Factlen ExplainerOpen BankingPolicy ExplainerJul 2, 2026, 4:56 PM· 6 min read· #2 of 2 in finance

The Mechanics of Regulatory Fragmentation: How the CFPB's Limited Open Banking Rule is Triggering a Patchwork of State Data-Sharing Laws

With the federal open banking mandate stalled in court and limited in scope, states like New York are advancing their own aggressive financial data laws, sweeping in excluded sectors like insurance and creating a complex compliance patchwork.

By Factlen Editorial Team

Regulators & Consumer Advocates 35%Fintech Innovators 35%Financial Institutions 30%
Regulators & Consumer Advocates
Argue that consumers own their data and should be able to port it freely to secure better rates, supporting aggressive state laws if the federal government stalls.
Fintech Innovators
Depend on open data to underwrite policies and offer competitive services, pushing for standardized APIs and zero-fee access to incumbent data.
Financial Institutions
Concerned about the immense compliance costs and cybersecurity risks of building bespoke APIs for a fragmented patchwork of 50 different state regulations.

What's not represented

  • · Small regional credit unions facing disproportionate compliance burdens
  • · Cybersecurity professionals auditing state-level API vulnerabilities

Why this matters

The transition to open banking means you will finally own your financial and insurance data, allowing you to seamlessly shop for better rates. However, the lack of a unified federal standard means the privacy protections and access rights you enjoy will increasingly depend on which state you live in.

Key points

  • The CFPB's federal open banking rule was stayed in 2025 amid industry lawsuits, creating a regulatory vacuum.
  • The original federal mandate excluded massive financial sectors, including mortgages, student loans, and insurance.
  • States like New York are advancing their own comprehensive data-sharing laws to fill the void and expand consumer rights.
  • New York's proposed legislation bans API access fees, includes small businesses, and imposes $10,000 penalties per violation.
  • The resulting patchwork of state laws creates a complex and costly compliance labyrinth for banks and fintechs.
  • Despite mechanical hurdles, the shift toward state-led open banking signals an unstoppable momentum for consumer data rights.
$10,000
Max penalty per violation under NY's proposed law
$6 million
Average cost of a financial sector data breach
1033
Dodd-Frank section establishing data rights

The fundamental promise of "open banking" is simple: the financial data generated by your daily life belongs to you, not the institution holding it. In a fully realized open-finance ecosystem, a consumer can seamlessly and securely port their transaction history, asset data, or insurance claims to a competing provider to secure a better rate. While jurisdictions like the European Union achieved this years ago through unified directives, the United States has taken a decidedly rockier path. Today, the American push for data portability has fractured, transforming a unified federal vision into a complex, state-by-state labyrinth.[3]

The anchor for American open banking has long been Section 1033 of the 2010 Dodd-Frank Act. After years of delays, the Consumer Financial Protection Bureau (CFPB) finalized a landmark rule in October 2024 to implement this mandate. The regulation required banks to build secure Application Programming Interfaces (APIs)—standardized digital bridges that allow consumers to share their data with third-party financial technology apps without handing over their actual usernames and passwords. It was heralded as the death knell for "screen scraping," an outdated and insecure data-gathering method, and the dawn of a competitive new era.[1]

However, the federal framework almost immediately hit a legal wall. Banking industry groups filed lawsuits arguing that the CFPB had exceeded its statutory authority and imposed arbitrary technical burdens. Facing the prospect of a protracted court battle and a shifting legal landscape following recent Supreme Court rulings on agency power, the CFPB made a strategic retreat in mid-2025. The bureau stayed the enforcement of its own rule and announced a comprehensive rewrite, effectively plunging the nascent US open banking ecosystem into regulatory limbo.

Even before the legal pause, the CFPB’s initial rule was intentionally narrow in its scope. To make the rollout manageable, the bureau limited the data-sharing mandate to basic depository accounts—like checking and savings—and credit cards. While these products represent the bulk of daily consumer spending, the limitation explicitly excluded massive sectors of the financial ecosystem. Mortgages, auto loans, student debt, and crucially, insurance products were left entirely outside the federal open banking umbrella.[3]

State laws are stepping in to cover financial products, like insurance, that the federal mandate excluded.
State laws are stepping in to cover financial products, like insurance, that the federal mandate excluded.

For the insurance industry, this exclusion maintained a status quo of siloed data. Insurtech startups, which rely on fluid data to underwrite policies dynamically, were left without a standardized way to access a consumer's broader financial picture. Conversely, consumers lacked a secure, regulated mechanism to port their property, auto, or life insurance histories to new carriers. If a driver wanted to leverage a decade of flawless telematics and claims data to secure a cheaper premium from a competitor, the technical infrastructure to do so securely simply did not exist under the federal mandate.[3]

Nature abhors a regulatory vacuum, and state legislatures have proven unwilling to wait for Washington to resolve its legal disputes. With the federal government stalled, individual states have begun stepping into the void to guarantee data rights for their residents. This state-level intervention is rapidly shifting the landscape from a single national standard to a patchwork of localized data-sharing laws, fundamentally altering how financial institutions and insurers must operate.[2]

New York is currently leading the legislative charge. State lawmakers have advanced companion bills—A10640 and S9483—that aim to create a comprehensive, first-in-the-nation state-level financial data access regime. While the proposed legislation mirrors the core consumer-control concepts of the stalled CFPB rule, it serves as a template for how states plan to aggressively expand upon the federal baseline.

State lawmakers have advanced companion bills—A10640 and S9483—that aim to create a comprehensive, first-in-the-nation state-level financial data access regime.

The New York model goes significantly further than Section 1033 in several key areas. Most notably, it extends data access rights beyond individual consumers to include small businesses, a demographic often ignored in early open banking frameworks. Furthermore, the state bills strictly prohibit financial institutions from charging any fees for API access or data transfers. To ensure compliance, the legislation proposes severe financial penalties, including a maximum fine of $10,000 for each individual violation of the law.

New York's proposed legislation introduces severe financial penalties for institutions that fail to provide data access.
New York's proposed legislation introduces severe financial penalties for institutions that fail to provide data access.

For the insurance sector, this state-level legislative push is transformative. Because states are the primary regulators of the US insurance industry, local data-sharing bills are uniquely positioned to sweep insurance records into the open-finance mandate. As states like New York draft their frameworks, insurtechs are anticipating a future where they can seamlessly integrate banking data to verify assets for life insurance, or where consumers can instantly port their underwriting profiles across state lines.[3]

Yet, this momentum comes with a steep mechanical cost: regulatory fragmentation. A patchwork of 50 different state laws creates a labyrinth of compliance for financial technology companies, regional banks, and national insurers. Instead of building a single API that satisfies the CFPB, institutions must now prepare to navigate varying state-level security standards, consent requirements, and API performance metrics.[2]

Data aggregators—the companies that build the plumbing connecting banks to fintech apps—are bearing the brunt of this complexity. Firms must design infrastructure that remains flexible enough to comply with New York's strict fee prohibitions while simultaneously adhering to distinct privacy mandates emerging in other jurisdictions. For smaller community banks and regional credit unions, the cost of developing bespoke compliance solutions for multiple states threatens to become a crushing financial burden.[2]

The lack of a unified national standard also raises complex privacy and security questions. Unlike Europe, which operates under the overarching General Data Protection Regulation (GDPR), the US relies on a fragmented approach to data privacy. State laws differ wildly on critical issues such as data minimization—how much data a third party is actually allowed to pull—and whether that data can be retained or used for secondary purposes like targeted advertising.[3]

Insurtech startups rely on open data to dynamically underwrite policies and verify assets.
Insurtech startups rely on open data to dynamically underwrite policies and verify assets.

Without a federal floor, the risk of data misuse increases. The average cost of a data breach in the financial sector now exceeds $6 million, and the proliferation of state-specific APIs multiplies the potential attack vectors for cybercriminals. If a fintech app stretches a consent agreement to monetize access under a weaker state's law, the resulting breach of trust could set the entire open banking movement back by years.[3]

To mitigate these risks and survive the patchwork, the private sector is attempting to self-regulate. Industry consortiums and standard-setting bodies are working urgently to establish consensus-based technical frameworks. These private standards aim to create a baseline of interoperability and security that financial institutions can adopt universally, ensuring that their APIs function safely regardless of which state's legal jurisdiction they happen to fall under on any given day.[1]

Ultimately, the shift toward state-led open banking proves that consumer demand for data portability is an unstoppable force. The financial ecosystem is permanently moving away from the era of siloed data, driven by a public that increasingly views financial history as personal property rather than corporate leverage.[2][3]

Whether the final architecture of US open banking is dictated by a revived CFPB rule, congressional action to amend the Gramm-Leach-Bliley Act, or a coalition of aggressive state legislatures, the destination remains the same. For consumers and the insurance markets that serve them, the fragmentation is merely a mechanical growing pain on the path to a more competitive, transparent, and personalized financial future.[3]

How we got here

  1. October 2024

    The CFPB finalizes its long-awaited Section 1033 rule to establish a federal open banking standard.

  2. Mid-2025

    Facing industry lawsuits, the CFPB pauses enforcement of the rule and announces a comprehensive rewrite.

  3. August 2025

    The CFPB issues an Advance Notice of Proposed Rulemaking to gather input for the revised federal framework.

  4. Early 2026

    States like New York advance their own aggressive financial data access bills to fill the federal regulatory void.

Viewpoints in depth

Regulators & Consumer Advocates

Advocates argue that consumers fundamentally own their financial data and must be empowered to use it.

For consumer advocates and state regulators, the push for open banking is a matter of fundamental property rights. They argue that banks and insurers have historically hoarded consumer data to prevent customers from easily shopping around for better rates. By mandating secure, free API access, advocates believe consumers will finally be able to leverage their own financial history to secure cheaper insurance premiums, lower loan rates, and better wealth management services. If the federal government is paralyzed by litigation, these advocates fully support state legislatures stepping in to force the industry's hand.

Financial Institutions

Incumbents warn that a fragmented regulatory landscape creates unsustainable compliance costs and severe security risks.

Traditional banks, credit unions, and legacy insurers view the patchwork of state laws as a logistical nightmare. While many support the general transition away from insecure screen scraping, they argue that building bespoke APIs to satisfy 50 different state regulators is financially ruinous, particularly for smaller community institutions. Furthermore, they warn that without a unified national standard for data privacy and security, the proliferation of state-level data sharing mandates will inevitably lead to catastrophic data breaches, leaving the institutions themselves liable for the fallout.

Fintech Innovators

Startups and data aggregators rely on open access to disrupt legacy markets and offer personalized services.

For the fintech and insurtech sectors, open banking is the lifeblood of innovation. These companies rely on fluid access to consumer data to dynamically underwrite policies, verify assets, and offer personalized financial advice. They strongly support legislation like New York's proposed bill, which prohibits banks from charging fees for API access and extends data rights to small businesses. However, they also acknowledge the mechanical friction of a fragmented system, urging the industry to adopt consensus-based technical standards so their apps can function seamlessly across state lines.

What we don't know

  • Whether the CFPB's upcoming rewrite of the Section 1033 rule will successfully preempt state laws.
  • How quickly other major states like California will introduce their own competing open banking frameworks.
  • If Congress will intervene to modernize the Gramm-Leach-Bliley Act to create a unified national privacy standard.

Key terms

Section 1033
A provision of the 2010 Dodd-Frank Act that grants consumers the right to access and share their personal financial data.
API (Application Programming Interface)
A software intermediary that allows two different applications to communicate securely, replacing outdated methods like screen scraping.
Insurtech
Technology-driven companies that use data analytics and digital platforms to innovate and disrupt the traditional insurance industry.
Data Aggregator
A third-party service that compiles financial data from multiple institutions into a single platform, often acting as the plumbing for fintech apps.
Screen Scraping
An older, less secure method of data sharing where users provide their login credentials to a third party, which then logs in to copy data directly from the screen.

Frequently asked

What is Open Banking?

Open banking is a regulatory framework that gives consumers the right to securely share their financial data—such as transaction history or account balances—with third-party applications using standardized APIs.

Why did the CFPB pause its Section 1033 rule?

Facing lawsuits from banking industry groups over alleged regulatory overreach, the CFPB stayed the enforcement of its 2024 rule to rewrite the framework and address legal vulnerabilities.

How does this affect my insurance policies?

Because the federal rule excluded insurance data, states are drafting their own laws to allow consumers to port their insurance and claims history to new carriers, making it easier to shop for better rates.

What is the New York financial data bill?

It is a proposed state law that mirrors the federal open banking mandate but goes further by covering small businesses, strictly banning API access fees, and imposing heavy fines for non-compliance.

Sources

Source coverage

3 outlets

3 viewpoints surfaced

Regulators & Consumer Advocates 35%Fintech Innovators 35%Financial Institutions 30%
  1. [1]Consumer Financial Protection BureauRegulators & Consumer Advocates

    Personal Financial Data Rights Reconsideration

    Read on Consumer Financial Protection Bureau
  2. [2]FinovateFintech Innovators

    What Will Happen to Open Banking Regulation if the CFPB is Torn Down?

    Read on Finovate
  3. [3]Factlen Editorial TeamFinancial Institutions

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team
Stay informed

Every angle. Every day.

Get finance stories with full source coverage and perspective breakdowns delivered to your inbox.