Solar Data Privacy: What Your Monitoring System Reveals About You

Smart meter gateway with GPRS, WiFi and LAN radio links mounted in a consumer unit beside meter wiring


The interesting thing about a solar monitoring system is not that it watches your panels. It is that your installation was registered with your name, your address and a set of serial numbers, and the platform now holding that record is generally run by a company in another country, on infrastructure you do not control, under terms most people never read. Nobody broke into anything to arrange this. You signed up for a useful feature, and the privacy question starts there.

Solar data privacy is unglamorous but has one clear point: a system that tells you your power is flowing also knows a great deal about how you live. This is what gets recorded, who can read it, what Nigerian law says about it, and the decisions that put you back in charge.

What a monitoring system actually records

Break it into two piles, because they behave differently. The first is about the equipment: panel count and model, serial numbers, firmware versions, string voltages, energy generated and the fault history. That is hardware, and close to harmless in itself.

The second is about the household, and it arrives when the system measures consumption rather than generation. Import and export readings, a load figure, a battery state of charge at five-minute intervals, all timestamped to your site name and address. A production graph is a solar graph. A consumption graph is a domestic routine, plotted.

Then there is the account layer: an email address, a phone number if you enabled alerts, the users you invited, and a log of when each logged in and from where. This is the layer that turns a technical service into personal information, and the easiest to reduce and hardest to remove once it exists.

Solar data privacy and what your consumption curve reveals

This is the part worth thinking about, because it is not exotic. Someone with your data and nothing else can work out a great deal.

A long flat line in the middle of the day is a property that is empty. A load that appears every evening at the same time and lasts until late is a household with a routine. A step that never comes back down is a new permanent appliance, and a kilowatt or two points to something like an air conditioning unit or a water heater. A morning peak of around half a kilowatt that vanishes on Sundays suggests a pump on a timer. None of this requires hacking. It requires a graph and some patience.

It is also information about people who did not choose to share it. The household includes a tenant, a live-in househelp, children and visitors, and the curve describes all of them. That should make an installer or a business owner pause, and it is why minimising collection is not box-ticking. The UK Information Commissioner’s guidance on data minimisation puts it plainly: personal data should be adequate, relevant and limited to what is necessary, so hold that much and no more.

For a homeowner the practical version is simpler. If you only want alerts when the system stops producing, you do not need a portal keeping a year of five-minute data. That is a specification, not a complaint about the vendor, and privacy follows from it.

What the platform provider can see and do

Be clear-eyed about the relationship. The platform is a commercial service run by somebody else, and the terms accepted when the installer registered the site are the actual contract. Those terms decide who the data is shared with and how long it is kept.

What is held Who can realistically see it Why it matters
Site name, address, GPS location, equipment serial numbers The platform operator, the installer who registered it, their support staff Identifies a home and the value of what is inside it
Half-hourly or finer production and consumption history Platform operator; installers working on the account; the vendor’s own analytics Supports occupancy, routine and appliance inference
Account email, phone number, push notification tokens Platform operator, and any messaging provider it uses for alerts Contact details, and alert history showing when you are active

For a business, add the commercial dimension: site portfolios, aggregated performance, and who may see an employee’s home consumption pattern. For a home, the honest summary is that the data is valuable to a vendor and only mildly valuable to you. Larger organisations work through this deliberately, which is what the NIST Privacy Framework supports: a voluntary tool for identifying and managing privacy risk.

What the Nigeria Data Protection Act says about this

Nigeria has a data protection law with real teeth, and it reaches further than most people assume. Three provisions matter here, and none of them requires you to be a lawyer to apply.

The first is scope. The Act applies where the controller is domiciled in Nigeria, where processing happens in Nigeria, or where a controller outside Nigeria processes the personal data of a data subject in Nigeria. That last limb is why a platform hosted outside the country is not outside the law because its servers are elsewhere. Section 2 sets this out.

The second is the household exemption, and it has a condition people rarely notice. Section 3 says the Act does not apply to processing carried out solely for personal or household purposes, provided that such processing does not violate the fundamental right to privacy of a data subject. The proviso does real work: the moment a company runs an account on your behalf, or a platform starts serving a business rather than a household, the simple household framing stops being a complete answer.

The third is the substance, and it is close to what instinct already assumes. Section 24 requires personal data to be collected for specified, explicit and legitimate purposes, to be adequate, relevant and limited to the minimum necessary, to be retained no longer than needed, and to be processed with appropriate security. Section 27 requires a controller to tell you, before collecting, who they are, the lawful basis, the recipients, your rights and the retention period. Section 28 requires a data privacy impact assessment where processing is likely to create high risk. Part VI gives you the right to confirmation and access, to object, to withdraw consent as easily as you gave it, and not to face significant decisions made solely by automated processing including profiling. The Nigeria Data Protection Act 2023 is the text to read if this becomes concrete, and a lawyer is the person to ask a specific question rather than a general one.

Default credentials: the privacy hole nobody closes

The likeliest exposure is not a breach at the vendor. It is a default password on a logger or inverter whose local access point is still reachable, covered in our guide to solar monitoring security. Default credentials are the same problem across every connected device: they exist to get a product working in the first minute, they are published, and they are rarely changed.

The second path is social. A shared installer account means a former contractor can still see your history, address and contact details, because nobody closed the account when the job ended. Per-person accounts with the least access each person needs, removed on the day the work finishes, is the whole fix.

The third is the photograph. Nobody treats a commissioning photo as a privacy issue, and it is one: a close-up of a wall can show the distribution board, the property number, a neighbour’s gate and, often, a family picture in the background.

Solar data privacy decisions you can make today

Six, none needing a lawyer or a new device.

  1. Read the privacy notice and retention period on your portal, and find out how to request deletion. If the page does not say, that is your answer about how much attention privacy gets there.
  2. Turn off load reporting if offered and keep production alerts only. You lose a dashboard feature and gain most of the reduction in what is inferred.
  3. Rename the site so it reveals nothing. No trading name, no pharmacy name, no street address in the title.
  4. Use separate accounts for the owner, the business and each technician, and delete them when the work ends.
  5. Ask the provider one question in writing: who else receives my data, where is it stored, and how long is it kept.
  6. If you run a business, decide in advance whether staff home consumption is ever visible to a manager. If not, say so and configure the platform that way.

None of this is paranoia. It is the care you would give a bank account, applied to a service most people never thought held anything worth protecting.

Frequently asked questions

Is solar monitoring data really personal data?

It depends on who holds it and what it is attached to. Serial numbers and a production curve describe a device. Attach a name, an address and a half-hourly consumption history and you have information about an identifiable household. For a business aggregating sites, the analysis is easier still.

Can I delete my data from the monitoring platform?

Ask, and the answer is worth knowing either way. Some platforms let an owner request an export or deletion; others retain data for warranty and service purposes and will say so. If you are moving to a new installer, ask for an export of your commissioning data too, because its value rises sharply once the portal is gone.

Does anyone actually look at my consumption data?

Not a person, day to day. The concern is aggregation, automated analysis, a support team pulling your history when you ring with a fault, and a compromised account exposing it all to a stranger. How you manage credentials is the bigger lever.

Key Takeaways

  • Monitoring holds equipment data, but the household data arrives the moment the system measures consumption rather than generation.
  • A consumption curve reveals occupancy, routine, absence and which appliances you own, without any attack being needed.
  • The Nigeria Data Protection Act reaches controllers outside Nigeria processing the data of a data subject in Nigeria.
  • The household exemption in section 3 carries a condition, so business use and shared accounts change the analysis.
  • Sections 24 and 27 give you purpose, minimisation, retention and disclosure, and section 28 covers high-risk processing.
  • Site naming, per-person accounts, turning off load reporting and one written question to the provider are the practical steps.

For the technical side of keeping the account and the hardware to yourself, solar inverter and smart monitoring security is the next read.

Sources: Nigeria Data Protection Act 2023, sections 2, 3, 24, 27, 28 and Part VI; UK Information Commissioner’s Office, data minimisation; NIST Privacy Framework, managing privacy risk; Default password, why factory credentials are left unchanged.

ABDULHAFEEZ OYEWO Solar Security 0 Comments

0 Comments

Your email address will not be published. Required fields are marked *