Privacy by design for public digital money

Privacy by design for public digital money

20. März 2026
Working Paper 278
Martin Summer
LinkedIn Facebook X E-Mail
Link kopieren

Summary

As central banks develop digital currencies for public use, a critical challenge is protecting the privacy of granular data trails that digital payments leave behind. This paper argues that privacy should be a built-in feature of digital money, not a trade-off with crime prevention. Drawing on advances in privacy-enhancing technologies and strategic game-theoretic analysis, it shows that strong privacy and verifiable compliance can coexist. Three design principles are proposed for privacy protective CBDCs, along with a PET dashboard mapping technologies to system layers.

Highlights

Privacy and compliance are not opposing forces
Integrating a technical design framework with a strategic game[1]theoretic model, the paper shows that privacy and auditability can be engineered as two separate design dimensions. Modern privacy[1]enhancing technologies enable cryptographic shielding of routine payments while automatically triggering disclosure above policy[1]defined thresholds.

Architecture hard-codes incentives
Architectural choices made today will shape institutional credibility for decades. Payment data reveal not only consumption but also vulnerability. Privacy-enhancing technologies have advanced faster than most CBDC design processes could absorb — opening a window to strengthen protections before architectures are locked in

Core PET building blocks are production-ready
Authenticated encryption, zero-knowledge proofs, threshold cryptography, and network-layer protections are used in live systems today. The remaining gap is not scientific uncertainty but engineering maturity, regulatory clarity, and institutional commitment to making privacy a genuine design priority.