A central bank digital currency (CBDC) can, depending on its design, make it possible to trace transactions and attach usage rules to them: this is a real technical capability, not a fantasy. But this capability imposes no particular use. Models preserving strong privacy exist and are actively being studied. The real question is therefore not "can a CBDC surveil?" — technically, a centralised infrastructure can — but "which design is chosen, and which limits are written into law?". Distinguishing capability from political choice is the condition for an honest judgement.
Definition. The traceability of a CBDC refers to the possibility, for the issuer or an intermediary, of linking a transaction to an identity. Programmability refers to the possibility of attaching conditions to the money (expiry date, authorised purchase category). These are two distinct technical properties, configurable, and not inevitable characteristics of every CBDC.
It must be said plainly: a CBDC is, by construction, a digital currency issued and backed by a centralised infrastructure. Unlike cash, which circulates without leaving a nominal trace, a digital transaction leaves, in principle, a footprint. Depending on the architecture chosen, this footprint can be more or less identifying, and the money can technically carry usage conditions.
This capability covers two risks that are often conflated, which must be separated:
Recognising this capability is neither conspiracy nor catastrophism: it is to read it in the very design of the tool. What the tool can do and what we decide it will do are two different things — and it is precisely this boundary that is at stake in governance.
Technical capability is not destiny. The institutions designing CBDCs are actively exploring architectures that limit, by construction, what can be known. In its note on how central banks should explore a CBDC (FinTech Note 2023/008), the International Monetary Fund reports that several central banks explicitly state that their potential CBDC would not be programmable by the central bank or the State, precisely out of concern for freedoms and fungibility.
On the traceability front, intermediated-privacy models are under study. Project Aurum (run by the Bank for International Settlements Innovation Hub and the Hong Kong Monetary Authority, completed in July 2022) tests a two-tier architecture in which the interbank system keeps no personal information: only the intermediary in charge of identity checks sees who pays, and the central bank does not have the full nominal view. This is a design choice that deliberately separates issuance from surveillance. A second phase, Project Aurum 2.0, is explicitly devoted to strengthening the privacy of retail payments (pseudonymisation, zero-knowledge proofs).
The lesson is clear: the privacy of a CBDC is a design parameter, not a technological fatality. Where one chooses anonymity for small amounts, the non-correlation of uses and the absence of programmability, one obtains a tool very different from the feared grid. The debate is therefore not primarily technical; it is political and legal.
These trade-offs are discussed openly in public documents. The European Central Bank, which is examining the digital euro project, emphasises an objective of high privacy: for offline payments, the details of the operation would be known only to the payer and the payee, offering a level of privacy close to that of cash, while for online payments the Eurosystem would not be able to directly identify users. The design remains under debate: the exact degree of privacy, the holding limits, the role of intermediaries are points still discussed at European level, and liable to evolve.
An honest clarification is in order: one sometimes reads that a "3,000-euro limit" was decided for the digital euro. This claim is an inaccurate simplification — the holding thresholds remain under discussion and do not have the form often ascribed to them. Verifying before asserting is part of the method.
On the Chinese side, the digital yuan (e-CNY) is presented by its designers under the principle of managed anonymity: according to the People's Bank of China, the system follows the rule "anonymity for small amounts, traceability for large amounts" and does not provide information to third parties or to other government agencies unless otherwise provided by law. Neither the myth of total anonymity nor that of absolute traceability is accurate. The documented reality is a graduated traceability, configurable by the authority — and it is this parameter, which sets the threshold and can move it, that constitutes the true stake of power.
The recent history of CBDCs shows that demonstrating a capability is not the same as putting it into service. In the United States, Project Hamilton (Federal Reserve Bank of Boston and MIT) developed a very high-throughput transaction processor — on the order of 1.7 million transactions per second — before being closed in December 2022 with no decision to issue a digital dollar, the project declaring itself agnostic on any policy direction. What is more, Executive Order 14178 (signed on 23 January 2025) prohibited federal agencies from establishing, issuing, or promoting a U.S. CBDC. A major country has therefore, by political decision, closed that door.
This is the central lesson: the boundary between "can" and "does" depends less on technology than on governance and circumstances. A successful technical demonstration is not a deployment; an announced project is not a successful project. Useful vigilance therefore bears on legal safeguards — written into law, controllable, enforceable — far more than on a purely technical fantasy.
Understanding this distinction opens up precise demands, which fall under neither denial nor panic:
None of these demands presupposes that a CBDC is necessarily an instrument of surveillance. They presuppose only that a documented capability calls for deliberate and maintained limits. This is the difference between enduring an infrastructure and governing it.
Does a CBDC automatically make it possible to surveil citizens? No, not automatically. A centralised monetary infrastructure has the technical capability, but the degree of traceability depends on the design adopted. Intermediated-privacy models or models with anonymity for small amounts are being studied (Project Aurum, offline payments of the digital euro).
Is programmable money already decided? No. Several central banks state that their potential CBDC would not be programmable by the central bank or the State, out of concern for freedoms and fungibility (IMF, FinTech Note 2023/008). The technical capability exists, but the stated intention is, today, one of restraint — which makes its inscription in law decisive.
Are all CBDCs equal when it comes to privacy? No. The digital yuan applies a "managed anonymity" with configurable thresholds; the digital euro emphasises high privacy still under debate; the United States banned theirs in 2025. The political and legal model makes all the difference.
To situate this question within the whole file — money, identity and the biometric gaze, and the constant distinction between capability and intention — read the pillar article: CBDC and the digital euro, understanding. And if you want the full investigation, marked out level of certainty by level of certainty and backed by institutional sources, Tome 2 — The Architecture of Control takes up each piece of the file.
No, not automatically. A centralised monetary infrastructure has the technical capability, but the degree of traceability depends on the design adopted. Intermediated-privacy models or models with anonymity for small amounts are being studied (Project Aurum, offline payments of the digital euro).
No. Several central banks state that their potential CBDC would not be programmable by the central bank or the State, out of concern for freedoms and fungibility (IMF, FinTech Note 2023/008). The technical capability exists, but the stated intention is, today, one of restraint — which makes its inscription in law decisive.
No. The digital yuan applies a "managed anonymity" with configurable thresholds; the digital euro emphasises high privacy still under debate; the United States banned theirs in 2025. The political and legal model makes all the difference.
Dossier : Monnaie & identité numérique : l'architecture du contrôle
TOME 2: L'Architecture du Contrôle
Accueil · Collection · Journal · Dossiers · Sources