Privacy Policy
Updated 27 November 2023
This privacy policy is provided by Elexon Limited (referred to as “Elexon”, “us”, “we” or “our” in this privacy policy). It explains who we are, how we collect, use and protect your personal data, and your rights in relation to your personal data, in accordance with applicable data protection and privacy laws (including the General Data Protection Regulation (‘GDPR’) and the Data Protection Act 2018).
Elexon is a controller for the purposes of relevant data protection legislation and is responsible for the personal data we collect.
It is important that you read this privacy policy together with any other privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data.
This Website is not intended for children and we do not knowingly collect data relating to children.
The data we collect about you
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include anonymised data (where the individual is no longer identifiable).
The personal information that you provide and how we use it may differ depending on your relationship with us.
Representatives of BSC Parties and other market participants
BSC Parties, Party Agents, MHHS participants and other market participants under the BSC are required to provide certain information to Elexon under the Code and in relation to our payment and settlement activities, and may provide details of their employees or representatives in relation to BSC requirements. If you are one of these employees or representatives, we will process your personal data for the purposes described in the BSC, and to fulfil our obligations generally.
These purposes may include:
- progressing BSC changes and providing notices under the BSC
- accession to the BSC and maintaining records of Party details
- qualification, compliance and assurances processes under the BSC
- arranging meetings and recording meeting minutes
- providing industry training and information sessions
- other matters related to BSC management, such as notifying Parties about BSC developments, market information or any other purposes relating to the operation of the BSC
- to undertake payment and settlement functions under the BSC and in relation to the Electricity Market Reform (EMR) Contract for Difference (CFD) and Capacity Market (CM) mechanisms
- to provide, maintain and improve BSC Systems
- to fulfil our functions in relation to MHHS Implementation, and our role as MHHS Implementation Manager
- seeking feedback from our industry customers, including customer satisfaction surveys, to make improvements to our services
- to undertake any processing required by any law and/or requested by government or regulatory bodies, or law enforcement organisations
For this purpose, we may process the following types of personal data:
- name
- business contact details, including physical addresses, email addresses and phone numbers
- job title, and place of work/employer
- in relation to some settlement, assurance, audit and compliance activities, we may process data that includes electricity meter identification information, including residential addresses of electricity consumers, and electricity consumption data
Members or participants of any BSC panel, committee or workgroup
We may process your personal data if you are a BSC Panel member or a member of one of the Panel’s committees or workgroups, one of the MMHS Governance Framework bodies or industry groups, or attend other industry meetings at Elexon.
We process your personal data for the purposes of:
- arranging meetings and recording meeting minutes
- notifying you of BSC and market related developments
- providing industry training and information sessions
- Panel, committee and workgroup administrative matters
- administrative matters in respect of MHHS Governance Framework bodies and industry groups
- in respect of Panel members, in some cases remuneration related matters
- other matters related to the operation of the BSC and to fulfil Elexon’s duties under the BSC
- to undertake any processing required by any law and/or requested by government or regulatory bodies, or law enforcement organisations
For this purpose, we may process the following types of personal data:
- identity data including full name, title, date of birth and gender
- contact details, including physical addresses, email addresses and phone numbers (in most cases these will be business contact details unless you chose to provide home or personal contact details)
- in limited circumstances related to Panel member remuneration, bank account details
Service providers, contractors and suppliers
We may process your personal data if you are one of our service providers, or if you represent one of our service providers, for the following purposes:
- procurement or management of a contract
- to fulfil Elexon’s duties and perform our functions under the BSC
- to undertake any processing required by any law and/or requested by government or regulatory bodies, or law enforcement organisations
For this purpose, we may process the following types of personal data:
- name
- business contact details, including physical addresses, email addresses and phone numbers
- job title and place of work/employer
Electricity Consumers
If you are an electricity consumer and a customer of a BSC Party, we may process your personal data where we receive it from a BSC Party, Party Agent, our subsidiary EMR Settlements Limited, a BSC Agent, or from another code administrator or market participant.
We process this data for the following purposes:
- to fulfil Elexon’s duties and perform our functions under the BSC, including compliance and assurance processes for BSC Parties and market participants, and MHHS Implementation
- to undertake our functions in relation to payment and settlement activities
- to provide, maintain and improve BSC Systems
- to undertake any processing required by any law and/or requested by government or regulatory bodies, or law enforcement organisations
- in our role managing the implementation of MHHS programme, in order to test industry systems and processes and to manage the migration of market participants to new market arrangements
For this purpose, we may process the following types of personal data:
- name
- contact details, including physical addresses, email addresses and phone numbers
- in relation to some settlement, assurance, audit and compliance activities, we may process data that includes electricity meter identification information, including residential addresses of electricity consumers, and consumption data
- in relation to MHHS testing and migration, we may process data that includes electricity meter identification information (including MPANs)
Website use and general enquiries
You can visit https://www.elexon.co.uk (‘our Website’) and https://www.mhhsprogramme.co.uk without disclosing any personal information about yourself.
We endeavour to collect and use your personal information only with your knowledge. We typically collect personal information when you:
- use services
- make customer enquiries
- register for information or other services
- when you respond to communications from us (such as questionnaires or surveys)
We may also collect information we observe about you, for example via cookies when you visit our Website.
We will use your personal data for the purposes described to you at the time you provide your data to us. These purposes may include:
- Responding to and keeping a record of your enquiries if you contact us
- Sending you information about Elexon’s activities and the electricity market, including where you have subscribed via the Elexon Website or the MHHS website to receive circulars, newsletters or newscasts by email
- Investigate, respond to and/or process any complaints, claims for loss, damage and/or injury
- Aggregate/process personal data for research, statistical and/or scientific purposes in accordance with our commitment to health, safety, environmental, commercial interests and/or security purposes
- Any other processing for which you have given your consent
- Any processing required by any law and/or requested by government or regulatory bodies, or law enforcement organisations
Where you have subscribed to receive email communications, we may use your personal information to keep you informed of our activities, events and other general matters, as described in the subscription form. If you do not wish to be contacted for these purposes, please let us know by using the contact details in “Your Rights in Relation to Your Information” below.
The types of personal information collected for these purposes could include, for example, your:
- name
- contact details, including physical addresses, email addresses and phone numbers
- job title and place of work/employer
- IP address and information collected through cookies
We may also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.
We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data), and we do not collect any information about criminal convictions and offences.
Closed-Circuit Television (CCTV) use
We are committed to the safety and security of our employees and visitors. As such we use a closed-circuit television system (‘CCTV’), primarily at our access points such as the entrance and exit points and in our restricted areas.
We are aware that images of recognisable individuals such as employees and visitors, captured by the CCTV system constitute personal data and so we will ensure that the data it captures complies with the law.
The purpose of the CCTV system is to:
- increase the personal safety of our employees and visitors to our premises
- assist in detecting unauthorised access on our premises or in our restricted areas
- support our health and safety measures
- to protect our employees and visitors from intrusion, theft, vandalism, damage or disruption
Signs are displayed prominently around the premises to inform employees and visitors that CCTV cameras are in operation and who to contact for further information.
How we use your personal data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests. Our legitimate interests in processing personal data are our interests in in performing our functions and fulfilling our obligations under the BSC, including delivering payment and settlement services and BSC systems, and undertaking activities necessary for the performance of those functions.
- Where we need to comply with a legal obligation.
Where we process your data on the basis of legitimate interests, we have considered the impact of relevant processing on your interests and rights, and have in place appropriate safeguards to ensure that any intrusion on your privacy is reduced as much as possible.
Generally, we do not rely on consent as a legal basis for processing your personal data, although we may in some circumstances seek your explicit consent for certain processing. For example, we may seek your consent to provide your business contact details to other industry participants where this may facilitate efficiency and/or the coordination of industry change.
How long we store your personal information for
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including to meet any legal, accounting, or reporting requirements, including requirements under the BSC, in line with our retention policy.
When we determine how long we will keep your personal data, we consider any minimum retention requirements set out in law, as well as the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means.
CCTV footage is automatically deleted after 30 days, but if required for an incident investigation, may be extracted from the system and kept for as long as necessary in relation to that investigation.
To whom will your information be disclosed (“Recipients”)?
For the purposes detailed above, your information may be disclosed for processing to:
- selected Elexon employees
- Directors of Elexon
- our subsidiaries, including EMR Settlement Limited and Elexon Clear Limited, and their employees, contractors and other personnel who use personal information to provide payment and settlement services
- third party service providers who use your personal information to provide services to us (“Service Providers”)
- auditors, contractors or other advisers auditing any of our business processes or engaged to provide professional advice to the business (“Third Parties”)
- BSC Agents
- BSC Parties or Party Agents, including the National Electricity Transmission System Operator
- Members of the BSC Panel, committees and workgroups, and members of MHHS Governance Framework bodies and industry groups
- Ofgem and other government bodies or regulators, courts, or law enforcement bodies
- Other code managers or central industry bodies
Any processing performed by Elexon, Service Providers or Third Parties will be governed by an agreement requiring compliance with relevant data protection legislation. Our service providers are only permitted to process your personal data for specified purposes in accordance with our instructions.
Your rights in relation to your information
As a data subject you have rights in certain circumstances in relation to your personal data under relevant data protection legislation
Request access to your personal data
This is commonly known as a “data subject access request”. This enables you to receive a copy of the personal data we hold about you and to check that we are processing it lawfully.
Request correction of the personal data
This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
Request erasure of your personal data
This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with legal requirements. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Object to processing of your personal data
This enables you to object to processing where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms.
Upon receiving your request we will contact you and let you know if we are able to comply or if we have legitimate grounds to continue to process your data. Even after you exercise your right to object, we may continue to hold your data to comply with your other rights or bring or defend legal claims.
Request restriction of processing of your personal data
This enables you to ask us to temporarily suspend the processing of your personal data in the following circumstances:
- If you want us to establish the data’s accuracy.
- Where our use of the data is unlawful but you do not want us to erase it.
- Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
- You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
Request the transfer of your personal data
This can be transferred to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
Withdraw consent at any time
This enables you to withdraw consent at any time if we have notified you that we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain services to you. We will advise you if this is the case at the time you withdraw your consent.
Please be aware that there are exceptions and exemptions that apply to some of these rights, which we will apply in accordance with data protection legislation.
You can write to us at any time to exercise your rights. Please email us at: communications@elexon.co.uk
Or write to:
Elexon Ltd
4th Floor
350 Euston Road
London
NW1 3AW
Please include your name and address. We would be grateful if you could also provide brief details of the personal information of which you would like a copy or which you would like to be corrected (this helps us to locate your data more easily). We will require proof of your identity before providing you with details of any personal information we may hold about you.
We will attempt to respond to any rights that you exercise within a month of receiving your request, unless the request is particularly complex, in which case we may extend this timeframe.
International transfers
We process your data either in the UK or in the European Economic Area (EEA). Where our major suppliers (or their subsidiaries) undertake some operations outside the UK, we place them under contractual obligations to process your data in the EEA. Where our suppliers seek to transfer any personal data outside the EEA, we require that they first obtain our consent, and that they have in place an adequate level of protection for any personal data that is transferred in accordance with the requirements of relevant data protection legislation.
Information security
Please be aware that communications over the Internet, such as emails/webmails, are not secure unless they have been encrypted. Your communications may route through a number of countries before being delivered – this is the nature of the internet. Elexon does not accept responsibility for any unauthorised access or loss of personal information that is beyond our control.
We believe we have appropriate policies, rules and technical measures to protect the personal information that we have under our control (having regard to the type and amount of that data) from unauthorised access, improper use or disclosure, unauthorised modification, unlawful destruction or accidental loss.
All our employees and data processors that have access to, and are associated with the processing of your personal information, are obliged to respect the confidentiality of our visitors’ information.
We ensure that your personal information will not be disclosed to government institutions or authorities except if required by law or when requested to by regulatory bodies or law enforcement organisations.
Cookies
Please note that when you visit our Website we will use cookies. Cookies allow us to store your preferences to correctly present content, options or functions throughout our Website and distinguish you from other users of the Website.
They also allow us to analyse information about how many people use our website and what pages they tend to visit. We do this to provide you with a better Website by monitoring which pages you find useful and improving the Website to better meet your needs.
Cookies do not give us access to your computer or any information about you, other than the data you choose to share with us.
To learn more about the cookies that we use please view our Cookies Policy.
Third-party links and personal information submitted to other websites
This Website may include links to third-party websites. Accessing those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. We cannot be responsible for the privacy policies and practices of other websites even if you accessed the third party website using links from our Website, or you linked to our Website from a third party website.
We recommend that you check the privacy policy of each website you visit and contact the owner or operator of such website if you have any concerns or questions.
Changes to this policy and your personal information
We keep our privacy policy under regular review and reserve the right to amend or modify this Privacy Policy Statement at any time and in response to changes in applicable data protection and privacy legislation. This version was last updated on 18 October 2019.
In the event of processing change, then we will notify you as soon as practicable and seek your consent if appropriate where such notification relates to a new additional purpose for processing.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
Contact details
If you have an enquiry about:
- our data protection and privacy policy or practices
- any requests to exercise your legal rights,
please contact us in the following ways:
- Email address: communications@elexon.co.uk
- Postal address: Elexon Ltd, 4th Floor, 350 Euston Road, London NW1 3AW
- Telephone: +44 (0)20 7380 4100 (main switchboard)
You also have the right to make a complaint at any time about a data protection issue to the Information Commissioner’s Office (ICO), the UK regulatory authority for data protection. Information about how to make a complaint is available on the ICO’s website at www.ico.org.uk. We would, however, appreciate the chance to deal with your concerns before you approach the ICO, and would encourage you to contact us in the first instance using the contact details above.