Standards and schemes / Consumer, data and product schemes / GDPR and energy data

S-025·Standards and schemes / Consumer, data and product schemes

GDPR and energy data

Smart-meter, supplier and equipment-cloud data, including access choices, third-party sharing and household rights.

Home energy data does not all come from the smart meter. A supplier may hold account and meter readings, while a solar inverter, battery, EV charger or heat pump can send a separate stream of telemetry to its manufacturer’s cloud. An installer, tariff provider or flexibility service may have access to one system but not the other.

UK data-protection law applies where that information is personal data. The relevant framework is the UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Smart-meter access is also governed by energy-specific rules known as the Data Access and Privacy Framework.

As at 22 July 2026, all data-protection provisions of the 2025 Act are in force. It amended rather than replaced the UK GDPR. Consent remains important, but it is not the only lawful basis on which an organisation can process energy data.

Separate the data before asking who can see it

An Energy Stack installation can create several distinct records:

  • smart-meter consumption and export data, read through the regulated smart-meter system
  • supplier account data, including bills, tariff, payments and customer-service records
  • equipment telemetry, such as generation, state of charge, charging sessions, temperatures, faults, schedules and control commands
  • installer or service-platform data, copied into a monitoring portal, maintenance system, tariff service or flexibility platform

The smart-meter privacy framework governs access through the smart-meter system. It does not automatically govern an inverter or charger app. The manufacturer, installer or service provider must deal with that separate telemetry under general data-protection law and its own privacy notice.

This distinction matters when exercising a right. A supplier cannot provide cloud logs it never received, and a battery manufacturer cannot change the supplier’s smart-meter reading preference.

Current domestic smart-meter sharing choices

Ofgem’s current consumer guidance bases the default on the date of the smart-meter installation or the most recent supplier switch or new contract.

For a domestic customer whose smart meter was installed before 3 November 2022, and who has not switched supplier or agreed a new contract since that date:

  • the normal sharing level is daily
  • the customer can opt in to half-hourly sharing
  • the customer can opt down to monthly sharing

For a domestic customer whose meter was installed, supplier changed or new contract agreed after 3 November 2022:

  • the normal sharing level is half-hourly
  • the customer can opt down to daily sharing

These choices do not prevent access needed for billing or another regulated purpose. Network companies can also use smart-meter data for regulated network functions under the sector rules.

The old shorthand that domestic half-hourly data is always “opt-in only” is therefore no longer correct. It remains visible in older descriptions of the original framework and in material about the earlier settlement rules.

Tariffs and services that need detailed data

A time-of-use tariff, smart export tariff, managed EV-charging service or flexibility scheme may need half-hourly or more detailed data to calculate payments and prove when energy was used, exported or shifted.

The data choice and the product contract are separate questions. A domestic customer may have a general right to reduce smart-meter sharing to daily, but a particular half-hourly product may then cease to be available or may no longer work as intended. Before changing the setting, ask the supplier:

  1. which reading interval the tariff requires
  2. whether it uses smart-meter data, device telemetry or both
  3. which organisation receives each dataset
  4. what happens to the tariff or service if permission is withdrawn

Do not assume that giving an EV-tariff provider access to a charger also gives it access to the household smart meter, or the other way round.

Every organisation processing personal data needs a lawful basis. Depending on the purpose, this might be consent, performance of a contract, a legal obligation, public task or legitimate interests.

Withdrawing consent stops processing that relies on that consent. It does not cancel processing the organisation still needs for a contract, billing duty, settlement obligation, fraud investigation or legal claim. A privacy notice should identify the purpose and lawful basis rather than describing every use as consent.

Marketing is a separate use. Ofgem says suppliers and third parties can use smart data to offer products and services if the customer gives permission. Agreeing to detailed readings for a tariff should not be treated as open-ended permission for unrelated marketing.

Third-party and installer access

A third-party service can receive data with the customer’s authority, but the practical route varies. It may read smart-meter data through an authorised energy-market route, receive data from the supplier, connect to the manufacturer’s cloud or install a separate meter or gateway.

Before approving access, establish:

  • the legal name of the organisation acting as data controller
  • the exact data requested and whether it includes the whole home or one device
  • the purpose, lawful basis and duration
  • whether access continues after the trial, tariff or maintenance contract ends
  • which processors or overseas services receive the data
  • how to withdraw permission and revoke technical access
  • whether historic data is deleted, retained or anonymised afterwards

An installer login deserves the same attention as an app permission. Remove unused commissioning accounts, shared passwords and former installers. Give each continuing user the lowest access level they need, especially where the portal can change battery, charging or heating schedules rather than merely view them.

Your main data rights

Energy data that identifies or can be linked to a person can engage the normal UK GDPR rights. They are rights against each organisation holding the data, not a single request that automatically reaches the whole energy chain.

Access

A subject access request asks an organisation whether it is using or storing your personal data and requests a copy. It can cover readings, account history, device telemetry, access logs and inferred information that the organisation actually holds, subject to applicable restrictions and the rights of other people.

ICO guidance current at this review date says an organisation must make a reasonable and proportionate search and normally respond without undue delay and within one month. Identify the account, device, period and categories wanted so the result is useful.

Portability

The right to data portability can cover raw data observed through connected products, and the ICO expressly gives smart meters as an example. The right is narrower than subject access. It applies where processing is automated and based on consent or performance of a contract, and covers personal data the individual provided, including data observed from their use of a device.

Where it applies, the data should be supplied in a structured, commonly used, machine-readable format. It does not force two manufacturers’ systems to be technically interoperable and does not necessarily include a company’s derived model or analytics.

Correction, objection and deletion

You can ask for inaccurate personal data to be corrected and can object to some forms of processing. You can also ask for erasure in circumstances such as when data is no longer needed, consent is withdrawn with no other lawful basis, or processing was unlawful.

Erasure is not an unconditional right. An organisation can retain information where necessary to comply with law, perform a public task or establish, exercise or defend legal claims. There is no single GDPR retention period for all energy data. Each controller should state and justify its retention policy.

Connected-product data roles

The product’s data arrangements cover:

  • core operation when the cloud service is unavailable
  • whether cloud monitoring is optional or a condition of warranty or tariff participation
  • export of detailed data
  • transfer of ownership and administrator rights
  • access retained by the installer, manufacturer and any aggregator
  • multi-factor authentication
  • retention after the account is closed
  • effects of account deletion on local settings, warranty evidence and service history

Keep the privacy notice and terms that applied when the account was created. Online terms can change, and a later page may not show what was originally agreed.

Moving home or ending a service

Before a property changes hands or an energy service ends:

  1. Export any readings, fault history and settings you need to retain.
  2. Remove tariff, aggregator and installer permissions that should not continue.
  3. Follow the manufacturer’s ownership-transfer process rather than giving the buyer your login.
  4. Remove personal contact, payment and vehicle details from the old account.
  5. Confirm whether historic household data remains linked to you, the device or the property.
  6. Reset local devices only after recording configuration needed for safe handover.

A factory reset does not necessarily delete copies already held in a cloud service, supplier account or backup. Address each controller separately.

If something is wrong

Start with the organisation’s data-protection contact and keep the request and response. Under the law current at this review date, organisations must provide a way to make a data-protection complaint, acknowledge it within 30 days and respond without undue delay.

If the response does not resolve the issue, a complaint can be made to the Information Commissioner’s Office. A billing, switching or energy-service complaint may also follow the supplier’s energy complaints route, but that is separate from the ICO’s role.

  • Half-hourly settlement data
  • SMETS2 smart meter capability
  • Monitoring portal data
  • Battery firmware and cloud dependency
  • Energy gateway hardware
  • Virtual power plant participation

Applies to

Solar, Battery, EV charging, Heat

Last reviewed

22 Jul 2026