be tied to a valid Article 6 lawful basis, a clear purpose, transparency to the customer and suitable controls. Consent may be the right basis for some purposes, but regulated settlement, billing and network activities can involve other lawful bases when the legal and factual tests are met.

Half-hourly data beyond settlement, opt-in consent. If a supplier or third party wants to use half-hourly data for purposes beyond settlement (energy efficiency advice, time-of-use tariff design, appliance disaggregation), the customer must give explicit opt-in consent. This consent must be granular (specifying each purpose), informed (explaining what the data reveals), and withdrawable (the customer can change their mind at any time).

DNO access, privacy plan required. DNOs require access to consumption data for network planning and load management. Under the DAPF, DNOs must publish a privacy plan explaining what data they access, why they need it, how it is protected, and how long it is retained. The data must be pseudonymised or aggregated wherever possible.

Purpose separation is the control

The central privacy-control question is not whether half-hourly data is useful. It clearly is. The question is which purpose is being served and what lawful basis supports that purpose. The same 48 daily readings can support a regulated settlement process, a bill, a DNO load study, an energy-advice app or an appliance-disaggregation service. Those are different uses, and they should not be bundled into one broad permission.

A strong design separates purposes in the data model. It records the lawful basis, data fields, retention period, access parties and audit evidence for each purpose. If a supplier needs data for billing, that is one record of processing activity. If a third-party service wants the same data to recommend a tariff, that is a customer-authorised sharing flow with consent managed separately.

The DUA Act and Smart Data work make this separation more important, not less. Smart Data is designed to help consumers share their data with authorised third parties in a controlled way. Recognised legitimate interest may support specific public-interest processing where the statutory conditions are met. Neither route removes data minimisation, transparency, security, retention control or the need to explain the processing to the customer.

CCS consumer consent journey

Citizens Advice and the Department for Energy Security and Net Zero (DESNZ) have researched the consumer consent journey for smart meter data. Their findings are concerning: most consumers do not understand what half-hourly data reveals, many consumers believe their data is anonymous (it is not - it is linked to their MPAN and address), and the consent language used by suppliers is often unclear or buried in terms and conditions. Improving consumer understanding and consent quality is essential, regardless of which lawful basis ultimately prevails for settlement.

Common misconception

Smart meter data is anonymous because it is just numbers.

Half-hourly consumption data from a known address is personal data under UK GDPR. The ICO has confirmed this classification. Forty-eight readings per day reveal wake times, occupancy, cooking habits, EV charging, holidays, and potentially health conditions. Even aggregated data can become personal if the aggregation group is small enough (e.g., a single substation serving 10 houses).

9.3 Cybersecurity: PKI-E and NIS

Privacy frameworks protect data from misuse by authorised parties. Cybersecurity protects data from unauthorised access entirely. In the smart metering ecosystem, the primary cybersecurity mechanism is the Public Key Infrastructure for Energy (), operated by the DCC.

Four trust zones protect smart meter data from meter to third party

A reading that reaches a third party crosses four zones in sequence, meter and HAN, DCC and WAN, supplier and agents, then the authorised third party, meeting different controls and a different governing rule at each, so no single rule covers it end to end.

Four concentric trust zones around the smart meter: meter, DCC, supplier, third party. Source: PKI-E (SEC Annex L); NIS Regulations 2018; NCSC OT guidance.

Four trust zones protect smart meter data from meter to third party Four horizontal rows representing concentric trust zones around smart meter data. Zone 1 is the meter and HAN inside the home, emphasised. Zone 2 is the DCC and WAN between the home and the central platform. Zone 3 is the supplier and their agents behind the DCC. Zone 4 is the authorised third-party community accessed under consent. Each row names the scope, the controls that apply and the governing rule reference (SEC Annex L, PKI-E, REC Section 17, the NIS Regulations 2018). ZONE 1 · METER AND HAN Inside the home CONTROLS Local cryptographic keys, ZigBee mesh, IHD binding RULE SEC Annex L · SMETS2 ZONE 2 · DCC AND WAN Between the home and the central platform CONTROLS Mutual auth, message signing, role-based authorisation RULE SEC §H · PKI-E ZONE 3 · SUPPLIER, AGENTS Behind the DCC at the supplier and their agents CONTROLS Audited access, REC schedule controls, retention rules RULE REC §17 · DPA 2018 ZONE 4 · THIRD PARTY Consented use beyond the supplier CONTROLS CCS-scoped consent, ICO oversight, NIS duties RULE DUA 2025 · NIS Regs 2018

PKI-E four-tier certificate hierarchy

PKI-E uses a hierarchical certificate structure with four tiers:

Tier 1, Root Certificate Authority. The top of the hierarchy. The root CA issues certificates to Tier 2 CAs. Its private key is held in a hardware security module (HSM) in a physically secured facility and is used extremely rarely (only to sign Tier 2 certificates). Compromise of the root CA would undermine the entire smart metering security model.

Tier 2, Issuing Certificate Authorities. These CAs issue certificates to organisations (suppliers, DNOs, the DCC itself). There are separate issuing CAs for different purposes: one for device certificates, one for organisation certificates, and one for recovery certificates. This separation limits the blast radius of any single CA compromise.

Tier 3, Organisation certificates. Each licensed energy company that communicates with smart meters via the DCC holds an organisation certificate. This certificate authenticates the organisation to the DCC and authorises it to send specific Service Requests to specific meters. The certificate is bound to the organisation's licence: if the licence is revoked, the certificate is revoked.

Tier 4, Device certificates. Each SMETS2 smart meter holds a unique device certificate installed during manufacture. This certificate authenticates the meter to the DCC and encrypts the data in transit. Device certificates have a defined lifetime and must be renewed, though the renewal process is itself secured by the PKI-E hierarchy.

Every message between the DCC and a smart meter is encrypted and signed using certificates from this hierarchy. A supplier cannot read another supplier's meter data even if they intercept the communication, because the data is encrypted with keys that only the authorised parties hold.

NIS Regulations and CAF v4.0

The Network and Information Systems (NIS) Regulations 2018 designate energy as a critical national infrastructure sector. Operators of Essential Services (OES) in energy - including transmission and distribution network operators, NESO, and the DCC - must comply with the NIS Regulations, which require them to implement appropriate and proportionate security measures.

Ofgem, as the competent authority for energy under NIS, uses the Cyber Assessment Framework (CAF) version 4.0 to assess compliance. The CAF covers four objectives: managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of cyber security incidents. Each objective has contributing outcomes and indicators of good practice that Ofgem assesses.

The Cyber Security and Resilience Bill

The Cyber Security and Resilience Bill, introduced in 2025, will update the NIS framework to address evolving threats. Key provisions relevant to energy data include expanded scope (potentially covering more energy organisations beyond current OES designations), mandatory incident reporting within tighter timeframes, supply chain security requirements (ensuring that third-party IT providers meet minimum security standards), and enhanced enforcement powers for Ofgem.

The right to be forgotten: a cybersecurity dimension

The right to erasure under UK GDPR intersects with cybersecurity in a non-obvious way. When a customer exercises their right to be forgotten, the data controller must delete their personal data from all systems where it is held. But in a complex ecosystem like smart metering, data exists in multiple locations: the supplier's billing system, the DCC's communications logs, the DNO's network planning database, and potentially in backup systems and disaster recovery sites. Ensuring complete deletion across all these systems, while maintaining the integrity of aggregate data that depends on the individual records, is a significant technical challenge. Most organisations cannot currently guarantee complete erasure across all data stores.

Check your understanding

In the DCC's PKI-E hierarchy, what does a Tier 4 device certificate authenticate?

9.4 Consent gets infrastructure

Everything so far has treated consent as something a supplier collects: a form, a tick-box, a paragraph in the terms and conditions. That model does not scale to a market of many services. A household that wants a tariff-comparison tool, an energy-advice app and a demand-flexibility provider each to use its half-hourly data has to grant and manage a separate permission with each one, and revoke them one at a time. The DAPF sets the rules for who may access what, but it does not give the consumer a single place to grant, review and withdraw that access.

That missing piece is now being built. The Retail Energy Code Company (RECCo) is delivering the (CCS), a shared trust framework that holds consent centrally rather than inside each supplier. RECCo ran a design consultation from February to March 2026, and in May 2026 appointed Raidiam and PayPoint to build the trust framework. A minimum viable product is planned for 2026, with a minimum marketable product targeted for March 2027.

The destination is a market in which a consumer authorises a third party to use their data once, through one trusted route, and that authorisation is honoured across the industry. The tariff-data consumer-sharing milestone in November 2027 is the first concrete test of the route: from that point a consumer should be able to share tariff data with an authorised service through the shared framework rather than through a separate request to each supplier.

This changes who can build on consumer data. When consent lives inside each supplier, only that supplier can act on it without friction, and every new entrant has to negotiate its own consent journey. When consent lives in a shared trust framework governed by the DAPF, a smaller provider can reach a consumer who has already granted access on the same terms as an incumbent. The privacy questions from the previous sections, which purpose and which lawful basis, do not disappear. They become properties of the framework rather than of one supplier's form.

May 2026: Raidiam and PayPoint appointed to build the Consumer Consent Solution trust framework

In February 2026 RECCo opened a design consultation on how a shared consent framework for energy should work. By May 2026 it had appointed two delivery partners: Raidiam, which builds trust frameworks for open banking and open data, and PayPoint, which runs a large payments and retail network. The pairing is deliberate. The identity-and-trust engineering that lets a consumer authorise access safely is joined to a channel that reaches consumers who do not manage their energy online.

Read it as the moment consent stopped being a single supplier’s feature and became shared infrastructure. Ofgem’s consumer consent decision set the policy direction; RECCo’s appointment turned it into a build with named partners and dates. A data leader planning a consumer-facing service for 2027 should design against the CCS trust framework and the DAPF rules, not against a bilateral consent form with one supplier, because the bilateral route is the one being replaced.

Check your understanding

What is the RECCo Consumer Consent Solution (CCS) designed to replace?

Core distinctions

  • UK GDPR applies fully to smart meter data. Half-hourly readings from a known address are personal data. Key provisions include lawful basis requirements (consent, contract, legal obligation, legitimate interests), data minimisation, right to erasure, and data portability - each creating specific operational challenges for the energy sector.
  • The DUA Act 2025 added Smart Data and recognised legitimate interest, both in force, and both bounded. Smart Data is customer-authorised sharing with authorised third parties. Recognised legitimate interest applies only to specified public-interest purposes.
  • The DAPF-style tiered model separates monthly data, half-hourly settlement use, non-settlement half-hourly use and DNO access. Each tier needs a purpose, a lawful basis, access controls, retention rules and customer-facing transparency.
  • The DCC PKI-E uses a 4-tier certificate hierarchy (Root CA → Issuing CAs → Organisation certificates → Device certificates) to encrypt and authenticate all smart meter communications. NIS Regulations and CAF v4.0 set the broader cybersecurity framework, with the Cyber Security and Resilience Bill expanding scope and enforcement.

Standards and sources cited in this module

  1. ICO, Smart Metering and Privacy - Classification of Half-Hourly Data

    Personal data determination for smart meter readings

    Confirms that half-hourly consumption data from a known address is personal data under UK GDPR. Referenced in Section 9.1.

  2. Data (Use and Access) Act 2025 (Royal Assent 19 June 2025)

    Part 1: Smart Data; Part 4: Recognised Legitimate Interests

    Source for the Smart Data framework and recognised legitimate interest provisions. Referenced in Section 9.2.

  3. DCC, PKI-E Technical Architecture Documentation

    Certificate hierarchy and security model

    Source for the 4-tier PKI-E structure and the encryption model for smart meter communications. Referenced in Section 9.3.

  4. RECCo, design consultation for the Consumer Consent Solution

    CCS trust framework, delivery partners and timeline

    Source for the design consultation (February to March 2026) and the appointment of Raidiam and PayPoint in May 2026 to build the trust framework. Referenced in Section 9.4.

  5. Ofgem, consumer consent decision

    Centralised consent management for smart meter data

    Sets the policy direction for centralised consent that the RECCo Consumer Consent Solution delivers. Referenced in Section 9.4.

Module 14 of 31 · Energy System Data Applied