The shopkeeper who takes your twenty dollars learns nothing about you. Not an oversight. It's the oldest privacy protection in commerce, and we are about to lose it by upgrade rather than decree.

In an earlier piece I asked what a bank was actually built to do. Strip away the products, the departments and the vocabulary, and the answer came out narrow: keep value safe, keep an honest ledger, move value across distance. That essay ended on a complaint. An institution built for three jobs had taken a far larger position between people and their money, I said so, then stopped. Here is the question that comes after it.

Even if somebody must maintain the monetary ledger, what should they be permitted to do merely because they hold that position?

Physics kept it small. A ledger of paper in a locked room could only reach so far. Nothing keeps it small now, and the people building the replacement are not being asked by anyone who can compel an answer.

Start With Cash

You walk into a shop. Something on the shelf costs USD 20. You hand over USD 20, the shopkeeper hands you the thing, and it is done. Nobody asked your name.

The cash didn't want your address, your identity number, your occupation, or your opinion about the government. The merchant didn't need your legal identity to accept the money, and you didn't need his to hand it over. The exchange stood on its own.

Some transactions need more, and it is worth being exact about where the extra comes from. If the shopkeeper is delivering tomorrow, he needs an address. If you are signing something substantial, you will both want names and signatures, because a dispute is foreseeable. Applying for a passport? Then the office plainly needs to know who you are, because it is putting your face in a document that crosses borders.

The identity is required by the underlying activity, not by the money.

The office asks because it is issuing a passport. Your mother could have paid the fee, or your employer, or a friend settling an old favour, and none of that changes whose photograph belongs in the book. Who supplied the money has never established who should receive the passport.

Obvious with notes in your hand. It gets strangely hard to hold once the money stops being paper and becomes an entry on somebody else's screen.

Payment Proves Payment

A monetary transaction should answer one question. Was value transferred? It shouldn't answer a second question as a side effect, quietly, without anyone asking: who is this person?

Two different relationships, welded into one. If a business or a government department needs my identity, it can ask me. And if a deal carries enough future risk that I need to know who is on the other side, I should ask before I proceed, and then the other person decides. They can answer. They can refuse and walk away. Either way the decision sat with the person it belonged to.

What a monetary institution shouldn't be is the identity supplier standing behind every economic interaction, answering questions nobody asked it.

Payment proves payment. It does not prove identity.

An account-based system does differ from cash in one honest respect. Someone has to keep the account. If a ledger says an account holds USD 2,000, somebody must know whose account that is and who may move the money. It is the job.

Watch what happens next, though. I want to send USD 100 to another account. The institution must establish that my account exists, that I may use it, that the value is there, and that the receiving account is real. Every one of those is answerable without either side learning the other's identity number, address, telephone number or personal profile. The system validates both ends without introducing them to each other.

Two distinctions fall out of that, and they carry most of what follows. Authentication is not identification. Identification is not disclosure. An institution can know who controls an account without turning every payment out of that account into an identity event.

I would go further, and this is the part the industry will like least. If someone needs my identity, they should get it from me. Not from my bank. Not because it found a lawful route to sell what it knows, and not because I clicked a box I never read. My bank shouldn't be in the identity business at all.

I can tell a hospital or a ministry who I am, and I can decline and lose the service. That cost is mine. What I object to is my bank answering on my behalf while I stand there.

What the Ledger Is Actually For

A monetary institution has real work, and I'm not pretending otherwise. It must keep balances accurate, authenticate control, stop the same value being spent twice, secure the record, settle correctly, and notice patterns that break the rules that protect the system. That is a demanding job. None of it makes the institution judge of the lives on its ledger.

Keeping the record isn't the same as owning the decisions of the people recorded in it.

So a bank should not end up arbitrating an ordinary commercial dispute merely because the disputed payment crossed its books. Say I pay a merchant and later claim he never delivered. That is between him and me. We settle it ourselves, use a process we agreed on, or go to court. The institution can prove the payment happened.

Deciding who broke the contract was never its job, and it has neither the standing nor the evidence for it.

Cash makes the next part obvious. I hand a merchant USD 100. Later he agrees to refund me, so he hands me USD 100 back. Nobody pretends the first payment never happened, because there were two events in order: I paid him, then he paid me.

Digital money can keep that clarity. A refund should ordinarily be a new transfer, initiated by whoever is returning the value. The record doesn't need rewriting because a commercial relationship changed its mind later.

Not a Business Built on Watching Us

Here is the capability physical cash never had. Operate the payment system and you can watch a life: where somebody shops, what they buy, how often they travel, which organisations they give money to, when income arrives, and how it all shifts in the month after a diagnosis. That picture assembles itself. Nobody goes looking, because every piece is already in hand as a by-product of the job.

Holding it isn't the same as being entitled to use it.

The monetary function is the reason the information exists, and it should be the boundary of what the information is for. No selling transaction histories. No advertising profiles built from spending, no recommendations generated by reading somebody's ledger, and no second business grown on the private economic behaviour of participants who had no way to refuse.

Information obtained because an institution operates the money should be used for operating the money.

Collect what you need to run and protect the system, because a system that can't defend itself protects nobody. The participant is not the product.

A Rule Is Not a Verdict

None of this asks a monetary system to be defenceless. Every working system needs rules, and a digital one may detect certain signatures of misuse better than a shoebox of banknotes could. The distinction I care about sits elsewhere.

A rule says: these conditions apply equally to every participant in the same circumstances. Discretion says: we have decided that this person should not be permitted to transact. From a distance they look similar. They're not the same thing. A rule is published in advance, binds the institution as tightly as the participant, and can be cited by anyone it hits. A discretion is a verdict, handed down by an interested party, with no hearing. You find out at the till, when the card is declined and the voice on the helpline cannot tell you why.

Publish the rules first. A system that does can refuse a transfer or restrict an account when a defined, system-wide condition is triggered, known to every participant before joining. What it must never become is an opaque authority deciding, case by case, whose economic life has earned permission.

This is the part I'm least sure about. A rule can be drawn narrowly enough to name one person without naming them, and I have no test that separates a specific rule from a targeted one wearing a rule's clothes. My instinct is that the answer lives in who writes the rules, and how visibly, not in any one rule's text. An instinct, not a finding.

Improve Cash, Do Not Repossess It

Cash is remarkably free and painfully limited. It works beautifully across a shop counter and terribly across an ocean. Carrying USD 20 is nothing. Carrying USD 1 million needs a vehicle and an armed escort, and cash gets lost, and gets stolen, and will not divide below the smallest coin. It cannot pay itself on a schedule, settle a fraction of a cent, or cross a continent while you wait.

Digital money fixes most of that. Enormous value moves without anybody carrying anything, distance stops costing time, tiny fractions become possible, settlement leaves proof, and payments can be scheduled and read straight into an invoice. Two people in one shop with no network may eventually exchange value over NFC or Bluetooth, the last thing cash does better. These are enormous gains.

I want them. What I've never seen anyone justify is why collecting them should require surrendering the freedoms that made cash worth using in the first place.

Can we digitise the capabilities of money without digitising unnecessary control over the people who use it?

The Principles Belong to Every Currency, Including Mine

I started thinking about this while working on the architecture of GX Protocol. Writing that architecture means deciding, line by line, what your own system should never be permitted to do to the people who trust it. A strange thing to write. It's also why I don't want these principles to belong to GX.

They certainly shouldn't be drafted so that GX passes them automatically, which would make the whole exercise worthless. That is not a standard. It is a mirror.

Apply them the same way to a dollar, a euro, a pound, a yen, a dirham, a riyal, Bitcoin, a stablecoin, a central bank digital currency, a GX unit, or to a monetary system nobody has built yet.

The technology gets no special treatment. Neither does the issuer, including me. The question stays fixed no matter which one is on the table.

What powers should an institution acquire merely because it facilitates the storage and movement of somebody's money?

Only those reasonably necessary to perform the monetary function and to protect the integrity of the rules under which everyone agreed to participate.

Everything past that line needs its own justification. Argue it in the open, on its own merits, and not smuggled into a product update that nobody ever reads.

Come and Break Them

None of this is settled economics. It's not a declaration that every bank is unethical, every government wrong or every cryptocurrency right. These are questions of institutional governance, and they are urgent because digital payments, digital identity, stablecoins and central bank digital currencies are being built this decade by people nobody is asking.

Technology keeps making things possible that physical money never allowed. Possible is not permitted.

That an institution can know something doesn't mean it may use it. That it can block a payment does not mean it should decide whether the payment deserves to go through. That it can profile economic behaviour doesn't make the behaviour its property. And the fact that money is recorded digitally does not move ownership from the person holding it to the party keeping the record.

The keeper is not the owner.

So I want to write these up properly and in public: universal principles of monetary neutrality, transactional privacy and institutional conduct. Open to economists, bankers, regulators, lawyers, technologists, merchants, privacy researchers, and anyone who wants to buy bread without being profiled for it. Some of it will survive criticism unchanged. Some will need refinement. Some will turn out to be impossible to build the way I imagined, and I would rather hear that in a comment thread than four years into a build.

That is the point of publishing.

A principle that can't survive serious criticism should be changed. A principle that survives serious criticism is worth defending in public. I am not trying to win an argument about which currency is best, and have no appetite for another round of it.

What rights should people retain when the money in their hands becomes an entry on somebody else's machine?

Bring me the strongest objection you have. If a principle can't stand up to it, I don't want that principle either.