Administered by

  • HOME
  • CONTACT US
  • ABOUT THIS SITE
  • DISCLAIMER
  • Supported by
  • Australian Renewable Energy Agency (ARENA)
English (UK)
GB English (UK)
US English (US)
  • EXPLORE KNOWLEDGE BASE

  • CERI Knowledge Base

    • About the CERI knowledge base

      • Introduction to Australia’s electricity markets

        • Australian consumer insights

          • CER technical and interoperability standards

            • Connecting a customer to an electricity network

              • Connecting a generator to a distribution network

                • Utility interconnection (CSIP-AUS)

                  • Dynamic network export and generation control schemes

                    • Network load control schemes

                      • Network tariffs and network support services

                        • Participating in the National Electricity Market

                          • Participating in a frequency control market

                            • Participating in the RERT

                              • Participating in the Wholesale Electricity Market (Western Australia)

                                • Participating in the I-NTEM (NT)

                                  • Cyber security and data privacy arrangements

                                    • Consumer protection frameworks

                                    Access customer data and the Consumer Data Right

                                    Last Updated on 3 August 2026

                                    SUGGEST AN EDIT

                                    LIKE THIS PAGE?

                                    Table of Contents

                                    Key points What is the Consumer Data Right? What data is covered by the CDR? Data holders and data recipients Examples of potential CDR framework use-cases Practical implications for CER product developers Real time data access NEM12 consumer access and data format Recent privacy reforms and their impact Related articles

                                    As Australia’s energy sector becomes increasingly digital, the ability for consumers and authorised third parties to access energy data is central to innovation, transparency, and consumer empowerment. This section outlines the main mechanisms for data access within the NEM and reforms intended to support more flexible, real time and secure data exchanges into the future.

                                    Key points

                                    • The Consumer Data Right allows consumers to access certain data and authorise its sharing with accredited third parties.
                                    • Accredited data recipients must obtain consent and meet privacy, security and governance requirements.
                                    • CER providers can use authorised data to support system sizing, tariff comparison and customer onboarding.
                                    • NEM12 files provide interval metering data but can be difficult for residential customers to interpret.
                                    • Proposed real-time data arrangements would provide more granular smart-meter information through retailer or metering-coordinator interfaces.

                                    What is the Consumer Data Right?

                                    The CDR is a legislative framework that gives individuals and businesses the right to access data held about them by service providers and to authorise its secure sharing with accredited third parties. In the energy sector, the CDR covers a broad range of data, including customer details, account and billing information, metering data, tariff and product data, and DER Register data.

                                    The CDR’s main aim is to help consumers find better energy deals and to enable product innovation. For product developers, CDR provides a mechanism to access and leverage data types they may not otherwise be able to access provided they meet strict accreditation and compliance requirements.

                                    The Office of the Australian Information Commissioner (OAIC) oversees privacy compliance, while the ACCC manages accreditation, monitoring, and enforcement.

                                    What data is covered by the CDR?

                                    The CDR's scope is both broad and data types relevant to CER include:

                                    • Customer details (name, address, contact information, National Metering Identifier or NMI)
                                    • Energy generation and consumption data (from smart meters, rooftop PV, batteries, EV chargers)
                                    • Power quality data (voltage, frequency)
                                    • Telemetry data (automated sensing and control information)
                                    • Standing/connection point data (NMI, supply address, meter type, CER installation details)
                                    • Pricing data (tariffs, bills, fees, charges)

                                    Data holders and data recipients

                                    Under the CDR framework, data holders are organisations such as energy retailers or AEMO that are legally required to store and provide access to specific consumer datasets when requested. Their role is to securely manage and share this data in accordance with CDR rules and privacy safeguards. In contrast, accredited data recipients are third parties, like energy management platform providers or CER product developers, who have been formally accredited to receive and use CDR data. These recipients must obtain explicit consumer consent, meet strict privacy and security standards, and use the data solely for the agreed purposes, ensuring robust protection and responsible handling of consumer information.

                                    AEMO acts as a central gateway for certain technical datasets, such as metering data, NMI standing data, and DER Register information. However, customer-related data like account details and billing records are typically provided directly by electricity retailers. In summary, AEMO consolidates and provides technical and metering data, while retailers remain responsible for supplying most customer account and billing information.

                                    The CDR regime imposes a set of Privacy Safeguards on data holders and recipients that are stricter than the APPs in several respects:

                                    • Consent: Data sharing is opt-in and requires clear, granular, and revocable consent from the consumer.
                                    • Data minimisation: Only the data necessary for the requested service can be collected and used.
                                    • Security: Accredited parties must implement robust technical and organisational measures to protect CDR data, including encryption, access controls, and breach notification protocols.
                                    • Transparency: Consumers must be informed about what data is collected, how it will be used, and with whom it will be shared.
                                    • Access and correction: Consumers have the right to access and correct their CDR data.
                                    • Deletion: Data must be deleted or de-identified when no longer needed for the purpose for which it was collected.
                                    • No on-selling: CDR data cannot be sold or used for direct marketing without explicit consent.

                                    Examples of potential CDR framework use-cases

                                    By enabling secure, consent-driven access to detailed energy and customer data, the CDR allows providers to deliver more personalised, efficient, and value-added solutions to Australian consumers. Below are several illustrative examples illustrating how CER providers can leverage the CDR:

                                    • Personalised energy management: The CDR enables accredited third parties to obtain interval metering data (with consumer consent) from electricity retailers or AEMO. This data can be analysed to recommend optimal CER sizing and configuration based on actual consumption patterns.
                                    • Automated tariff comparison: The framework was specifically designed to empower consumers to find better energy deals by sharing their usage and tariff data with accredited comparison services.
                                    • Streamlined onboarding: Using DER Register and/or account information held by the energy retailer to pre-fill account details and verify eligibility for new CER products or services is also supported by the CDR. The framework allows access to customer account data and DER Register information (with consent), which can be used to simplify onboarding processes and ensure customers are matched with suitable products.

                                    Practical implications for CER product developers

                                    Access to CDR data enables developers to offer more tailored customer acquisition, onboarding and energy management solutions. However, all innovations must be underpinned by robust privacy and security practices. CER product developers and service providers looking to make use of CDR mechanisms need to understand the scheme requirements and processes which require significant time and effort. Some of the practical considerations when deciding whether to go down that path include:

                                    • Getting accredited: To access CDR data, CER product or service providers must become accredited data recipients. This involves a rigorous application process, demonstrating compliance with privacy, security, and governance requirements.
                                    • Customer interface requirements: For customer consent management data recipients must design user interfaces and consent flows so that are clear, user-friendly, and compliant with CDR rules. Consumers must be able to easily understand what data is being shared, for what purpose, and how to withdraw consent.
                                    • Data handling and security: All CDR data must be handled in accordance with the Privacy Safeguards which are more rigorous than baseline requirements under the Privacy Act. These include secure storage, transmission, and processing, as well as regular audits and breach reporting.
                                    • Ongoing compliance: The CDR framework is evolving, with new rules, standards, and datasets being introduced. Developers should stay up to date with regulatory changes and participate in industry consultations.

                                    Real time data access

                                    The AEMC has proposed Real-time data for consumers reforms to enable all electricity consumers to access real-time data from their smart meters. If the reform proceeds, starting 1 January 2028, consumers will be able to request this data directly from their electricity retailer or MC.

                                    Key information about the proposal:

                                    • Real-time data is defined as voltage, current, and phase angle typically recorded every second and delivered within a second
                                    • From 2028, specifications for newly installed smart meters will include functionality to communicate real-time data both wirelessly and through a wired connection. Customers without this metering capability will be able to access it via API.
                                    • Prior to 2028, customers may request data access for a fee (subject to retailer and MC capabilities).
                                    • Data must be provided in a standardised, interoperable format defined by AEMO
                                    • Retailers and metering coordinators will be responsible for facilitating consumer access to this data, following procedures set by AEMO. These procedures will likely include essential cybersecurity controls.

                                    Under this approach, the AEMC estimates that approximately 15 per cent of consumers across NSW, the ACT, SA and QLD would have access to real-time data, at no charge, by 2030. Victorian customers already have access to near-real-time data at no charge

                                    For CER product developers, this reform presents significant opportunities and new requirements. CER will be able to leverage granular, real-time data to optimise device operation and comply with export limits with reduced costs associated with additional CT and metering hardware and installation costs. However, developers must ensure their products can securely interface with smart meters and retailer or metering coordinator APIs, process high-frequency data streams, and comply with evolving privacy and cybersecurity requirements.

                                    The proposed reforms for real time data access operate in parallel to the current CDR framework. While CDR governs verified, settlement-quality energy data (e.g., metering data, NMI standing data, DER Register information) shared through accredited data holders like AEMO and retailers, real-time data is raw, unvalidated telemetry, making many CDR obligations, in the AEMC’s consideration unsuitable.

                                    NEM12 consumer access and data format

                                    NEM12 is the standard file format used in the NEM for providing interval metering data to consumers and authorised third parties. The format was established as part of reforms introduced by the AEMC in 2015, which aimed to give consumers better access to their energy data and empower them to make informed choices about energy usage and tariffs.

                                    Under NER Clause 7.16, AEMO is responsible for setting procedures for how metering data must be provided and it determined that retailers are required to supply customers with their interval data in the NEM12 format. This is a structured and machine-readable CSV file containing half-hourly or five-minute energy consumption readings, meter identifiers, and timestamps.

                                    To facilitate understanding, each retailer must also provide a “Retail Customer Metering Data Guide.” This guide helps customers interpret the NEM12 file, explaining the meaning of each field and how to use the data for analysis or comparison.

                                    Consumers can request their NEM12 data directly from their retailer, who must supply it within a set timeframe. Accredited third parties, such as energy management platforms or comparison services, can also access this data with the customer’s consent, supporting innovation and personalised energy solutions.

                                    Despite the goals of this reform, the NEM12 format is broadly considered too complex to be used effectively by most residential consumers.

                                    Recent privacy reforms and their impact

                                    Australia’s privacy regime is undergoing its most significant overhaul in decades. The Privacy and Other Legislation Amendment Act 2024 introduced reforms that began rolling out in late 2024 and will continue through 2026.

                                    These changes could have significant implications for CER product and service providers. Enforcement powers have been expanded, giving the Office of the Australian Information Commissioner (OAIC) the ability to issue infringement notices and impose civil penalties of up to AU$3.3 million for companies. Security obligations have been clarified, requiring documented technical and organisational measures rather than vague policy statements.

                                    By 10 December 2026, organisations regulated by the Privacy Act will be required to update their privacy policies and disclose when decisions such as tariff recommendations or energy optimisation that could significantly affect individuals’ rights or interests are made using algorithms, AI or other automation systems.

                                    These changes signal a shift towards a more rigorous, GDPR-like model that prioritises accountability and harm prevention. For CER developers, compliance must be embedded in product design and reflected in associated online and printed documentation. CER providers should limit data collection to what is necessary for functionality and provide clear, informed consent processes. Security measures such as encryption, secure APIs, and role-based access controls must be implemented alongside governance frameworks that demonstrate compliance.

                                    Cross-border data transfers need careful planning, particularly if offshore cloud services are involved. Organisations should monitor developments on “whitelisted” jurisdictions for streamlined transfers.

                                    A second tranche of changes is expected after 2025, potentially introducing a “fair and reasonable” test for data handling. Staying engaged with OAIC guidance and industry consultations will be critical.

                                    Related articles

                                    • Cybersecurity and data privacy arrangements
                                    • Australia’s Privacy Principles
                                    • Data sovereignty and data residency requirements
                                    • Consumer protection frameworks
                                    consumer rights data access data cdr framework real time data nem privacy reform privacy

                                    Copyright 2026 – CERI.

                                    Knowledge Base Software powered by Helpjuice

                                    Expand