The CFPB's Personal Financial Data Rights Rule: A Guide to US Open Banking and API Mandates
The CFPB's Section 1033 rule aims to modernize US finance by mandating secure data sharing, but legal challenges have left the transition to open banking in regulatory limbo.
- Traditional Banks & Credit Unions
- Banks argue that building secure APIs is costly and they should be allowed to charge for access.
- Fintechs & Data Aggregators
- Fintech companies argue that consumer data belongs to the consumer, and access fees will stifle innovation.
- Consumer Privacy Advocates
- Advocates focus on eliminating screen scraping and enforcing strict limits on secondary data use.
Why this matters
This transition dictates how securely you can connect your bank accounts to budgeting apps, payment services, and investment platforms. Moving away from risky password sharing to secure APIs protects your financial data from breaches and unauthorized harvesting.
Key points
- The CFPB's Section 1033 rule mandates that banks provide secure APIs for consumer data sharing.
- The rule aims to eliminate 'screen scraping,' a risky practice where consumers share banking passwords with third-party apps.
- A federal court injunction and a formal CFPB reconsideration process have paused the rule's enforcement.
- Despite the regulatory freeze, major banks are moving forward with API integrations to meet consumer demand.
For years, the United States financial system has operated on a fragmented and often insecure approach to consumer data sharing. When individuals want to connect their bank accounts to budgeting applications, payment services, or investment platforms, they frequently have to hand over their actual banking usernames and passwords to third-party aggregators. This risky practice, known across the industry as "screen scraping," allows automated bots to log into banking portals and extract data indiscriminately. It exposes consumers to significant privacy and security risks, while leaving financial institutions blind to exactly who is accessing their systems and for what specific purpose.[1][2]
To modernize this ecosystem and align the U.S. with global financial standards, the Consumer Financial Protection Bureau (CFPB) finalized the Personal Financial Data Rights Rule in October 2024. Commonly referred to as the Section 1033 rule—named after the dormant provision of the 2010 Dodd-Frank Act it activated—the regulation was designed to formally usher in "open banking" in the United States. The core premise of the rule is simple: consumers own their financial data, and they have the legal right to access it and share it securely with authorized third parties without facing artificial barriers or fees.[1][3]
The mechanism for this transformation relies on mandating secure technology. The 2024 rule required banks, credit card issuers, and other financial providers to build dedicated, secure Application Programming Interfaces (APIs). These developer interfaces allow authorized third-party applications to access specific consumer data—such as account balances and transaction history—without ever seeing the user's login credentials. By forcing the industry to transition from screen scraping to standardized APIs, the CFPB aimed to boost competition, making it easier for consumers to switch banks or shop around for better financial products.[1]

However, as of mid-2026, the regulatory landscape for U.S. open banking is in a state of extraordinary flux. The first major compliance deadline for the largest banks and data providers arrived on April 1, 2026, but it passed without becoming a binding enforcement trigger. Instead of a synchronized rollout of consumer data rights, the industry is navigating a complex legal and political limbo where the federal rule exists on paper but cannot currently be enforced by the agency that wrote it.[2]
The delay stems from a protracted legal battle that began almost immediately after the rule's publication. Banking industry groups, including the Bank Policy Institute and the Kentucky Bankers Association, sued the CFPB in a Kentucky federal court. They argued that the agency had exceeded its statutory authority under the Dodd-Frank Act and imposed arbitrary, overly burdensome requirements on financial institutions. In late 2025, the federal court sided with the banks, issuing an injunction that halted the CFPB from enforcing the compliance deadlines while the litigation proceeded.[2]
The delay stems from a protracted legal battle that began almost immediately after the rule's publication.
Concurrently, under new leadership, the CFPB itself initiated a formal reconsideration process, effectively pausing its own mandate while it rewrites key provisions of the regulation. In a rare legal maneuver in May 2025, the agency even asked the court to vacate its own rule so it could start fresh. The CFPB's August 2025 Advance Notice of Proposed Rulemaking signaled that the agency intends to substantially revise the framework, leaving banks and fintechs to guess what the final compliance architecture will look like when the dust settles.
The most contentious issue in the ongoing rewrite is the question of "data tolls." The original 2024 rule strictly prohibited banks from charging fees to third-party apps and data aggregators for accessing consumer data, arguing that such fees would stifle innovation and limit consumer choice. Banks fiercely opposed this ban, arguing that building and maintaining secure, high-volume APIs requires massive ongoing investment. They contend that they should be permitted to recoup those costs from the commercial entities that are profiting off the data access, rather than subsidizing the fintech industry.[1]

The revised rulemaking process has explicitly reopened this fee debate. Recent indications suggest the CFPB may eliminate the total ban on data provider fees, potentially allowing banks to charge aggregators after a certain number of requests have been fulfilled for free. This shift has fiercely divided the industry. Fintech trade associations warn that allowing banks to charge for access will ultimately pass operating costs down to consumers and crush smaller startups, while banks view it as a necessary mechanism to ensure the safety and soundness of the data-sharing ecosystem.[2]
Despite the regulatory freeze at the federal level, the transition to open banking is happening anyway, driven by intense consumer demand and market realities. Millions of Americans already rely on interconnected financial apps, and financial institutions recognize that they can no longer support the security liabilities of screen scraping. Consequently, many large banks have moved forward with API integrations of their own accord, striking bilateral, fee-bearing agreements with major data aggregators to ensure secure data transfer outside the purview of the frozen CFPB rule.[2]
These early design decisions and private contracts are effectively setting the de facto standard for the U.S. open banking market. Legal experts note that the architecture being built today will heavily influence future compliance requirements. Even without active federal enforcement, institutions that treat the current pause as a permanent reprieve risk falling severely behind. Furthermore, the federal vacuum has prompted states like New York to consider stepping in with their own open banking legislation, raising the specter of a fragmented, state-by-state compliance patchwork.
For consumers, the underlying promise of open banking remains a powerful force for financial empowerment. The shift toward secure, consumer-permissioned data sharing represents a permanent evolution in how financial services operate. While the exact regulatory parameters—and the ultimate allocation of infrastructure costs—are still being negotiated in Washington and the courts, the era of siloed financial data and risky password sharing is coming to an end, paving the way for a more competitive and secure digital economy.[1][4]
Beyond just access and fees, the open banking transition also introduces critical new privacy safeguards. Under the envisioned framework, third parties can only collect, use, or retain data to deliver the specific product the consumer requested. This bans "bait-and-switch" data harvesting, where an app might offer a budgeting tool but secretly use the harvested transaction data for targeted advertising or sell it to data brokers. Regardless of how the final rule is rewritten, these baseline privacy expectations are becoming the new industry standard, ensuring that consumers finally have transparency and control over their digital financial footprints.[1][4]
How we got here
October 2024
The CFPB finalizes the Personal Financial Data Rights Rule, mandating secure APIs and banning data access fees.
May 2025
The CFPB asks a federal court to vacate its own rule to allow for a comprehensive rewrite.
August 2025
The CFPB issues an Advance Notice of Proposed Rulemaking to reconsider the rule, including the fee ban.
October 2025
A federal court in Kentucky issues an injunction halting enforcement of the rule.
April 2026
The first major compliance deadline for the largest banks passes without becoming a binding enforcement trigger.
Viewpoints in depth
Traditional Banks & Credit Unions
Banks argue that building secure APIs is costly and they should be allowed to charge for access.
Financial institutions emphasize that they bear the primary responsibility for safeguarding consumer data and preventing fraud. Building, maintaining, and securing high-volume APIs for third-party access requires significant capital investment. They argue that a blanket ban on data access fees forces them to subsidize the operations of for-profit fintech companies. Furthermore, banks express concern over liability if a third-party app suffers a data breach after receiving consumer data via the mandated API.
Fintechs & Data Aggregators
Fintech companies argue that consumer data belongs to the consumer, and access fees will stifle innovation.
The financial technology sector views open banking as a critical driver of competition. They argue that consumers, not banks, own their financial data, and consumers should be able to share it freely with whichever service they choose. Fintechs warn that allowing banks to impose "data tolls" will create insurmountable barriers to entry for smaller startups, ultimately reducing consumer choice and passing costs down to the end-user. They advocate for a free, standardized API ecosystem to level the playing field.
Consumer Privacy Advocates
Advocates focus on eliminating screen scraping and enforcing strict limits on secondary data use.
For consumer protection groups, the primary goal of open banking regulation is to end the dangerous practice of screen scraping, which exposes consumers to severe security risks. They strongly support the CFPB's provisions that ban "bait-and-switch" data harvesting, ensuring that third parties can only use consumer data for the specific service requested. Advocates emphasize that true open banking must prioritize informed consent, easy revocation of access, and robust data minimization standards.
What we don't know
- Whether the revised CFPB rule will ultimately allow banks to charge fees for API access.
- When the new compliance deadlines will be finalized and enforced.
- If states like New York will successfully implement their own open banking laws before a federal framework takes effect.
Key terms
- Open Banking
- A system that provides third-party financial service providers open access to consumer banking, transaction, and other financial data from banks and non-bank financial institutions through the use of APIs.
- API (Application Programming Interface)
- A set of protocols that allows different software applications to communicate with each other securely, enabling data transfer without exposing user credentials.
- Screen Scraping
- An outdated data collection method where a user provides their login credentials to a third party, which then uses automated scripts to log into the user's account and extract information.
- Section 1033
- A provision of the 2010 Dodd-Frank Wall Street Reform and Consumer Protection Act that grants consumers the right to access their financial records in an electronic format.
- Data Aggregator
- A company that acts as a middleman, collecting financial data from various institutions and supplying it to consumer-facing fintech applications.
Frequently asked
What is open banking?
Open banking is a financial framework that allows consumers to securely share their financial data with third-party apps and services using standardized APIs instead of sharing passwords.
What is screen scraping?
Screen scraping is a risky practice where consumers give their bank login credentials to a third-party app, which then uses automated bots to log into the bank's portal and extract data.
Why is the CFPB rule currently paused?
A federal court in Kentucky issued an injunction in late 2025 after banking groups sued, arguing the CFPB exceeded its authority. The CFPB is currently rewriting the rule.
Can banks charge fees for sharing my data?
The original 2024 rule banned data fees, but the CFPB is reconsidering this provision, and revised rules may allow banks to charge third-party apps for API access.
Sources
[1]Consumer Financial Protection BureauConsumer Privacy Advocates
CFPB Finalizes Personal Financial Data Rights Rule
Read on Consumer Financial Protection Bureau →[2]American BankerFintechs & Data Aggregators
On the day of a would-be deadline, open banking is in flux
Read on American Banker →[3]Open Banking TrackerConsumer Privacy Advocates
CFPB Section 1033 Timeline
Read on Open Banking Tracker →[4]Factlen Editorial Team
Synthesis by Factlen editorial team
Read on Factlen Editorial Team →
Every angle. Every day.
Get guides stories with full source coverage and perspective breakdowns delivered to your inbox.





