Security, Privacy and Regulatory Governance in Digital Payments. A Systematic Review and Cross-Architecture Framework for PIX, Blockchain, and Central Bank Digital Currencies
Abstract
Abstract Purpose. This study examines how instant payment systems such as Brazil's PIX, public and permissioned blockchains, and central bank digital currencies (CBDCs) govern the trade-off among security, privacy, and regulatory compliance, including anti-money-laundering requirements. It consolidates the fragmented evidence into a single comparative instrument. Design and methodology. A systematic review compliant with PRISMA 2020 examined eighteen peer-reviewed studies on the three systems from 2014 to 2025. Studies were appraised and positioned within a Digital Payment Governance Framework, DPGF, whose three axes are the locus of control, the privacy spectrum, and the compliance architecture, each scored from 1 to 5, and interpreted against anti-money-laundering standards. Findings. PIX corresponds to a regulatory clarity model, with scores of 1 for locus of control, 4 for privacy spectrum, and 1 for compliance architecture. Public blockchains correspond to an autonomy model with scores of 5, 2, and 5. CBDCs and permissioned blockchains correspond to a hybrid governance model, with scores of 2, 2, and 2. Zero-knowledge proofs and homomorphic encryption are the most widely adopted techniques, and both face scalability and metadata limits. Hybrid architectures recur as the design preferred across the corpus. Originality. The DPGF supports comparing governance arrangements across centralized, decentralized, and hybrid architectures and identifies the security, privacy, and compliance balance of each. Selective disclosure embedded by design at the protocol level, supported by cross-system indicators, is the direction with the most support for next-generation payment governance.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.