Privacy by design for public digital money
Privacy by design for public digital money
Summary
As central banks develop digital currencies for public use, a critical challenge is protecting the privacy of granular data trails that digital payments leave behind. This paper argues that privacy should be a built-in feature of digital money, not a trade-off with crime prevention. Drawing on advances in privacy-enhancing technologies and strategic game-theoretic analysis, it shows that strong privacy and verifiable compliance can coexist. Three design principles are proposed for privacy protective CBDCs, along with a PET dashboard mapping technologies to system layers.
Highlights
Privacy and compliance are not opposing forces
Integrating a technical design framework with a strategic game[1]theoretic model, the paper shows that privacy and auditability can be engineered as two separate design dimensions. Modern privacy[1]enhancing technologies enable cryptographic shielding of routine payments while automatically triggering disclosure above policy[1]defined thresholds.
Architecture hard-codes incentives
Architectural choices made today will shape institutional credibility for decades. Payment data reveal not only consumption but also vulnerability. Privacy-enhancing technologies have advanced faster than most CBDC design processes could absorb — opening a window to strengthen protections before architectures are locked in
Core PET building blocks are production-ready
Authenticated encryption, zero-knowledge proofs, threshold cryptography, and network-layer protections are used in live systems today. The remaining gap is not scientific uncertainty but engineering maturity, regulatory clarity, and institutional commitment to making privacy a genuine design priority.