Smart Meter Data Privacy And Consent Frameworks
Competition Law and Layered Platform Dominance Theories
1. Concept and Regulatory Purpose
Smart meters continuously generate detailed information concerning electricity or gas consumption. Because granular consumption data may reveal household routines, occupancy patterns and appliance usage, its collection and disclosure raise significant privacy and data-protection concerns. In Great Britain, smart-meter privacy is governed through a combination of the UK GDPR, Data Protection Act 2018, energy supply licence conditions, the Smart Energy Code (SEC), and Data Communications Company (DCC) arrangements.
SEC Section I specifically regulates data privacy and access to consumption data. It requires users to inform consumers about relevant collection periods, purposes of use and rights to object or withdraw consent.
2. Data Protection Principles
Smart-meter consumption information capable of identifying or relating to an individual constitutes personal data. Processing therefore engages UK GDPR principles including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality and accountability.
A supplier or authorised third party must identify an appropriate lawful basis for processing. Consent is only one possible lawful basis; therefore, not every processing operation depends upon consumer consent.
Where consent is relied upon, Article 4(11) UK GDPR requires it to be freely given, specific, informed and unambiguous, demonstrated through a statement or clear affirmative action. Consumers must also be able to withdraw consent easily. Silence, inactivity and pre-ticked boxes are insufficient.
3. Smart Energy Code Consent Framework
SEC Section I creates additional sector-specific safeguards. Depending upon the identity of the party and purpose of access, a user must possess the relevant “Appropriate Permission.” Consumers must receive information concerning the periods of consumption data obtained, purposes for which it may be used and applicable objection or withdrawal mechanisms.
For example, joining certain Type 2 Devices to smart-meter infrastructure requires Unambiguous Consent, subject to specified exceptions. Consumers must also be informed where joining a device may result in their data being shared with third parties.
Other Users are subject to privacy assessments examining compliance with SEC Section I. The SEC privacy-assessment regime includes independent assessment and operates on a three-year assessment cycle.
A significant development occurred through SEC Modification MP219, implemented on 19 May 2025. It amended the framework so contracted Other Users acting on behalf of specified suppliers or network operators may obtain consumption data under defined arrangements without independently collecting Unambiguous Consent from every consumer.
4. DCC Confidentiality and Data Sharing
The DCC provides the communications infrastructure through which smart-meter information is transmitted. Its ability to disclose confidential information is legally constrained. For example, Ofgem granted specific consent in 2024 allowing DCC disclosure of certain information for projects researching fuel poverty, illustrating that socially beneficial secondary uses remain subject to regulatory controls rather than unrestricted disclosure.
As of September 2026, Ofgem is also consulting on a Smart Data Repository, intended to make specified electricity data available to third parties through consumer-consent mechanisms and interoperability with the Consumer Consent Solution.
5. Case Law
Lloyd v Google LLC [2021] UKSC 50
Facts: Google was alleged to have secretly tracked the internet activity of millions of Apple iPhone users and processed browser-generated information without their knowledge.
Legal Issue: Whether damages could be recovered collectively for unlawful processing without establishing individual material damage or distress.
Judgment: The Supreme Court rejected the representative damages claim in the form advanced.
Legal Principle/Ratio: Mere unlawful processing does not automatically establish compensatory damages under the statutory framework considered; individual damage must ordinarily be demonstrated.
Significance: Although not a smart-meter case, it is important by analogy because mass processing of digitally generated household data can create similar questions concerning privacy, unlawful collection and remedies.
Vidal-Hall v Google Inc [2015] EWCA Civ 311
Facts: Claimants alleged that Google collected browser information without their knowledge through tracking technology.
Legal Issue: Whether misuse of private digital information and data-protection violations could support claims for compensation.
Judgment: The Court of Appeal recognised the substantial privacy interests associated with digitally collected behavioural information.
Legal Principle/Ratio: Personal data and privacy protections can apply strongly to systematic technological monitoring.
Significance: The reasoning supports rigorous protection of granular smart-meter information capable of revealing behavioural patterns.
6. Conclusion
Smart-meter privacy law combines general data-protection rules with specialised energy-sector governance. Effective compliance therefore requires lawful processing, transparency, purpose limitation, proportionate access, cybersecurity, auditable permission mechanisms and genuine consumer control where consent is required. The emerging Smart Data Repository demonstrates the continuing shift toward greater energy-data sharing, but within structured consent and governance safeguards rather than unrestricted access.

comments