Abstract The rollout of smart metering in the European Union (EU) electricity sector highlights a structural tension between, on the one hand, the need for enhanced grid observability under Directive (EU) 2019/944 and, on the other, the safeguards required by the Charter of Fundamental Rights of the European Union (CFR) and the General Data Protection Regulation (GDPR). This tension is intensified by the horizontal regimes introduced by the Data Act and the NIS2 Directive; although designed to promote, respectively, data sharing and cybersecurity resilience, they may fragment the regulatory landscape and weaken sector-specific constraints in EU energy law. The article argues that, when combined with inference techniques such as Non-Intrusive Load Monitoring, metering data can produce a ‘Panopticon effect’ that demands a careful balancing of the energy system’s ‘big data’ needs against the GDPR’s data minimization imperative. It further shows how the Data Act’s commodification logic (treating data as an economic asset) poses a risk of ‘regulatory bypass’, by enabling transfers of metering data outside the eligibility and purpose constraints of electricity law. Finally, it frames cybersecurity as an autonomous pillar: NIS2’s integrity and availability objectives, together with the Cyber Resilience Act’s security-by-design duties, complement the GDPR’s requirements and can, if properly coordinated, reinforce minimization by reducing the attack surface. On that basis, the article proposes an ‘inter-regulatory proportionality’ framework to reconcile these regimes, in which data protection and privacy set limits, energy law defines functions, and cybersecurity guarantees resilience, all within a coherent governance hierarchy.
Komninos Komnios (Thu,) studied this question.