Series · 13 parts · Grid & storage

Smart Grids, Smart Meters and the New Ethics of Data

Smart meters as the substrate of grid modernisation: a tool of empowerment or a new instrument of exclusion?

RK

R. K. Mundoli

Director — Projects & Advisory, Terrastrom Solutions

August 2026 · 12 min read · Part 6 of 13

25 years across the renewable value chain; 1,700 MW of independent diligence; lead developer of the 5 GW KREDL hybrid DPR.

⚠ On May 8, 2026, Uttar Pradesh became the first major Indian state to roll back its smart prepaid metering programme — after 255 consumers permanently disconnected rather than accept automated power cuts.

⚠ The technology did not fail. The governance did.

Smart meters are the substrate of every grid-modernisation idea in this series. Whether they become a tool of empowerment or a new instrument of exclusion is a design choice — and 2026 is where that choice is being made.

Privacy & algorithmic cut-offs — what the May 2026 UP rollback revealed

THE UP ROLLBACK · MAY 2026 · NATIONAL INFLECTION POINT

On May 8, 2026, the Uttar Pradesh government announced it would discontinue its smart prepaid metering programme following widespread consumer protests and a series of documented harms: automatic disconnections at night, bill spikes with no human review, and a Supreme Court petition challenging the rollout.

It is the most consequential setback to RDSS implementation since the scheme launched in 2021–22. Five other states — Bihar, Maharashtra, Kerala, Assam, Karnataka — recorded parallel resistance. The common thread is not fear of technology. It is rejection of algorithmic rigidity.

01 · WHAT 2026 SMART METERING HAS ENABLED

The RDSS is India’s largest grid digitisation programme. The technology delivers genuine value.

The Revamped Distribution Sector Scheme (RDSS) is the most consequential grid digitisation programme in Indian history. Its target: 25 crore advanced metering infrastructure (AMI) installations across all states by 2025–26. The scheme funds the smart meters, the communication infrastructure, and the meter data management systems that sit behind them.

The technology delivers genuine value. Smart meters enable real-time demand-side management — the operational backbone of time-of-day tariffs, VPP aggregation, and the load-limiting protocols that Part 03 argued should replace total disconnection during grid stress events. Without granular, near-real-time consumption data, none of Part 05’s VPP architecture is buildable at scale.

The 2025–26 deployment also generated India’s largest documented privacy and consumer-protection controversy in the grid sector. The events in Uttar Pradesh are the clearest expression of a national pattern that has been building for three years.

02 · THE UP ROLLBACK AND THE NATIONAL PATTERN

Six states. The same complaint: algorithmic disconnection without human review.

The Uttar Pradesh timeline is now well documented. UPPCL targeted ~3.5 crore conventional meter replacements. By mid-April 2026, ~78 lakh smart prepaid meters had been installed — roughly 22% of the target.

November 2025: 255 consumers in Banda, Jhansi and Kanpur permanently disconnect rather than accept smart prepaid mode. No compensation; no data on what happened to these households’ grid access.

Early 2026: Complaints of sudden bill spikes, power cuts despite positive balance, technical glitches causing disruptions during examinations and medical situations.

April 1, 2026: CEA amends smart metering regulations, removing the previously mandatory prepaid mode. Union Power Minister confirms in Parliament: prepaid mode is optional, not compulsory.

May 8, 2026: UP Energy Minister A K Sharma announces full state-wide rollback.

The UP case is not unique. Comparable consumer resistance occurred in at least five other states:

▸ Bihar (2023–24). An automated bill of ₹76 lakh issued to a rural consumer in Muzaffarpur; another for ₹18 lakh to a household in Purnia. Both traced to smart-meter integration errors with legacy billing systems. No human review triggered the bills; none caught them before issuance.

▸ Maharashtra (2024–25). MSEDCL and BEST consumers reported sudden bill spikes — the “fast meter” allegation — and disrupted automated billing cycles. Formal consumer complaints under MERC exceeded prior-year averages by 34% in the relevant quarters.

▸ Kerala (2023). KSEB trade unions (CITU, AITUC, INTUC) threatened indefinite strike against the central smart-meter mandate. State government publicly sided with unions; Kerala DISCOM effectively opted out of the RDSS prepaid framework.

▸ Assam — Cachar region (2023). APDCL prepaid meters cut power the moment balances hit zero — which violated the Electricity Act’s 15-day disconnection notice requirement. Consumer groups filed before AERC.

▸ Karnataka (2025–26). BESCOM rollout faced cost-transparency resistance — a single smart meter pegged at ₹10,000–₹12,000 installed cost, passed through to consumers in tariff revisions. Consumer groups petitioned KERC for an independent cost audit.

The common thread across all six states is not fear of technology. It is rejection of algorithmic rigidity without human recourse.

03 · DATA, THE DPDP ACT AND THE SECTOR-SPECIFIC MAPPING

A three-layer architecture is now in place. The gap is implementation.

The Digital Personal Data Protection Act 2023 establishes the framework. Seven principles: consent and notice, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards, and accountability. Smart-meter data — granular consumption patterns, appliance-level behaviour inferred from load signatures — falls squarely within its scope as personal data capable of revealing sensitive household information.

The framework’s translation to smart-meter data is happening through three specific instruments:

▸ RDSS Standard Bidding Document (SBD), updated early 2026. DISCOMs are defined as Data Fiduciary; AMI vendors as Data Processors. Data access for third parties (RE developers, VPP aggregators, demand-response platforms) requires explicit consumer consent. Anonymisation standards for aggregated load data are specified.

▸ CEA Cyber Security in Power Sector Regulations 2025/2026. Smart meter data classified as “Critical Information Infrastructure.” Data localisation requirement: all AMI data must reside on Indian servers. Breach notification to CERT-In within 6 hours of discovery.

▸ NOMC Standard Operating Procedure for Network Operations Centres. Data Retention and Minimisation rules: raw 15-minute interval data retained for 13 months; aggregated data for 7 years; billing dispute data until final resolution. Access tiering: DISCOM operations vs billing vs third-party analytics — each with separate permissions.

The architecture is therefore layered: DPDP Act (data baseline) + CEA regulations (sectoral implementation) + NOMC SOP (operational specifics). The gap is not legal text. It is the operationalisation of enforcement.

04 · ALGORITHMIC RIGIDITY AND THE ELECTRICITY ACT, 2003

The law already prohibits what the smart-prepaid algorithm was doing. The conflict is governance.

The UP rollback exposed a deeper legal conflict than just consumer dissatisfaction.

Section 47(5) of the Electricity Act, 2003 grants consumers the right to choose their payment mode (prepaid or postpaid). The CEA’s April 2026 amendment was not new law — it was a clarification of rights that always existed. The rollout had simply ignored them.

The 15-day notice rule: the Act mandates 15 days’ written notice before disconnection. A prepaid algorithm that cuts power the moment a balance hits zero does not provide 15 days’ notice. It provides zero seconds’ notice. Every automated cut during the UP rollout was, in this reading, an unlawful disconnection.

UPERC (UP Electricity Regulatory Commission) findings: reconnections after recharge occurred within 30 seconds in most cases — demonstrating that the disconnection was never a technical necessity. It was a policy choice embedded in the algorithm.

The legal collision is the most important governance event in the rollout to date. The technology has outrun the governance — not because the governance was absent, but because the operators did not apply it.

05 · HITL — HUMAN-IN-THE-LOOP AS A DESIGN CONSTRAINT

Three Indian frameworks explicitly require human oversight in automated systems. This is one.

The case for human oversight in smart-meter operations is now textually supported by three Indian frameworks:

▸ NITI Aayog’s Responsible AI Approach Document (Parts 1 & 2, 2021). Explicitly requires human review before automated decisions with significant individual consequences. A disconnection is precisely such a decision.

▸ The Digital Personal Data Protection Act 2023. Implements consent and grievance-redress requirements that include a right to human review of consequential automated decisions affecting personal data.

▸ MeitY’s India AI Governance Guidelines (5 November 2025). Extend the framework through seven sutras and explicitly require human oversight before high-stakes automated decisions — disconnection of household power supply qualifies unambiguously.

In operational terms for smart meters, HITL means three concrete things:

▸ A 15-day grace window with human verification before automated disconnection.

▸ A consumer-side appeal channel for algorithmic billing anomalies that a human reviews, not just a chatbot.

▸ A registry of vulnerable-load consumers — home medical equipment, critical agricultural pumps, essential services — for whom automated disconnection is never permissible regardless of balance.

None of this requires new law. It requires DISCOMs to operationalise the law that exists.

06 · PROCEDURAL JUSTICE AND THE “SMART POSTPAID” CONVERGENCE

The states are diverging. The convergence point is Smart Postpaid — real-time data, postpaid billing.

The Part 02 Energy Justice framework’s second pillar — Procedural Justice — applies directly. The technology was deployed without the affected consumers being part of the decisions about how it would operate. The UP rollback is what Procedural Justice failure looks like at scale.

A “Smart Postpaid” compromise is the plausible convergence point. DISCOMs retain real-time data, remote monitoring, and the demand-response capability that justifies the investment. Consumers retain postpaid billing, 15-day notice rights, and protection from automated instantaneous disconnection. The operational benefits of smart metering are preserved; the governance failures that caused UP’s rollback are designed out.

State strategies are already diverging. Uttar Pradesh has fully retreated. Kerala chose a sovereign-utility model (KSEB, state-owned) with union co-governance from the start. Karnataka BESCOM is pursuing a hybrid: postpaid smart meters for residential, prepaid optional for commercial consumers above a defined consumption threshold.

For independent power producers and renewable developers, the shift carries a financial implication. Smart-postpaid consumers are more expensive to serve (higher collection risk, lower balance predictability) but politically sustainable. Smart-prepaid consumers are cheaper to serve but, as UP demonstrated, politically fragile at scale.

07 · THE VERDICT

Smart metering is the substrate of every grid-modernisation idea in this series. The substrate must be trustworthy.

Smart metering is the substrate of every other grid-modernisation idea in this series — load-limiting instead of blackouts, VPP aggregation, time-of-day tariffs, demand-response programmes that help rather than harm the grid’s poorest consumers. None of it works without the data layer that smart meters provide.

The UP rollback is therefore not a setback to one state’s metering programme. It is a warning to the entire grid-modernisation agenda: the substrate must be trustworthy, or the architecture built on it is unstable.

The framework exists — DPDP Act, CEA regulations, NITI Aayog HITL principles, Section 47(5) of the Electricity Act. What is missing is not law. What is missing is the institutional will to apply it to a technology that procurement departments and vendors have been allowed to deploy faster than governance could follow.

The framework exists — DPDP Act, CEA regulations, NITI Aayog HITL principles, Section 47(5) of the Electricity Act. What is missing is not law. What is missing is the institutional will to apply it consistently. The question for every DISCOM and every AMI vendor active in India in 2026: have you built Human-in-the-Loop into your disconnection workflow — or have you left that as a future upgrade?

ANNEX A · DPDP ACT AND GDPR — THE DIVERGENCE THAT MATTERS FOR SMART METERS


The Digital Personal Data Protection Act 2023 with its 2026 Rules has officially turned smart-meter data handling in India into a compliance domain distinct from GDPR. Two divergences are especially significant for the grid sector.

▸ Consent-driven, not legitimate-interest-driven. Unlike GDPR, which allows data processing under a “legitimate interest” basis (commonly invoked by European utilities for network management), the DPDP Act has no equivalent carve-out. Indian DISCOMs cannot rely on “legitimate interest” to process smart-meter data without explicit consumer consent. Every new use case — demand forecasting, third-party VPP access, academic research — requires a fresh consent layer.

▸ Notice in local languages, Right to Erasure on meter history. Every smart-meter installation in 2026 must be accompanied by a clear notice available in the consumer’s language under the Official Languages Act. The Right to Erasure applies to behavioural inference data (appliance-level disaggregation profiles, consumption pattern analyses) — though raw billing data is exempt from erasure for regulatory and legal hold periods.

ANNEX B · THE MAY 2026 REGULATORY STATE — DPDP RULES BEGIN TO BITE


Three concrete regulatory moves have made DPDP operational for the grid by mid-2026.

▸ DERC Business Plan amendments (effective 30 April 2026). Require Data Governance Layers under Privacy by Design principles for all AMI deployments in Delhi. DISCOMs must publish a Data Processing Register listing every category of smart-meter data, its purpose, its retention period, and the third parties with access.

▸ CEA Cyber Security Regulations 2026 enforcement window opens. Following a six-month grace period, AMI vendors are now subject to mandatory security audit before deployment. Non-compliant meters cannot be installed under RDSS funding. The first enforcement actions (two vendor disqualifications) were reported in April 2026.

▸ ISGF’s National Smart Grid Data Governance Framework (consultation draft, April 2026). Proposes a unified Data Governance Architecture for smart grids — distinguishing Operational Data (real-time grid management), Consumer Data (billing and behaviour), and Market Data (aggregated demand signals for RE procurement). Public consultation closed May 2026; final framework expected Q3 2026.

The cumulative effect: in 2026, the smart meter is no longer a “spy in the home” or a “transparent consumer” — it is a regulated data device with defined rights, obligations, and enforcement mechanisms. Whether those mechanisms are applied consistently is the governance question that the UP case has made impossible to defer.

→ · COMING UP IN PART 7


Part 7 examines nuclear energy’s returning role in India’s grid stability strategy — the case for small modular reactors as firm, low-carbon baseload, the political economy of nuclear expansion, and the ethical questions around waste, risk, and intergenerational consent.

#EthicsofGridStability #RenewableEnergy #IndianRESector #SmartMeters #DPDP #DataEthics #EnergyJustice #RDSS #GridModernisation #AlgorithmicAccountability

Related work

We do this for a living, not only in writing.

Grid and evacuation design to 400 kV, storage sizing on hybrid programmes, and 1,700 MW of independent generation and grid evaluation for investors and lenders.