About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline



1 [1] (September 30, 2025)

handle is hein.crs/hsefrd0001 and id is 1 raw text is: 





Congressiona R Fesedrch Service
Informina th  leoisIlive deat  since 1914


                                                                                                 September 30, 2025

Access to Consumer Financial Data: Open Banking and the

CFPB's Section 1033 Rule


Open  banking refers to a relationship among consumers,
financial services providers, and authorized third parties
that enables consumers to transfer their information
electronically from one firm to another for varied purposes.
Motivations for open banking include making it easier to
move  financial accounts between providers and enabling
free flow of information to novel applications. However,
the degree to which adoption of open banking should be
market-driven by industry due to consumer demand or
regulation-led is debated. Open banking also relates to a
broader policy issue regarding ownership of data and the
degree to which data should belong to a consumer or to the
financial institution.

Section 1033 of the Dodd-Frank Wall Street Reform and
Consumer  Protection Act (P.L. 111-203) requires covered
financial institutions to make available to consumers upon
request certain data associated with their accounts, subject
to rules prescribed by the Consumer Financial Protection
Bureau (CFPB).  The CFPB  finalized a rule in October
2024, with implementation originally set to begin in April
2026. Currently, the rule is the subject of litigation and
reconsideration by new CFPB  leadership.

Background
In practice, open banking consumer-permissioned data
transfers originate from data providers, often the depository
institutions where consumer hold their primary accounts,
generally through data aggregators that verify the
information and connect it to authorized third parties. For
example, a consumer with a checking account, investment
account, and credit card account at three separate financial
institutions may authorize a financial technology (fintech)
app provider to show the accounts' balances on one
interface for budgeting purposes. Examples of these firms
that could act as data providers or authorized third parties
include depository institutions or nonbanks such as
payment  platforms, budgeting applications, or crypto firms.
Financial institutions that are primarily data providers, data
aggregators, or authorized third parties may have different
policy motivations for this policy issue.

Data sharing platforms in financial services are common in
the United States, with previous estimates finding that, as of
2024, at least 100 million consumers authorized third
parties to access their financial data. Among other things,
the Gramm-Leach-Bliley  Act (GLBA,  P.L. 106-102)
regulates the disclosure and safeguard of non-public
information in the financial sector. GLBA generally
prohibits financial institutions from disclosing non-public
information to non-affiliated third parties without providing
consumers  notice and a reasonable ability to opt out of such
disclosures. One exception to GLBA is that consumers may


consent to or direct such disclosures, hence enabling the
current system of data sharing. Data sharing often uses
application programming interfaces (APIs) or sometimes
(and more controversially) screen scraping to facilitate
information sharing without the need for manual input.
Screen scraping refers to a consumer providing his or her
account credentials and permission to a third party to
scrape the account and activity information from a
financial institution's user interface. Scraping enables the
transfer of data, although such practices may present added
data security and privacy risks. API connections are most
common   at the larger banks, and smaller banks may face
challenges in setting up these platforms, as creating and
maintaining these connections may be relatively costlier for
smaller institutions and impose additional risks. Financial
institutions of different varieties and sizes have differing
interests related to consumer financial data, its access, who
pays for sharing, what types of data are shared, and
compliance with scam-related or data-privacy-related
statutes that correspond with such sharing.

Section 1033 of Dodd-Frank and the
C FPB Rule
Though  a rule implementing Section 1033 was not finalized
until 2024 and is currently set to be implemented over the
course of the next several years, Certain financial firms had
already begun offering open banking services, before the
finalized rule, driven by anticipated regulatory action and/or
consumer  demand  for such services. Regulatory standards
that mandate open banking are fairly common in European
countries, although their specific rules may differ from the
final rule of Section 1033.

As discussed in greater detail below, this rule is currently
the subject of litigation and reconsideration by new
leadership at the CFPB. In short, the final rule says the
following:

*  Covered  entities, such as depository institutions with
   $850  million or more in assets and certain nonbanks,
   must make  certain data available to consumers and
   authorized third parties in an electronic form.

*  Covered  financial data include transactions from the
   past 24 months, terms and conditions associated with the
   account, and personal account information.

*  The rule was set to take effect starting January 2025.
   The  original implementation timeline varied based on
   institution size and meant that the largest bank and
   nonbank  data providers would have had to comply in
   April 2026. The smallest depository institutions covered