In this article
Your solar monitoring knows when the house is empty. Not because anyone designed it to, but because a consumption graph with a flat weekday between 9 and 3 and a spike at 6 is a description of your household’s routine. That is the honest starting point for this conversation, and most quotes never mention it.
In short
- Energy data is behavioural data. Generation, consumption, battery charge and discharge together describe occupancy patterns.
- The real risks are boring: default passwords, installer accounts left active, and firmware nobody updates. Not sophisticated attacks.
- Ask three questions of any provider: what is collected, where is it stored, and who still has access after the install.
- PSW does not sell customer energy data. Ask any provider that directly and get the answer in writing.
Energy data and household routines
A modern system records how much you generate, how much you use, when you use it, how the battery charges and discharges, and how all of that interacts with the grid. Every one of those is needed to make the system work and to spot a fault early. None of it is sinister on its own.
The privacy question is what the pattern implies once it is tied to an address. A fortnight of flat daytime consumption reads as an empty house. A sharp drop across two weeks in January reads as a holiday. For a business it is more sensitive again: load profile is production schedule, and shift patterns are visible in it.
This is not a reason to avoid monitoring, which is the thing that tells you a string has dropped out before you notice it on a bill. It is a reason to know where the data goes.
Common access risks
Not a targeted attack. The realistic failures are unglamorous and common: a default password never changed at commissioning, an installer account left enabled years after the job, firmware two versions behind because updating it was nobody’s job, or a monitoring login shared by a household and then by a former housemate.
For a home the consequence is usually privacy rather than damage. For a business with a system that can be reconfigured remotely, someone changing settings could affect operations, which is a different order of problem and worth treating that way.
Questions for the provider
1. What is collected, and why?
Ask which data points the platform collects and what each one is used for. An answer such as “For performance optimisation” needs more detail.
2. Where is it stored?
Most platforms use cloud storage so you can check the system remotely. Ask who operates it, usually the equipment manufacturer, and which jurisdiction holds the data.
3. Who has access, and for how long?
Ask whether your installer, the manufacturer or a third-party monitoring service has access, how long data is kept, and what happens if you sell the house or change installers.
Ask for the data-handling terms in writing so you can check them after the conversation.
PSW’s data handling
We collect what is needed to run, monitor and support the system, and not more. We do not sell customer energy data and we do not treat it as an asset. External access is limited and purposeful. Access to monitoring platforms is controlled, and remote connections are handled with standard security practice rather than shared credentials.
Worth being straight about the limits of that: most of the platform is the manufacturer’s, not ours. When you install a Tesla or a Sigenergy system, you are also entering that manufacturer’s data arrangement, and their privacy terms apply alongside ours. Anyone claiming complete control over data that lives on someone else’s cloud is overstating it.
The detail is in the PSW Cybersecurity and Personal Data Management Policy. If you would rather ask a person, PSW Life Support will take the question.

