EDPS Opinion 22/2026 on the Proposal for a Regulation as regards future-proofing electricity bills in the Union, through reducing system costs and fostering electrification and digitalisation.
Opinion 22/2026
on the Proposal for a Regulation as regards future-proofing electricity bills in the Union, through reducing system costs and fostering electrification and digitalisation
0
The European Data Protection Supervisor (EDPS) is an independent institution of the EU, responsible under Article 52(2) of Regulation 2018/1725 ‘With respect to the processing of personal data… for ensuring that the fundamental rights and freedoms of natural persons, and in particular their right to data protection, are respected by Union institutions and bodies’, and under Article 52(3)‘… for advising Union institutions and bodies and data subjects on all matters concerning the processing of personal data’.
Wojciech Rafał Wiewiórowski was appointed as Supervisor on 5 December 2019 for a term of five years. The selection procedure for a new EDPS mandate for a term of five years is still ongoing.
Under Article 42(1) of Regulation 2018/1725, the Commission shall ‘following the adoption of proposals for a legislative act, of recommendations or of proposals to the Council pursuant to Article 218 TFEU or when preparing delegated acts or implementing acts, consult the EDPS where there is an impact on the protection of individuals’ rights and freedoms with regard to the processing of personal data’.
This Opinion relates to the Proposal for a Regulation of the European Parliament and of the Council amending Regulation (EU) 2019/943, as regards future-proofing electricity bills in the Union, through reducing system costs and fostering electrification and digitalisation . This Opinion does not preclude any future additional comments or recommendations by the EDPS, in particular if further issues are identified or new information becomes available. Furthermore, this Opinion is without prejudice to any future action that may be taken by the EDPS in the exercise of his powers pursuant to Regulation (EU) 2018/1725. This Opinion is limited to the provisions of the Proposal that are relevant from a data protection perspective.
Executive Summary
On 17 July 2026, the European Commission adopted the Proposal for a Regulation of the European Parliament and of the Council amending Regulation (EU) 2019/943, as regards future-proofing electricity bills in the Union, through reducing system costs and fostering electrification and digitalisation.
The EDPS recognises the importance of the Proposal’s objective of improving grid efficiency and enabling innovative digital solutions for the electricity system, and acknowledges the significant efforts made to ensure that the proposed measures are accompanied by data protection, data governance and cybersecurity safeguards. At the same time, the EDPS recalls that smart metering data can reveal detailed information on household habits, occupancy patterns and potentially sensitive inferences, and therefore require a high level of transparency and control for consumers.
One of the aims of the Proposal is to facilitate the primary and secondary use of energy data. Given the sensitivity of granular consumption data, the EDPS underlines the importance of ensuring compliance with principle of data minimisation. In this regard, the EDPS positively notes that the Proposal indicates that operators should in principle only exchange aggregated or anonymized data and that personal data should only be shared for primary purposes when anonymised data are not sufficient for the objective pursued.
Regarding the secondary use of energy data, the EDPS considers that the Union-level Framework for grid data re-use should also ensure compliance with the principle of data minimisation. In this regard, the EDPS considers that the Proposal should specify the categories and sources of personal data in a more clear and comprehensive manner. The Proposal should equally specify that personal data may only be shared pursuant to the Framework when anonymised (or pseudonymised) data are not sufficient for the objective pursued. Moreover, appropriate measures must be put in place to ensure that any residual risks of reidentification are adequately mitigated.
In cases where the Framework for grid data re-use would entail processing of personal data, even on a limited basis, it should clearly determine the respective data protection roles and responsibilities of the parties involved. In this regard, the EDPS recalls that large scale processing of electricity grid data, when this processing entails the processing of personal data, may require a data protection impact assessment pursuant to Article 35 GDPR.
2
Contents
THE EUROPEAN DATA PROTECTION SUPERVISOR,
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (‘EUDPR’) , and in particular Article 42(1) thereof,
HAS ADOPTED THE FOLLOWING OPINION:
1. Introduction
1. On 17 July 2026, the European Commission adopted the Proposal for a Regulation of the European Parliament and of the Council amending Regulation (EU) 2019/943 , as regards future-proofing electricity bills in the Union, through reducing system costs and fostering electrification and digitalisation (‘the Proposal’).
2. The objective of the Proposal is to improve the design of network charges with a view to enhancing the cost-efficiency of transmission and distribution networks, as well as to encourage both system operators and system users to make more effective use of the existing infrastructure. Furthermore, the Proposal clarifies the role of national regulatory authorities in ensuring access to transmission and distribution networks in an efficient, transparent, and non-discriminatory manner, in particular in situations of grid congestion .
3. The Proposal supports the objective of the Commission Communication AccelerateEU , which sets out the reasons for reducing energy costs by accelerating the deployment of homegrown clean energy and increasing the rate of electrification, in combination with the upgrading of the electricity system through measures relating to the construction of new grid infrastructure, the use of existing infrastructure and taxation.
4. The present Opinion of the EDPS is issued in response to a consultation by the European Commission of 17 July 2026, pursuant to Article 42(1) of EUDPR. The EDPS welcomes the reference to this consultation in Recital 31 of the Proposal.
2. General remarks
5. The EDPS notes that the objectives of the Proposal are to reduce costs for consumers, to support the competitiveness of Union industry and to promote investment in renewables and low-carbon technologies, notably through more efficient network charges, the better use of existing grid infrastructure and an appropriate tax framework.
6. The EDPS also notes that the Proposal is consistent with the Union’s broader policy objectives of accelerating electrification while ensuring affordability, as reflected in 7 8 AccelerateEU, the Clean Industrial Deal and the Electrification Action Plan . The Proposal 9 10 is also coherent with the European Grids Package and the Citizens Energy Package , in particular as regards the promotion of smart, digital and non-wire solutions, improved grid access and the deployment of smart meters to facilitate consumer participation and demand-side flexibility. More generally, the EDPS notes that the Proposal would be aligned with the Union’s wider digital and energy framework, including relevant rules on data use, interoperability, data protection and cybersecurity .
7. The EDPS recalls that smart metering data can reveal detailed information on household habits, occupancy patterns and potentially sensitive inferences, and therefore require a high level of transparency and control for consumers .
8. The EDPS further recalls that Article 5(3) of Directive 2002/58/EC (ePrivacy Directive) applies to smart metering systems, as they include smart meters that constitute terminal equipment where information is stored in, or accessed. Accordingly, the consent of the subscriber or user is required before information is stored, or access is obtained to information already stored, in the terminal equipment of a subscriber or end-user, unless such storage or access is strictly necessary for the provision of an information society service explicitly requested by the subscriber or user . Any subsequent processing of personal data, including personal data obtained through such access to terminal equipment, must also rely on a legal basis under Article 6 GDPR in order to be lawful.
9. The EDPS welcomes the specification that any processing of electricity grid data containing personal data must be carried out in accordance with the applicable data protection rules, in particular Regulation (EU) 2016/679 (GDPR). As Article 5(3) of the ePrivacy Directive also applies to smart metering systems, the EDPS recommends adding to Recital 20 of the Proposal a reference to the applicability of the ePrivacy Directive.
10. The EDPS notes that the Proposal aims to facilitate the primary and secondary use of energy data . Given the sensitivity of granular consumption data, the EDPS underlines the importance of ensuring compliance with principle of data minimisation. In this regard, the EDPS positively notes that the Proposal indicates that operators should in principle only exchange aggregated or anonymized data and that personal data should only be shared for primary purposes when anonymised data are not sufficient for the objective pursued .
11. At the same time, the EDPS considers it equally important to ensure compliance with the principle of data minimisation in the context of secondary use and this Opinion provides specific recommendations to this effect .
12. Finally, the EDPS also welcomes the specification in Recital 25 that electricity grid data form part of an increasingly digitalised electricity system and therefore a high level of operational resilience throughout their lifetime should be ensured, considering the relevant Union cybersecurity legislation and explicitly mentioning data protection as an aspect to be safeguarded.
3. Specific remarks
3.1 Smart electricity grid indicators and innovation
13. The EDPS positively notes the specification that data, to be supplied by transmission system operators (TSOs) and distribution system operators (DSOs) to the regulatory authorities and to Agency for the Cooperation of Energy Regulators (ACER), to allow measuring the uptake and performance of smart and innovative grid technologies, must not include any personal data .
14. Moreover, the Proposal provides that, for the development, deployment, and effective use of smart grids, system operators should in principle only exchange aggregated or anonymised data and that personal data shall only be shared when anonymised data are not sufficient for the objective pursued. This EDPS welcomes this specification which reflects the data protection principle of data minimisation .
15. The EDPS also notes that Article 18a(4) of the Proposal provides that, where electricity grid data fall within the scope of Chapter II of Regulation (EU) 2023/2854 (Data Act), rights and obligations laid down in that Chapter should apply .
3.2 Voluntary Union-level framework for data re-use
16. Article 18a(5) of the Proposal would establish a voluntary Union-level framework for the lawful, secure, and controlled re-use of electricity grid data for research and innovationinterest purposes of public interest, supporting the operation and optimisation of the electricity system pursuant to Article 18a (‘the Framework’), that would be coordinated by the European Network of Transmission System Operators (ENTSO) for Electricity and by EU DSO entity.
17. The EDPS welcomes the requirement that the Framework must ensure compliance with energy, cybersecurity and data legislation, including the Data Act, the GDPR and the AI Act , and that it must include the specification of technical and operational measures for confidentiality, safety and cybersecurity.
18. The Framework, once established, will facilitate large-scale data processing for secondary use. In this regard, the EDPS recommends that the Proposal should specify the categories and sources of personal data in a more comprehensive manner. As currently drafted, the Proposal leaves considerable uncertainty as to the categories and sources of data that may be processed under the Framework. The notion of ‘grid data’ is not defined by the enacting terms of the Proposal and the description provided in Recital 19 does not provide a clear indication of whether such grid data is limited to higher level information or also includes granular consumption data of individuals customers. The EDPS therefore recommends clarifying, in the enacting terms of the Proposal, which categories and sources of data may be processed under the Framework.
19. In addition, the EDPS recommends explicitly clarifying also in paragraph 18a(5) that personal data shall only be shared when anonymised data (or pseudonymous data) are not sufficient for the objective pursued. In case any processing of personal data, even if limited, should be necessary, the Framework should clearly define the (data protection) roles and 26 27 responsibilities of the parties involved . Moreover, the EDPS recommends providing that the Framework shall ensure that any residual risks of reidentification are adequately mitigated through appropriate technical and organizational measures.The EDPS also positively notes that Article 18a(5) of the Proposal requires the Commission, when assessing the coordinated grid data exchange agreement, to consult the EDPS where the elements to be communicated by the European Network of Transmission System Operators (ENTSO) for Electricity and the EU DSO entity, listed at points (a)-(e) of Article 18a(5) of the Proposal concern the processing of personal data.
20. Considering the potential high risk to the rights and freedoms of individuals resulting from large-scale processing of electricity grid data, when this processing entails the processing of personal data, the EDPS considers that processing of personal data may require data protection impact assessment (DPIA) under Article 35 GDPR.
3.3 Implementing acts
21. The Proposal empowers the Commission to adopt implementing acts under the amended Article 61 of Regulation 2019/943, adding paragraphs 5a and 5b. In particular, Article 61(5b) would empower the Commission to adopt implementing acts setting out detailed requirements to enable the lawful, secure and controlled reuse of data for research and innovation-interest purposes of public interest, supporting the operation and optimisation of the electricity system pursuant to Article 18a. Those implementing acts shall (a) specify and update technical data models, formats, ontologies, interfaces, and data interoperability, (b) specify conditions of transparent and accountable operations of secure processing enabling data exchange for innovation, and (c) specify liability, risk mitigation and incident reporting in accordance with the AI Act.
22. Should any of these implementing acts concern the processing of personal data, the EDPS expects to be consulted on these legal acts pursuant to Article 42(1) EUDPR.
4. Conclusions
31. In light of the above, the EDPS makes the following recommendations:
1. To add in Recital 20 of the Proposal a reference to the applicability of the ePrivacy Directive; 2. To clarify, in the enacting terms of the Proposal, which categories and sources of data may be processed for secondary purposes under the Union-level framework; 3. To specify, in Article 18a(5) that personal data shall only be shared pursuant to the Framework when anonymised (or pseudonymised) data are not sufficient for the objective pursued and that appropriate measures must be put in place to ensure that any residual risks of (re)identification are adequately mitigated; 4. To specify that in cases where the Framework for grid data re-use would entail processing of personal data, even on a limited basis, it should clearly determine the respective data protection roles and responsibilities of the parties involved; 5. To recall, by way of a recital, the obligation to conduct a data protection impact assessment for processing operations likely to result in a high risk, which may be the case in case of large-scale processing of electricity grid data involving personal data. Brussels, 9 September 2026 (e-signed) Wojciech Rafał WIEWIÓROWSKI 8
Fotnoter
- 1 COM(2026) 600 final. 1
- 2 OJ L 295, 21.11.2018, p. 39. 3 Regulation (EU) 2019/943 of the European Parliament and of the Council of 5 June 2019 on the internal market for electricity (recast), (OJ L 158, 14.6.2019, pp. 54–124), ELI: http://data.europa.eu/eli/reg/2019/943/oj. 4 COM(2026) 600 final. See COM(2026) 600 final, Explanatory Memorandum p. 1. 6 COM(2026) 370 final. 4
- 7 COM(2025) 85. 8 COM(2026) 595. 9 COM(2025) 1005. 10 COM(2026) 115. 11 See COM(2026) 600 final, Explanatory Memorandum, p. 7. 12 See EDPS TechDispatch #2: Smart Meters in Smart Homes. See also recital 24 of the Proposal, referring to “granular consumption data”. 13 Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications), (OJ L 201, 31.7.2002, p.37), ELI: http://data.europa.eu/eli/dir/2002/58/oj. 14 See recital 16, Commission Implementing Regulation (EU) 2023/1162 of 6 June 2023 on interoperability requirements and nondiscriminatory and transparent procedures for access to metering and consumption data, (OJ L 154, 15.6.2023, pp. 10–40). See also Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive. 15 See the EDPS Formal comments on the draft Commission Implementing Regulation on interoperability requirements and nondiscriminatory and transparent procedures for access to metering and consumption data, 24 Augustus 2022, paragraph 15. 16 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, pp. 1-88), ELI: http://data.europa.eu/eli/reg/2016/679/oj. 5
- 17 See also SWD(2026) 600 final, p. 32. 18 Recital 20 and Article 18a(4) of the Proposal. 19 See section 3.2. 20 Article 18a(2) that data, introduced by Article 1(2) of the Proposal. 21 Article 18a(4) of the Proposal. 22 Article 5(1)(c) GDPR. 23 Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act) (OJ L, 2023/2854, 22.12.2023), ELI: http://data.europa.eu/eli/reg/2023/2854/o 24 Chapter II Data Act provides rights and obligations in the context of business to consumer and business to business data sharing. 6
- 25 Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act), (OJ L, 2024/1689, 12.7.2024), ELI: http://data.europa.eu/eli/reg/2024/1689/oj. 26 By specifying if they will act as controllers (Article 24 GDPR), as joint controllers (Article 26 GDPR), and/or as processors (Article 28 GDPR). On this see Guidelines 07/2020 on the concepts of controller and processor in the GDPR. 27 The reference is to the different entities that would be operational under the Framework: TSOs, DSOs, ENTSO E, the EU DSO. 7