<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>consultation &#8211; Icebreaker One</title>
	<atom:link href="https://ib1.org/tag/consultation/feed/" rel="self" type="application/rss+xml" />
	<link>https://ib1.org</link>
	<description>Making data work harder to deliver net-zero</description>
	<lastBuildDate>Thu, 10 Sep 2026 09:25:42 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.6</generator>

<image>
	<url>https://ib1.org/wp-content/uploads/2020/11/cropped-00-IB1-Roundel-Yellow-X-Small-128px-rgb-32x32.png</url>
	<title>consultation &#8211; Icebreaker One</title>
	<link>https://ib1.org</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>IB1 response to DSIT’s Empowering people through data intermediaries consultation</title>
		<link>https://ib1.org/2026/08/27/ib1-response-to-dsits-consultation-empowering-people-through-data-intermediaries/</link>
		
		<dc:creator><![CDATA[Emma Gray]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 13:53:53 +0000</pubDate>
				<category><![CDATA[Consultations]]></category>
		<category><![CDATA[consultation]]></category>
		<category><![CDATA[smart data]]></category>
		<guid isPermaLink="false">https://ib1.org/?p=21828</guid>

					<description><![CDATA[This is Icebreaker One’s response to DSIT’s Empowering people through data intermediaries. It can be published openly. Please note that throughout this consultation, Icebreaker One uses the terms Open, Shared and Closed data as defined here. If you have any questions about our submission or require clarifications please do not hesitate to contact us via [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">This is Icebreaker One’s response to DSIT’s <a href="https://assets.publishing.service.gov.uk/media/6a230cba56960b0542c0b11f/E03616462_-_Data_Intermediaries_Consultation_Accessible_v03.pdf">Empowering people through data intermediaries</a>. It can be published openly.</p>



<p class="wp-block-paragraph">Please note that throughout this consultation, Icebreaker One uses the terms Open, Shared and Closed data as defined <a href="https://icebreakerone.org/open-shared-closed/">here</a>.</p>



<p class="wp-block-paragraph">If you have any questions about our submission or require clarifications please do not hesitate to contact us via <a href="mailto:policy@ib1.org">policy@ib1.org</a>. We have omitted questions which we did not answer.&nbsp;</p>



<p class="wp-block-paragraph">Thank you for considering our submission.</p>



<h1 class="wp-block-heading"><strong>Consultation response:</strong></h1>



<p class="wp-block-paragraph"><strong>Amending UK GDPR</strong></p>



<p class="wp-block-paragraph"><strong>Question 1: To what extent do you agree or disagree with this statement: Providing legislative clarity alone in UK GDPR would be sufficient to address barriers faced by intermediaries?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 2: If UK GDPR were amended to clarify the role of intermediaries, do you think any further details should be included alongside explicit delegation of data subject rights, for example, guidance, code of practice, specific data formats, frequency, or how portability should operate in practice?</strong></p>



<p class="wp-block-paragraph">While we agree that clarification of delegation would be beneficial to data subjects, any amendment to UK GDPR must be made carefully, in consultation with EU and other international data protection counterparts alongside operators of UK governance schemes that incorporate GDPR such as Open Banking and the Smart Energy Code. In particular, the change must not put EU adequacy determinations at risk, as the economic and social impacts of a weakened or lost adequacy status are likely to be disproportionate to the benefit.</p>



<p class="wp-block-paragraph">If UK GDPR is amended, the purpose of, and limits to operation of, data intermediaries need to be made clear in the drafting in order to build trust. The drafting should include requirements for them to be: Neutral &#8211; the purpose for the data processing cannot be set by the intermediary; Fiduciary &#8211; acting strictly in the data subject’s interest, not in their own or a third party’s; Permissioned &#8211; possessing reliable evidence for permission to act as delegate for a scoped purpose.</p>



<p class="wp-block-paragraph">To aid adoption and oversight, these requirements could be provided as model contract or privacy policy terms for intermediaries to execute as part of their usage agreements with the data subjects on whose behalf they act.</p>



<p class="wp-block-paragraph"><strong>Regulation</strong></p>



<p class="wp-block-paragraph"><strong>Question 3: What obligations on data controllers, if any, would be effective in supporting requests made via authorised data intermediaries?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 4: How burdensome would an authorisation or registration requirement on intermediaries be for your organisation?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 5: What would be the advantages and/or disadvantages of the UK implementing a regime similar to that of the EU’s regime?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 6: To what extent could it help to build trust between intermediaries, controllers and individuals?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 7: How important do you view regulatory alignment with the EU for your operations, given potential changes arising from the Digital Omnibus proposal?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 8: To what extent would a voluntary registration process for intermediaries likely be sufficient, to ensure services comply with rules?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 9: For data controllers: would an EU-style model make you more likely to accept delegated requests from intermediaries on an official register?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 10: If a certification scheme were adopted for data intermediaries in the UK, who would be best suited to carry out the certification process? For example: self-certification, regulator certification, government certification or third-party certification.</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 11: To what extent do you agree or disagree with the following statement: an authorisation scheme (whether notification-based, registration, or licensing-based) would meaningfully reduce the uncertainty or friction you/your organisation currently face?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 12: For data controllers: How important is formal recognition of intermediaries (e.g., being listed, registered, or licensed) in giving you confidence as a data controller to accept delegated rights requests?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 13: Which of the following approaches would best strike the right balance between assurance and proportionality for your sector?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 14: To what extent would requiring the use of Portability APIs affect the level of friction your organisation experiences when responding to or submitting delegated data access requests?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 15: How would requiring mandatory APIs affect your organisation’s compliance costs, especially relative to existing data portability obligations?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 16: Which of the following would need further standardisation to make mandatory APIs more workable?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Non-Legislative Options</strong></p>



<p class="wp-block-paragraph"><strong>Question 17: For data controllers: To what extent would a non-statutory authorisation scheme, potentially run by industry, increase your willingness in using or accepting requests from data intermediaries?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><br><strong>Question 18: What standards or criteria would be most important for an industry-run authorisation scheme to be effective?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 19: What oversight or accountability arrangements would be necessary to ensure an industry-run scheme remains trusted?</strong></p>



<p class="wp-block-paragraph">An industry-run scheme must have strong, visible governance to maintain trust and ensure the scheme operates in an accountable and legitimate way. This includes establishing principles and processes, defining roles and responsibilities, and a significant investment in public communication. Delivery oversight with operational monitoring and clear routes to redress are also required.</p>



<p class="wp-block-paragraph">Governance must be based on principles of transparency, accountability, engagement and responsiveness, with enough flexibility to adapt to specific socio-technical contexts and goals. Adopting an iterative, collaborative approach with stakeholder engagement and regular review ensures that an industry-led scheme remains effective, credible and trusted.&nbsp;</p>



<p class="wp-block-paragraph"><br><strong>Question 20: What measures, if any, would be needed to ensure such a scheme does not disadvantage new or smaller entrants?</strong></p>



<p class="wp-block-paragraph">Schemes should provide a clear, tested pathway to operation, with transparent requirements, onboarding and compliance expectations. Providing a tested pathway to operation gives greater certainty and reduces the cost and complexity of entering the market. The pathway may include variable entry requirements dependent on considerations such as data sensitivity, tiers of purposes, and number of data subjects using the intermediary.&nbsp;</p>



<p class="wp-block-paragraph">IB1’s Project <a href="https://ib1.org/perseus/">Perseus</a>, the UK’s first cross-sector Smart Data scheme, provides a practical example. Its 6-month pilot phase tested the technical, legal and user experience aspects of a trust framework, highlighting the need to reduce friction and enhance the way Perseus works for SMEs, energy data providers, carbon accounting providers and financial service providers. A sandbox environment enables all participants to develop their implementations safely using synthetic data, and to continuously improve SME user experience. The scheme also provides onboarding support and guidance, open source example implementations, case studies from participants and supporting discussion channels.&nbsp;</p>



<p class="wp-block-paragraph"><br><strong>Question 21: For data controllers: Could a statutory code of practice increase your confidence in using or accepting requests from intermediaries?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 22: Would an industry-led code provide meaningful reassurance about the credibility of intermediaries?</strong></p>



<p class="wp-block-paragraph">Yes, a well-governed industry-led code should provide meaningful reassurance about the credibility of intermediaries, provided that it meets the requirements for transparency, accountability, engagement and responsiveness mentioned in Q19. Particular attention must be paid to messaging and communication intended to inform and reassure data subjects so they are not unduly burdened in their decision to use an intermediary as a delegate, and are clear about routes to redress if there are issues with the intermediary or the data transfer and onward use.</p>



<p class="wp-block-paragraph"><strong>Question 23: Do you believe voluntary, industry led approaches can meaningfully reduce data controller friction that was reported in our call for evidence last year?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 24: Would updated ICO guidance meaningfully change how your organisation handles delegated rights requests?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 25: What specific elements of guidance would be most useful to you?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 26: Would guidance alone be enough, or would you expect additional regulatory or legislative measures to address barriers facing the intermediaries market?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Data Portability Through Smart Data Schemes</strong><strong>&nbsp;</strong></p>



<p class="wp-block-paragraph"><strong>Question 27: To what extent could a Smart Data scheme provide sufficient trust for intermediaries operating in your sector?</strong></p>



<p class="wp-block-paragraph">Smart Data schemes are a proven, scalable approach to secure, private data sharing and should be built as a priority. Building interoperable schemes that are based on harmonised legal, procedural and technical definitions will provide the basis for trusted data sharing and for intermediaries to operate effectively.&nbsp;</p>



<p class="wp-block-paragraph">Our experience with Perseus demonstrates that trust is strengthened when Schemes have a clear purpose, with well-defined roles and responsibilities, transparent governance, assured data flows, proportionate technical requirements and onboarding support. Its pilot and sandbox also showed the value of testing these elements with participants and iterating the framework in response to stakeholder feedback.&nbsp;</p>



<p class="wp-block-paragraph">By defining priority user needs and use cases, schemes can be designed and adapted to real-world requirements, identify and mitigate uncertainties early and reduce friction for participants. This approach provides clarity and assurance needed for intermediaries while allowing schemes to evolve as the market develops.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Question 28: What measures would be needed to ensure Smart Data schemes adequately support intermediaries, or vice versa?</strong></p>



<p class="wp-block-paragraph">A Smart Data scheme involving intermediaries simply needs to include them in the governance framework: defining their roles and responsibilities, accountability and liability the same as for other scheme participants. This provides certainty for all participants, reduces friction and supports trusted data sharing.</p>



<p class="wp-block-paragraph">Smart data schemes should provide communication guidelines or requirements that assist intermediaries in their approach to building user journeys, disclosures and permissions.</p>



<p class="wp-block-paragraph">Smart data schemes should be designed for continuous improvement and adaptation so that they remain relevant and effective as technology, markets and user needs evolve. Care must be taken to ensure that ongoing changes do not become onerous for participants, or introduce risk or confusion for end users.</p>



<p class="wp-block-paragraph"><strong>Question 29: How do you see a Smart Data scheme in digital markets interacting with data intermediaries?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 30: What would each of their respective roles be in supporting effective data portability?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Final Questions</strong></p>



<p class="wp-block-paragraph"><strong>Question 31: Are you aware of good international examples where action has been taken to improve the operation of data intermediaries?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 32: Do you think one option or a combination of the options discussed in this consultation would work best to improve the operation of data intermediaries in the UK?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 33: What other options should be considered in your opinion?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 34: What additional infrastructure, if any, do you think is essential to enable data intermediaries to operate effectively especially in high-priority sectors (for example, finance, energy, health</strong> or transport)?</p>



<p class="wp-block-paragraph">Trust frameworks operate at sector level to collaboratively establish and maintain a light layer of identity management, governance, common definitions, principles and open standards for data sharing. They provide the foundations of a trusted data-sharing ecosystem that sector- or use case-specific schemes can build on.&nbsp;</p>



<p class="wp-block-paragraph">Trust frameworks and Smart Data schemes should be complementary. Trust frameworks provide the common foundation for identity, governance and interoperability across a sector or sectors while individual schemes can build upon these foundations to target specific market-wide applications. This approach enables targeted and efficient data sharing and identity verification without requiring every scheme to recreate underlying trust infrastructure.<br></p>



<p class="wp-block-paragraph"><strong>Question 35: What interoperability challenges currently limit the effectiveness of data intermediaries?</strong></p>



<p class="wp-block-paragraph"><em>No response</em></p>



<p class="wp-block-paragraph"><strong>Question 36: What types of infrastructure would help address these challenges? (For example, technical standards, governance arrangements, or supporting services).</strong></p>



<p class="wp-block-paragraph">Infrastructure that enables and supports trust frameworks for data sharing should be prioritised. This includes clear governance, open standards and identity and assurance mechanisms that support participants to interact with confidence.&nbsp;</p>



<p class="wp-block-paragraph">Good governance also addresses challenges of adoption by providing participants with clarity and confidence needed for technical infrastructure. Governance should be designed into the framework from the outset rather than through a technical-first approach. Infrastructure should be designed as an enabling layer for the trust framework, with technical standards and supporting services developed to implement and reinforce agreed governance principles.&nbsp;</p>



<p class="wp-block-paragraph">As more schemes are rolled out, work is needed to characterise and harmonise the ID &amp; verification, accreditation, legal, licensing and procedural aspects of data sharing in order to ensure schemes are interoperable and remove friction for participants and end-users. It is likely that these considerations, not technical interoperability, will cause the majority of bottlenecks to realising the full value of data portability enabled by data intermediaries.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>IB1 response to Ofgem’s AI assurance in the energy sector consultation</title>
		<link>https://ib1.org/2026/08/12/ib1-response-to-ofgems-call-for-input-ai-assurance-in-the-energy-sector/</link>
		
		<dc:creator><![CDATA[Emma Gray]]></dc:creator>
		<pubDate>Wed, 12 Aug 2026 10:53:18 +0000</pubDate>
				<category><![CDATA[Consultations]]></category>
		<category><![CDATA[Energy]]></category>
		<category><![CDATA[consultation]]></category>
		<category><![CDATA[energysector]]></category>
		<guid isPermaLink="false">https://ib1.org/?p=21703</guid>

					<description><![CDATA[This is Icebreaker One’s response to Ofgem’s Call for Input on AI Assurance in the Energy Sector. It can be published openly. Please note that throughout this consultation, Icebreaker One (IB1) uses the terms Open, Shared and Closed data as defined here. If you have any questions about our submission or require clarifications please do [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">This is Icebreaker One’s response to Ofgem’s Call for Input on <a href="https://www.ofgem.gov.uk/sites/default/files/2026-06/ai-assurance-call-for-input.pdf">AI Assurance in the Energy Sector</a>. It can be published openly.</p>



<p class="wp-block-paragraph">Please note that throughout this consultation, Icebreaker One (IB1) uses the terms Open, Shared and Closed data as defined <a href="https://icebreakerone.org/open-shared-closed/">here</a>.</p>



<p class="wp-block-paragraph">If you have any questions about our submission or require clarifications please do not hesitate to contact us via <a href="mailto:policy@ib1.org">policy@ib1.org</a>. We have omitted questions which we did not answer.&nbsp;</p>



<p class="wp-block-paragraph">Thank you for considering our submission.</p>



<h1 class="wp-block-heading"><strong>Call for input response:</strong></h1>



<p class="wp-block-paragraph">As stated in IB1’s response to Ofgem’s <em>AI in the Energy Sector Guidance Consultation</em>, AI presents immense opportunities for delivering customer benefits, driving economic growth, accelerating the transition to net zero, and enhancing financial and regulatory frameworks. However, AI must be deployed responsibly &#8211; ensuring trust, transparency, and interoperability across sectors.</p>



<p class="wp-block-paragraph">The questions in this consultation lean towards gathering information on what individual organisations are doing to assure themselves about their own use of AI. This is a necessary first step, but covers only a part of today’s interconnected energy sector services. To have real impact, assurance must be extended to cover AI-mediated data that is shared and used across organisations, sectors and use cases. It is in that context of <em>data</em> <em>sharing</em> <em>governance</em> that IB1 is responding to the consultation.&nbsp;</p>



<p class="wp-block-paragraph">IB1 highlights two key points about data assurance:</p>



<ol class="wp-block-list">
<li><strong>Assurance is evaluated in the context of the entity using the data, not the entity providing it. </strong>What is adequate for one usage situation may not be enough for another. Consequently, data sharing assurance can only be established by convening data users and publishers and developing their assurance needs and options around clearly defined use cases</li>



<li><strong>Assurance is a journey, not a destination. </strong>As available data, data users and use cases proliferate, so do their assurance needs. A sector approach to assurance must establish an agile process for determining assurance needs, and encoding and enforcing them so that machines (AI or otherwise) can rely on them at scale.</li>
</ol>



<p class="wp-block-paragraph">These requirements for data sharing assurance existed before recent AI advances. AI hasn’t changed them, but the opacity of inference and the non-deterministic nature of outputs that are features of Generative Pretrained Transformer (GPT) models bring new challenges compared to deterministic and probabilistic approaches. A distinction between “Narrow AI” (AI designed for a specific task such as weather forecasting) and “General AI” (AI with human-like performance at different task types) may prove useful in assurance. Despite the rapid uptake of both types of AI, governance is still nascent <em>within</em> organisations, and even more so <em>between</em> them. These factors amplify the need and shorten the timelines for determining what “fit for purpose” means.&nbsp;</p>



<p class="wp-block-paragraph">Over the past six years, IB1 has developed and openly published co-design processes (Icebreaking) and Trust Framework-based approaches to enable rapid decision-making and implementation of governance of data sharing. These apply equally when AI is in the mix. Trusted use of AI demands well-understood, open governance with agile co-design by market participants delivered at ecosystem scale. The importance of these factors multiply as AI capacity and independence grows, with oversight often taking time to catch up.</p>



<p class="wp-block-paragraph">IB1 recommends that, at the end of this information-gathering phase of its AI work, Ofgem ensures that the proposed Digitalisation Coordination Function is tasked with convening data stakeholders and working at pace to uncover, elucidate and specify assurance standards within a governance framework.</p>



<p class="wp-block-paragraph"><strong>Question 1: Current AI assurance practices</strong></p>



<ol class="wp-block-list">
<li><strong>How do organisations evidence that AI systems are operating as intended and delivering safe, fair and effective outcomes?</strong></li>
</ol>



<p class="wp-block-paragraph"><em>No response</em></p>



<ol start="2" class="wp-block-list">
<li><strong>What AI assurance approaches are currently used or under development, including in-house and third-party?</strong></li>
</ol>



<p class="wp-block-paragraph"><em>No response</em></p>



<ol start="3" class="wp-block-list">
<li><strong>What tools and technical capabilities are available to support AI assurance in practice, how mature and effective are they, and where are there gaps or opportunities for shared or sector-wide approaches?</strong></li>
</ol>



<p class="wp-block-paragraph">A range of tools are available to support AI assurance, including model testing, performance monitoring, explainability techniques, audit logging and cybersecurity controls. While these approaches are becoming increasingly mature for assuring AI within individual organisations, there is much less maturity in assessing AI operating across organisational boundaries and shared data ecosystems. A lack of trusted data flows into AI systems could lead to poor, potentially unaccountable, decisions made or informed by machines and human-machine systems.</p>



<p class="wp-block-paragraph">Effective AI assurance depends on trusted data flows. Capabilities such as provenance and lineage metadata, verifiable signatures, machine-readable licenses and organisational identity provide confidence in where data originated, how it has been processed and who is accountable.&nbsp;</p>



<p class="wp-block-paragraph">However, the characterisation and verification of AI models and their applications within data-sharing remains immature. More work is needed to identify and develop use cases that surface assurance requirements. Developing assurance around real-world use cases will help establish reusable assurance ontologies, with lessons drawn from more mature sectors such as autonomous vehicles or medical diagnostics.&nbsp;</p>



<ol start="4" class="wp-block-list">
<li><strong>How are AI governance frameworks translated into operational practice?</strong></li>
</ol>



<p class="wp-block-paragraph"><em>No response</em></p>



<ol start="5" class="wp-block-list">
<li><strong>Which assurance or governance practices are most effective in supporting reliable outcomes?</strong></li>
</ol>



<p class="wp-block-paragraph">The most effective assurance and governance practices are those that provide clear, proportionate evidence that data and AI systems are fit for their intended purpose. Assurance should be assessed in the context of how AI-mediated data will be used, recognising that while assurance signals originate from the data publisher, the decision to trust and use that data ultimately sits with the data user.&nbsp;</p>



<p class="wp-block-paragraph">IB1’s work on data assurance is a good starting point to adapt for AI-mediated data. Organisational and dataset assurance can be extended to provide consistent, machine-readable signals relating to provenance, quality, governance, licensing and accountability. As AI becomes more prevalent, these assurance signals become increasingly important for establishing credibility, compliance, quality and usability across organisational boundaries.</p>



<p class="wp-block-paragraph">AI governance in the energy sector must also be codified to require a demonstrable contribution to <em>net zero targets</em> and <em>consumer outcomes</em>. This should be supported by appropriate explainability standards that are needed for AI-driven decisions, such as pricing and grid management, alongside regulatory monitoring to prevent AI-driven market monopolisation.</p>



<ol start="6" class="wp-block-list">
<li><strong>What skills, expertise and resources are required for effective AI assurance, and where are the main capability gaps?</strong></li>
</ol>



<p class="wp-block-paragraph">Effective AI assurance requires a combination of technical expertise, governance, and stakeholder engagement. While AI introduces new technical considerations, many of the core capabilities are the same as those required for trusted data sharing.&nbsp;</p>



<p class="wp-block-paragraph">Core capabilities include:&nbsp;</p>



<ul class="wp-block-list">
<li>Stakeholder engagement to understand ecosystem needs and develop proportionate, useful assurance to meet those needs</li>



<li>Appropriate model and process selection</li>



<li>Risk characterisation and management</li>



<li>Data annotation (metadata) using appropriate standards</li>



<li>Quality control and verification</li>
</ul>



<p class="wp-block-paragraph">AI’s potential to unlock data-driven innovation must be balanced with privacy, security, and ethical considerations. Therefore, IB1 advocates for AI models that:</p>



<ul class="wp-block-list">
<li>Respect consumer consent and data sovereignty, using decentralised identity frameworks</li>



<li>Support open standards to ensure interoperability between AI-driven systems</li>



<li>Embed transparency and explainability to mitigate AI biases and prevent regulatory fragmentation</li>
</ul>



<p class="wp-block-paragraph">Organisations using AI must possess relevant expertise that encompasses the above bullet points to ensure their solutions provide, secure, fair and sustainable AI.</p>



<p class="wp-block-paragraph"><strong>Question 2: Risks and challenges</strong></p>



<ol class="wp-block-list">
<li><strong>What are the main barriers to implementing effective AI assurance?</strong></li>
</ol>



<p class="wp-block-paragraph">The fundamental barriers to effective assurance of AI-mediated data are structural and cultural. Organisations tend to work in siloes, which limits the sharing of both data and assurance practice. There is no accepted standard for AI explainability or verification, making it hard to establish a common baseline for what &#8220;good&#8221; assurance looks like. This is compounded by the pace of change in the underlying technology &#8211; rapidly evolving models and increasingly agentic processes make static assurance frameworks quickly outdated.</p>



<p class="wp-block-paragraph">Stemming from this, the data which AI requires is also fragmented, held in inconsistent formats across organisations, and subject to different consent regimes to access. System-wide data that would support assurance work, such as LV feeder loads, flexibility capacity, and network constraints, often exists but remains inaccessible or non-interoperable between organisations.&nbsp;</p>



<p class="wp-block-paragraph">Privacy-preserving technology and synthetic data are effective methods to enable innovation without creating data protection issues. While good work is being done to provide this for smart meters, such as via the Faraday project, there is a need for similar efforts on other datasets, such as flexibility assets and behind-the-meter energy use.&nbsp;</p>



<p class="wp-block-paragraph">Finally, there is a lack of structured methods to evaluate and communicate assurance for data processing, including using AI, across organisational boundaries, so even where individual organisations assure their own systems, that assurance doesn&#8217;t travel or compound across the sector. This is worsened by a general lack of consideration by data publishers about appropriate AI use by the downstream applications of data users. For instance, no mechanism exists to signal which models are appropriate for which specific applications, leaving adopters to make that judgement without guidance.</p>



<ol start="2" class="wp-block-list">
<li><strong>What are the key risks associated with AI use in the energy system (including system reliability, market functioning and consumer outcomes)?</strong></li>
</ol>



<p class="wp-block-paragraph">The key risks associated with AI in the energy system extend beyond performance of individual AI models to the governance of the data ecosystems on which they depend. <em>Focusing solely on AI assurance for organisations’ use of their own AI systems risks overlooking compounding risks for data sharing scenarios across organisations, use cases and sectors.</em></p>



<p class="wp-block-paragraph">Without clear, actionable assurance signals describing the provenance, quality, licensing and appropriate use of AI-mediated data, downstream users may be unable to assess whether the data is fit for purpose. Similarly, without the use of open and shared access frameworks, AI capabilities will consolidate in the hands of large incumbents who already hold proprietary datasets, creating market concentration risks that undermine innovation, consumer, and environmental benefits.&nbsp;</p>



<p class="wp-block-paragraph">We anticipate that cost, usage and IP conditions will hamper otherwise technically possible uses of the data. We recommend early surfacing of this information to mitigate five risks:&nbsp;</p>



<p class="wp-block-paragraph"><strong>1. Regulatory and compliance complexity:</strong> Data licensing must align with compliance rules around grid data, market data, and critical infrastructure. It is important to ensure data inputs to AI systems, and the outputs of the AI, remain compliant.</p>



<p class="wp-block-paragraph"><strong>2. Third-party data dependencies</strong> AI models in energy often rely on weather feeds, satellite imagery, market pricing, and sensor data from multiple vendors. Each source carries its own licensing terms around permitted use, commercial exploitation, and AI training rights. Identifying these dependencies early prevents data supply chain disruptions during development, or worse, after deployment.</p>



<p class="wp-block-paragraph"><strong>3. Intellectual property and model ownership:</strong> Who owns the AI model trained on licensed data? Many data providers now include clauses that restrict or claim rights over derivative works, including trained models.</p>



<p class="wp-block-paragraph"><strong>4. Onward data publishing and monetisation: </strong>Energy sector companies typically want to share or sell AI-derived insights. Licensing terms set upstream can block valuable downstream opportunities.&nbsp;</p>



<p class="wp-block-paragraph"><strong>5. Long-term data access and continuity risk:</strong> Many foreseeable AI systems in the energy sector (e.g. predictive maintenance, load forecasting) need consistent, long-term data access. Identifying long-term data rights is critical to operational resilience.</p>



<ol start="3" class="wp-block-list">
<li><strong>Which risks are most difficult to assess, evidence, or link to real-world outcomes?</strong></li>
</ol>



<p class="wp-block-paragraph">Risk assessment must be based on concrete use cases. These allow the counter-assessment of the risks of <em>not</em> using AI or <em>not</em> sharing the data created. The hardest risks to assess are those where there is insufficient information for a data user to make an informed judgement.<br></p>



<ol start="4" class="wp-block-list">
<li><strong>Where are current AI assurance approaches most limited in practice?</strong></li>
</ol>



<p class="wp-block-paragraph">Data assurance, whether the data was generated by AI or otherwise, is unevenly applied in the UK energy sector. There is a lack of attention to the data foundations and their transparency and accountability. A coherent, well-governed trust framework with standards for assurance signals is required, along with processes to develop and monitor them.</p>



<p class="wp-block-paragraph">As discussed in 1c, the characterisation and verification of AI models and their applications within data-sharing remains immature. More work is needed to identify and develop use cases that surface assurance requirements. Developing assurance around real-world use cases will help establish reusable assurance ontologies that can be implemented within trust frameworks.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Question 3: Critical infrastructure considerations</strong></p>



<ol class="wp-block-list">
<li><strong>How should AI assurance reflect the criticality of energy systems as national infrastructure?</strong></li>
</ol>



<p class="wp-block-paragraph"><em>No response</em></p>



<ol start="2" class="wp-block-list">
<li><strong>What level of rigour is appropriate for high-impact or safety-critical AI use cases?</strong></li>
</ol>



<p class="wp-block-paragraph">An appropriate level of rigour can only be determined on a use case by use case basis.</p>



<p class="wp-block-paragraph"><strong>Question 4: Consumer protection and fairness</strong></p>



<ol class="wp-block-list">
<li><strong>How can AI assurance support fair treatment of consumers, including vulnerable groups?</strong></li>
</ol>



<p class="wp-block-paragraph">AI assurance can support fair treatment of consumers by ensuring that AI-enabled decisions are transparent, accountable and designed around the needs of those affected, including vulnerable groups. This requires more than assessing technical performance; it requires governance arrangements that consider social impacts, consumer rights and the ability for individuals to understand and challenge decisions that affect them.&nbsp;</p>



<p class="wp-block-paragraph">IB1 advocates that data governance should establish clear principles, structures, roles and responsibilities, agreed by market participants, to enable accurate and timely data sharing at market-wide scale. These principles extend to AI assurance, ensuring that approaches are developed with cross-sector collaboration and learning rather than imposed through a purely top-down process.<em><br></em></p>



<ol start="2" class="wp-block-list">
<li><strong>What risks arise from AI-driven pricing, segmentation or prioritisation, e.g. fairness, transparency, consumer outcomes?</strong></li>
</ol>



<p class="wp-block-paragraph">We strongly advocate for the adoption of a broader concept of<strong> social sustainability</strong> in defining fairness. This must conceptualise people in a manner beyond their economic roles and should also be capable of viewing people in terms of groups. This approach is vital to assessing a more holistic range of AI impacts beyond the individualised economic sphere.&nbsp;</p>



<p class="wp-block-paragraph">As stated by Which? “consumers [must] have the right to challenge decisions that are made about them by computers alone. This right is particularly important because it forces transparency and accountability in systems, making sure companies can be held to account if things go wrong”. Transparency and accountability are precisely what assurance seeks to bring.</p>



<p class="wp-block-paragraph"><strong>Question 5: Cyber security and resilience</strong></p>



<ol class="wp-block-list">
<li><strong>How should AI assurance align with existing cyber and operational security frameworks, e.g. NIS Regulations?</strong></li>
</ol>



<p class="wp-block-paragraph">Assurance must align entirely.</p>



<ol start="2" class="wp-block-list">
<li><strong>How can AI assurance support system resilience, including identifying and mitigating cyber, operational and AI-specific risks?</strong></li>
</ol>



<p class="wp-block-paragraph">IB1’s 2025 Positioning Paper on AI set out five dimensions of resilience for consideration with AI, going beyond the purely technical. The benefits of assurance to each are below:</p>



<ol class="wp-block-list">
<li>Economic Resilience
<ul class="wp-block-list">
<li>Assurance enhances the likelihood that AI-driven data-sharing infrastructure (e.g. smart data initiatives​) is interoperable and equitable, preventing market concentration and boosting innovation and SME growth</li>
</ul>
</li>



<li>Sustainability and Environmental Resilience
<ul class="wp-block-list">
<li>Assurance can increase confidence in the use of AI to optimise energy efficiency, emissions tracking, and climate risk modelling, helping industries and governments meet net zero goals​.</li>



<li>Assurance can be used to evidence that AI contributes to the UK’s net zero targets, enabling the requirement to be open to monitoring and audit</li>
</ul>
</li>



<li>Regulatory and Governance Resilience
<ul class="wp-block-list">
<li>Consistent, well-understood assurance signals enable AI-driven compliance automation, reducing administrative burden and maintaining public trust in AI-enabled services</li>
</ul>
</li>



<li>Digital and Cyber Resilience
<ul class="wp-block-list">
<li>Open and interoperable digital identity frameworks alongside clear governance and accountability enable data users to be assured about the provenance of the information being relied upon to make operational decisions</li>



<li>Robust data governance policies, evidenced as part of assurance, ensure AI systems remain secure, transparent, and resistant to manipulation</li>
</ul>
</li>



<li>Social and Community Resilience
<ul class="wp-block-list">
<li>Well-understood, structured assurance enables confident deployment of&nbsp; data-driven AI interventions to novel scenarios, including emergency responses and disaster preparedness</li>



<li>AI assurance can demonstrate that inferences and decisions are free from bias and discrimination, ensuring fair access to economic opportunities, financial services, and public resources.</li>
</ul>
</li>
</ol>



<p class="wp-block-paragraph"><strong>Question 6: Proportionality</strong></p>



<ol class="wp-block-list">
<li><strong>What does proportionate AI assurance look like across different use cases and risk levels?</strong></li>
</ol>



<p class="wp-block-paragraph">The use cases drive both the assurance and the proportionality. Potential aspects of the assurance include:</p>



<ul class="wp-block-list">
<li>The identity of the assuring party</li>



<li>Information about the training data</li>



<li>Information about the contextual data used for a specific inference</li>



<li>Model choice and use</li>



<li>Explainability</li>



<li>Verification</li>



<li>Data protection</li>



<li>Liability and redress</li>



<li>Prompts for appropriate use</li>



<li>Reports from other users</li>



<li>Monitoring reports and incident logging</li>



<li>Reproducibility</li>



<li>Reliability of data availability and comparability in the long term</li>
</ul>



<ol start="2" class="wp-block-list">
<li><strong>How can assurance approaches be tailored while remaining effective and practical, including for smaller organisations?</strong></li>
</ol>



<p class="wp-block-paragraph">Clarity on the data use case, by both data producer and data user, greatly assists in identifying appropriate, proportionate assurance. Over time, informed by modelling and in-use analysis, individual use cases may well cluster into categories, further simplifying decision-making. Case studies, automated compliance, and effective, transparent monitoring and verification all lead to building greater confidence amongst stakeholders.</p>



<p class="wp-block-paragraph"><strong>Question 7: External assurance and standards</strong></p>



<ol class="wp-block-list">
<li><strong>Are existing frameworks and standards sufficient, or is sector-specific AI assurance guidance needed?</strong></li>
</ol>



<p class="wp-block-paragraph">Existing standards are not sufficient, especially in data sharing ecosystems involving LLMs and agents. Governance concepts, structures and implementations are nascent, both within organisations and and between them.</p>



<p class="wp-block-paragraph">Ideally, the UK would have cross-sector guidance and standards for AI assurance to enable assured data flows throughout the economy. Ofgem would then build on this where further refinement is needed, for example regarding critical national infrastructure and energy supply considerations.&nbsp;</p>



<p class="wp-block-paragraph">In the absence of UK-wide guidance, approaches taken by Ofgem should be designed to be replicable elsewhere by adopting existing standards where available, and openly publishing governance processes, data standards, and ontologies.</p>



<ol start="2" class="wp-block-list">
<li><strong>What role should independent assurance (e.g. audits, certification) play?</strong><strong><br></strong></li>
</ol>



<p class="wp-block-paragraph">The role of independent assurance is use case specific. It is likely to be required for scenarios involving personal/customer data and where decision-making affects customers.&nbsp;</p>



<p class="wp-block-paragraph">Audits may be applied to both parties sharing data: the AI-mediated data provider to ensure their assurance signals are correct, and the data user to ensure they are not using AI-mediated data for unintended purposes.<strong><br></strong></p>



<ol start="3" class="wp-block-list">
<li><strong>What are the benefits and risks of external assurance approaches?</strong></li>
</ol>



<p class="wp-block-paragraph"><em>No response</em><br></p>



<p class="wp-block-paragraph"><strong>Question 8: Future guidance</strong></p>



<ol class="wp-block-list">
<li><strong>What would be most useful in future AI assurance guidance for the energy sector?</strong></li>
</ol>



<p class="wp-block-paragraph">Future AI assurance guidance for the energy sector should focus on supporting practical decision-making rather than prescribing a single approach. Guidance should help organisations identify their AI use cases, understand the level of assurance required for the intended purpose and apply proportionate governance measures based on risk and impact.&nbsp;</p>



<p class="wp-block-paragraph">A key priority should be the development and adoption of open standards for representing assurance information, enabling organisations to communicate. Similar to the role of standards like Dublin Core in describing metadata, common assurance standards would support interoperability, transparency, and more efficient trust decisions across AI-enabled data ecosystems.<br><br>Guidance should also support cross-sector collaboration, engagement and knowledge sharing through forums where organisations can exchange approaches. IB1’s own experience with collaborative governance models and Trust Frameworks demonstrates the value of bringing participants together to establish shared principles, standards and assurance approaches.<br></p>



<ol start="2" class="wp-block-list">
<li><strong>What types of evidence are most useful in demonstrating outcomes in practice?</strong></li>
</ol>



<p class="wp-block-paragraph">Useful evidence should demonstrate that assurance requirements are being met and that they lead to reliable outcomes in practice. This could include:</p>



<ul class="wp-block-list">
<li>Membership of data sharing Schemes</li>



<li>Volume and continuity of data transactions</li>



<li>New products and services enabled by AI-intermediated data</li>



<li>Evidence of exceptions, “Red Flags,” when assured data hasn’t proven to be as reliable as asserted</li>



<li>Audit reports<strong><br></strong></li>
</ul>



<ol start="3" class="wp-block-list">
<li><strong>What examples or case studies would be valuable?</strong></li>
</ol>



<p class="wp-block-paragraph"><em>Assured Open Data</em></p>



<p class="wp-block-paragraph">With input from Open Energy members, IB1 developed the Assured Open Data (AOD) scheme in the Energy Sector Trust Framework in order to provide a standard externally credible mechanism for organisations to demonstrate their implementation of Data Best Practice Guidance (DBPG).&nbsp;</p>



<p class="wp-block-paragraph">In the scheme, progressive assurance levels operate at both organisational and dataset level. Organisational assurance verifies identity, governance, and accountability. Dataset assurance covers metadata quality, format, provenance, licensing, accessibility, and update cadence. Four cumulative levels run from minimum DBPG-aligned entry expectations through to comprehensive, machine-readable cross-market reuse. Assurance is signalled through metadata that maps to human-readable badges.</p>



<p class="wp-block-paragraph">SSEN-D was the first organisation to adopt AOD and has assured many datasets on its portal (e.g. SSEN Substation Data). AOD is in the process of implementation by other UK regulated energy sector companies.</p>



<p class="wp-block-paragraph"><em>Perseus Assurability Framework</em></p>



<p class="wp-block-paragraph">Perseus is a UK-led Smart Data Scheme for SMEs to embed sustainable finance with trusted, automated carbon emissions reporting. In it, SMEs give permission for their energy consumption data to be processed securely by carbon accounting platforms in order to provide emissions data to financial service providers to evidence carbon reductions.</p>



<p class="wp-block-paragraph">In order for financial service providers to reach reasonable assurance in the data they receive under the scheme, an assurability framework was developed, implemented by signed provenance records provided at each data exchange. These capture the identity of the sending and receiving parties within the trust framework, specify the data’s origins, codify the processing that has taken place, and make clear the permission and licence that covered the processing and transfer. Provenance records are chained as data is shared onwards, providing a verifiable record of assurance claims by processing parties.</p>



<p class="wp-block-paragraph">While the assurance information carried is use case specific, the building blocks of provenance records &#8211; identity, origin, licence, permission, processing, transfer, receipt &#8211; are broadly applicable. This enables assurance requirements, once defined, to be deployed within trust frameworks very rapidly.</p>



<p class="wp-block-paragraph"><strong>Question 9: Communication</strong></p>



<ol class="wp-block-list">
<li><strong>&nbsp;How should organisations communicate AI assurance to different audiences?</strong></li>
</ol>



<p class="wp-block-paragraph">By working in collaboration with the users of AI-mediated data to identify use cases and the assurance they require, organisations can design and communicate assurance in terms that are meaningful to those users. Open publication of the purpose and rationale for the assurance signals provided allows for a rapid adopt-and-adapt approach for new scenarios.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">To support this, well-defined frameworks and guidance should be established, facilitating open standards, clear ontologies and machine readable formats for interoperability among people and systems.&nbsp;</p>



<ol start="2" class="wp-block-list">
<li><strong>What information is most useful for consumers, boards, senior management and affected groups?</strong></li>
</ol>



<p class="wp-block-paragraph">The type and usefulness of information is use case specific, and should be developed alongside the assurance needs for each use case.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>IB1 response to Ofgem’s Securing open data in the energy sector consultation</title>
		<link>https://ib1.org/2026/07/23/ib1-response-to-ofgems-consultation-securing-open-data-in-the-energy-sector/</link>
		
		<dc:creator><![CDATA[Emma Gray]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 14:24:56 +0000</pubDate>
				<category><![CDATA[Consultations]]></category>
		<category><![CDATA[Energy]]></category>
		<category><![CDATA[consultation]]></category>
		<category><![CDATA[open energy]]></category>
		<guid isPermaLink="false">https://ib1.org/?p=21502</guid>

					<description><![CDATA[This is Icebreaker One’s response to Ofgem’s consultation: Securing Open Data in Energy. It can be published openly. Please note that throughout this consultation, Icebreaker One uses the terms Open, Shared and Closed data as defined here. If you have any questions about our submission or require clarifications please do not hesitate to contact us [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">This is Icebreaker One’s response to <a href="https://www.ofgem.gov.uk/sites/default/files/2026-05/Securing-open-data-in-energy-20260529.pdf">Ofgem’s consultation: Securing Open Data in Energy</a>. It can be published openly. Please note that throughout this consultation, Icebreaker One uses the terms Open, Shared and Closed data as defined <a href="https://icebreakerone.org/open-shared-closed/">here</a>.</p>



<p class="wp-block-paragraph">If you have any questions about our submission or require clarifications please do not hesitate to contact us via <a href="mailto:policy@ib1.org">policy@ib1.org</a>. We have omitted questions which we did not answer.</p>



<h2 class="wp-block-heading"><strong>Overall Position&nbsp;</strong></h2>



<p class="wp-block-paragraph">We welcome Ofgem’s focus on strengthening the governance of energy system data but believe this<strong> consultation should fundamentally be about improving decision-making</strong> rather than selecting a technical solution. Before investing in new infrastructure, there must be a clear, transparent, and consistent process for assessing what data should be open, shared, or closed. Processes must be applicable at the level of individual datasets, however the sector also requires a mechanism for considering publishing decisions at the aggregate level, for example when risks associated with publication multiply at scale. Without this, there is a risk of building technology that does not address the underlying governance challenge.&nbsp;</p>



<p class="wp-block-paragraph">We support the Educational Model as the preferred approach, subject to some adjustments, as it addresses the challenge of improving decision-making without introducing centralised infrastructure that has potential to compound security and resilience risks. We also recommend expanding the assessment criteria to explicitly consider <strong>liability, governance, resilience, and interoperability</strong>. Responsibility should remain clearly assigned to each data publisher while recognising that some risks require collective assessment. A <strong>Trust Framework</strong> provides the appropriate mechanism for a collective approach to decision-making, data triage and risk assessment without centralised data infrastructure.</p>



<p class="wp-block-paragraph"><strong>Effective governance</strong> should define, articulate, mandate, and enforce a monitoring, reporting, and verification process to ensure published data meets agreed requirements while allowing technical implementation to remain decentralised. This approach avoids creating single points of failure, strengthens system resilience, and maintains interoperability through common standards and assurance mechanisms. The Digitalisation Coordinator should focus on establishing and maintaining governance processes rather than operating centralised technical services.</p>



<p class="wp-block-paragraph">We strongly recommend the adoption of a <strong>transparent, evidence-based approach to risk assessment</strong>. The consultation proposes solutions before clearly describing the threats, vulnerabilities, or risk reduction expected from each option. A structured risk assessment with established methodologies, such as the NCSC Framework, should underpin any changes to Open Data policy. Security considerations must also be balanced against the UK’s net zero objectives, recognising that unnecessarily restricting data access may hinder consumer benefits, innovation, system coordination, and decarbonisation without reducing risk. Given that much infrastructure information is already publicly available, decisions should be made based on <strong>demonstrable risk reduction</strong> rather than assumptions about the benefits of data restriction.&nbsp;</p>



<h2 class="wp-block-heading"><strong>Consultation question responses:</strong></h2>



<p class="wp-block-paragraph"><strong>Question 1: Please provide examples of where data made available under DBP Guidance has allowed your business model to develop either new products and services, or make efficiency savings?</strong></p>



<p class="wp-block-paragraph">Icebreaker One and partners have used the data extensively in our work to assess and develop use cases enabling data to work harder to support energy system decarbonisation. Data made available under the DBP guidance has supported use cases in areas including, but not limited to:</p>



<ul class="wp-block-list">
<li><a href="https://ib1.org/wp-content/uploads/2024/07/Office-of-Zero-Emission-Vehicles-Public-Electric-Vehicle-Use-Case-report-2022-05-10-PUBLIC-WEBSITE.pdf">EV infrastructure development, including a targeted use case serving households without off-street parking&nbsp;</a></li>



<li><a href="https://ib1.org/wp-content/uploads/2024/07/Research_-Open-Energy-Heating-Use-Case-Report-2022-02-28-OPEN-WEBSITE.pdf">Heat decarbonisation and heat pump roll-out</a></li>



<li><a href="https://ib1.org/wp-content/uploads/2024/07/Research_-MEDA-Open-Energy-Local-Authority-Use-Case-v1.0-Website-version-Public.pdf">Local authority</a> planning and LAEP development</li>



<li>Cross sector data sharing between energy-water-telecoms for e.g. storm response</li>



<li>Community energy build out supporting the Local Power Plan</li>
</ul>



<p class="wp-block-paragraph">Use cases are especially valuable in considering data security as these provide an opportunity to clearly define the purpose of data access, identify relevant stakeholders, and understand user needs. This approach helps minimise unintended consequences by ensuring that decisions about whether data should be open, shared, or closed are based on clear understanding of who needs the data, for what purposes, and under what conditions.&nbsp;</p>



<p class="wp-block-paragraph">Currently, we are using the data to form part of our development work to assess how a data sharing scheme could <a href="https://ib1.org/2026/06/25/key-takeaways-from-our-ic-flexibility-workshop/">accelerate Industrial and Commercial (I&amp;C) participation in electricity flexibility</a>. Data included in the landscape assessment supporting the use case includes: network flexibility data (e.g. forecasts, zoning, trades), network constraints/headroom, and connections data (e.g. LCT connections, capacity registers).&nbsp;</p>



<p class="wp-block-paragraph"><strong>Question 2: Do you agree with the criteria underpinning the Options Analysis as described above?&nbsp;</strong></p>



<p class="wp-block-paragraph">The proposed criteria provide a useful basis for the Options Analysis, but we believe they are currently incomplete and, in some cases, do not fully support an objective comparison of the proposed models. We make the following observations on the existing criteria.</p>



<p class="wp-block-paragraph"><strong>Ownership and accountability:</strong> We are concerned that the current scoring does not appear to reflect that distributed responsibilities, when supported by common standards and governance, can provide clear and consistent accountability. There is a risk that the scoring methodology unintentionally favours centralised delivery models by assuming that the Digitalisation Coordination Function (DCF) is able to define and operate triage standards and processes internally that cannot be disseminated and carried out by data publishers. The scoring should assess how standardisation and governance can reduce risk irrespective of architecture. They should also flag where risks are present with regards to assigning responsibilities to the DCF as a body whose remit has not yet been defined.<br><br>The assessment should also consider how conflicts of ownership and decision-making would be managed in practice. For example, tensions may arise between network operators and a central coordination body where publication decisions differ, particularly if decisions contradict current publication requirements set out by sector governance regimes such as the Codes. Similar complexity exists for smart meter data, where governance may overlap between the Smart Energy Code (SEC), Central Switching Service (CCS/RECCo), UK GDPR, the Data (Use and Access) Act, Data Access and Privacy Framework, and Ofgem&#8217;s Data Best Practice Guidance. We therefore recommend that the assessment explicitly considers governance arrangements and conflict resolution mechanisms, in addition to whether any proposed central body (e.g. DCF) would assume the role and responsibilities of Data Controller under UK GDPR.</p>



<p class="wp-block-paragraph"><strong>Data security:&nbsp; </strong>We agree that data security should remain a core assessment criterion. However, security should be assessed across the entire data lifecycle, including how data is stored, governed, transferred, and accessed, rather than focusing solely on publication decisions. In particular, the analysis should recognise that centralising data storage or transferring data to a central body may increase systemic risk by creating attractive targets for attack and introducing potential single points of failure. These architectural trade-offs should be explicitly reflected in the assessment.</p>



<p class="wp-block-paragraph"><strong>Data quality:&nbsp; </strong>We welcome the inclusion of data quality into the assessment. To clarify scoring in this area, we suggest providing an authoritative definition of what is meant by &#8220;data quality&#8221;, distinguishing, for example, between schema compliance, completeness, accuracy, timeliness, and fitness for purpose. This distinction is particularly important when assessing the extent to which automated processes can improve quality. The assessment should also identify who is responsible for improving data quality under each option, together with the associated implementation and operational costs.</p>



<p class="wp-block-paragraph"><strong>Cost:</strong><br>We encourage further transparency on the assumptions underpinning the cost assessment. In particular, it is unclear how anticipated savings for individual licensees have been calculated and whether these represent genuine efficiency gains or simply the transfer of costs to a central coordination function. The analysis should also consider how any savings would be used in practice. For example, would reduced expenditure on local publishing platforms enable greater investment in data quality, governance, and workforce capability, or would these simply be treated as financial savings? In addition, we are concerned that indirect costs &#8211; including staff training, specialist expertise, organisational change, and ongoing governance &#8211; are underrepresented relative to technical implementation costs. In our experience, these organisational costs frequently exceed technology costs and should form part of any comparison of delivery models.</p>



<p class="wp-block-paragraph"><strong>Question 3: Would you suggest any other criteria that you would consider critical for analysis?</strong></p>



<p class="wp-block-paragraph">We recommend the following additions to Ofgem’s analysis criteria:</p>



<p class="wp-block-paragraph"><strong>Liabilities</strong>: while ownership/accountability is an analysis criteria, this does not fully enable the required assessment of who/which body would be held liable for publication decisions, nor assess processes required to handle situations in which data publishers and other relevant decision-makers disagree. In the Hybrid model, it is also notable that the use of automated processing may incur a specific discussion of liability where machine decision-making interacts with human decisions. Liabilities assigned to a potential DCF are also significant and not yet discussed, which requires further thought &#8211; particularly where liabilities are affected by other forms of legislation (e.g. Data Use and Access Act (DUAA)) or Codes (e.g. DCUSA data publishing specifications).</p>



<p class="wp-block-paragraph"><strong>Governance</strong>: The governance of a system cannot be left as separate to the architecture of the system, but governance details would benefit from further depth in all options. In the Central and Hybrid functions in particular, this creates a large and undefined burden on a future body, whose own format and governance model remains subject to future consultation. As part of governance assessment, we suggest that Ofgem considers the clarity, transparency, and accountability of decision-making processes. For example, processes for assessing risks at the collective level, and determining action, would benefit from further detail. Such processes are important as they intersect with liability assessments. For example, if a licensed entity’s decision to publish Open data is challenged, this is left at conflict with the licensee’s internal process and/or potential obligations under industry codes.</p>



<p class="wp-block-paragraph"><strong>Resilience</strong>: current analysis does not identify and assess risks emerging from the potential to create new single points of failure within the energy data landscape. This consideration goes beyond practices within monopoly bodies to also implicate single points of failure regarding aspects such as:</p>



<ul class="wp-block-list">
<li>An open data publishing portal (central/hybrid models)</li>



<li>Decision-making (central model)</li>



<li>Automation processes (central/hybrid models)</li>
</ul>



<p class="wp-block-paragraph"><strong>Interoperability</strong>: while the consultation presents arguments for open data publishing to be architecturally separate from other Trust Frameworks, this separation should not be extended to process and data assurance. IB1 suggests that the triage process &#8211; and the off-ramp for sharing data subject to restrictions (Shared data) &#8211; is not adequately discussed. Rather than presenting a vulnerability, consistency of process and data governance between the DSI, adjacent Trust Frameworks (e.g. CCS, Open Banking, IB1) and Open Data practices lend benefit to data security. Additionally, integration with Trust initiatives in the sector could offer the benefit of integrating Identity and Verification (ID&amp;V) for data users and publishers, thereby streamlining onboarding, increasing confidence in the provenance of published Open Data and reducing the capacity for bad actors to misrepresent themselves across different platforms and processes. Failing to integrate could also unintentionally increase costs through duplication, as flagged via industry engagement groups in relation to Trust Frameworks being developed for the DSI and CCS.</p>



<p class="wp-block-paragraph">We include analysis under these four categories as part of our response to Q4-6 below.</p>



<p class="wp-block-paragraph"><strong>Question 4: Do you agree with our Option Assessment scoring and conclusion for the Centralised Model?</strong></p>



<p class="wp-block-paragraph">Our analysis suggests that a Centralised model presents the highest risks and lowest additional advantage as a pathway for improving the sector’s open data security, as well as uncertainty on costs. While the current Options Assessment captures some of these risks, we suggest that the full depth of risks to data security presented through centralised infrastructure have not been fully explored. There are also considerable legal and governance implications for permitting a central coordination body to view and triage all raw data. We suggest a number of points below that, if incorporated in the scoring, we believe would downgrade the Centralised model to the lowest scoring option.</p>



<p class="wp-block-paragraph">Data security:</p>



<ul class="wp-block-list">
<li>3.9: ‘The process flow diagram above shows how licensees would send ESD (untriaged) through their Data Preparation Node (DPN) across the Data Sharing Infrastructure (DSI), where it would be subject to Data Quality (DQ) review and then passed to a Triage Function within the Digitalisation Coordination Function.’:
<ul class="wp-block-list">
<li>Transference of large volumes of data to a central body creates a large threat risk, as acknowledged in the wider literature on information security and engineering. While section 3 describes this as ‘reducing the threat surface area’ this is not an accurate representation of risk; rather than reducing the threat, it concentrates it.</li>



<li>Currently, the Options Assessment does not specify how the proposed central structure would handle key governance decisions such as data deletion. If the body decides that data should not be published, it is unclear how the data is handled, where it sits within the central body vs licensees, and how decisions are documented and recorded.&nbsp;</li>



<li>The boundaries of what raw data is transferred to the central function on this basis are unclear, as well as who makes the decision about what is or isn’t included for analysis. Scope creep presents a potential issue which could increase costs and act as a resource drain in the central body.</li>
</ul>
</li>



<li>3.16 ‘the risk of accidental over-publication is lowered’ &#8211; analysis currently makes the assumption that trained individuals in the centralised process are less likely to create errors. It is unclear how this is different to equivalently-trained individuals in distributed licensees. Additionally, when they occur, a centralised body potentially increases the scale of consequences for errors.</li>



<li>We suggest that tooling or methods applied to check triage compliance and consistency could be decentralised, defined and enforced via a Trust Framework. Centralisation of this function is not necessary to deliver the same outcomes.</li>
</ul>



<p class="wp-block-paragraph">Cost:</p>



<ul class="wp-block-list">
<li>We agree with the assessment on cost (score 1 &#8211; poor). Design, implementation and operation of the triage/data publishing service would duplicate functions already present in DNOs.</li>



<li>The overall cost score appears to be contradicted by point 3.14: ‘The model should provide savings for the licensees, as the costs of triage and running an Open Data Platform would be reduced significantly’. This depends on how the DCF is funded and managed, which is not yet determined.</li>
</ul>



<p class="wp-block-paragraph">Data quality:</p>



<ul class="wp-block-list">
<li>We query why this metric is scored as 4. In particular, we raise concerns that assumptions have been made about the necessity and feasibility of the role that the central function is envisaged to perform in 3.16 ‘Additional data utility benefits can be accrued through a single centralised portal, increasing interoperability, and allowing for data quality and schema validation as part of data processing, increasing the consistency of data offerings across the sector.’:
<ul class="wp-block-list">
<li>Analysis assumes that the digital coordinator is successful in defining a schema all parties agree with, and&nbsp;</li>



<li>Will ensure that data provided using the schema is conformant (this may be costly or face limits on compliance).&nbsp;</li>
</ul>
</li>



<li>We suggest that schema agreement and conformance do not require centralisation; the same outcomes could also be achieved in a decentralised manner via mandating the use of a Trust Framework.</li>
</ul>



<p class="wp-block-paragraph">Liability:</p>



<ul class="wp-block-list">
<li>Structure not currently discussed, though the model implies a high degree of reliance on the process and decisions of the DCF.&nbsp;</li>



<li>Potential for liability conflict unless clarified.</li>
</ul>



<p class="wp-block-paragraph">Governance:</p>



<ul class="wp-block-list">
<li>Governance of key processes run by the DCF are as yet undefined.</li>



<li>Governance of the process to decide whether metadata is published openly is unclear.</li>
</ul>



<p class="wp-block-paragraph">Resilience:</p>



<ul class="wp-block-list">
<li>This model creates single points of failure in relation to process/decision-making and technical architecture (portal).&nbsp;</li>



<li>Relationships/liabilities between data providers and the DCF require clarifying with regards to how licensees may be impacted by a failure or breach of centralised systems.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Interoperability:</p>



<ul class="wp-block-list">
<li>If successfully imposed (this is a risk &#8211; see Q2-3), the application of Schema could result in a high degree of data interoperability with the DSI. However, a centralised approach is not the only way to ensure this.</li>



<li>Legal interoperability must also be addressed; the consultation currently does not propose a function to address licence consistency.</li>



<li>Interoperability with other Trust Frameworks has not been actively considered in the consultation document.</li>
</ul>



<p class="wp-block-paragraph"><strong>Question 5. Do you agree with our Option Assessment scoring and conclusion for the Hybrid Model?</strong></p>



<p class="wp-block-paragraph">Presentation of the Hybrid model offers advantages in terms of checks for consistent application of triage processes, while retaining primary decision-making as a decentralised function. However, the current Option Assessment for the Hybrid Model does not adequately address the governance of automated checks, how this functions with human decision-making, how collective decision-making will be conducted, or how data quality improvements are guaranteed. We believe that amendments to scoring based on points raised below would downgrade the Hybrid model’s overall score and encourage Ofgem to consider this when determining their minded-to position.</p>



<p class="wp-block-paragraph">Data security:</p>



<ul class="wp-block-list">
<li>Issues related to data centralisation and deletion remain, as described in Q4.</li>



<li>The automated component of the model may function for certain aspects of assessment &#8211; e.g. providing an additional compliance function to check triage steps have been followed &#8211; however further exploration of how this interacts with human decision-making would be beneficial.</li>



<li>Governance of automated checks is not fully described at present. This potentially interacts with gaps in liability assessment identified in Q2-3. Example: dataset is approved by automated compliance function but later found to present risks that were not picked up: does the original data publisher, centralised body, or provider of the tool (if third party) hold liability?</li>



<li>The model does not fully address how decisions beyond compliance will be made, particularly regarding data which:
<ul class="wp-block-list">
<li>requires an assessment of risk at the collective level, and</li>



<li>requires an assessment of risk related to landscape changes over time.</li>
</ul>
</li>



<li>We suggest that tooling or methods applied to checking triage compliance and consistency could be decentralised, using a Trust Framework to both define good and enforce it.</li>
</ul>



<p class="wp-block-paragraph">Data quality:</p>



<ul class="wp-block-list">
<li>Observations outlined in Q4 are also applicable to the Hybrid model; it is unclear how data quality improvements are guaranteed through this proposal in a manner that is different to improved coordination/accountability applied to decentralised data triage.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Liability:</p>



<ul class="wp-block-list">
<li>The Hybrid model’s liability structure, and relationship to DCF liabilities, is not yet defined.</li>



<li>Liabilities for automated processing decisions are not discussed.</li>
</ul>



<p class="wp-block-paragraph">Governance:</p>



<ul class="wp-block-list">
<li>Governance of key processes run by the DCF requires definition.</li>



<li>Governance of automated processes is not currently discussed.</li>



<li>Monitoring, Reporting, and Verification (MR&amp;V) mechanisms are missing to ensure data published conforms to requirements.</li>
</ul>



<p class="wp-block-paragraph">Resilience:</p>



<ul class="wp-block-list">
<li>This model reduces certain single points of failure present in the Centralised model by keeping triage processing decentralised and adding an automated process check.&nbsp;</li>



<li>However, the data portal element remains centralised, as does data Schema assessment.</li>
</ul>



<p class="wp-block-paragraph">Interoperability:</p>



<ul class="wp-block-list">
<li>If successfully imposed (this is a risk &#8211; see Q2-3), the application of Schema could result in a high degree of data interoperability with the DSI. However, this can also be achieved in a more decentralised manner than the Hybrid model presents.</li>



<li>Legal interoperability must also be addressed; the consultation currently does not propose a function to address license consistency.</li>



<li>Interoperability with other Trust Frameworks has not been actively considered in the consultation document.</li>
</ul>



<p class="wp-block-paragraph"><strong>Question 6: Do you agree with our Option Assessment scoring and conclusion for the Educational Model?</strong></p>



<p class="wp-block-paragraph">We disagree with the current scoring of the Educational Model. In particular, the Options Assessment does not address how decentralisation automatically increases security threats despite high cybersecurity standards within licensees, why data quality cannot be assured with effective data governance, or any MR&amp;V mechanisms for the proposed model.&nbsp;</p>



<p class="wp-block-paragraph">Ownership and accountability:&nbsp;</p>



<ul class="wp-block-list">
<li>We suggest that this score is revisited; distributed ownership does not necessarily complicate accountability. All data publishers are regulated parties whose accountability to Ofgem, and other bodies, is guaranteed in relation to many other functions they deliver. We disagree with the current assessment score on this basis.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Data security:</p>



<ul class="wp-block-list">
<li>We disagree with the low scoring for this category. Licensees are required to maintain high cybersecurity standards for many forms of operational data, including critical national infrastructure. Based on this, it is unclear why distributed responsibility equates to low cybersecurity scoring.</li>



<li>We suggest that distributed data presents a lower security threat than centralised infrastructure for several reasons. This includes:
<ul class="wp-block-list">
<li>No single point of failure or leverage</li>



<li>Different internal security infrastructure at each licensee makes “full spectrum” breaches much harder</li>



<li>Untriaged data does not leave the organisation boundary</li>
</ul>
</li>



<li>On this basis we suggest that the data security score is reviewed and recategorised.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Data quality:</p>



<ul class="wp-block-list">
<li>We disagree with the low scoring for this category. The assessment appears to define data quality through only a centralised scheme validation despite the ability for agreed standards, accountability, and assurance processes with effective data governance.&nbsp;</li>



<li>The same data quality investments considered for the Centralised and Hybrid model should be included for the educational model.&nbsp;</li>
</ul>



<p class="wp-block-paragraph">Liability:</p>



<ul class="wp-block-list">
<li>Liability is clearly assigned to each data publisher.</li>



<li>Collective liability would need to be addressed, e.g. in the case where data publishing needs to be assessed at the collective level. This could be addressed meaningfully through a Trust Framework approach with appropriate governance and associated decision-making.</li>
</ul>



<p class="wp-block-paragraph">Governance:</p>



<ul class="wp-block-list">
<li>Effective governance within a Trust Framework can define what is required and enforce it without centralisation.</li>



<li>MR&amp;V mechanisms would be required to ensure data published conforms to requirements.</li>



<li>The Educational Model could be adapted to give publishing parties the triage check tooling from the Hybrid Model that otherwise sits centrally in the digitalisation coordinator. The DCF, or anyone else who has the specifications and technical ability, could provide the checking functionality, allowing the DCF to focus only on decision-making and collective assessments.</li>
</ul>



<p class="wp-block-paragraph">Resilience:</p>



<ul class="wp-block-list">
<li>See security section above: this option presents significant advantages by avoiding the creation of single points of failure and making a full spectrum breach less likely.&nbsp;</li>



<li>We do not believe that system resilience has been adequately accounted for in Ofgem’s current analysis &#8211; doing so could significantly change the minded to position.</li>
</ul>



<p class="wp-block-paragraph">Interoperability:</p>



<ul class="wp-block-list">
<li>A Trust Framework can support interoperability by establishing common requirements and assurance mechanisms across publishers.</li>



<li>Identities and standards established in the DSI trust framework may be used to harmonise trust signals for Open data, such as provenance and assurance, with those for data shared securely within the DSI, with both operating the same peer-to-peer data sharing principle.</li>
</ul>



<p class="wp-block-paragraph"><strong>Question 7: Do you agree with our minded to position? If not, what is your view as to the best approach to this issue?</strong></p>



<p class="wp-block-paragraph">We support Ofgem’s focus on strengthening data governance but believe the key challenge is improving the decision-making framework and governance processes that determine whether data should be Open, Shared, or Closed, rather than developing new technical infrastructure. Our preferred approach is the Educational Model, strengthened through a Trust Framework, enabling collective decision-making and standard-setting for data triage and risk assessment. With the addition of governance, liability, resilience, and interoperability as core criteria, the Educational Model provides more robust assurance while avoiding unnecessary centralisation of technology or liability. Effective governance should establish clear standards with monitoring, reporting, and verification processes, allowing the DCF to focus on oversight and decision-making. Any changes to Open Data policy should be supported by evidence-based risk assessment that balances security considerations with consumer benefits, innovation, system coordination, and progress towards net zero.&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Open Energy consultation: Assured Open Data</title>
		<link>https://ib1.org/2025/05/20/open-energy-consultation-on-assured-open-data-scheme/</link>
		
		<dc:creator><![CDATA[Chris Pointon]]></dc:creator>
		<pubDate>Tue, 20 May 2025 15:06:42 +0000</pubDate>
				<category><![CDATA[Consultations]]></category>
		<category><![CDATA[Energy]]></category>
		<category><![CDATA[consultation]]></category>
		<category><![CDATA[open energy]]></category>
		<category><![CDATA[trust frameworks]]></category>
		<guid isPermaLink="false">https://ib1.org/?p=17367</guid>

					<description><![CDATA[Open Energy, the governance body of the Energy Sector Trust Framework, is seeking feedback from its members and the public on the scheme agreement and assurance levels of its proposed Assured Open Data scheme]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Open Energy, the governance body of the Energy Sector Trust Framework, is seeking feedback from its members and the public on the two main components of its proposed Assured Open Data scheme:</p>



<ul class="wp-block-list">
<li>The scheme agreement [<a href="https://ib1.org/wp-content/uploads/2025/05/Scheme_-ESTF-Assured-Open-Data-Scheme-Agreement-for-Data-Sharing-Terms-v2025-05-01-DRAFT-website.pdf">pdf</a>, <a href="https://docs.google.com/document/d/1NNUVMtDNZ6rOG3zZNs8A4aUylIxH_aBHPF3NSH8YH5c/edit?usp=sharing">Google Doc</a> for comment]</li>



<li>The assurance levels:
<ul class="wp-block-list">
<li>Organisation assurance [<a href="https://specification.docs.ib1.org/generic-organizational-assurance-levels/1.0/">specification</a>]</li>



<li>Dataset assurance [<a href="https://specification.docs.ib1.org/generic-dataset-assurance-levels/1.0/">specification</a>]</li>



<li>Both specifications are also available in a <a href="https://docs.google.com/document/d/1_1ZyIDb3JSSMjkk1FhcX_ep_j1SRttbW1VcA_L-sncA/edit?usp=sharing">Google Doc</a> for comment</li>
</ul>
</li>
</ul>



<p class="wp-block-paragraph">Please comment directly on the Google Docs if you are able, or email feedback to <a href="mailto:openenergy@ib1.org">openenergy@ib1.org</a>. Comments received before June 2 2025 will be considered for inclusion in the initial scheme implementation.</p>



<h2 class="wp-block-heading">Background</h2>



<p class="wp-block-paragraph">Open Energy is proposing to add an Assured Open Data scheme to the Energy Sector Trust Framework (ESTF). The scheme has these main aims:</p>



<ul class="wp-block-list">
<li>Provide assurance to consumers of Open Data published by Members</li>



<li>Enhance the quality, consistency, and reliability of published data</li>



<li>Ensure Members comply with relevant data protection, privacy, and security regulations (e.g. members don&#8217;t publish any data subject to data protection regulations such as GDPR as Open Data under the scheme)</li>



<li>Promote transparency and accountability within the data-sharing ecosystem.</li>
</ul>



<p class="wp-block-paragraph">The scheme incorporates updated organisational and dataset assurance levels based on feedback on the original levels that Icebreaker One <a href="https://ib1.org/2023/09/21/assurance-open-consultation/">announced in September 2023</a>.&nbsp;These levels are already being used, for example by Open Energy members SSEN-D on their <a href="https://data.ssen.co.uk/">data portal</a>.</p>



<p class="wp-block-paragraph">Joining the scheme will be free to ESTF members. In order to assert the assurance levels members must execute the scheme agreement that sets out their commitments, and liabilities should they fail to meet them.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Outcomes of Open Energy Phase 3 Policy Consultations</title>
		<link>https://ib1.org/2021/07/15/outcomes-of-open-energy-phase-3-policy-consultations/</link>
		
		<dc:creator><![CDATA[Gavin Starks]]></dc:creator>
		<pubDate>Thu, 15 Jul 2021 15:12:33 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[consultation]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[energydata]]></category>
		<category><![CDATA[opendata]]></category>
		<category><![CDATA[openenergy]]></category>
		<category><![CDATA[shareddata]]></category>
		<guid isPermaLink="false">https://energy.ib1.org/?p=883</guid>

					<description><![CDATA[Between March and June 2021, Open Energy conducted three public consultations to inform the design and development of core policies underpinning the Open Energy Governance Service (OEGS) for Shared data. Now all consultations have closed, and in line with our ethos of working in the open, we would like to feed back the outcomes of [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Between March and June 2021, Open Energy conducted three public consultations to inform the design and development of core policies underpinning the <a href="https://energydata.org.uk/directory/">Open Energy Governance Service (OEGS)</a> for Shared data. Now all consultations have closed, and in line with our ethos of working in the open, we would like to feed back the outcomes of these consultations and to thank all who contributed.&nbsp;</p>



<p class="wp-block-paragraph">All terms used in the blog are defined in the glossary <a href="https://icebreakerone.github.io/open-energy-python-infrastructure/glossary.html">here</a>. All policies will also be published in the Phase 3 operational guidelines (forthcoming end July 2021). For any questions stemming from this blog, or materials within, please contact <a href="mailto:openenergy@ib1.org">openenergy@ib1.org</a>.</p>



<h3 class="wp-block-heading"><strong>Data Sensitivity Classes</strong></h3>



<p class="wp-block-paragraph">Open Energy facilitates sharing of a wide variety of data types, with varied levels of sensitivity. In order to handle this complexity, and to ensure data is appropriately protected, Open Energy has developed a system of data sensitivity classification. This policy details five Open Energy data sensitivity classes, graded across three dimensions of sensitivity: personal, commercial, and security. They are designed to complement <a href="https://www.ofgem.gov.uk/publications/consultation-data-best-practice-guidance-and-digitalisation-strategy-and-action-plan-guidance">Ofgem’s Data Best Practice guidance</a>, by adding nuance to how Data Providers can classify types of Shared data.</p>



<p class="wp-block-paragraph">Consultation during policy development informed a range of changes including:</p>



<ul class="wp-block-list"><li>Reducing the number of classes from 6 to 5,</li><li>Improving descriptions and example data types provided for each class; and</li><li>Updating guidance regarding the classification of aggregated and anonymised personal data.</li></ul>



<p class="wp-block-paragraph">Details of public consultation feedback, and Open Energy’s responses, can be found <a href="https://docs.google.com/spreadsheets/d/1x7xKfnsUqwzDiZcRTrcwP9QuhuuDYYcEEAkxv8y3OPY/edit#gid=0">here</a>. A copy of the updated policy can be found <a href="https://docs.google.com/document/d/1DmH26BTXJ5KwQfXpuOOZh4t3hkN-8dH_JBjCodHPetg/edit">here</a>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><a href="https://docs.google.com/document/d/1DmH26BTXJ5KwQfXpuOOZh4t3hkN-8dH_JBjCodHPetg/edit"><img fetchpriority="high" decoding="async" src="https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.04-1.png" alt="" class="wp-image-885" width="339" height="174" srcset="https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.04-1.png 678w, https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.04-1-600x308.png 600w, https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.04-1-230x118.png 230w, https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.04-1-350x180.png 350w, https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.04-1-480x246.png 480w" sizes="(max-width: 339px) 100vw, 339px" /></a></figure></div>



<h3 class="wp-block-heading"><strong>Data Access Conditions</strong></h3>



<p class="wp-block-paragraph">Once Data Providers have allocated their datasets to appropriate sensitivity classes, they will then specify the access conditions for each dataset. To encourage the creation of&nbsp; access conditions that are fair and proportionate to the dataset’s sensitivity profile, data sensitivity classes will be used as a guiding basis for considering access conditions, though not a complete determinant. As such, we define a standardised range of access condition types that Data Providers can associate with a particular dataset. This acknowledges the need for more nuance than would be captured under a ‘one size fits all’ approach for each sensitivity class, while still enabling standardisation of condition types. The policy focuses on access conditions for classes OE-SA and OE-SB only as personal data (OE-SP) are out of scope for Open Energy Phase 3.&nbsp;</p>



<p class="wp-block-paragraph">Consultation during policy development informed a range of adaptations including:</p>



<ul class="wp-block-list"><li>Dividing group-based access conditions into externally defined and self defined types;</li><li>Tightening the scope of use case-based access conditions to promote clarity and fairness; and</li><li>Removing purpose-based access conditions to reflect coverage of these conditions elsewhere in ways that reduce implementation difficulties.</li></ul>



<p class="wp-block-paragraph">Details of public consultation feedback, and Open Energy’s responses, can be found <a href="https://docs.google.com/spreadsheets/d/1aEScmtWxy9HR60nfqANES0ugeHLT1B1E4RuUp2GXMvk/edit#gid=0">here</a>. A copy of the updated policy can be found <a href="https://docs.google.com/document/u/0/d/1u57oRvOmD6lOLunevEva1khjxUz_Dln5dnHMlJbTQTM/edit">here</a>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><a href="https://docs.google.com/document/u/0/d/1u57oRvOmD6lOLunevEva1khjxUz_Dln5dnHMlJbTQTM/edit"><img decoding="async" src="https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.19-1.png" alt="" class="wp-image-886" width="341" height="173" srcset="https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.19-1.png 682w, https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.19-1-600x304.png 600w, https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.19-1-230x117.png 230w, https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.19-1-350x178.png 350w, https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.19-1-480x244.png 480w" sizes="(max-width: 341px) 100vw, 341px" /></a></figure></div>



<h3 class="wp-block-heading"><strong>Data Licensing&nbsp;</strong></h3>



<p class="wp-block-paragraph">This represents the final step of the journey that Data Providers must take in order to ready their datasets for sharing via Open Energy. It consists of two parts: creating access rules, then associating the grant of a set of capabilities and obligations with each rule to form the license. Our model proposes a system whereby access and capability grants are determined, for each request to a Data Provider’s API, on the basis of a set of rules defined and published by that Data Provider. This is different from the single licensing model that is commonly used in the sector, whereby one license is produced to cover all circumstances of the dataset’s use. It also responds to industry feedback regarding problems with the length and complexity of single licenses, which can increase cost, friction and risk associated with data use. By contrast, the Open Energy model permits reasonable multiple licensing within a set of transparent, standardised parameters that enable each license to be significantly simplified.&nbsp;</p>



<p class="wp-block-paragraph">Consultation during policy development informed a range of changes including:</p>



<ul class="wp-block-list"><li>Sharpening the descriptions of certain capabilities;&nbsp;</li><li>Confirming use of the ‘data pyramid’ to support the definition of different levels of onward sharing permissions; and</li><li>Honing a set of clarifications provided with the policy to support understanding.</li></ul>



<p class="wp-block-paragraph">Details of public consultation feedback, and Open Energy’s responses, can be found <a href="https://docs.google.com/spreadsheets/u/0/d/1dbCSVSYC_ppihfTjkne5S2dyTS2LEBH25UeFfthITAg/edit">here</a>. A copy of the updated policy can be found <a href="https://docs.google.com/document/u/0/d/1K2P3mkHIHur9Ntug2_Rv9HCqtJFpZ33OCSn9ab2sOI8/edit">here</a>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><a href="https://docs.google.com/document/u/0/d/1K2P3mkHIHur9Ntug2_Rv9HCqtJFpZ33OCSn9ab2sOI8/edit"><img decoding="async" src="https://ib1.org/wp-content/uploads/2021/07/Screenshot-2021-07-15-at-14.52.37-1.png" alt="" class="wp-image-887" width="342" height="176"/></a></figure></div>



<h3 class="wp-block-heading"><strong>What’s next?&nbsp;</strong></h3>



<p class="wp-block-paragraph">In the next phase of development, Open Energy will produce guidance and tooling designed to support Data Providers to comply with Open Energy policies. We aim for this to build trust and fairness in the ecosystem, while making it as easy as possible for Data Providers to get up and running. The next phase of the project will also explore policy development around dispute resolution and we expect to hold a further public consultation on this topic in due course.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Share your Feedback: Open Energy Data Classes</title>
		<link>https://ib1.org/2021/04/13/share-your-feedback-open-energy-data-classes/</link>
		
		<dc:creator><![CDATA[Gavin Starks]]></dc:creator>
		<pubDate>Tue, 13 Apr 2021 14:52:14 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Classification]]></category>
		<category><![CDATA[consultation]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[energy]]></category>
		<guid isPermaLink="false">https://energydata.org.uk/?p=411</guid>

					<description><![CDATA[Summary We are seeking feedback on a system of data classification proposed for the Open Energy ecosystem. Comments are welcomed from all energy sectors organisations and users of energy data. Feedback will be used to shape the Open Energy data classes policy and inform subsequent development of data access and licensing policies (to be consulted [&#8230;]]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-large"><img decoding="async" src="https://ib1.org/wp-content/uploads/2021/04/Open-Energy-social-media-1-1-1024x576.jpg" alt="" class="wp-image-413"/></figure>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">We are seeking feedback on a system of data classification proposed for the <a href="https://energy.ib1.org/">Open Energy</a> ecosystem. Comments are welcomed from all energy sectors organisations and users of energy data. Feedback will be used to shape the Open Energy data classes policy and inform subsequent development of data access and licensing policies (to be consulted on in due course). The consultation is open until 30 April 2021 and can be accessed <a href="https://docs.google.com/document/u/0/d/1A9Aj7uW5DEkhZjdBw5JI6t7qi_ojMIeKrBxyDWhD2n8/edit">here</a>.</p>



<div class="wp-block-image is-style-default"><figure class="aligncenter size-large is-resized"><a href="https://docs.google.com/document/u/0/d/1A9Aj7uW5DEkhZjdBw5JI6t7qi_ojMIeKrBxyDWhD2n8/edit"><img loading="lazy" decoding="async" src="https://ib1.org/wp-content/uploads/2021/04/callout-OC-energy-data-1.png" alt="" class="wp-image-415" width="419" height="206"/></a></figure></div>



<p class="wp-block-paragraph"><strong>Background</strong></p>



<p class="wp-block-paragraph">Open Energy aims to modernise access to energy and related data and break down barriers to data sharing. Open Energy will make it easier to both share and access data, supporting the sector’s drive towards decarbonisation, as well as related social and economic benefits. The project aims to serve all energy sector actors looking to share data, access data, or both.</p>



<p class="wp-block-paragraph">Open Energy builds on learning from Open Banking &#8211; identifying which elements are transferable to the energy sector, and which require adaptation or fresh thinking. Our ethos emphasises openness, transparency and sector engagement to ensure that the project meets the widest possible variety of needs. We are now seeking feedback on the first of a set of three policies aiming to navigate one of the most significant differences between Open Energy and Open Banking: the diversity of datasets shared within their respective ecosystems.&nbsp;</p>



<p class="wp-block-paragraph">Open Banking only handles two categories of data: open data and personal data. By contrast, Open Energy will incorporate more categories of data that have varied levels of sensitivity. In order to handle this complexity, and to ensure data is appropriately protected, Open Energy is developing a system of data classification. <strong><em>This consultation focuses on sharpening the descriptions, examples and criteria forming the data classes proposed. </em></strong>Follow-up consultations exploring data access and data licensing will take place later.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Proposal</strong></p>



<p class="wp-block-paragraph">We propose a system of six data classes, graded across three dimensions of sensitivity: personal, commercial, and security. Proposed classes are presented in Table 1 of the <a href="https://docs.google.com/document/d/1A9Aj7uW5DEkhZjdBw5JI6t7qi_ojMIeKrBxyDWhD2n8/edit#">consultation document</a>. It is proposed that &#8211; once finalised &#8211; a definition, specification and dataset examples for each class will be provided in the Open Energy Operational Guidelines. Data Providers (organisations sharing data via the Open Energy ecosystem) will then assess their datasets and self-allocate them to a class, prior to sharing them via Open Energy.&nbsp;</p>



<p class="wp-block-paragraph">Open Energy data classes are designed to supplement, not replace, the Modernising Energy Data Best Practice Guidance (<a href="https://modernisingenergydata.atlassian.net/wiki/spaces/MED/pages/69042178/Data+Best+Practice+latest+release+v0.21">current version</a> Point 12) determining whether data should be made Open, Shared or Closed. In particular, Open Energy data classes are designed to provide nuance to different classes of Shared data, with different sensitivity profiles.</p>



<p class="wp-block-paragraph"><strong>How can you help?</strong></p>



<p class="wp-block-paragraph">We are seeking feedback on the proposal through our consultation <a href="https://docs.google.com/document/u/0/d/1A9Aj7uW5DEkhZjdBw5JI6t7qi_ojMIeKrBxyDWhD2n8/edit">here</a>. It takes around 30 minutes to respond. The consultation explores questions including:&nbsp;</p>



<ul class="wp-block-list"><li>Are proposed data classes appropriate and clear?</li><li>Are example datasets given for each class are accurate?</li><li>Are any types of sensitivity missing from our analysis?</li></ul>



<p class="wp-block-paragraph">The consultation is open until <strong>30 April 2021</strong> and responses are encouraged from all actors in the energy sector, or who work with energy and related data. Any queries should please be directed to <a href="mailto:emily.judson@ib1.org">emily.judson@ib1.org</a>.&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Icebreaker One response to Australian Energy Rules Framework Consultation</title>
		<link>https://ib1.org/2020/09/25/icebreaker-one-response-to-australian-energy-rules-framework-consultation/</link>
		
		<dc:creator><![CDATA[Miles Cheetham]]></dc:creator>
		<pubDate>Fri, 25 Sep 2020 15:58:39 +0000</pubDate>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[consultation]]></category>
		<category><![CDATA[policy]]></category>
		<guid isPermaLink="false">https://ib1.org/?p=2594</guid>

					<description><![CDATA[Target audience(s): Policy experts, energy sector experts — Estimated reading time: 12-15 minutes Reference: Australian policy consultation — Energy Rules Framework Icebreaker One Response — August 2020 Executive Summary We welcome the publication of this consultation document and fully support consumer control over their energy data through the Consumer Data Right (CDR). We believe this [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Target audience(s): </strong>Policy experts, energy sector experts — <strong>Estimated reading time</strong>: 12-15 minutes</p>



<p class="wp-block-paragraph">Reference: <a href="https://consultation.accc.gov.au/consumer-data-right/energy-rules-framework-consultation/">Australian policy consultation — Energy Rules Framework</a><br></p>



<p class="wp-block-paragraph">Icebreaker One Response — August 2020<br></p>



<h4 class="wp-block-heading"><strong>Executive Summary</strong></h4>



<p class="wp-block-paragraph">We welcome the publication of this consultation document and fully support consumer control over their energy data through the Consumer Data Right (CDR). We believe this is an inflection point that will enable a thriving ecosystem of private service providers, new entrants and existing energy stakeholders, expanding to provide the innovation the whole system requires to meet its goals. Access to data will clarify inefficiencies and identify opportunities, bringing considerable efficiency gains and savings as digitalisation, decentralisation and decarbonisation accelerate. <br></p>



<p class="wp-block-paragraph">To achieve this, the use of energy data must be characterised by strong governance, standards and architectural agility. We hold an ambitious view for the future energy system: one which is highly innovative, delivering strong environmental, economic and societal benefits by fostering a decentralised data ecosystem, enabling widespread machine-to-machine data exchange and the ability to address privacy challenges. This will require additional consumer protections and enhanced rights. We advocate the principles of consumer primacy, control of consent throughout the provisioning chain, and greater emphasis on liability and redress.&nbsp;<br></p>



<p class="wp-block-paragraph">We recently published relevant reports through our associated company, Dgen, for the UK Government on consent, liability and redress. These are pertinent to your consultation and you can find them here:</p>



<p class="wp-block-paragraph"><a href="https://www.gov.uk/government/publications/smart-data-research-on-consent-liability-and-authentication">https://www.gov.uk/government/publications/smart-data-research-on-consent-liability-and-authentication</a></p>



<p class="wp-block-paragraph"><strong>Overview of Icebreaker One&nbsp;</strong><br></p>



<p class="wp-block-paragraph">Icebreaker One is an independent, non-partisan, global non-profit. Our vision is to develop the data infrastructure to deliver a demonstrably net-zero future. We connect private and public sector leaders to help reduce risk and grasp the opportunity to transform the climate crisis into economic innovation.<br></p>



<p class="wp-block-paragraph">We understand that every asset, system, organisation and network in energy (and beyond) will be producers and consumers of data. These systems will increase in complexity: they are not only being digitalised, they are becoming data-driven. The growth in data connections will be exponential as the market matures.&nbsp;<br></p>



<p class="wp-block-paragraph">We believe the energy ecosystem must implement a data architecture which can scale in data-type, volume and connectivity, across use-cases, organisational and logistical boundaries, sectors and jurisdictions. It must deliver this in a secure, safe, robust and adaptable environment with trusted governance.&nbsp;</p>



<h4 class="wp-block-heading"><strong>Responses to Consultation Questions</strong><br></h4>



<p class="wp-block-paragraph">We have responded to questions 1, 2, 3, 4, 20, 22, 24, 26, 34, 35 where we believe Icebreaker One (IB1) expertise and experience will be helpful.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Consultation questions: an approach to data sets in energy rules</strong></p>



<h5 class="wp-block-heading"><strong>1. Do you agree with our proposed approach to data sets in the energy rules? Why or why not?</strong></h5>



<p class="wp-block-paragraph">We recommend that all data sets and assets should include descriptive metadata. The approach adopted should enable the ability to “crawl” energy metadata for both open and shared data. This approach enables searchable energy datasets and assets and understands <em>relationships</em> and <em>meaning</em>. Furthermore, it will enable links to be created between related assets and datasets e.g. metadata about a dataset linking to metadata about the physical asset from which the dataset was recorded.&nbsp;&nbsp;</p>



<h5 class="wp-block-heading"><strong>2. Considering the above discussion about potentially sensitive information, what data, if any, should be subject to specific arrangements (for example, during the consent process)? Should any particular sensitive data be explicitly excluded from the proposed data sets?</strong></h5>



<p class="wp-block-paragraph">We agree that hardship details and concession details be separately categorised to allow ADRs to clearly explain the purpose and benefit of a consumer consenting to the sharing of these data sets. This confirms research in the UK by the Money &amp; Mental Health Policy Institute which considered how firms might use data which suggests a consumer may be vulnerable. A key recommendation from this was for government to create a shared space for regulators, firms and consumer groups to consider how such data can be used appropriately. Ethical use of data must be a key focus of regulation and should ensure that those consumers choosing not to share such sensitive data do not face prejudice.</p>



<p class="wp-block-paragraph">Moreover, it is essential that consumers are fully informed when making decisions and are asked to consent. From a consumer perspective ‘consent’ is often not clear because to access a product or service consumers must understand and agree the company Terms and Conditions as well as the way in which their data will be used. This is a lot of information to absorb and is often poorly presented. This raises the risk that consumers do not genuinely understand what they are agreeing to, and the potential consequences of their actions.&nbsp;</p>



<p class="wp-block-paragraph">We, therefore, recommend that a Standard for consent that requires ADRs to put the interests of consumers first. This should be implemented as a codified approach with a common set of parameters and values that is presented to the consumer in an easily understood way. For example, such a standard should include:</p>



<ul class="wp-block-list"><li>The purpose of data sharing (with a clear explanation of the value exchange)</li><li>Other organisations involved in the data sharing, if this is the case</li><li>What data items will be shared</li><li>Draw attention to any sensitive data</li><li>Access and individual rights of the consumer</li><li>Information governance arrangements (such as accuracy of data, the deletion of data, termination of data sharing and complaints management)</li><li>End date and review periods for the agreement</li></ul>



<p class="wp-block-paragraph">This should be developed from the consumer perspective, with an emphasis on comprehension and user experience, and allowing for the interconnected nature of the data provisioning chain.&nbsp; We note that such a Standard would enable the development of an API specification and associated metadata that enables the detail of the consent to be checked by other parties in any provisioning chain or carried alongside the consumer’s data in an API payload. This requirement is not unique to the energy sector and should be applied to any sector where personal data is shared. We trust that these aspects of the consent approach and process are included in the scope of the planned work on authentication and authorisation.&nbsp;</p>



<h5 class="wp-block-heading"><strong>Consultation questions: approach to the Rules, standards and privacy safeguards to accommodate the gateway data access model</strong></h5>



<h5 class="wp-block-heading"><strong>3. Do you consider the proposed approach to the gateway rules, standards and privacy safeguards appropriate for CDR in energy?</strong></h5>



<p class="wp-block-paragraph">We are concerned that the proposed approach may limit the potential for the use of energy data in Australia. While noting the rationale behind the original decision and extensive stakeholder engagement, we are encouraged at the inclusion of a 3-year review of the gateway approach as in the longer-term this approach:</p>



<ul class="wp-block-list"><li>Will create a single point of failure;</li><li>May prove to be costly and inefficient to ensure consistent, reliable real-time access to the data required in use-cases that will become widely adopted;</li><li>Adds a layer of complexity in the development of the CDR rules and data standards to ensure interoperability with the broader CDR ecosystem, potentially hindering the emergence of cross-sector services;&nbsp;</li><li>Is not the favoured option for innovative technology companies that will be critical in the drive to decarbonise;</li><li>Does not, in our view, take into account the powerful mitigating impact in the economy-wide model of Technology Service Providers, which have emerged in the data-sharing ecosystem to provide integration, implementation and aggregation services, as well as consent management services.</li></ul>



<p class="wp-block-paragraph">Our experience through extensive stakeholder engagement in the UK energy sector repeatedly emphasised that there cannot be a ‘single platform’ in which ‘all data is put’ to address ‘all use cases’. Energy data is highly diverse and is evolving too rapidly for any central, proprietary IT system to keep up. </p>



<h5 class="wp-block-heading"><strong>4. If not, which aspects of the approach should be reconsidered or amended, and why?</strong></h5>



<p class="wp-block-paragraph">We favour a fully decentralised approach &#8211; akin to the economy-wide model considered &#8211; in which data and metadata is distributed, always up-to-date, and managed real-time on data holders’ servers. </p>



<p class="wp-block-paragraph">We acknowledge that decentralised data and asset search is challenging and existing datasets are not strongly linked. However, search and discovery technology offers a solution to this problem.</p>



<p class="wp-block-paragraph">Data should be searchable, accessible and available to agreed standards. This approach can provide the common rules, controls and processes needed for access, discovery, security, commercial applications, privacy and regulatory compliance. This will enable an energy data ecosystem to develop, which will lead to greater innovation that brings both direct consumer benefits and will support solutions that enable more rapid decarbonisation.</p>



<h5 class="wp-block-heading"><strong>Consultation questions: dashboards</strong></h5>



<h5 class="wp-block-heading"><strong>20. Of the three options for data holder dashboards, which do you prefer and why?&nbsp;</strong></h5>



<p class="wp-block-paragraph">We welcome the inclusion of dashboards as a tool to enable authorisation and consent management. However, we recommend that an alternative approach is considered, enabling new approaches and entities for consumers to manage their consents. It will be insufficient to consider just the retailer or AEMO, as we fully expect a thriving ecosystem of third party service providers to develop innovative, value-adding solutions as the market develops. This will lead to complexity in the provisioning chains as data will necessarily be shared with other parties. This means that consumers may be faced with managing many consents, some of which is likely to relate to data drawn from multiple sectors.</p>



<p class="wp-block-paragraph">Given the complexity of managing ongoing consents, and the proliferation of consent and access management across those sectors opening up to the data-sharing ecosystem, it would be useful to consider early how this could be managed most effectively for the consumer and market alike so that they have the tools and a good understanding of the way in which these tools can be used. Alternative models should therefore be explored.</p>



<h5 class="wp-block-heading"><strong>22. What other options should we consider?&nbsp;</strong></h5>



<p class="wp-block-paragraph">We recommend consideration of new models such as companies or entities that undertake the management of the consumer’s consents on their behalf across all sectors covered by the CDR. This can be achieved using a common consent standard, API specifications and associated metadata.&nbsp;</p>



<h5 class="wp-block-heading"><strong>24. What consumer experience factors should we take into account with respect to how dashboards should be presented to CDR consumers?</strong></h5>



<p class="wp-block-paragraph">We strongly recommend a common set of language, with common terminology applicable across sectors wherever possible.&nbsp; From the consumer’s perspective, easily comprehensible words and phrases must be widely used that are easy to read and well understood. This will encourage wider acceptance, trust and adoption of services.</p>



<p class="wp-block-paragraph">We also recommend that dashboards should be considered as tools which enable consumers to view which data has been received into the firm, as well as data which the firm has shared with other participants (data ‘in’ and data ‘out’).&nbsp;</p>



<p class="wp-block-paragraph">Dashboards should include:</p>



<ul class="wp-block-list"><li>The recognisable consumer brand with whom a consumer has shared their data, and any party to whom data has been onward shared.</li><li>The specific data clusters/types being accessed, clearly explained.</li><li>Why the data is needed &#8211; the purpose, so that this can be easily understood.</li><li>What specifically it is used for &#8211; the processing activities and any sharing with other parties in a provisioning chain.</li><li>The duration that access to the data is granted for.</li><li>Their rights, and the way in which they can manage their data should be clearly explained.</li><li>The ability to revoke consent and notification that this has taken place and how data collected previously will be dealt with (e.g. ‘put out of use’/’deleted’)</li><li>Consents should be sortable and clearly outline those which are active, expired or cancelled</li></ul>



<p class="wp-block-paragraph">Additionally, the introduction of a recognised approach to the provision of consent management tools, and potentially a guarantee or certification will help consumer trust. The location of the dashboard should be easy to find from the main menu. You may also wish to make requirements about the accuracy and timeliness of the data held on the dashboard (for instance, the dashboard should update in real-time to avoid any miscommunication).</p>



<h5 class="wp-block-heading"><strong>Consultation questions: internal dispute resolution</strong></h5>



<h5 class="wp-block-heading"><strong>26. How important do you consider consistency of IDR approaches across sectors at this stage of the CDR regime?&nbsp;</strong></h5>



<p class="wp-block-paragraph">We observe that, as a proxy measure, the UK Open Banking initiative has undergone a rapid evolution in the way in which products and services are provided to consumers, through complex provisioning chains. We believe that this will become a characteristic across all markets and sectors. We observe new risks associated with opening up data as well as the risks which are exacerbated by the intelligence afforded by data. Data risks are often interlinked so that a mistake at a data holder creates risks downstream, not just for the ADR but for other parties involved in the provisioning chain.&nbsp;</p>



<p class="wp-block-paragraph">Furthermore, data will be used in services which cross regulatory/sector perimeters, meaning that there must be a consistent approach so that consumers can always feel confident and trust that if anything goes wrong, they know how to have things put right. In particular, consideration should be given to the assessment of liability and apportionment of redress both in the energy sector in and cross-sector, cross regulatory cases, which will prove to be complex. </p>



<p class="wp-block-paragraph">We, therefore, recommend that early attention is given to the creation of a single, accessible dispute resolution system for problem resolution, that facilitates effective inter-organisational communication and has common rules and processes. This will require consistency between regulatory approaches across different sectors. </p>



<p class="wp-block-paragraph">Internal Dispute Resolution will be greatly improved where data is more easily traceable. We, therefore, recommend that metadata attaches to consent. This aids discussions about liability and dispute resolution.</p>



<p class="wp-block-paragraph">We also recommend that consideration is given to how consumers may access redress which is simple, free and timely without recourse to the courts. This work includes understanding the value of energy data, how it may be used by nefarious actors (e.g. isolating when a family are at home and when the house is empty for instance), and what the value associated with privacy, were this data to be breached. This includes consideration of the use of energy data outside the energy sector by other third parties and the jurisdiction of any ombudsmen.&nbsp;</p>



<h5 class="wp-block-heading"><strong>Consultation questions: issues relating to accreditation</strong></h5>



<h5 class="wp-block-heading"><em>Energy data</em></h5>



<h5 class="wp-block-heading"><strong>34. Do you agree that energy data sets are less sensitive than banking data sets?</strong></h5>



<p class="wp-block-paragraph">We agree with this statement at present, but advise that this situation will change. As energy generation decentralises and decarbonises, with wider use of DERs, data originating at the household level (including personal data) will become more widely used. Therefore, the sensitivity of this data will increase. Moreover, the combination of energy data with data from other sectors will enable greater levels of analysis and inference.</p>



<h5 class="wp-block-heading"><strong>35. Should any energy data sets, or subsets of those data sets, be treated with a higher degree of security (due to potential sensitivities), similar to banking data?</strong></h5>



<p class="wp-block-paragraph">Any data originating at household-level, or where individuals and their behaviour are identifiable, should be treated with a higher degree of security. We see a range of use cases, such as home energy management or localised/community resource management where such data will be critical.<br></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
