UPDATES

02/10/2026

AI, privacy, data protection & cybersecurity new regulation framework and its impact on the energy market

From Digital Transformation to a New European Regulatory Framework 

Over the last 25 years, technology development is increased exponentially and has transformed the world we live today from markets, living, public administration and services, Industry to leisure and culture. The Digital transformation has shaped our lives in a very different way as it was before the Big Data Transformation. Nowadays, Artificial Intelligence, Generative AI or AI Agents are becoming a breakthrough that threatens fundamental aspects and rights of our lives. While this landscape was building up, the European Union (EU) was watching and defining the principal EU Strategies to tackle technology challenges in the present and the future. 

Digitalisation has brought an increase of 5-6 times from 2018 to 2025 of data volume. This growth brings new major opportunities but also new challenges of how to deal and manage them. As a result, the European Commission established the EU Data Strategy, which aims to provide a clear regulation framework to enhance and leverage the data economy of the future. The strategy relies on the vision that the human being is at the centre, a key element. This strategy has settled the basis to develop the actual regulation framework of Data Protection and Privacy, such as GDPR (General Data Protection Regulation), DGA (Data Governance Act), DA (Data Act) or even Artificial Intelligence Act. 

Building a European Framework for Data and Cybersecurity – Towards a Digital Single Market 

The goal is to achieve by 203O a clear policy and regulation framework on a user centric vision to handle data and leverage the data market in the European Union. The common rules should ensure a Data flow within the EU and different sectors, access and use of data FAIR rules through trustworthy data governance mechanisms and respect regulation on privacy and data protection, consumer and competition. The new regulation framework aims to tackle and ensure the most relevant problems with data, such as: the availability and how to share data between private entities or public ones, reduce the market imbalance, data interoperability and quality, governance and the lack of infrastructures and technologies to ensure cybersecurity. 

Together with the Data Strategy has arrived the EU Cybersecurity Strategy which aims to improve cybersecurity across main strategic sectors and its critical infrastructures, such as Transport, Energy, Health, Telecommunications or Finance. The continuous evolving geopolitical situation has pointed out the critical infrastructures of Energy, Transport, Health or Telecommunications sectors as war hybrid targets. Collaboration through the EU and between National authorities is becoming critical in order to enhance better Cybersecurity across Europe. This strategy is in line with the Data Strategy and settles the basis for part of the Regulation framework such as Cybersecurity Act, NIS2 Directive, Cyber Solidarity Act or Cyber Resilience Act.  

Together with the Data Strategy has arrived the EU Cybersecurity Strategy which aims to improve cybersecurity across main strategic sectors and its critical infrastructures, such as Transport, Energy, Health, Telecommunications or Finance. The continuous evolving geopolitical situation has pointed out the critical infrastructures of Energy, Transport, Health or Telecommunications sectors as war hybrid targets. Collaboration through the EU and between National authorities is becoming critical in order to enhance better Cybersecurity across Europe. This strategy is in line with the Data Strategy and settles the basis for part of the Regulation framework such as Cybersecurity Act, NIS2 Directive, Cyber Solidarity Act or Cyber Resilience Act. 

Moreover, other relevant legislations have emerged such as Digital Service Act or eIDAS, which reinforce digital trust identity even on products, see Digital Product Passport. 

GDPR: Human being at the Centre of Data Protection 

Artificial Intelligence has brought again to the frontline Privacy and Data Protection regulation, which was officially legislated in May 2018 with the entry into force of the General Data Protection Regulation. The GDPR tackles challenges aspects such as the lawfulness of data processing (Art. 5, 6), is it necessary to collect those data?, is it proportional to the purpose?, which is the purpose of the processing and data collection? GDPR establishes the rules for a lawful data processing. But it also specifies data strategies such as minimization of data collection, anonymization or pseudonymization to reduce potential privacy risks with personal data or sensitive data.  

GDPR clearly defines a special category of data, SENSITIVE data (Art. 9, 10), which are data related to health, political opinion, philosophical or religious beliefs, ethnic or racial origin, sexual orientation, biometric data, genetic data or trade union membership. This special category implies more risks for the individuals and are subject to more accurate risks assessments before using them in any data processing, DPIA (Art. 35, 36). 

The key points that GDPR brings to shift human being in the centre are the Consent (Art. 7) to give for a specific data processing and collection; and the rights of the data subject. Users can exercise the new rights, but entities must provide mechanisms to the users to exercise them. From transparency (Art. 12), information and access to their data (Art. 13, 15), Rectification (withdraw at any time, Art. 16), Erasure or Right to be forgotten such as in the network (Art. 17), Restriction of processing (Art. 18), data portability (right to change of provider with no inconvenient on data transport to the new provider, Art. 20) or right to object (Art. 21). All these new rights provide the individuals many controls over their data, to access and be informed to any processing, problem or risk involved; but also to withdraw and change their mind on their data sharing at any time with no cost (economic, professional or personal).  

On the other hand, an interesting point of this law is the new roles or positions defined, such as a DPO (Data Protection Officer). The figure of the DPO (Art. 37, 38, 39) supports entities to comply with the law but also act as the thread or contact with the users and their rights. But who is supervising any break of the law, the possible fines…?, GDPR defines also the DPA (Data Protection Authorities, Art. 31, 33, 51 to 62), which collaborate with the DPOs in case a privacy breach occurs.   

GDPR has strongly impacted within any business, as large companies are obliged to design a DPO, risks assessments on large data processing. An important step starts in the GDPR for data sovereignty, the data transfers rules. The law specifies what to do for data transfers to third parties or third countries where the GDPR does not apply. It is a first step on the data sovereignty that is becoming extremely important together with the Data Governance, these days. 

The impact of the GDPR has been evaluated as positive and negative, depending on the side, outside the EU it is seen as a burden to develop the Digital Single Market and Data Market. But on the other hand, the law enhances the European values of having the human being rights in the centre and tries to add control on the data collection and processing to avoid individuals’ harms. 

The AI Act: Regulating Artificial Intelligence Through Risk 

The discussion has raised another level with the Artificial Intelligence. The disruptive Generative AI or the new AI Agents are coming faster that the application of the AI Act. This law brings the first step to classify any AI system depending on its risk and impact and it is an outcome of the AI Strategy, which aims to enhance competitiveness of strategic sectors and strengthen the EUs technological sovereignty.  AI strategy has brought the AI office and the GenAI4EU initiative to enhance projects on Generative AI in Industrial ecosystems and public sector.  

The AI Act tackles two main challenges the AI systems classification and the requirements per type of AI system. The law classifies each AI system from unacceptable risks (prohibited practices, chapter II, Art. 5), High-risk (Chapter III, Art. 6 and Annex III) to limited risks (e.g. chatbots and deepfake content) or minimal risk (e.g. AI in video games, Spam filters, Recommendations based on AI for entertainment). Depending on the classification, the AI system could be prohibited, prove and apply several requirements during design and implementation or no requirements, just transparency on what the system does and uses. Most of the high-risk AI systems obligations rely on providers, deployers and importers of the systems. It is relevant to say that the General Purpose AI systems, such as a chatbot, the obligations are minimal and very similar to the GDPR ones, related to transparency to the users. When it comes to AI systems assessment, the systems must respect the AI Trustworthiness through different characteristics such as Risk management system (Art. 9), Data and data governance (Art. 10), Record keeping (Art. 12), Transparency and provision of information to deployers (Art. 13), Human oversight (Art. 14), Cybersecurity (Art. 15), Accuracy (Art. 15) or Robustness (Art. 15). Disruptive Generative AI and AI Agents are one of the reasons for the preparation of the AI Act 2.  

Innovation, Regulation and the European AI Dilemma 

The law clearly splits between systems forbidden, others with restrictions and specific requirements and no further requirements. The regulation framework of GDPR and AI Act creates a strong impact in the development of AI and data processing technologies, from now on. Any AI system must be evaluated from the design to its implementation and deployment to comply with the law requirements. In comparison with other countries such as EEUU or China, where there is no regulation that restricts the development of AI or data processing technology, it could be challenging to be a competitor for the EU. On the other hand, it ensures that individuals are respected and matter if they are harmed by the use of technology. The law keeps on having the human being in the centre, is it a benefit? Or is it the opposite, a business burden to leave EU out of the AI global race? The AI systems are an incredible source of improvement in energy businesses, flexibility services, forecasting consumptions to provide the users more information to take better energy decisions. The impact of this new regulation framework translates into more efforts to assess systems, provide technical implementation and tools to exercise users’ rights or dedicate human resources to individuals’ rights. This is a reality, it is not yet evaluated what will bring to the AI systems as the AI act has entered into forced by the end of 2026. The consequences of its application are still ongoing and will be more visible within 2 or 3 years.  

Cybersecurity and Data Sharing: Completing the Regulatory Landscape 

GDPR and AI Act are not the only new laws, the Cybersecurity has been reinforced through the NIS2 Directive, Cybersecurity Act or Cyber Resilient Act. These new laws have reinforced the ENISA role and its capabilities but also set the rules for digital devices providers that will have to ensure specific technical requirements to reduce risks against cyber vulnerabilities of the devices.  

Data is the key point for any system, any AI algorithm or ML, any provider in the Energy domain with the new digital counters is collecting data regularly from users, personal data. Data spaces, data marketplaces share data, use data for business…it means that there is a need to establish rules on how to share data for business and for altruist purposes. This is what Data Act and Data Governance Act regulate in order to foster the Data Market and enhance the data flow for business purposes or altruist purposes. The DA and DGA are becoming relevant and starting to have impact in all the critical sectors where the exchange and sharing data is constant and in large amounts. Any contract with individuals or even between companies should be compliant with the regulation, which clearly impacts in the business flow, too.  

What Does This Mean for the Energy Sector? 

Globally, the new regulation framework for privacy, data protection and cybersecurity is impacting in all sectors and of course, in the energy sector in several aspects and in most of the big stakeholders. The energy sector is one of the most important sectors that data exchange and sharing has increased exponentially in the last 5 to 10 years. Any new digital service, application within the sector is based on the data processing of the users and networks, which implies a strong impact of the regulation. Any user contract or between companies must comply the GDPR, DA or DGA, an analysis work on the regulation is needed by companies with experts on the subject. Then, the adaptation of the new contracts to regulation takes more work, but finally establishes a clear path on how to share and collect data. In the next years, the consequences on the market and individuals could be measured and have more accurate conclusions on the impact of the regulation. For now, it is, somehow, uncertain to quantify the benefits or barriers for the market, but what it is clear is that the European values where individuals are in the centre, keep being key for our development. 


TAGS:

UPDATE