FPF Summary of CPUC Smart Grid Rules

FPF Summary of CPUC Smart Grid Rules

On May 6, 2011, the California Public Utilities Commission (CPUC) issued a proposed decision addressing privacy and security concerns around the Smart Grid.  The CPUC proposed decision is significant, because it presents the most significant step yet in the U.S. towards a comprehensive set of smart grid privacy rules. 
With that in mind, we have prepared a brief summary of the CPUC proposed decision to help navigate the terrain.  

Among the highlights: 

  • Overall, the proposed decision develops a regulatory framework that is wide-ranging in reach.  It would apply privacy and security rules to customers of California’s three investor-owned electric utilities offering or proposing to install smart meters, and extend the proposed rules to the companies that contract with these utilities. 
  • Most notably, the proposed rules would also apply, by utility tariffs, to certain third party companies that are not in contractual privities with a utility.
  • Specifically, a third party would have to comply with the PUC rules when it obtains access to customer’s usage data via Home Area Netwok (HAN)-enabled devices that are “locked” to automatically transfer usage data to the third party. 
  • According to the proposed rules, a covered entity would have to provide customers with transparency through a notice and privacy policy that will be “meaningful, clear, accurate, specific, and comprehensive notice regarding the collection, store, use, and disclosure of covered information.”  Customers would be given access to, and a certain level of control over the collection, storage, use and disclosure of their covered information.  
  • The proposed rules would require utilities to provide third parties with access to usage data that customers authorize if the third parties comply with the privacy and security rules. 

There are several principles targeted toward data management. Covered entities will be limited in their ability to collect data—only information that is “reasonably necessary” or “authorized by the Commission” to accomplish primary or secondary purposes.  Covered entities must have prior customer consent to collect, store and use information, except that electrical corporations may collect and store customer data without customer consent if for a primary purpose.  Subject to certain conditions, covered entities may share information with service providers without consent.  Covered entities must also ensure the quality, integrity, and security of the data. Finally, the PUC imposes data security and privacy audit and reporting requirements which include providing copies of the privacy notices for customers, internal privacy and data security policies, third party disclosure information and secondary uses authorization forms.  The PUC rejected suggestions that third parties should be required to register for certification to offer services that require access to customer energy consumption data.

For a more comprehensive look into the proposed decision, see the FPF summary here

The CPUC is accepting comments regarding its proposed rules until May 26, 2011, with reply comments due five days after that deadline.  FPF will be filing its comments in the upcoming weeks.

Many thanks to our colleague Tim Tobin for his excellent and comprehensive review of the decision.

Leave a Reply

Privacy Calendar

all-day Global Privacy Summit 2015
Global Privacy Summit 2015
Mar 4 – Mar 6 all-day
For more information, click here.
6:00 pm CDT Annual Dinner “TechProm” 2015
CDT Annual Dinner “TechProm” 2015
Mar 10 @ 6:00 pm – 9:00 pm
Featuring the most influential minds of the tech policy world, CDT’s annual dinner, TechProm, highlights the issues your organization will be facing in the future and provides the networking opportunities that can help you tackle[...]
all-day BCLT Privacy Law Forum
BCLT Privacy Law Forum
Mar 13 all-day
This program will feature leading academics and practitioners discussing the latest developments in privacy law. UC Berkeley Law faculty and conference panelists will discuss cutting-edge scholarship and explore ‘real world’ privacy law problems. Click here[...]
all-day PL&B’s Asia-Pacific Roundtable (...
PL&B’s Asia-Pacific Roundtable (...
May 27 all-day
PROFESSOR GRAHAM GREENLEAF, Asia-Pacific Editor, Privacy Laws & Business International Report, will lead a roundtable on the countries of most interest to business in the Asia-Pacific region. Click here for more information.
all-day PL&B’s 28th Annual International...
PL&B’s 28th Annual International...
Jul 6 – Jul 8 all-day
The Privacy Laws & Business 27th Annual International Conference featured more than 40 speakers and chairs from many countries over 3 intensive days. At the world’s longest running independent international privacy event participants gained professionally by[...]
all-day Data Privacy Day
Data Privacy Day
Jan 28 – Jan 29 all-day
“Data Privacy Day began in the United States and Canada in January 2008, as an extension of the Data Protection Day celebration in Europe. The Day commemorates the 1981 signing of Convention 108, the first[...]
all-day Data Privacy Day
Data Privacy Day
Jan 28 – Jan 29 all-day
“Data Privacy Day began in the United States and Canada in January 2008, as an extension of the Data Protection Day celebration in Europe. The Day commemorates the 1981 signing of Convention 108, the first[...]

View Calendar