Fundamentals

Central Bank Digital Currencies and Privacy: What Is at Stake and Which Limits Matter

By Daniel Sardá · Published on

8 min read1,542 words

In this article · 7 sections

The privacy of a central bank digital currency does not follow from a label; it depends on its architecture, its rules, and effective limits on access to and use of data.

When we pay for a coffee, who can know what we bought, where, when, and how much remains in our account? With cash, the merchant witnesses the transaction, but a central record tied to our identity is not normally created. A digital payment, by contrast, may involve banks, processors, apps, and public authorities with varying degrees of access.

Central bank digital currencies add a new possibility to that picture. Also known as CBDCs, they would be public money in digital form. The important question is not whether “digital” destroys privacy, but who can connect each payment to a person, under what rules, and with what remedies when power is abused.

Key idea: “CBDC” identifies the issuer and nature of the money, not a particular level of privacy. Two designs can share the label while offering very different safeguards.

What a CBDC is—and is not

A retail CBDC is a digital instrument denominated in the national currency, issued as a direct liability of the central bank, and available to the public for everyday payments. That is how the Bank for International Settlements’ foundational principles describe it. It is the form relevant to an ordinary purchase; a wholesale CBDC, by contrast, is intended for transactions among financial institutions.

The distinction may sound technical, but it matters. The balance in an ordinary bank account is a liability of the commercial bank. A CBDC would be a liability of the central bank, even if a private entity operated the wallet or served the user. To better understand the issuer, it helps to begin with what central banks are and how they exercise monetary power.

Nor would it be a private cryptocurrency simply because it uses digital technology. Bitcoin has no central-bank issuer; a stablecoin will generally represent a liability or reserve managed by a private entity. Comparing it with Bitcoin can clarify differences in control and governance, but it does not make all these instruments equivalent.

The path of the data matters more than the screen

To assess privacy, it is not enough to ask whether the central bank “sees” a payment. We need to follow the data through its whole path.

When a wallet is opened, an intermediary may verify the user’s identity. When it is funded, the bank or provider may record where the funds came from. During payment, the merchant knows at least what was purchased; the provider may process identifiers, amount, and time; and the infrastructure operator may receive technical information. Other stages follow: fraud prevention, dispute resolution, record retention, and responses to an authority’s order.

That is why a statement such as “the central bank does not see the identity” can be true and still incomplete. An intermediary may nevertheless be able to link the identity to a transaction history. Separate datasets may be cross-referenced. The reverse is also possible: a tightly limited public infrastructure might expose less commercial information than a system financed by consumer profiling.

The question should be asked by actor and by stage:

Privacy is not the same as anonymity

Financial privacy means that there are limits on observing, linking, retaining, reusing, and disclosing our payment data. It does not necessarily require that no one can identify us in any circumstance.

Anonymity means that a person cannot reasonably be identified. Pseudonymization, by contrast, replaces directly identifying data with codes or other identifiers. It reduces immediate exposure, but it can be reversed when someone has additional information. The European Union’s General Data Protection Regulation treats pseudonymized data that permits reidentification as personal data, not anonymous information.

This distinction avoids false reassurance. If a CBDC operator receives transactions under a pseudonym, the protection depends on who holds the matching key, when it may be used, and whether every query leaves an auditable trace.

Online and offline payments

An offline payment can settle between devices without consulting a remote system at that moment. If designed well, it can reduce the transaction data shared with intermediaries and keep working during a connectivity failure. It is not, however, a perfect copy of cash.

Funding and unloading a wallet may leave records. Limits on balances or amounts, needed to contain loss, fraud, or double spending, also require controls. And “offline” can describe different degrees of disconnection depending on the architecture.

The digital euro provides a useful case, so long as it is presented as a proposal rather than a universal model. The European Central Bank has proposed that offline payments be known only to payer and payee, while online payments would provide the Eurosystem with pseudonymized data and intermediaries would meet applicable legal obligations. These are announced features of a design under development, not evidence that every CBDC works this way or a guarantee on their own.

In 2023, Europe’s independent data-protection authorities called for clearer responsibilities, limits to necessary data, and safeguards against excessive centralization. Their observation reveals an essential difference: an architectural promise must become enforceable obligations.

Key idea: An offline payment may resemble cash from the perspective of particular observers, but it does not necessarily erase the data created when funds are obtained, risks are managed, or the system reconnects.

A comparison without false absolutes

Each payment method distributes trust and visibility differently:

La diferencia puede resumirse así:

The table does not produce an automatic winner. Cash protects well against systematic recordkeeping, but has practical limits. Bank payments facilitate dispute resolution and fraud prevention at the cost of creating histories. A CBDC might reduce reliance on companies that monetize data, but it could also create a powerful surveillance infrastructure if it lacks limits.

The same is true of so-called programmability. Automating a transfer when a condition is met—for example, releasing payment once delivery is confirmed—is not the same as allowing the issuer to decide where or when every unit may be spent. Nor does the technical capacity to freeze funds by itself create unlimited legal authority. But a written prohibition does little without technical controls, oversight, and effective remedies.

From promise to guarantee

Technical and legal privacy reinforce one another, but neither substitutes for the other. Data minimization reduces what can leak or be misused. Encryption, separated databases, and offline functionality can lessen exposure. Even so, software changes, exceptions expand, and an administration may interpret rules differently.

A robust safeguard should be able to answer, at minimum, these questions:

  1. Purpose: For what specific purpose is each item of data collected?
  2. Minimization: Can the payment be completed with less information?
  3. Retention: When is the record deleted, and who verifies that it happens?
  4. Access: Which official or entity may consult data, and under what authorization?
  5. Audit: Does every access leave a trail that an independent supervisor can review?
  6. Due process: Can a person challenge a freeze, correct an error, and obtain redress?
  7. Rule changes: Can uses be expanded without public debate or judicial review?
  8. Choice: Do cash and viable private alternatives remain available?

Fraud, money laundering, and other crimes create legitimate needs. Precisely for that reason, discretionary access should be replaced with general rules: a defined purpose, necessity, proportionality, authorization, traceability, and independent review. General laws and limits on arbitrary power do not prevent investigation; they seek to ensure that the exception does not become ordinary surveillance.

Key idea: A safeguard is credible when it combines a clear rule, verifiable implementation, independent oversight, and a remedy for the person affected.

Privacy and freedom of choice

From a liberal perspective, financial privacy protects a sphere of everyday autonomy. Buying a book, supporting an association, or receiving medical treatment should not make someone the object of permanent monitoring. That freedom does not rest on hiding all activity from every investigation; it rests on preventing power from observing or conditioning everyone without individualized cause.

The ability to exit also matters. If a CBDC coexists with cash and private means of payment, people retain alternatives when systems fail, exclusions occur, or policy changes. If it becomes the only practical way to pay, even a formally generous guarantee loses force: users can no longer refuse intrusive terms.

Central bank digital currencies do not inevitably lead either to total surveillance or to stronger privacy. They can be designed to limit exposure, but they can also concentrate data and capabilities. Responsible assessment begins where the label ends: in the real path of information, legal powers, independent controls, and an effective ability to choose. That is where it is decided whether a monetary innovation serves people or expands a power that will later be difficult to constrain.

Privacy: What It Is and Why It MattersPrivacy protects a sphere of personal discretion and decision-making. Understanding it requires distinguishing it from secrecy, anonymity, and data protection.What Are Central Banks? Functions, Monetary Power and Liberal CritiquesWhat central banks are, how they work, why they influence inflation, credit and public debt, and the main critiques from a liberal-libertarian perspective.What Is a Central Bank and What Does It Do?A central bank manages the basic forms of money and exercises the powers assigned to it by law. Its decisions matter for payments and financial conditions, but cannot replace production, fiscal discipline, or credible rules.