Skip to main content
ExplainerOpen BankingExplainerAug 24, 2026, 4:53 AM· 4 min read· in finance

CFPB Finalizes 'Open Banking' Rule Mandating Free Consumer Access to Financial Data

The Consumer Financial Protection Bureau has finalized a landmark rule requiring financial institutions to let consumers access and share their financial data free of charge. The mandate aims to eliminate 'junk fees' for data transfers and make it easier for Americans to switch banks or use third-party financial apps.

By Bo Feng

Consumer Advocates 40%Traditional Banks 30%Fintech Innovators 30%
Consumer Advocates
View data portability as a fundamental right that will lower fees and increase competition.
Traditional Banks
Warn that the rule imposes massive unfunded technological costs and creates severe cybersecurity liabilities.
Fintech Innovators
Celebrate the mandate as a victory that guarantees the reliable data access needed to build new financial products.

Key terms

Open Banking
A financial framework where consumers can securely share their banking data with third-party providers to access new financial products.
API (Application Programming Interface)
A secure digital bridge that allows two different software systems, like a bank and a budgeting app, to communicate and share data directly.
Screen Scraping
An outdated practice where consumers give their bank passwords to a third-party app, which then logs in as the user to read and copy their financial data.
Section 1033
The specific provision of the 2010 Dodd-Frank Act that grants consumers the legal right to access and control their personal financial data.
Cash-Flow Underwriting
A method of assessing creditworthiness based on a consumer's real-time income and expenses in their checking account, rather than a traditional credit score.

Key points

  • The CFPB has finalized a rule requiring banks to provide free, secure access to consumer financial data.
  • The mandate aims to make it easier for consumers to switch banks and use third-party financial apps.
  • Financial institutions are prohibited from charging 'junk fees' for data access.
  • The rule bans the insecure practice of 'screen scraping' in favor of tokenized API connections.
  • Third-party apps are strictly forbidden from selling consumer transaction data to data brokers.

Most consumers assume that when they log into their online banking portal, the transaction data they see belongs to them. In reality, traditional financial institutions have long treated consumer transaction histories, account balances, and payment routing numbers as proprietary corporate assets, strictly controlling who can access them and how.[3]

The Consumer Financial Protection Bureau (CFPB) has fundamentally altered that dynamic by finalizing its long-awaited "Open Banking" rule. Issued under Section 1033 of the Dodd-Frank Act, the mandate legally establishes that consumers have a right to their own financial data and requires banks to make it available upon request, entirely free of charge.[1][2]

Rather than relying on outdated and insecure methods, the rule forces depository institutions, credit card issuers, and digital wallet providers to build secure application programming interfaces (APIs). These digital bridges allow consumers to seamlessly share their data with authorized third parties—such as budgeting apps, alternative lenders, or rival banks—without handing over their account passwords.[1][4]

The rule mandates a shift away from insecure screen scraping toward tokenized API access.

The immediate practical effect is a drastic reduction in the friction required to switch financial providers. Historically, moving a primary checking account meant manually downloading years of statements and painstakingly re-establishing direct deposits and automated bill payments, creating a moat that protected incumbent banks from competition.[3]

Under the new framework, consumers can authorize a new bank to pull their historical data and payment routing information instantly. This portability is designed to spur intense competition for deposits, forcing institutions to offer higher yields and lower fees to retain customers who can now leave with the tap of a screen.[1][3]

Crucially, the CFPB rule explicitly bans financial institutions from charging consumers or third-party apps "junk fees" for accessing this data. Several large banks had previously attempted to monetize data access by levying per-call API fees on fintech companies, costs that were inevitably passed down to the end user.[1][4]

Crucially, the CFPB rule explicitly bans financial institutions from charging consumers or third-party apps "junk fees" for accessing this data.

The transition to secure APIs also addresses a massive, long-standing cybersecurity vulnerability known as "screen scraping." For years, consumers wanting to use popular financial apps had to provide their actual bank usernames and passwords to third-party aggregators, who would then log in on their behalf to read the screen data.[1][3]

Screen scraping not only violated many banks' terms of service but also created vast repositories of highly sensitive login credentials outside the banking system. The new rule mandates tokenized access, meaning consumers grant permission via a secure digital token that can be revoked at any time, without ever exposing their underlying passwords.[1][4]

Traditional financial institutions have fiercely contested the breadth of the mandate. Industry lobbying groups argue that forcing banks to build and maintain high-capacity APIs without the ability to charge for access represents an unfunded mandate that will disproportionately burden smaller community banks and credit unions.[3][4]

Industry groups warn that the API mandate will disproportionately impact smaller institutions.

Furthermore, banks have raised alarm over liability in the event of a data breach. If a consumer authorizes a third-party app to access their data, and that app subsequently suffers a cyberattack, traditional institutions fear they will be held responsible for the resulting fraud or financial loss, despite having no control over the third party's security infrastructure.[3][4]

The CFPB has attempted to address these concerns by establishing strict authorization and data-use limitations for third parties. Fintech apps are explicitly prohibited from collecting, using, or retaining consumer data for any purpose other than delivering the specific product the consumer requested—effectively banning the secondary sale of transaction data to advertisers or data brokers.[1][4]

The rule traces its origins back to a 2021 executive order on promoting economic competition, which directed the CFPB to finally implement the dormant Section 1033 of the 2010 Dodd-Frank Act. The administration views financial data portability as a critical lever for reducing corporate concentration in the banking sector.[2]

The CFPB's rule implements a dormant section of the 2010 Dodd-Frank Act.

Beyond switching banks, the rule accelerates the shift toward "cash-flow underwriting." Millions of Americans with thin credit files or poor traditional FICO scores can now easily grant lenders access to their real-time checking account data, proving their ability to repay loans based on consistent income and rent payments rather than historical debt usage.[1][3]

The rule will be implemented in a tiered rollout to ease the burden on smaller institutions. The largest national banks and digital wallet providers will be required to comply first, while community banks and smaller credit unions will have an extended runway to build the necessary technological infrastructure.[1][4]

Frequently asked

Will I still have to give my bank password to budgeting apps?

No. Under the new rule, you will authorize access through a secure digital token, meaning third-party apps will never see or store your actual bank password.

Can my bank charge me a fee for sharing my data?

No. The CFPB rule explicitly prohibits financial institutions from charging consumers or third-party apps any fees for accessing this data.

What happens if I want to stop sharing my data?

The rule requires that consumers be provided with a simple, straightforward way to revoke data access permissions from any third-party app at any time.

Can third-party apps sell my transaction data?

No. The rule strictly prohibits fintech apps from collecting, using, or retaining your data for any purpose other than providing the specific product you requested.

Sources

Source coverage

5 outlets

3 viewpoints surfaced

Consumer Advocates 40%Traditional Banks 30%Fintech Innovators 30%
  1. [1]Consumer Financial Protection BureauConsumer Advocates

    Personal Financial Data Rights

    Read on Consumer Financial Protection Bureau
  2. [2]Legal Information InstituteFintech Innovators

    12 U.S. Code § 5533 - Consumer rights to access information

    Read on Legal Information Institute
  3. [3]Factlen Editorial TeamConsumer Advocates

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team
  4. [4]Federal RegisterTraditional Banks

    Required Rulemaking on Personal Financial Data Rights

    Read on Federal Register
  5. [5]Congress.gov

    Public Law 111-203: Dodd-Frank Wall Street Reform and Consumer Protection Act

    Read on Congress.gov

Comments

Stay informed

Every angle. Every day.

Get finance stories with full source coverage and perspective breakdowns delivered to your inbox.