Articles Default

€rypto: the digital euro still has a privacy problem

On 9 July 2026, shortly before the summer break, the European Parliament confirmed its negotiating position on the regulation establishing a digital euro, by 416 votes to 169 with 22 abstentions. The vote followed the position adopted by the Economic and Monetary Affairs Committee on 23 June by 43 votes to 14, and was triggered when three political groups challenged the committee’s decision to move straight into negotiations.

This is a mandate to negotiate, not a finished law. Talks between Parliament, Council and Commission are under way, with a deal targeted for the end of 2026. The European Central Bank (ECB) has penciled in a pilot for 2027 and a possible first issuance in 2029. There is still time to influence the design — which is precisely why the design deserves scrutiny now.

The case for the digital euro is real and should be stated fairly. Europe currently depends on a small number of non-European card networks and, increasingly, on dollar-denominated stablecoins. A public digital payment instrument is a serious answer to that dependency. Parliament has also strengthened the proposal in consumer-friendly ways, capping holdings and reinforcing protections for physical cash.

The question is not whether Europe needs public digital money. It is what that money reveals about the people who use it.

Why the shopkeeper matters

Some members of the European Parliament have argued the digital euro should be built on a blockchain, or distributed ledger technology (DLT) — a shared transaction record that participants can read and verify independently.

That design carries a specific and underappreciated consequence for ordinary shoppers. Merchants must keep books. Every payment must be reconciled and survive a tax inspection, which means the customer’s wallet address ends up in the shop’s accounts and accounting software. On an open ledger, a wallet address is not merely a reference number: it is a permanent, publicly searchable financial history. Anyone holding it can look up the balance and every past transaction.

In practice, a corner shop could see a customer’s account balance and spending history. Until now, that capability has belonged to banks, which are supervised, bound by confidentiality rules, and answerable for misuse.

But this is an important distinction: that is not the architecture currently being developed for the digital euro. The blockchain scenario is therefore a useful illustration of what can go wrong when payment architecture makes financial activity unnecessarily observable, rather than a description of the system now on the table.

The privacy question does not disappear simply because the proposed architecture is different. It changes form.

Two fixes, two different failures

Two mitigations are usually proposed, and both carry costs worth weighing openly.

The first asks users to protect themselves: a fresh wallet address for every payment, and mixing services that pool funds so they cannot be traced onward. This works only if applied consistently — a single reused address links the record permanently, and ledgers do not forget. It also asks people to run technical routines just to buy groceries, making privacy a benefit available mainly to expert users. Mixing services additionally sit close to, and sometimes inside, the legal definition of money laundering.

The second inserts a regulated payment service provider (PSP) — a bank or licensed payments firm — between shopper and shop. This does remove the merchant’s view. It does not remove the observer; it appoints one. The intermediary sees both sides of every transaction, across every customer and merchant it serves, and gains authority over who may transact. That describes banking, which raises a fair question: if the answer to the privacy problem is a regulated intermediary holding all the data, what has the new architecture added?

Between the two, the trade-off is one of scope. User-side mixing fails individually, silently and unevenly. An appointed intermediary becomes permanent financial infrastructure with a lasting commercial interest in the data it holds.

What is actually proposed

Fairness requires an important correction. The digital euro is not being built on distributed ledger technology. The design is a centralized settlement platform operated by the Eurosystem, with no public ledger exposing anyone’s balance. The blockchain scenario above remains conditional.

What survives the correction is the second concern. Under the proposed model, payment service providers hold users’ identities, perform identity checks and manage accounts. The ECB processes only pseudonymized data. The intermediary, however, sees every transaction. The trusted-party critique is not an objection to a rejected design; it describes the chosen one.

The offline euro and the data it leaves behind

The proposal’s strongest privacy feature is offline payment: funds are pre-loaded onto a tamper-resistant chip in a phone or card and transferred directly between devices, with no intermediary involved.

The detail that deserves public attention is what happens on reconnection. Offline funds must eventually be verified, because the Eurosystem has to detect counterfeiting and double-spending. ECB documents describe this online reconciliation as the “ultimate line of defence”, and record that each loading and unloading operation exposes the amount, the identifier of the storage device, the date and hour, and the online account used.

Individual purchases may remain private. The pattern around them does not. A person who loads €200 on a Tuesday and returns €12 to their account on a Friday has disclosed a €188 difference, the timing of both operations, the device that held the funds, and the account behind it. Repeated over a year, that yields a detailed picture of someone’s spending without a single purchase ever being recorded. Metadata of this kind is not a weaker form of monitoring than transaction data. It is a more efficient one, because it is structured, consistent and cheap to analyze at scale.

Merchants reconcile as well. Offline acceptance depends on terminals going online regularly to deposit what they have taken, which is precisely what limits the damage a compromised chip can do. Both ends of a cash-like payment therefore surface in back-end records — which returns the question to the merchant’s books, where this article began.

One sentence in the ECB’s own documents deserves particular attention. On what the Eurosystem receives, they state that “data elements depend on the technical solution which will evolve with the state-of-the-art of anti-forgery checks”.

That is a blank cheque. The privacy of the offline euro is not a property of the money. It is a promise about the contents of a database schema that is explicitly unfinished and explicitly expected to change, governed by an anti-fraud rationale that only ratchets one way. No one has ever proposed collecting less data to fight forgery – a fiction!

Both weaknesses in one design

Offline payment is offered as the alternative to the two mitigations described above. On inspection, it reproduces the drawbacks of each.

From the user side, mixing it inherits a burden placed on the individual. Protection depends on how much a person loads, how often, and onto which device — behavioral discipline rather than a cryptographic guarantee. As with a poorly executed mix, it fails without the user being aware of it.

From the intermediary model, it inherits a central observer. Reconciliation does not remove the watcher; it defers it. But where a regulated intermediary’s obligations are set out in law, the scope of what reconciliation records is left to a technical specification.

The combination creates a distinct risk for consumers. Offline payment will be chosen disproportionately by the people who most value privacy, for the transactions they most want kept private. That concentrates sensitive activity in the one channel whose record-keeping is least clearly bounded, and makes the loading pattern itself a signal. The part of the system promoted for its confidentiality should not be the part least defined in law.

Better designs exist

Stronger approaches have been available for decades. Stefan Brands’ 1993 offline cash scheme keeps transactions private unless a user double-spends, at which point the protocol mathematically reveals their identity — privacy by default, withdrawn only on proven cheating. GNU Taler, funded by the European Commission and the Swiss state, makes payers anonymous while keeping merchant income fully auditable, protecting shoppers without creating a shelter for undeclared revenue.

Neither is a complete substitute. Brands’ scheme does not support wallet-to-wallet transfers; Taler requires the payer to be online. Both, however, demonstrate that meaningful privacy is an engineering choice rather than a technical impossibility.

What European Pirates call for

Trilogue negotiations offer a genuine opportunity to strengthen the text. Four priorities matter for consumers:

First, offline payment should be a core feature, not a last resort; if the digital euro is to supplement cash, privacy must be built in from the start, not added as an optional extra.

Second, the limits in place should be high enough to prevent people from being directed online by default. If the limits imposed on offline payments are so strict that they become impractical for normal use, then the most private form of digital-euro payment will end up being the least used.

Thirdly, the reconciliation data set should be specified in the regulation itself, and the types of information gathered when offline funds are loaded, unloaded and reconciled should have clearly defined legal boundaries, not leave them open-ended as technical solutions develop.

Fourth, there must be clearly defined legal limits as to what payment service providers can do with the transaction data which they are already able to see. The rules need to ensure that payment information is not used as a resource for profiling or for commercial exploitation or for any uses that are unrelated to the purposes for which it was collected.

These safeguards are not arguments against a digital euro. They are conditions for making a public digital payment system worthy of public trust.

Cash still solves this problem. It works without connectivity, technical skill, or a trusted third party. Any digital successor should be held to that standard.

Europe does not have to choose between digital payments and privacy. It does, however, have to choose whether privacy is treated as a fundamental feature of digital public money or as something that can be adjusted later, once the infrastructure is already in place.

 

0 comments on “€rypto: the digital euro still has a privacy problem

Leave a Reply

This website generates anonymous visitor statistics to measure user engagement. You agree by using the website further.

Privacy policy