Abstract2.1. Introduction2.2. The Dutch Case Study: A Smart Grid Roll-Out that Neglected Individual Interests2.3. The Smart Grid: A Socially Complex Phenomenon with a Surveillance Dimension2.4. Privacy and Personal Data Protection in the European Legal Order2.5. Privacy Testing and Data Protection Testing of Smart Grids2.6. Regulating Smart Grids in Europe: A “Light” Approach to Personal Data Protection2.7. The EU “Light” Regulatory Approach to Personal Data Protection in Smart Grids: An Evaluation2.8. Conclusion: DPIA Testing is a First Good Step but a More Inclusive, Easy to Apply and Flexible Solution is NecessaryAcronyms