Administered by

  • HOME
  • CONTACT US
  • ABOUT THIS SITE
  • DISCLAIMER
  • Supported by
  • Australian Renewable Energy Agency (ARENA)
English (UK)
GB English (UK)
US English (US)
  • EXPLORE KNOWLEDGE BASE

  • CERI Knowledge Base

    • About the CERI knowledge base

      • Introduction to Australia’s electricity markets

        • Australian consumer insights

          • CER technical and interoperability standards

            • Connecting a customer to an electricity network

              • Connecting a generator to a distribution network

                • Utility interconnection (CSIP-AUS)

                  • Dynamic network export and generation control schemes

                    • Network load control schemes

                      • Network tariffs and network support services

                        • Participating in the National Electricity Market

                          • Participating in a frequency control market

                            • Participating in the RERT

                              • Participating in the Wholesale Electricity Market (Western Australia)

                                • Participating in the I-NTEM (NT)

                                  • Cyber security and data privacy arrangements

                                    • Consumer protection frameworks

                                    Australia’s Privacy Principles

                                    Last Updated on 3 August 2026

                                    SUGGEST AN EDIT

                                    LIKE THIS PAGE?

                                    Table of Contents

                                    Key points What CER data is personal information? How does the CDR apply to customer energy data? Noteworthy Australian Privacy Principles Emerging considerations for Artificial Intelligence Related articles

                                    The Privacy Act 1988 regulates how CER manufacturers and service providers collect, use, disclose and protect personal information. It applies to most private sector organisations with an annual turnover above AU$3 million, as well as smaller entities that handle sensitive data. It is built around the APPs, which set standards for how organisations manage “personal information”.

                                    Key points

                                    • Organisations should collect only the information needed for their activities and explain how it will be used.
                                    • Personal information must be protected against misuse, loss and unauthorised access or disclosure.
                                    • Overseas disclosure and sharing between organisations require appropriate privacy controls.
                                    • AI creates additional challenges involving training data, transparency, retention and deletion.

                                    What CER data is personal information?

                                    Under the Privacy Act, personal information (often referred to as “PII, personally identifiable information”) is any data or combination of data that can reasonably identify an individual or make them reasonably identifiable. In the CER context, personal information can include:

                                    • obvious identifiers such as names, addresses, contact details and customer account information
                                    • NMI-linked data
                                    • meter identifiers, standing or connection point data, IP addresses
                                    • telemetry, interval energy data, device-level operational data or power-quality data when associated with a specific household
                                    • any information that can reveal behavioural patterns such as occupancy, appliance use, EV charging routines or battery usage
                                    • inferred or derived data that can be reasonably linked back to a person or premises

                                    Not all CER data is automatically personal information. It becomes personal information where it is linked, or can reasonably be linked, to a person, household, address or device in a way that makes an individual identifiable.

                                    How does the CDR apply to customer energy data?

                                    Under the CDR, datasets such as customer details, account information, billing history, metering data and DER Register information are treated as “CDR data” and are subject to strict privacy safeguards. Data-sharing agreements and contractual privacy clauses are increasingly important for managing compliance and liability when CER data is exchanged between entities.

                                    Noteworthy Australian Privacy Principles

                                    The 13 Australian Privacy Principles include:

                                    • APP 1: Open and transparent management of personal information: Organisations must manage personal information in an open and transparent way, including having a clearly expressed and up-to-date privacy policy.
                                    • APP 3: Collection of solicited personal information: Organisations can only collect personal information that is reasonably necessary for their functions or activities and must do so by lawful and fair means.
                                    • APP 5: Notification of the collection of personal information: Organisations must notify individuals when collecting their personal information, including why it is being collected and how it will be used.
                                    • APP 6: Use or disclosure of personal information: Personal information can only be used or disclosed for the purpose for which it was collected, unless an exception applies (such as consent or legal requirement).
                                    • APP 8: Cross-border disclosure of personal information: Organisations must ensure that overseas recipients of personal information provide equivalent privacy protections.
                                    • APP 11: Security of personal information: Organisations must take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure.
                                    • APP 12: Access to personal information: Individuals have the right to access their personal information held by organisations, subject to certain exceptions.

                                    For CER developers, the most relevant principles might include those requiring transparency and accountability. Organisations must publish clear privacy policies and allow individuals to access and correct their data. They must also ensure that personal information is collected only when necessary and used for the purpose stated at the time of collection.

                                    APP 11 requires organisations to take reasonable steps to protect personal information, which now means implementing robust technical and organisational measures such as encryption, access controls, and governance frameworks. Data masking is considered a key technical control for protecting personal information within the energy sector. Data masking involves systematically obfuscating or de-identifying sensitive data elements in datasets, ensuring that personal information cannot be directly linked to individuals when shared internally or with third parties.

                                    Cross-border transfers are another area of concern, as APP 8 restricts overseas disclosures unless equivalent protections apply. This is further discussed in the article on Data Sovereignty and Data Residency Requirements.

                                    Emerging considerations for Artificial Intelligence

                                    Artificial Intelligence (AI) is emerging as a key factor in the cybersecurity and data governance landscape of Australia’s energy sector. As CER programs and devices generate large volumes of operational and customer data, AI is increasingly used for processing, optimisation, forecasting, anomaly detection and producing insights.

                                    For CER developers and data holders, AI introduces new considerations:

                                    • Data handling: Training models often require historical telemetry and customer data. When this includes personal or CDR data, compliance with the Privacy Act, APPs, and CDR Privacy Safeguards is essential.
                                    • Control and transparency: Automated decision-making raises due diligence requirements around decision-making governance, model transparency and auditability, critical for both cyber, safety, and authorised use.
                                    • Data retention: Once data has been used to train a model, it is difficult to remove if consent is later withdrawn, which creates tension with privacy obligations. Additionally, contractual issues can arise when data is required to be deleted at the end of a services agreement.
                                    • Restrictions on public AI models: Many businesses voluntarily prohibit public AI tools for sensitive data due to risks of leakage and foreign jurisdiction access. There is growing demand for models to be hosted in Australia to meet Australian data and privacy requirements. It is not uncommon for critical infrastructure providers (and other businesses) to require separation between public AI models from ICT systems containing sensitive data covered by federal or state legislation.

                                    AI is a rapidly evolving area of regulatory focus. As adoption grows, industry expects stricter requirements to emerge around transparency in AI usage, data retention and data partitioning.

                                    Related articles

                                    • Cybersecurity and data privacy arrangements
                                    • Access customer data and the Consumer Data Right
                                    • CER Cybersecurity Roadmap
                                    • Consumer protection frameworks
                                    privacy regulations australia cer privacy act regulatory confidentiality data protection

                                    Copyright 2026 – CERI.

                                    Knowledge Base Software powered by Helpjuice

                                    Expand