Skip to main content
ExplainerOpen BankingExplainer· 6 min read· in Guides

The CFPB's Personal Financial Data Rights Rule: A Guide to US Open Banking and API Mandates

The CFPB's Section 1033 rule aims to modernize US finance by mandating secure data sharing, but legal challenges have left the transition to open banking in regulatory limbo.

By Paige Carter

Traditional Banks & Credit Unions 35%Fintechs & Data Aggregators 35%Consumer Privacy Advocates 30%
Traditional Banks & Credit Unions
Banks argue that building secure APIs is costly and they should be allowed to charge for access.
Fintechs & Data Aggregators
Fintech companies argue that consumer data belongs to the consumer, and access fees will stifle innovation.
Consumer Privacy Advocates
Advocates focus on eliminating screen scraping and enforcing strict limits on secondary data use.

Perspectives this story doesn't cover

  • Small community banks exempt from the rule

For years, the United States financial system has operated on a fragmented and often insecure approach to consumer data sharing. When individuals want to connect their bank accounts to budgeting applications, payment services, or investment platforms, they frequently have to hand over their actual banking usernames and passwords to third-party aggregators. This risky practice, known across the industry as "screen scraping," allows automated bots to log into banking portals and extract data indiscriminately. It exposes consumers to significant privacy and security risks, while leaving financial institutions blind to exactly who is accessing their systems and for what specific purpose.[1][2]

To modernize this ecosystem and align the U.S. with global financial standards, the Consumer Financial Protection Bureau (CFPB) finalized the Personal Financial Data Rights Rule in October 2024. Commonly referred to as the Section 1033 rule—named after the dormant provision of the 2010 Dodd-Frank Act it activated—the regulation was designed to formally usher in "open banking" in the United States. The core premise of the rule is simple: consumers own their financial data, and they have the legal right to access it and share it securely with authorized third parties without facing artificial barriers or fees.[1][3]

The mechanism for this transformation relies on mandating secure technology. The 2024 rule required banks, credit card issuers, and other financial providers to build dedicated, secure Application Programming Interfaces (APIs). These developer interfaces allow authorized third-party applications to access specific consumer data—such as account balances and transaction history—without ever seeing the user's login credentials. By forcing the industry to transition from screen scraping to standardized APIs, the CFPB aimed to boost competition, making it easier for consumers to switch banks or shop around for better financial products.[1]

Open banking APIs allow third-party apps to access financial data without ever seeing the user's login credentials.

However, as of mid-2026, the regulatory landscape for U.S. open banking is in a state of extraordinary flux. The first major compliance deadline for the largest banks and data providers arrived on April 1, 2026, but it passed without becoming a binding enforcement trigger. Instead of a synchronized rollout of consumer data rights, the industry is navigating a complex legal and political limbo where the federal rule exists on paper but cannot currently be enforced by the agency that wrote it.[2]

The delay stems from a protracted legal battle that began almost immediately after the rule's publication. Banking industry groups, including the Bank Policy Institute and the Kentucky Bankers Association, sued the CFPB in a Kentucky federal court. They argued that the agency had exceeded its statutory authority under the Dodd-Frank Act and imposed arbitrary, overly burdensome requirements on financial institutions. In late 2025, the federal court sided with the banks, issuing an injunction that halted the CFPB from enforcing the compliance deadlines while the litigation proceeded.[2]

The delay stems from a protracted legal battle that began almost immediately after the rule's publication.

Concurrently, under new leadership, the CFPB itself initiated a formal reconsideration process, effectively pausing its own mandate while it rewrites key provisions of the regulation. In a rare legal maneuver in May 2025, the agency even asked the court to vacate its own rule so it could start fresh. The CFPB's August 2025 Advance Notice of Proposed Rulemaking signaled that the agency intends to substantially revise the framework, leaving banks and fintechs to guess what the final compliance architecture will look like when the dust settles.

The most contentious issue in the ongoing rewrite is the question of "data tolls." The original 2024 rule strictly prohibited banks from charging fees to third-party apps and data aggregators for accessing consumer data, arguing that such fees would stifle innovation and limit consumer choice. Banks fiercely opposed this ban, arguing that building and maintaining secure, high-volume APIs requires massive ongoing investment. They contend that they should be permitted to recoup those costs from the commercial entities that are profiting off the data access, rather than subsidizing the fintech industry.[1]

Legal challenges and a formal reconsideration process have effectively paused the federal enforcement of the open banking rule.

The revised rulemaking process has explicitly reopened this fee debate. Recent indications suggest the CFPB may eliminate the total ban on data provider fees, potentially allowing banks to charge aggregators after a certain number of requests have been fulfilled for free. This shift has fiercely divided the industry. Fintech trade associations warn that allowing banks to charge for access will ultimately pass operating costs down to consumers and crush smaller startups, while banks view it as a necessary mechanism to ensure the safety and soundness of the data-sharing ecosystem.[2]

Despite the regulatory freeze at the federal level, the transition to open banking is happening anyway, driven by intense consumer demand and market realities. Millions of Americans already rely on interconnected financial apps, and financial institutions recognize that they can no longer support the security liabilities of screen scraping. Consequently, many large banks have moved forward with API integrations of their own accord, striking bilateral, fee-bearing agreements with major data aggregators to ensure secure data transfer outside the purview of the frozen CFPB rule.[2]

These early design decisions and private contracts are effectively setting the de facto standard for the U.S. open banking market. Legal experts note that the architecture being built today will heavily influence future compliance requirements. Even without active federal enforcement, institutions that treat the current pause as a permanent reprieve risk falling severely behind. Furthermore, the federal vacuum has prompted states like New York to consider stepping in with their own open banking legislation, raising the specter of a fragmented, state-by-state compliance patchwork.

For consumers, the underlying promise of open banking remains a powerful force for financial empowerment. The shift toward secure, consumer-permissioned data sharing represents a permanent evolution in how financial services operate. While the exact regulatory parameters—and the ultimate allocation of infrastructure costs—are still being negotiated in Washington and the courts, the era of siloed financial data and risky password sharing is coming to an end, paving the way for a more competitive and secure digital economy.[1][4]

Beyond just access and fees, the open banking transition also introduces critical new privacy safeguards. Under the envisioned framework, third parties can only collect, use, or retain data to deliver the specific product the consumer requested. This bans "bait-and-switch" data harvesting, where an app might offer a budgeting tool but secretly use the harvested transaction data for targeted advertising or sell it to data brokers. Regardless of how the final rule is rewritten, these baseline privacy expectations are becoming the new industry standard, ensuring that consumers finally have transparency and control over their digital financial footprints.[1][4]

The stakes

This transition dictates how securely you can connect your bank accounts to budgeting apps, payment services, and investment platforms. Moving away from risky password sharing to secure APIs protects your financial data from breaches and unauthorized harvesting.

The essentials

  • The CFPB's Section 1033 rule mandates that banks provide secure APIs for consumer data sharing.
  • The rule aims to eliminate 'screen scraping,' a risky practice where consumers share banking passwords with third-party apps.
  • A federal court injunction and a formal CFPB reconsideration process have paused the rule's enforcement.
  • Despite the regulatory freeze, major banks are moving forward with API integrations to meet consumer demand.

Timeline

  1. October 2024

    The CFPB finalizes the Personal Financial Data Rights Rule, mandating secure APIs and banning data access fees.

  2. May 2025

    The CFPB asks a federal court to vacate its own rule to allow for a comprehensive rewrite.

  3. August 2025

    The CFPB issues an Advance Notice of Proposed Rulemaking to reconsider the rule, including the fee ban.

  4. October 2025

    A federal court in Kentucky issues an injunction halting enforcement of the rule.

  5. April 2026

    The first major compliance deadline for the largest banks passes without becoming a binding enforcement trigger.

Perspectives explored

Traditional Banks & Credit Unions

Banks argue that building secure APIs is costly and they should be allowed to charge for access.

Financial institutions emphasize that they bear the primary responsibility for safeguarding consumer data and preventing fraud. Building, maintaining, and securing high-volume APIs for third-party access requires significant capital investment. They argue that a blanket ban on data access fees forces them to subsidize the operations of for-profit fintech companies. Furthermore, banks express concern over liability if a third-party app suffers a data breach after receiving consumer data via the mandated API.

Fintechs & Data Aggregators

Fintech companies argue that consumer data belongs to the consumer, and access fees will stifle innovation.

The financial technology sector views open banking as a critical driver of competition. They argue that consumers, not banks, own their financial data, and consumers should be able to share it freely with whichever service they choose. Fintechs warn that allowing banks to impose "data tolls" will create insurmountable barriers to entry for smaller startups, ultimately reducing consumer choice and passing costs down to the end-user. They advocate for a free, standardized API ecosystem to level the playing field.

Consumer Privacy Advocates

Advocates focus on eliminating screen scraping and enforcing strict limits on secondary data use.

For consumer protection groups, the primary goal of open banking regulation is to end the dangerous practice of screen scraping, which exposes consumers to severe security risks. They strongly support the CFPB's provisions that ban "bait-and-switch" data harvesting, ensuring that third parties can only use consumer data for the specific service requested. Advocates emphasize that true open banking must prioritize informed consent, easy revocation of access, and robust data minimization standards.

Sources

Source coverage

4 outlets

3 viewpoints surfaced

Traditional Banks & Credit Unions 35%Fintechs & Data Aggregators 35%Consumer Privacy Advocates 30%
  1. [1]Consumer Financial Protection BureauConsumer Privacy Advocates

    CFPB Finalizes Personal Financial Data Rights Rule

    Read on Consumer Financial Protection Bureau
  2. [2]American BankerFintechs & Data Aggregators

    On the day of a would-be deadline, open banking is in flux

    Read on American Banker
  3. [3]Open Banking TrackerConsumer Privacy Advocates

    CFPB Section 1033 Timeline

    Read on Open Banking Tracker
  4. [4]Factlen Editorial Team

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get Guides stories with full source coverage and perspective breakdowns delivered to your inbox.