Skip to main content
Open BankingPolicy ExplainerAug 5, 2026, 7:28 AM· 7 min read

CFPB Finalizes 'Open Banking' Rule, Mandating Free Consumer Access to Financial Data

The Consumer Financial Protection Bureau has finalized its landmark open banking framework, requiring financial institutions to provide secure, free data access to authorized third-party apps. However, ongoing industry lawsuits have placed the rule's implementation in regulatory limbo.

By Andre Figueira

Fintechs & Consumer Advocates 35%Traditional Banks & Credit Unions 35%Regulatory & Legal Analysts 30%
Fintechs & Consumer Advocates
Argue that free, standardized data access lowers barriers to entry, boosts competition, and gives consumers control over their own financial information.
Traditional Banks & Credit Unions
Contend that the rule unfairly forces them to bear the costs of building data interfaces while exposing them to liability for third-party data breaches.
Regulatory & Legal Analysts
Focus on the ongoing litigation, compliance uncertainty, and the mechanics of how the rule will ultimately be enforced.

Why this matters

This rule fundamentally changes who controls your financial data. By forcing banks to share your transaction history securely and for free, it makes it significantly easier to switch banks, use budgeting apps, or secure alternative loans without relying on risky password-sharing practices.

Key points

  • The CFPB finalized the Section 1033 rule to mandate free, secure consumer data sharing.
  • The framework phases out 'screen scraping' in favor of standardized developer APIs.
  • Third-party apps are strictly banned from using collected data for targeted advertising.
  • Banks strongly oppose the rule's prohibition on charging fees for data access.
  • A federal court injunction has temporarily paused enforcement while the CFPB revises the rule.
100 million+
Consumers using third-party financial apps
$850 million
Asset threshold for bank exemption
99.5%
Minimum required API response rate
24 months
Historical transaction data required

The Consumer Financial Protection Bureau (CFPB) has fundamentally reshaped the landscape of American finance by finalizing its Personal Financial Data Rights rule, a landmark regulation designed to activate Section 1033 of the Dodd-Frank Act. For years, the statutory provision remained a dormant legal authority, but the new framework aims to drag the United States into the modern era of "open banking." At its core, the regulation mandates that financial institutions, credit card issuers, and digital wallet providers unlock consumer financial data and transfer it to authorized third parties upon request. By establishing a standardized, secure ecosystem for data sharing, the CFPB intends to dismantle the walled gardens of traditional banking, giving consumers unprecedented control over their own financial footprints.[1]

The central mechanism of the open banking rule is the requirement for data providers to establish dedicated, high-performance developer interfaces. Historically, the financial technology sector relied heavily on "screen scraping"—a cumbersome and inherently risky practice where consumers handed over their bank usernames and passwords to third-party apps. Those apps would then deploy automated bots to log into the bank's portal and extract the necessary information. The CFPB's framework effectively phases out this practice, requiring institutions to build secure Application Programming Interfaces (APIs) that allow data to flow directly between servers without exposing consumer login credentials.[1]

Under the regulation, the scope of "covered data" is extensive. Financial institutions must provide authorized third parties with at least 24 months of historical transaction data, including amounts, dates, payment types, and merchant names. The mandate also covers real-time account balances, upcoming bill information, and the data necessary to initiate payments directly from a Regulation E account. To ensure these systems are reliable for everyday consumer use, the CFPB stipulated rigorous performance specifications, requiring developer interfaces to maintain a minimum response rate of 99.5 percent each month.[6]

The ultimate objective of this data portability is to supercharge competition within the consumer finance sector. When financial history is locked inside a single institution, consumers face high friction when attempting to switch providers. By making data portable, the CFPB hopes to empower individuals to seamlessly transfer their banking history to a competitor offering better interest rates, lower fees, or superior customer service. This frictionless mobility is expected to incentivize incumbent banks to improve their offerings rather than relying on customer inertia to maintain their deposit bases.[1]

Under Section 1033, banks must provide secure, standardized data access to authorized third parties without charging fees.
Under Section 1033, banks must provide secure, standardized data access to authorized third parties without charging fees.

Alongside data access, the rule introduces stringent privacy safeguards designed to curb the unchecked monetization of consumer information. The CFPB explicitly banned "bait-and-switch" data harvesting, a practice where companies collect financial data to provide a requested service but subsequently use that data for unrelated business purposes. Under the new framework, third-party apps are legally restricted to collecting, using, and retaining data only as reasonably necessary to deliver the specific product the consumer requested. Secondary uses, such as targeted advertising or cross-selling alternative financial products, are strictly prohibited without separate, explicit authorization.[1][6]

To further cement consumer control, the regulation establishes robust revocation and deletion rights. Consumers maintain the ongoing ability to view which third parties have access to their accounts and can revoke that authorization at any time through a centralized dashboard. Once access is revoked, the rule dictates that data sharing must cease immediately. Furthermore, revocation triggers a default requirement for the third party to delete the consumer's previously collected data, ensuring that digital footprints do not linger indefinitely on external servers once a service is no longer needed.[1]

To further cement consumer control, the regulation establishes robust revocation and deletion rights.

The fintech industry and consumer advocacy groups have largely celebrated the open banking framework as a necessary modernization of the U.S. financial system. Proponents argue that the rule breaks the data monopolies held by legacy institutions, leveling the playing field for innovative startups. By guaranteeing free and standardized access to financial data, the regulation lowers the barrier to entry for budgeting applications, alternative credit scoring models, and automated savings tools. Fintech leaders assert that this competitive ecosystem ultimately benefits the consumer through lower prices and highly tailored financial products.

However, the rule has faced fierce and organized opposition from traditional banks and credit unions. The primary point of contention is the CFPB's strict prohibition on charging fees for data access. Financial institutions argue that building, maintaining, and securing the high-capacity APIs required by the rule represents a massive capital expenditure. Industry groups contend that it is fundamentally unfair to force banks to bear the entire financial burden of this infrastructure while third-party data aggregators and fintech companies profit from the seamless flow of information.[3]

Compliance was originally scheduled in tiers, though ongoing litigation has placed the timeline in flux.
Compliance was originally scheduled in tiers, though ongoing litigation has placed the timeline in flux.

Beyond the economics of API development, traditional banks have raised severe alarms regarding asymmetrical liability and data security. When a consumer authorizes a third-party app to access their account, the bank loses visibility into how securely that data is stored downstream. If a lightly regulated fintech startup suffers a catastrophic data breach or facilitates unauthorized fraudulent transfers, banking executives fear that the consumer—and regulators—will ultimately hold the primary financial institution responsible. Banks argue that without symmetrical security standards across the entire data supply chain, the open banking rule introduces systemic vulnerabilities.[3]

In an effort to mitigate the regulatory burden on the smallest community institutions, the CFPB included a targeted exemption in the final rule. Depository institutions that hold assets equal to or less than the Small Business Administration's size standard for commercial banking—currently set at $850 million—are entirely exempt from the data-sharing mandates. While this carve-out provides relief for local credit unions and small community banks, industry advocates argue that mid-sized regional banks are still left grappling with compliance costs that disproportionately impact their bottom lines compared to Wall Street giants.[3][6]

The intense industry pushback quickly transitioned from public comment letters to formal litigation. Shortly after the rule was finalized, a coalition of banking trade groups, including the Bank Policy Institute and the Kentucky Bankers Association, filed a federal lawsuit challenging the regulation. The plaintiffs argued that the CFPB exceeded its statutory authority under the Dodd-Frank Act, particularly regarding the outright ban on data access fees and the broad definition of authorized third parties. The lawsuit effectively paralyzed the rollout of the open banking framework.[2][5]

The legal challenge yielded a significant procedural victory for the banking sector when a federal judge in the Eastern District of Kentucky issued a preliminary injunction. The court order suspended the enforcement of the open banking rule, placing the entire national data-sharing framework in a state of regulatory limbo. The injunction prevents the CFPB from implementing the mandates until the agency completes a comprehensive reconsideration of the rule, leaving both banks and fintechs operating without a clear, enforceable federal standard.[2]

In response to the injunction and sustained industry pressure, the CFPB formally initiated a full notice-and-comment rulemaking process to revise Section 1033. Abandoning earlier plans to issue a quick interim final rule, the agency acknowledged the complexity of the ecosystem and the need for extensive public input. The reconsideration process has reopened debates on the most contentious aspects of the framework, including the definition of consumer consent, the allocation of fraud liability, and the highly disputed question of whether data providers can negotiate market-based fees for API access.[4][5]

The regulatory pause has fundamentally disrupted the original compliance timeline. The CFPB's initial framework established a phased schedule, with the largest depository institutions required to comply by April 2026. Because of the court injunction, that deadline passed without becoming a binding enforcement trigger. However, legal and regulatory analysts warn that financial institutions cannot afford to abandon their open banking preparations. The underlying architecture of API-driven data sharing is already being built, and institutions that halt their development risk falling severely behind when a revised federal rule inevitably emerges.[5]

How we got here

  1. 2010

    Congress enacts the Dodd-Frank Act, including the dormant Section 1033 regarding consumer data rights.

  2. October 2024

    The CFPB finalizes the Personal Financial Data Rights rule, establishing the open banking framework.

  3. May 2025

    Banking trade groups file a lawsuit challenging the CFPB's statutory authority to mandate free data sharing.

  4. July 2025

    A federal court stays the litigation and enjoins the rule while the CFPB initiates a reconsideration process.

  5. January 2026

    The CFPB formally abandons plans for an interim rule, committing to a full notice-and-comment rewrite.

  6. April 2026

    The original first-tier compliance deadline passes without becoming a binding enforcement trigger.

Viewpoints in depth

Fintechs & Consumer Advocates

Viewing open data as a catalyst for competition.

Proponents argue that consumers own their financial data, not the banks that store it. By mandating free and standardized access, the rule lowers the barrier to entry for new financial apps, budgeting tools, and alternative lenders. Advocates stress that without a strict fee prohibition, incumbent banks could price competitors out of the market, effectively maintaining a monopoly over consumer financial insights.

Traditional Banks & Credit Unions

Raising alarms over unfunded mandates and security liabilities.

Financial institutions argue they are being forced into an unfunded mandate. Building and maintaining high-availability developer interfaces requires significant capital investment, yet the rule forbids them from charging the third-party aggregators who profit from the data. Furthermore, banks warn of asymmetrical liability: if a lightly regulated fintech app suffers a data breach or facilitates a fraudulent transfer, consumers will likely blame their primary bank, leaving the institution to absorb the reputational and financial damage.

What we don't know

  • Whether the CFPB will ultimately allow banks to charge fees to third-party data aggregators.
  • How liability will be legally apportioned if a fintech app suffers a data breach.
  • When the revised compliance deadlines will officially take effect.

Key terms

Open Banking
A financial framework where banks allow third-party providers secure access to consumer financial data through standardized interfaces.
Screen Scraping
A risky practice where consumers provide their bank login credentials to a third-party app, which then logs in to extract data.
Application Programming Interface (API)
A set of protocols that allows different software systems to communicate securely without sharing user passwords.
Data Aggregator
A middleman company that collects financial data from various institutions and supplies it to fintech applications.

Frequently asked

Will I have to pay to share my financial data?

No. Under the CFPB's framework, financial institutions are prohibited from charging consumers or authorized third parties fees for accessing covered data.

Is my bank required to participate?

Most banks and credit card issuers are covered, but the rule exempts smaller depository institutions with less than $850 million in assets.

Can third-party apps sell my data?

No. The rule strictly bans 'bait-and-switch' data harvesting, requiring third parties to use your data only for the specific product or service you requested.

When does the open banking rule take effect?

The original compliance deadlines began in April 2026, but a federal court injunction has paused enforcement while the CFPB revises the regulation.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

Fintechs & Consumer Advocates 35%Traditional Banks & Credit Unions 35%Regulatory & Legal Analysts 30%
  1. [1]Consumer Financial Protection BureauFintechs & Consumer Advocates

    CFPB Finalizes Personal Financial Data Rights Rule to Boost Competition, Protect Privacy, and Give Families More Choice in Financial Services

    Read on Consumer Financial Protection Bureau
  2. [2]FinTech WeeklyFintechs & Consumer Advocates

    Federal Court Blocks CFPB's Open Banking Rule

    Read on FinTech Weekly
  3. [3]Independent BankerTraditional Banks & Credit Unions

    Community banks and the open banking rule

    Read on Independent Banker
  4. [4]CU TimesTraditional Banks & Credit Unions

    CFPB Abandons Interim Final Rule for Section 1033 Rewrite

    Read on CU Times
  5. [5]Open Banking TrackerRegulatory & Legal Analysts

    Section 1033 timeline

    Read on Open Banking Tracker
  6. [6]DLA PiperRegulatory & Legal Analysts

    What Does the CFPB Open Banking Rule Entail?

    Read on DLA Piper

Comments

Stay informed

Every angle. Every day.

Get finance stories with full source coverage and perspective breakdowns delivered to your inbox.