Core Focus: The critical trade-off between user privacy and regulatory oversight in CBDC design, the various privacy-enhancing technologies available, and the policy frameworks for balancing these competing objectives.
In-Depth Notes:
Privacy is arguably the most contested issue in CBDC design. Users demand privacy, while regulators require transparency to prevent illicit finance. This tension is not merely a technical problem but a fundamental governance challenge.
User Demand for Privacy:
Evidence from a survey experiment in the US shows that strong privacy safeguards raise adoption willingness by up to 60%, underscoring that privacy is not merely a civil liberty concern but a prerequisite for widespread CBDC success. The IMF has warned that jurisdictions designing rCBDCs should conduct thorough, ongoing AML/CFT risk assessments and adopt a risk-based approach to mitigation . Privacy and offline payments, features often prioritised to increase uptake, add further trade-offs .
Privacy-Enhancing Technologies:
Several privacy-enhancing technologies can be deployed to protect user privacy while maintaining regulatory compliance. A paper by the Bank of England’s CBDC Technology Forum explored a hybrid account-token model which aimed to ensure protection of user balances, support for offline payments and improved user privacy . The proposed model blended aspects of the account system, such as balance protection, and the token system, such as offline capability, while allowing for improved privacy . Some Members warned that relying on encryption alone to protect transaction data shouldn’t be an acceptable proposition, as it had to be assumed encryption could be broken in the future .
Design Solutions for Privacy:
To balance privacy and traceability, CBDC designs often incorporate a multi-layered approach:
-
Pseudonymisation: User identities are replaced with pseudonyms for routine transactions, with real identities revealed only when necessary for AML/CFT compliance.
-
Zero-Knowledge Proofs: These allow a user to prove that a transaction is valid without revealing the details of the transaction.
-
Tiered Wallets: Users can choose between wallets with different levels of privacy and holding limits. A token-based CBDC could provide anonymity for small-value transactions, while account-based wallets with higher limits would be subject to full KYC.
-
Data Minimisation: Only the minimum data necessary for compliance is collected and retained.
Financial Integrity Implications:
The IMF stresses that key design choices, including token- versus account-based models, intermediated distribution, offline functionality and privacy features, have major implications for who holds responsibility for AML/CFT controls . For account-based retail CBDC issued directly by the central bank, the responsibility to perform due diligence and report suspicious transactions shifts to the central bank, potentially requiring it to expand its operations beyond existing mandates . For account-based retail CBDC issued indirectly through financial intermediaries, the responsibility to conduct KYC naturally lies with those intermediaries . The IMF recommends privacy-preserving options combined with regulatory safeguards so that user protection does not become a loophole for illicit flows .