Basics
Can the ECB see everything I buy with the digital euro?
Not directly — the digital euro is pseudonymised and offline payments are cash-like. What the Eurosystem can and can't see about your payments.
On this page
Not directly. The digital euro is built on pseudonymisation: the Eurosystem would not identify the people making or receiving payments, and cannot directly identify individuals from payment data. And the offline version is more private still — cash-like, with only the payer and payee knowing the details.
Privacy is the single most-asked-about part of the digital euro, so let's be precise about what that actually means, rather than reassuring or alarming.
Two different privacy levels
The digital euro isn't one privacy setting. Online and offline sit at different points.
| Online digital euro | Offline digital euro | |
|---|---|---|
| Where value sits | An account, settled on the DESP | A secure chip on your device |
| Connection needed | Yes | No |
| Who sees the payment | Your PSP handles the details; the Eurosystem is pseudonymised | Only the payer and payee |
| Closest analogy | A very private bank transfer | Cash |
What pseudonymisation actually means
Pseudonymisation is not the same as "no data exists." It means the data that flows through a payment is separated from your identity, so the Eurosystem can't look at payment data and see you.
Two mechanisms make that concrete rather than a promise:
- Aliases. You can be paid via a pseudonymous identifier — like a phone number — that can only be linked back to you by the PSP that distributes your digital euro, or by you. To everyone else in the flow it's an opaque handle.
- SEPI (Secure Exchange of Payment Information). Payment details can be replaced with a surrogate value that carries no information itself, while still letting the authorised PSP retrieve what it needs to settle.
So the party that knows who you are is your PSP — the bank or provider you already have a relationship with — not the central bank. That's the same trust boundary as your current account.
Offline: as private as cash
For offline payments, the value lives on a secure chip on your device and moves straight to the other person's device over NFC. There's no central platform in the loop, so only the payer and payee know the transaction details.
That's the cash model, rebuilt digitally. It's the strongest privacy the digital euro offers, and it's a deliberate design goal — not an afterthought.
Why not just make everything fully anonymous?
Fully anonymous digital money at any scale collides with anti-money-laundering law. The design's answer is pseudonymisation for online payments and cash-like privacy for smaller offline ones — strong privacy within the rules, rather than a promise it couldn't legally keep.
What this rules out
Because the Eurosystem can't tie payment data to individuals, the "central bank watching every purchase" picture doesn't match the design. And since the digital euro is not programmable money, it can't be used to restrict what you buy either — more on that here.
The honest caveat: this rests on published ECB material and a scheme rulebook that is still a draft, with the regulation in the EU legislative process. The privacy architecture described here is the stated design; the final law is what will enforce it.
The bottom line
- The Eurosystem cannot directly identify you from payment data — the system is pseudonymised.
- The party that knows your identity is your own PSP, not the central bank.
- Offline payments are cash-like: only you and the person you paid know.
For the rest of the common concerns, see the FAQ or the complete guide.
Sources
Related reading
Can I use my crypto wallet for the digital euro?
No — the digital euro isn't crypto and isn't on a blockchain, so a wallet like MetaMask or Ledger can't hold it. Here's how you'll actually access it.
How much digital euro will I be allowed to hold?
There will be a holding limit, but the amount isn't decided yet. Why the limit exists, and how you can still pay beyond your balance anyway.