Smart Meter Data Privacy Regulation .

 Competition Law and Layered Platform Dominance Theories

1. Introduction

Smart meter data privacy regulation governs the collection, transmission, storage, sharing and use of information generated by smart electricity and gas meters. In Great Britain, smart meters can generate highly granular consumption information, including half-hourly readings. Such information may reveal patterns of household activity and, where linked to an identifiable consumer, will generally fall within personal-data regulation. The regulatory objective is therefore to obtain the benefits of digitalised energy systems while protecting privacy, security and consumer autonomy. The UK Government’s Data Access and Privacy Framework (“DAPF”) expressly adopts consumer control as its central principle.

2. Legal and Regulatory Framework

The principal general framework consists of the UK GDPR and Data Protection Act 2018, supplemented by energy-sector rules contained in electricity and gas supply licences and the Smart Energy Code (SEC). The DAPF complements rather than replaces general data-protection legislation.

Processing must therefore satisfy core data-protection principles, including lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability. Depending on the processing activity, organisations must establish an appropriate lawful basis and respect data-subject rights.

The sector-specific framework distinguishes data according to its granularity. Suppliers may access certain monthly or daily consumption information subject to regulatory conditions, while access to data more detailed than daily, such as half-hourly consumption data, generally requires consumer consent. Explicit consent is also required where consumption data is used for marketing.

3. Consumer Control and Third-Party Access

Consumers should be able to access their own consumption information and voluntarily share it with authorised service providers. Third parties obtaining consumption information through the Data Communications Company must obtain consumer consent, provide appropriate information about data use and take steps to verify that consent comes from the relevant occupier. They are also subject to privacy-assurance arrangements under the SEC.

Network operators may require granular information for network planning and operation. However, access to sub-monthly consumption information generally requires either consumer consent or Ofgem-approved procedures designed, as far as reasonably practicable, to prevent association of the information with an individual consumer or premises.

The framework remains important as data access expands. In 2026, DESNZ and Ofgem have been considering wider access and smart-meter data repositories, including consented third-party access to historical information.

4. Case Law

Lloyd v Google LLC [2021] UKSC 50

Facts: Google was alleged to have secretly collected browser-generated information from millions of iPhone users without their knowledge or consent.

Legal Issue: Whether compensation could be obtained through a representative action merely for unlawful processing without proving individual material damage or distress.

Judgment: The Supreme Court allowed Google’s appeal and rejected the damages claim as formulated.

Legal Principle/Ratio: Compensation under the applicable Data Protection Act 1998 regime required proof of recoverable individual damage; mere loss of control was insufficient for the uniform damages claim advanced.

Significance: For smart-meter disputes, unlawful processing does not automatically establish identical compensatory damages for every affected consumer.

WM Morrison Supermarkets plc v Various Claimants [2020] UKSC 12

Facts: An employee deliberately disclosed payroll information concerning thousands of employees after copying it from workplace systems.

Legal Issue: Whether Morrisons was vicariously liable for the employee’s wrongful disclosure.

Judgment: The Supreme Court held Morrisons was not vicariously liable because the wrongful disclosure was not sufficiently connected with the employee’s authorised activities.

Legal Principle/Ratio: Data-protection legislation does not itself exclude vicarious liability, although ordinary principles determining whether wrongdoing occurred in the course of employment still apply.

Significance: Smart-meter operators must maintain strong organisational and cybersecurity controls, while liability for employee misuse depends on the legal relationship between employment and the wrongful processing.

5. Conclusion

Smart meter privacy regulation combines general data-protection law with specialised energy-sector controls. Its central themes are consumer control, informed consent, lawful processing, purpose limitation, data minimisation, cybersecurity and accountability. As smart-meter information becomes increasingly important for flexibility markets, network management and personalised energy services, privacy governance must ensure that digital innovation does not undermine consumers’ control over identifiable consumption information.

LEAVE A COMMENT