Skip to main content
AnalysisOpen BankingPolicy ReversalAug 29, 2026, 6:20 AM· 6 min read· in opinion

How the CFPB's Open Banking Reconsideration Re-Entrenches Banks as Data Gatekeepers

The CFPB's reconsideration of its landmark Section 1033 rule signals a shift from a fee-free open banking mandate to a commercialized framework where banks retain economic control over consumer data.

By Ling Zhou

Incumbent Banks 35%Fintech & Aggregators 30%Consumer Advocates & Regulators 20%Market Analysts 15%
Incumbent Banks
Argue that building secure APIs is costly and they should be allowed to charge third parties for data access to recover costs and manage fraud risks.
Fintech & Aggregators
Argue that consumers own their data and that allowing banks to charge access fees will stifle innovation and raise costs for end users.
Consumer Advocates & Regulators
Focus on eliminating risky screen-scraping practices and ensuring consumers can freely port their data to switch financial providers.
Market Analysts
View the regulatory shift as a pragmatic compromise that trades the ideal of free data for a legally durable framework.

The U.S. financial system is currently fighting a multi-billion-dollar war over a seemingly simple question: who owns your bank data? On one side, financial technology companies and consumer advocates argue that individuals own their transaction histories and should be able to port that data to any app for free. On the other side, incumbent banks argue that the secure infrastructure required to transmit that data costs money, and they should not be forced by the government to subsidize their direct competitors.[1][5]

The Consumer Financial Protection Bureau (CFPB) attempted to settle this in October 2024 with its landmark Section 1033 Personal Financial Data Rights rule, which mandated free, secure data sharing. But the evidence from the past two years suggests that the 2024 rule was not the final birth of U.S. open banking. Instead, it was the opening skirmish in a protracted legal and regulatory battle that is now poised to re-entrench banks as economic gatekeepers of consumer data.[1][5]

To understand the current regulatory retreat, we must first look at what the data actually says about the original mandate. The 2024 rule was designed to strip banks of their technical gatekeeper status by activating a dormant provision of the 2010 Dodd-Frank Act. It required financial institutions to build developer interfaces—Application Programming Interfaces (APIs)—that could securely transmit up to 24 months of transaction history, account balances, and routing information to authorized third parties.[1]

Crucially, the 2024 rule explicitly prohibited banks from charging fees for this access and mandated a strict 99.5% API uptime. The stated goal was to eliminate "screen scraping"—a risky but ubiquitous practice where consumers give their bank passwords to fintech apps, which then log in as the user to extract data. By mandating free APIs, the CFPB aimed to make it frictionless for consumers to switch to better financial products, effectively creating a utility-style open banking model similar to the frameworks seen in the United Kingdom and the European Union.[1][2][5]

Key provisions and shifts in the CFPB's Section 1033 rulemaking.

However, the data shows that this free-access regime collapsed almost immediately upon contact with the federal judiciary. The Bank Policy Institute, alongside regional banking associations, sued the CFPB in a Kentucky federal court shortly after the rule was finalized. Their primary legal claim was that the agency overstepped its statutory authority by forcing private companies to share proprietary infrastructure without compensation.[2][3]

The court agreed enough to issue an injunction, halting the rule's implementation. As a direct result, the highly anticipated April 1, 2026, compliance deadline for the largest U.S. banks passed without becoming a binding enforcement trigger. For banks and fintechs alike, this created a chaotic dynamic: a landmark regulation that existed on paper but carried no legal weight in practice.[3][4]

The court agreed enough to issue an injunction, halting the rule's implementation.

The evidence of the CFPB's subsequent regulatory pivot is now formalized in the public record. Recognizing the legal vulnerability of the fee ban, the Bureau issued an Advance Notice of Proposed Rulemaking (ANPR) in August 2025 to formally reconsider the rule. By August 2026, the CFPB took the definitive step of submitting a revised Notice of Proposed Rulemaking (NPRM) to the White House's Office of Information and Regulatory Affairs (OIRA).[1][2][4]

The strongest counter-argument to the CFPB's original fee ban—and the likely catalyst for the 2026 revision—comes directly from the banks' balance sheets and security logs. Building, maintaining, and scaling secure, high-volume APIs is an expensive enterprise, particularly for community banks that rely heavily on third-party core processors. The Independent Community Bankers of America successfully lobbied for exemptions for banks under $850 million in assets, but mid-sized and large banks remained on the hook for massive infrastructure costs.

Furthermore, banks argue that forcing them to open their systems to thousands of third-party fintechs exposes the financial system to severe fraud risks. If a bad actor poses as a legitimate budgeting app and drains a consumer's account via a mandated API, the bank often bears the reputational damage and the financial liability for making the customer whole. From the banking industry's perspective, data-access fees are not just a revenue stream; they are a necessary mechanism for cost recovery and risk management in a highly regulated environment.[2]

The proposed introduction of fees changes the economic dynamics of the data-sharing ecosystem.

The CFPB appears to have conceded this economic reality. While the exact text of the August 2026 NPRM remains under OIRA review and out of public view, regulatory filings and industry consensus strongly indicate that the revised rule will permit banks to charge reasonable fees to third parties for data access. This concession represents a fundamental shift in the trajectory of U.S. open banking.[2][3][5]

If fintechs and data aggregators must pay to access consumer data, the fundamental economics of the ecosystem change overnight. The Financial Technology Association has warned that such fees will inevitably be passed down to consumers. A fee-bearing model threatens the viability of free budgeting apps, alternative credit scoring models that rely on cash-flow underwriting, and low-cost digital wallets. It shifts the power dynamic back to the institutions that hold the data.[3]

We must be explicit about where the evidence is currently thin: we do not yet know the exact fee structures or caps the CFPB will propose. It is entirely possible that the CFPB will attempt to thread the needle by capping fees at strict cost-recovery levels, preventing banks from using pricing as a punitive weapon to price competitors out of the market. We also do not know how the courts will treat this revised framework, or if fintech trade groups will launch their own lawsuits in response.[2][5]

Fintech advocates warn that data-access fees will ultimately be passed down to consumers.

Furthermore, the market is not waiting for the regulators to finalize the rules of engagement. In the absence of an enforced federal mandate, major institutions like JPMorgan Chase have already begun striking bilateral, paid data-access deals with major aggregators. These private contracts are establishing a de facto commercial standard for data access before the CFPB can codify a regulatory one.[3][5]

Ultimately, the CFPB's Section 1033 saga demonstrates that declaring the end of banks as data gatekeepers was premature. The U.S. is indeed moving toward a formalized open banking system, and the days of insecure screen scraping are numbered. But the transition from the 2024 rule to the 2026 reconsideration reveals a crucial compromise. Banks are losing their ability to outright deny data access, but they are retaining their ability to toll the roads. By shifting from technical gatekeeping to economic gatekeeping, incumbent financial institutions have ensured that the future of U.S. open banking will be built on their commercial terms.[1][2][5]

24 months
Required transaction history
99.5%
Minimum API uptime mandated
$850M
Asset threshold for bank exemption

Limits of the evidence

  • The exact fee caps or cost-recovery formulas the CFPB will propose in the forthcoming NPRM.
  • How federal courts will interpret the statutory authority of the Dodd-Frank Act regarding compensated data access.
  • Whether fintech trade groups will launch their own lawsuits in response to a fee-bearing framework.

Sources

Source coverage

5 outlets

4 viewpoints surfaced

Incumbent Banks 35%Fintech & Aggregators 30%Consumer Advocates & Regulators 20%Market Analysts 15%
  1. [1]Consumer Financial Protection BureauConsumer Advocates & Regulators

    CFPB Finalizes Rule to Give Consumers Control Over Their Financial Data

    Read on Consumer Financial Protection Bureau
  2. [2]American BankerMarket Analysts

    What we know about the CFPB's forthcoming open-banking rule

    Read on American Banker
  3. [3]Open Banking TrackerMarket Analysts

    CFPB Section 1033 Timeline and Compliance Tracker

    Read on Open Banking Tracker
  4. [4]Cozen O'ConnorIncumbent Banks

    Section 1033 Compliance Date: Open Banking Rule Enjoined and Under Reconsideration

    Read on Cozen O'Connor
  5. [5]Factlen Editorial TeamMarket Analysts

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get opinion stories with full source coverage and perspective breakdowns delivered to your inbox.