The Bank of Italy has published an analysis of how privacy-enhancing technologies can protect users of digital payment systems while preserving regulatory auditability and accountability. Covering decentralized, centrally managed and hybrid infrastructures, the paper finds that no single technology can satisfy all privacy and compliance objectives. Effective designs instead require layered combinations of cryptographic tools, payment architecture and governance arrangements tailored to specific risks and policy goals. The analysis assesses anonymity, confidentiality and unlinkability across account-based and token-based models. It examines tools including blind signatures, commitments, threshold encryption, one-time addresses and zero-knowledge proofs, noting their different implications for trust, performance, scalability and disclosure powers. Auditability can be built through measures such as anonymity budgets, transaction and holding limits, revocable anonymity, coin tracing and verification of compliance without disclosing underlying transaction data. The paper emphasizes that system design must define who may trigger disclosure or tracing, under what conditions and with what safeguards, particularly where Anti-Money Laundering and Combating the Financing of Terrorism requirements apply.
Source: 2026-09-29Bank of Italy
Bank of Italy maps privacy technologies and auditability tradeoffs in digital payment systems
The Bank of Italy has mapped how privacy-enhancing technologies can reconcile user privacy with oversight in digital payment systems. The paper finds that no single tool meets all objectives and that effective systems require layered cryptographic, architectural and governance choices. Auditability options include operating limits, revocable anonymity, tracing and compliance verification without disclosure.