Central bank digital currency has moved from a research curiosity to a policy project, and in several economies it has moved from a project to a live system. The technical questions that once dominated the discussion — whether a CBDC would use a distributed ledger, how it would handle offline payments, whether it could process transactions fast enough — have largely been answered. What has not been answered is the political question, and it is the one the public actually cares about: what does it mean for the state to hold every citizen's money directly?
The privacy debate around CBDCs is not really about the technology. It is about the relationship between the citizen and the state, and money is the terrain on which that relationship is contested. A central bank that can see every transaction, freeze any account, and program how money can be spent is a central bank with powers no paper currency ever granted. Whether those powers are used is a separate question from whether they exist, and the public is right to be uneasy about powers that exist.
What a CBDC actually is
A central bank digital currency is, at its simplest, a digital form of central bank money — the same kind of money a commercial bank holds in its reserve account, extended to the public. In most designs, citizens would hold CBDC in a wallet provided by or linked to the central bank, and transactions would settle directly on the central bank's ledger rather than through commercial banks. The appeal to the central bank is control and efficiency: no intermediaries, no settlement risk, no dependence on private payment rails.
The appeal to the citizen is less obvious. In economies with well-functioning payment systems, a CBDC offers little the citizen does not already have. The case is stronger in economies where payment infrastructure is poor, where the unbanked are numerous, or where the government wants to displace an undesirable private currency. In most developed economies, the justification for a CBDC is preventive — keeping a public payment option available as private options consolidate.
The surveillance question
The concern that has dominated the public debate is surveillance, and it is a fair one. A payment system in which the central bank is the ledger-keeper is a payment system in which the central bank can, in principle, see every transaction. The design choices matter — a token-based system can offer more privacy than an account-based one, and some designs include technical limits on what the central bank can observe — but no design eliminates the fact that the institution issuing the money also operates the ledger.
Defenders of CBDCs point out that commercial banks and payment processors already collect this data, and that a properly designed CBDC could offer better privacy protections than the existing private system. This is technically true and politically unpersuasive. The public trusts a corporation with its data differently than it trusts the government, because the government has powers a corporation does not — the power to tax, to investigate, to prosecute — and the combination of payment data and state power is what makes people uneasy.
The programmability concern
More troubling to privacy advocates than surveillance is programmability — the ability to attach rules to the money itself, restricting how, when or where it can be spent. A CBDC could be programmed to expire, to be spendable only on certain goods, or to be valid only in certain regions. These capabilities have legitimate uses — directing stimulus, preventing fraud, enforcing sanctions — but they also represent a degree of control over individual spending that cash never permitted.
The central banks building CBDCs have mostly disclaimed interest in programmable money, aware of the public reaction. But the capability is inherent in the technology, and once the infrastructure exists, the temptation to use it in a crisis will be considerable. The argument of the skeptics is not that programmability will be abused on day one; it is that the infrastructure makes abuse possible, and democracies should be cautious about building infrastructure whose misuse is hard to reverse.
The question of cash
Underlying the privacy debate is the question of what happens to cash. If a CBDC succeeds, it will displace some use of cash, and the more it displaces, the harder cash becomes to maintain — the ATM networks shrink, the merchants who accept it dwindle, the cost of supporting it rises. A society in which cash has effectively disappeared is a society in which every transaction is mediated by a financial institution, and the option of anonymous exchange that cash provides is lost.
This is why the privacy fight over CBDCs is, at bottom, a fight over cash. The central banks insist they intend to keep cash available alongside any digital currency. Whether they can — whether the economics of cash distribution hold up when usage falls — is an open question, and the answer will determine whether the privacy of physical money survives the transition to digital.
Join the discussion · 218 comments