Designing against state digital surveillance: two doctrinal tests for retail central bank digital currencies in the European Union and China
Whether retail central bank digital currencies normalise financial surveillance turns on design choices made once and then defended by the legal order that bears them. Scholarship is descriptively rich but offers few standards for testing a design's privacy claims. This article proposes two tests: non-generation, which asks whether a perimeter exists where no centralised record is created; and non-linkability, which asks whether identifiers are separated so that ecosystem-wide profiling is impracticable. Distilled from CJEU reasoning on watertight separation in La Quadrature du Net II and relative identifiability in EDPS v SRB, they are analytical standards rather than obligations imposed on payment systems. They operate on different segments of the payment flow, apply cumulatively, and are assessed for legality, feasibility and time consistency. Applied to the digital euro as amended for trilogue in 2026, and to the e-CNY reclassified as interest-bearing deposit money, the tests show the digital euro satisfying both only partially and on fragile foundations; the e-CNY, consistent with its legal order's premises, exhibits neither. The article also argues that, under the relative conception of identifiability consolidating in Union law, the architecture of separation determines whether data protection law applies at all, an implication reaching beyond digital currency.
Authors
- Ammar Zafar (ORCID: https://orcid.org/0009-0008-0367-8139)
Institutions
- University of Liverpool (GB)
Publication Details
- Journal
- Information & Communications Technology Law
- Published
- 2026-09-30
- DOI
- https://doi.org/10.1080/13600834.2026.2739711
- Primary Topic
- Security, Politics, and Digital Transformation
- Type
- article
- Field-Weighted Citation Impact
- 0.00