Piero Cipollone, a member of the European Central Bank’s (ECB) Executive Board, recently claimed that the digital euro—Europe’s central bank digital currency (CBDC)—“guarantees the maximum level of privacy that current technology can offer.”
The surveillance capabilities of CBDCs have long been a concern, especially in Western Democracies that have increasingly taken an interest in techno-authoritarianism (whether they believe it or not). Cipollone, however, assured the interviewer that Europeans should not be concerned about financial surveillance with the digital euro since offline transaction details “will only be available to the payer and the payee.”
For online transactions, however, the Eurosystem (the monetary authority consisting of the ECB and the national central banks that have adopted the euro) would not be able to identify the parties involved, but “the banks involved in the transaction would be able to do so, including for anti-money laundering purposes.” Stated differently, the EU governments won’t be keeping a close eye on Europeans themselves, they’ll just have the banks do it for them and report back. So, not too different from the current more-or-less fully surveilled financial system.
These are two very different statements for the two modes of transactions that can occur with the digital euro (i.e., offline and online), so it would be good to better understand what’s actually going on, according to the ECB’s draft rulebook for a digital euro.
Cipollone states that transactions occurring offline are private and peer-to-peer (he doesn’t use that exact term but I’m contractually required to use it in our newsletter); whereas, online transactions would work the same as traditional digital payments, where an intermediary is involved but settlement would occur on one central infrastructure and not with various banks.
Online transactions go something like this:
Alice wants to send money to Bob;
Alice initiates the transaction through a payment service provider’s (PSP) application;
The PSP authenticates her and validates/screens the transaction;
Alice’s PSP sends the payment instruction to the Eurosystem’s Digital Euro Service Platform (DESP);
DESP forwards it to Bob’s PSP for validation;
After each PSP validates the transaction, DESP settles it and confirms settlement to both PSPs, which then notify Alice and Bob.
That last point is where Cipollone states that banks (i.e., PSPs) would identify parties involved in a transaction—that is, identify their respective customers. This is how the world currently works, so this is no surprise.
Offline transactions are more representative of peer-to-peer transactions (I get paid by the amount of times I say it), where a payer is able to send money to a payee between their devices without an intermediary, where transaction authentication happens locally on each participant’s device.
Here is how offline transactions work:
Alice enters the transaction details into her application and the software in her device authenticates the details locally;
The payer and payee tap their phones using near field communication (NFC), which allows two devices to exchange communications when they are near each other;
The two applications authenticate each other; both devices validate the transaction (meaning the payer’s device ensures they have enough money and the payee’s device ensures that receiving the money would not exceed its offline holding limit or transaction-number limit);
The balances then update locally;
The payee confirms the settlement by sending confirmation back to the payer’s application. (Look to Annex B2, pages 222-224, for more details.)
But while the transaction itself is designed to be peer-to-peer when done offline (there’s my annual bonus), onboarding and device registration still requires user verification and identification with a PSP. The DESP is also informed of when euros are issued to a device and when they are redeemed. For example, Alice would go through the DESP to move €100 to her offline wallet; the DESP processes the transaction; and Alice’s device now has an offline balance of €100. The operation is processed through Alice’s PSP and DESP. And when Alice sends €80 to Bob, there is no involvement of a PSP nor DESP. However, if Bob then redeems the €80, he would have to do so online through a PSP and DESP.
Here is where things get tricky. These offline transactions are not entirely similar to cash transactions, because while the transaction can be done in a peer-to-peer manner, the registered devices are still subject to limits and periodically required to complete integrity checks with the DESP. Furthermore, as previously mentioned, there are offline holding limits that dictate how much a device can hold offline, meaning that a user’s device could reject a transaction if the user hits their limit. The device would also reject transactions if the user reaches a certain number of consecutive offline transactions.
All this in mind, the digital euro and its associated software would be best described as having mechanisms in place for peer-to-peer transactions, but also having mechanisms in place for centralized controls on transactions and checkpoints for user identification. Is this the kind of technology that would maximize privacy for users? Not quite. It allows for some privacy, but information leakage is very much prevalent. Nor is this the kind of technology that empowers Europeans with greater autonomy the way cash does. There are very strict limitations that exist at the discretion of EU authorities.
The digital euro remains in negotiations between the EU Commission, Parliament, and Council. Meanwhile, the ECB is currently developing a pilot and, as of mid-August, has requested participants for developing offline digital euro standards. The draftbook (that has acted as our point of reference) will continue evolving consistent with negotiations and technical developments.
This timeline has always seemed inevitable. Monetary policy and fiat currency have historically been useful instruments in domestic and foreign influence—nation states were not going to simply lie down while financial technology evolved towards peer-to-peer networks and (actual) user-controlled wallets. But we knew this, and so our fight continues towards privacy-preserving electronic cash that operates on open, decentralized blockchain networks.
-Laz
What else we’re reading
Peter wrote a fiery blog about the recent ID leak. It’s become our most popular post yet. You should read it: The huge driver’s license hack was inevitable. It’s time to get mad.
Roman Storm, a creator of Tornado Cash who has become the face of open source developers being held accountable for other people’s illicit use of his code, wrote a response as well: Privacy for Criminals, Ladies and Gentlemen
Lawsuit challenges Tether for allegedly freezing $42.4 million USDT before U.S. warrant - An interesting result of the debate over best practices for proactive stablecoin freezing.
Autistici/Inventati is furious at their Italian bank for caving by U.S. sanctions.
Thanks for reading. If you found this interesting, please share it. We are trying to grow this thing.







