Introduction: Your Energy Monitor Knows More Than You Think
Smart energy monitors have become an increasingly popular addition to UK homes, promising to slash electricity bills by revealing exactly where power is being consumed. Whether you have a SMETS2 smart meter supplied by your energy provider or a clip-on clamp monitor attached to your consumer unit, these devices are quietly collecting detailed data about your household's behaviour — often far more than most homeowners realise.
In 2026, with the UK's smart meter rollout now covering over 35 million meters and third-party Consumer Access Devices (CADs) widely available, the question of what happens to your energy data has never been more pressing. This guide examines the privacy and security implications of smart energy monitors in UK homes, covering what data is collected, who can access it, how it is protected, and what you can do to stay in control.
What Data Do Smart Energy Monitors Actually Collect?
The answer depends on the type of device you are using, but the data collected is often surprisingly granular.
SMETS2 Smart Meters and In-Home Displays (IHDs)
If your energy supplier has installed a second-generation smart meter (SMETS2), it communicates via the UK's national Data Communications Company (DCC) network — a secure, government-regulated infrastructure. Your meter records electricity and gas consumption at half-hourly intervals by default, though this can be adjusted.
The In-Home Display (IHD) provided by your supplier — such as the Geo Trio II or the Chameleon IHD6 — shows this data locally within your home. These devices receive data directly from the meter via a secure Zigbee Home Automation (ZHA) radio link and do not transmit your consumption data to the internet independently.
However, your energy supplier receives your half-hourly readings via the DCC network. Under the Smart Energy Code (SEC), suppliers are permitted to use this data for billing, network balancing, and — with your explicit consent — for additional services such as personalised tariff recommendations.
Consumer Access Devices (CADs)
CADs are third-party devices that connect to your SMETS2 meter's Home Area Network (HAN) and relay your consumption data to an app or cloud service. The most widely used CAD in the UK is the Hildebrand Glow (as of August 2026, available from Hildebrand's website at approximately £35–£45 including VAT). The Glow connects to your smart meter via Zigbee and sends data to Hildebrand's cloud servers, where it is accessible through the Bright app.
This is where privacy considerations become more complex. Unlike your IHD, a CAD sends your consumption data to a third-party company's servers. Hildebrand states in its privacy policy that data is stored in the UK and EU, is not sold to third parties, and is used to provide the app service and for anonymised research. However, as with any cloud-connected device, you are trusting a private company with detailed records of your household's energy use.
Clamp-Based Energy Monitors
Clip-on clamp monitors — such as the OWL Intuition-e (approximately £79.99 at Amazon UK as of August 2026) and the Efergy Elite Classic (approximately £49.99 at Amazon UK as of August 2026) — work differently. They attach a current transformer (CT) clamp to the live cable at your consumer unit and transmit readings wirelessly to a display unit or hub.
The OWL Intuition-e connects to your home Wi-Fi and uploads data to OWL's cloud platform, accessible via a web dashboard. The Efergy Elite Classic uses a proprietary 433 MHz radio link to a local display unit, with no internet connectivity in its base configuration — making it the more privacy-preserving option of the two.
More advanced whole-home monitors, such as the Sense Energy Monitor (approximately £299 at Amazon UK as of August 2026, though availability in the UK is limited — verify current stock before purchasing), use machine learning to identify individual appliances from the electrical signature on your mains supply. This device sends detailed, device-level consumption data to Sense's US-based servers — a significant privacy consideration for UK users, as data may be subject to US law rather than UK GDPR.
The Privacy Risks: What Could Go Wrong?
Behavioural Profiling from Energy Data
Academic research — including studies published by UK universities and cited by the Information Commissioner's Office (ICO) — has demonstrated that half-hourly or more frequent energy readings can reveal a surprising amount about household behaviour. Patterns in consumption data can indicate when occupants wake up, when they leave for work, when they cook meals, and even whether the property is occupied. This level of detail makes energy data a sensitive category under UK GDPR.
For clamp-based monitors that identify individual appliances (such as the Sense monitor), the granularity is even greater — potentially revealing the use of specific medical devices, the timing of television viewing, or the operation of security systems.
Data Breaches and Third-Party Access
Any cloud-connected energy monitor is only as secure as the company operating it. If a third-party CAD or monitor provider suffers a data breach, your historical consumption records could be exposed. Unlike a compromised password, you cannot simply change your energy usage history.
It is worth checking whether your chosen provider encrypts data both in transit (using TLS) and at rest, and whether they have achieved any recognised security certifications. Hildebrand, for example, states that data is encrypted in transit and at rest, though independent audits of such claims are not always publicly available.
Smart Meter Data Sharing: Who Has Access?
Under the Smart Energy Code, your energy supplier has a right to access your smart meter data for billing purposes. However, sharing your data with third parties — including price comparison sites, energy management apps, and research organisations — requires your explicit consent under UK GDPR.
The government-backed Smart Energy GB initiative and the Energy Systems Catapult have both published guidance on consumer data rights. The key points are:
- You can request that your supplier only share daily (rather than half-hourly) readings, reducing the granularity of data available.
- You can withdraw consent for third-party data sharing at any time by contacting your supplier.
- Your supplier must provide a clear explanation of how your data is used before you consent to any additional services.
UK Regulatory Framework: What Protections Exist?
UK GDPR and the Data Protection Act 2018
Energy consumption data is personal data under UK GDPR. Any company processing your energy data must have a lawful basis for doing so, must be transparent about how it is used, and must implement appropriate technical and organisational security measures. You have the right to access your data, request its deletion, and object to certain types of processing.
If you believe a company is mishandling your energy data, you can raise a complaint with the Information Commissioner's Office (ICO), the UK's data protection regulator.
The Smart Energy Code (SEC)
The SEC is a legally binding framework that governs how smart meter data is collected, stored, and shared in Great Britain. It sets strict rules on data minimisation, purpose limitation, and security standards for all parties connected to the DCC network — including energy suppliers, network operators, and authorised third parties.
Importantly, the SEC requires that any third party wishing to access your smart meter data via the DCC must be an authorised SEC party and must obtain your explicit consent. This provides a meaningful layer of protection compared to unregulated clamp-based monitors.
The Product Security and Telecommunications Infrastructure (PSTI) Act 2022
The PSTI Act, which came into full effect in April 2024, requires manufacturers of internet-connected consumer devices sold in the UK to meet minimum security standards. These include banning universal default passwords, providing a public point of contact for vulnerability reporting, and being transparent about the minimum period for which security updates will be provided.
When purchasing any Wi-Fi-connected energy monitor, check whether the manufacturer complies with PSTI requirements. Reputable UK retailers including Currys, John Lewis, and Amazon UK are required to ensure products they sell meet these standards.
Comparing the Privacy Profiles of Popular UK Energy Monitors
| Device | Data Destination | Internet Required? | UK GDPR Compliant? | Approx. UK Price (Aug 2026) |
|---|---|---|---|---|
| Geo Trio II IHD | Local only (no cloud) | No | N/A (local device) | Free from supplier |
| Hildebrand Glow CAD | Hildebrand UK/EU servers | Yes | Yes (stated) | ~£35–£45 |
| OWL Intuition-e | OWL UK servers | Yes | Yes (stated) | ~£79.99 |
| Efergy Elite Classic | Local display only | No | N/A (local device) | ~£49.99 |
| Sense Energy Monitor | Sense US servers | Yes | Uncertain (US-based) | ~£299 (limited UK availability) |
Prices are approximate as of August 2026 and are subject to change. Verify current pricing at UK retailers before purchasing.
Practical Steps to Protect Your Privacy
1. Choose a Local-First Device Where Possible
If detailed cloud analytics are not important to you, a local-only device such as the Efergy Elite Classic or your supplier-provided IHD offers the strongest privacy protection. Your data never leaves your home network.
2. Review the Privacy Policy Before Connecting
Before setting up any cloud-connected energy monitor, read the provider's privacy policy. Key questions to ask:
- Where is my data stored — UK, EU, or elsewhere?
- Is my data sold to or shared with third parties?
- How long is my data retained?
- Can I request deletion of my data?
- Is data encrypted in transit and at rest?
3. Adjust Your Smart Meter Data Sharing Settings
Contact your energy supplier to review your data sharing preferences. You can typically request:
- Daily readings only (rather than half-hourly), reducing behavioural granularity
- Withdrawal of consent for third-party data sharing
- A copy of all data your supplier holds about you (a Subject Access Request under UK GDPR)
4. Keep Firmware Updated
For any Wi-Fi-connected monitor, ensure the device firmware is kept up to date. Manufacturers are required under the PSTI Act to provide security updates for a stated minimum period — check the product listing or manufacturer's website for this information before purchasing.
5. Use a Separate IoT Network Segment
If your router supports it (many modern mesh systems from brands such as Eero, TP-Link Deco, and BT Whole Home Wi-Fi do), place your energy monitor on a separate IoT VLAN or guest network. This limits the device's access to other devices on your home network, reducing the impact of any potential compromise.
6. Be Cautious with Third-Party App Integrations
Many energy monitor apps offer integrations with platforms such as IFTTT, Google Home, or Amazon Alexa. Each integration is an additional data-sharing relationship. Only enable integrations you actively use, and review the permissions requested by each connected service.
The Loop App: A Note on Smart Meter Data Aggregators
The Loop app (free, available on iOS and Android) is a popular UK service that connects to your SMETS2 smart meter via the DCC network and provides detailed consumption analysis, tariff comparisons, and carbon footprint estimates. Loop is an authorised SEC party, meaning it must comply with the Smart Energy Code's data protection requirements.
Loop's privacy policy states that data is stored in the UK, is not sold to third parties, and is used to provide the app service and for anonymised research. The app has been positively reviewed by consumer groups including Which? for its transparency. However, as with any third-party service, you should review the current privacy policy before connecting your meter, as terms can change.
What About Smart Meter Hacking? Is It a Real Risk?
The DCC network uses end-to-end encryption and requires cryptographic authentication for all communications. The risk of a remote attacker directly accessing your smart meter via the DCC is considered low by the National Cyber Security Centre (NCSC). However, the NCSC has noted that the broader ecosystem of third-party apps and CADs introduces additional attack surface.
The more realistic risks are:
- Account compromise: If your energy monitor app account is accessed by an attacker (e.g., through a weak or reused password), they could access your historical consumption data.
- Insecure home Wi-Fi: A poorly secured home network could allow a local attacker to intercept data from a Wi-Fi-connected monitor.
- Supply chain risks: Devices from less reputable manufacturers may contain vulnerabilities or undisclosed data collection.
Using a strong, unique password for your energy monitor app account and enabling two-factor authentication (2FA) where available are the most effective mitigations against account compromise.
Conclusion: Informed Choices for a Smarter, Safer Home
Smart energy monitors offer genuine value — helping UK households reduce bills, understand consumption patterns, and contribute to a more efficient national grid. But they also introduce privacy considerations that deserve careful thought.
The good news is that the UK's regulatory framework — combining UK GDPR, the Smart Energy Code, and the PSTI Act — provides meaningful protections that are stronger than those available in many other countries. By choosing reputable devices, reviewing privacy policies, adjusting your data sharing settings, and following basic security hygiene, you can enjoy the benefits of smart energy monitoring while keeping your household data under control.
As with all smart home technology, the key is to make an informed choice rather than simply plugging in and hoping for the best. Your energy data is a detailed portrait of your home life — it deserves the same care as any other personal information.