Skip to content

Independent intelligence on digital money in motion

Saturday, September 12, 2026

Latest MoneyGram Launches Stablecoin-Backed Visa Card in Colombia
CBDCs

ECB Draws Digital Euro Privacy Boundary Around Banks

The ECB says it would not be able to identify digital euro payers or recipients, while banks would retain the data needed for anti-money-laundering checks.

The European Central Bank has sharpened its explanation of who would be able to identify users in a future digital euro system: banks would retain the customer information needed to meet legal obligations, while the Eurosystem would not be able to directly link people to their payments.

Piero Cipollone, a member of the ECB’s Executive Board, set out that division in an interview conducted on August 10 and published by the central bank on August 24. He said the Eurosystem would not be able to identify the users making or receiving payments. Banks involved in a transaction, however, would be able to identify customers, including for anti-money-laundering purposes.

The distinction is operationally important for payment providers. The ECB’s privacy model does not remove regulated intermediaries from customer due diligence or financial-crime controls. Instead, it is intended to separate the information available to banks from the pseudonymised data available to the Eurosystem.

Offline and online payments have different data paths

Cipollone described a stronger privacy model for offline use. In that mode, transactions would take place directly between individuals, with payment details available only to the payer and recipient. For online payments, the Eurosystem would process data without being able to connect a payment directly to a named individual, according to the ECB.

The central bank’s digital euro privacy page provides additional detail. It says data available to the ECB would be pseudonymised and would not include personal data that could identify a user. It also says an intermediary such as a bank would have access only to the personal information necessary to comply with EU law, including anti-money-laundering and counter-terrorist-financing rules. Using that information for commercial purposes would require the customer’s explicit consent.

Those claims describe the planned design rather than the performance of a live payment system. The digital euro has not yet demonstrated these controls at production scale, and the final allocation of responsibilities will depend on the governing EU framework and its implementation.

Banks remain the regulated identity layer

For banks and payment service providers, the proposed boundary creates a familiar responsibility in a new settlement architecture. Institutions would still need to identify customers, apply sanctions and transaction-monitoring controls where required, manage access credentials and respond to lawful information requests. At the same time, the Eurosystem’s inability to connect pseudonymised records directly to individuals is intended to limit centralised visibility into payment behaviour.

This separation also creates design questions for providers. A useful privacy boundary must survive exception handling, fraud investigations, account recovery, disputes and the movement of funds between online and offline modes. Providers will need clear rules governing which data can be exchanged, under what authority and for how long. The ECB interview does not specify those implementation details.

Offline payments present a separate control challenge. Restricting transaction details to the payer and recipient can deliver more cash-like privacy, but providers will still need safeguards for device loss, double spending and illicit-finance risk. How those controls are balanced against privacy will matter as much as the high-level promise that the Eurosystem cannot identify users.

A design claim, not anonymity

The ECB’s position should not be read as a promise of anonymous online payments. Banks would remain able to identify their customers and would continue to apply legal controls. The narrower claim is that the Eurosystem itself would not be able to directly associate a payment record with a particular person.

For the payments industry, that makes data governance a central part of the digital euro proposition. Adoption will depend not only on acceptance, pricing and user experience, but also on whether institutions can prove that the separation among identity data, transaction data and central-bank processing works under routine and exceptional conditions.