Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Regulatory Compliance

CFPB Section 1033 Open Banking Rule: What Financial Institutions Need to Know While the Litigation Plays Out

CFPB finalized its Section 1033 open banking rule in October 2024, requiring covered institutions to share consumer financial data via permissioned APIs. Then a federal court enjoined enforcement in October 2025. Here's what the rule requires, where the litigation stands, and why your compliance team should be building toward it anyway.

By Rebecca Leung · June 5, 2026 ·
Table of Contents

TL;DR:

  • The CFPB finalized its Section 1033 “personal financial data rights” rule on October 22, 2024, requiring covered institutions to share consumer financial data via permissioned APIs. A federal court enjoined enforcement in October 2025; the CFPB is now reconsidering the rule.
  • The rule covers depository institutions with $850 million or more in assets. Required data: 24 months of transaction history, account terms and conditions, payment initiation information, and upcoming payments. No fees permitted.
  • Third parties accessing data have strict use limitations: no targeted advertising, no cross-selling, no data sales. They must maintain GLBA-equivalent information security programs and retain authorization records for three years.
  • The litigation uncertainty is real — but the direction isn’t. Build toward a Section 1033-compliant data sharing architecture during the current window rather than waiting for a final rule to begin.

The Right to Your Own Financial Data

The premise of Section 1033 is deceptively simple: you generated the transaction data in your bank account, you should be able to access it. In a format you can actually use. Without calling a branch or waiting for a PDF export.

That premise has been in the Dodd-Frank Act since 2010. It took the CFPB 14 years to finalize implementing rules. The October 2024 rule was immediately challenged in federal court. By October 2025, a Kentucky federal judge had issued an injunction preventing enforcement. By June 2026, the CFPB was in active rulemaking reconsideration.

And yet the rule matters — not only for what it requires when it does take effect, but for what it reveals about where financial data regulation is heading and how much infrastructure work lies between here and compliance.

This is the version for compliance teams who need to understand the rule’s actual requirements, the current litigation status, and what to actually do in the meantime.

What the Rule Requires

The CFPB’s final rule under 12 CFR Part 1033 establishes a framework for consumer-permissioned financial data access with four core components.

Data Providers Must Make Data Available

Covered data providers — primarily depository institutions with $850 million or more in assets — must make available to consumers upon request the following categories of data:

  • Transaction information: Account balance and at least 24 months of transaction history
  • Terms and conditions: Fee schedules, interest rates, annual percentage rates applicable to the account
  • Payment initiation information: Information sufficient to facilitate payment transactions from the account
  • Account information: Basic account identification data
  • Upcoming bills and payments: Where the data provider has this information

The data must be provided in a standardized electronic format — not PDFs or manual exports. Institutions cannot charge consumers fees for data access.

Notably, the rule explicitly does not require data providers to maintain data they don’t already maintain. The obligation runs to data you have, in the ordinary course of your business. There is no duty to create new data systems to satisfy a Section 1033 request.

Consumers Can Authorize Third Parties

This is the open banking core: consumers can instruct their data provider to share their data with a regulated third party of their choosing — a financial planning app, a lending platform, a money management service.

The authorization process requires:

  • The third party provides the consumer an authorization disclosure before accessing data
  • The consumer grants express informed consent (written or electronic signature)
  • Authorization is limited to a maximum of one year — after which new authorization is required

Third parties must also agree, through a certification process, to comply with the rule’s data use limitations and security obligations before accessing any data.

Third-Party Obligations Are Strict

The rule’s obligations on data-receiving third parties are more prescriptive than many institutions anticipate. A third party accessing consumer data under Section 1033 must:

Limit data collection and use to what is “reasonably necessary” to provide the specific product or service the consumer requested. Three use cases are explicitly prohibited regardless of consumer authorization:

  • Targeted advertising
  • Cross-selling other products or services
  • Selling consumer data to any other party

Maintain information security standards. Third parties subject to GLBA must comply with Section 501 information security requirements. Those not subject to GLBA must comply with the equivalent FTC Safeguards Rule standards. This brings fintech data aggregators — even those that wouldn’t otherwise be GLBA-covered — into a GLBA-equivalent security posture.

Retain compliance records for at least three years after the consumer’s most recent authorization, including signed authorization disclosures and any data aggregator certifications.

Limit retention of data received. Third parties may not retain data beyond what is reasonably necessary for the service — and must have written policies for data retention and purge.

The Developer Interface Requirement

Data providers must maintain a “developer interface” — essentially a customer-permissioned API — through which third parties can securely request and receive consumer data. The rule does not specify a particular API standard (like the UK’s Open Banking Implementation Entity specifications), but does require the interface to be secure, standardized, and available.

Building and maintaining a developer interface is the most significant infrastructure obligation in the rule — and the primary reason large institutions would need several years of implementation time.

Who Is and Isn’t Covered

Covered data providers under the final rule include:

  • Depository institutions with $850 million or more in total assets offering transaction accounts or credit cards
  • Nondepository covered persons with $10 billion or more in annual receipts from covered financial products

Exempt:

  • Depository institutions with less than $850 million in assets (explicitly exempt)
  • Most community banks and credit unions
  • Mortgage loans, auto loans, payday loans, investment accounts, retirement accounts — these were excluded from the first rulemaking

Practical implication: The rule in its current form primarily targets the largest banks and fintechs. But that’s also who sets the consumer expectation. When the biggest players are required to offer permissioned API access, consumer-facing fintechs and smaller institutions feel competitive pressure to match — regardless of regulatory obligation.

Original Compliance Timeline

The final rule established a phased compliance schedule based on asset size:

TierInstitution SizeOriginal Deadline
1≥$250B assets or ≥$10B nondepository receiptsApril 1, 2026
2$10B–$250B assetsApril 1, 2027
3$3B–$10B assetsApril 1, 2028
4$1.5B–$3B assetsApril 1, 2029
5$850M–$1.5B assetsApril 1, 2030

Those timelines are currently stayed.

Where the Litigation Stands

The rule was challenged on the day it was finalized. A national bank and two bank trade associations filed suit in the U.S. District Court for the Eastern District of Kentucky (Forcht Bank, N.A., et al. v. Consumer Financial Protection Bureau, No. 5:24-cv-304-DCR).

On October 29, 2025, the court issued a preliminary injunction preventing the CFPB from enforcing the rule, finding the plaintiffs had demonstrated a likelihood of success on their statutory authority claims.

In August 2025, before the injunction, the CFPB under new leadership had already begun signaling reconsideration — publishing an Advance Notice of Proposed Rulemaking and indicating that the rule as written may need to be revised for alignment with the CFPB’s statutory authority under Dodd-Frank Section 1033.

As of June 2026: the rule’s compliance dates are suspended. The CFPB is expected to issue a revised proposed rule, but the timeline and scope of revisions are not yet clear. The litigation also continues on the merits.

What does this mean practically? The rule will not be enforced as written. A revised version is likely — but may be narrower in scope, different in implementation requirements, or have materially different compliance timelines.

What Institutions Should Do Now

The uncertainty is real. The direction is not.

The fundamental regulatory objective — consumer access to their own financial data via permissioned APIs — has bipartisan support and strong industry acceptance from large fintech players who benefit from data access. Whatever a revised rule looks like, the infrastructure obligation (developer interfaces, authorization frameworks, data governance) will remain.

Here’s what to build during the current window:

1. Map Your Data Architecture

Understand what data you currently maintain that would be covered: transaction histories by account type, account terms, payment information. Many institutions discover during this mapping that data they “have” is scattered across legacy systems in formats that aren’t easily standardized or API-accessible.

2. Assess Developer Interface Readiness

Do you have any consumer-permissioned API capability today? If not, what would it take to build one? This is typically the longest lead-time item — 12–24 months for institutions starting from scratch. The gap between “we have no API” and “we have a standardized, secure, consumer-permissioned developer interface” is a multi-year infrastructure project.

3. Audit Existing Third-Party Data Sharing Arrangements

Section 1033 will introduce new formalized third-party access. Audit your existing data sharing arrangements — through screen-scraping aggregators, data broker relationships, existing API partnerships — against the use limitation, security, and retention requirements the rule imposes. Relationships that don’t meet the standard will need to be renegotiated or terminated.

4. Review Data Governance and Retention Policies

The GLBA Regulation P privacy framework governs how you share with third parties today. Section 1033 adds an affirmative obligation to share. Your data governance policies need to address both the “when you must share” obligation (Section 1033) and the “how you limit sharing in other contexts” obligations (Regulation P, state privacy laws). Building a unified framework now — rather than three separate compliance programs — is significantly more efficient.

5. Monitor the Rulemaking

Subscribe to CFPB notices and Federal Register alerts for Section 1033 rulemaking activity. The comment period on any revised proposed rule will be the primary opportunity to shape what the final compliance requirements actually look like. Track the litigation: if the court rules on the merits in the plaintiffs’ favor, it may constrain what a revised rule can require.

The Consumer Data Rights Landscape Is Broader Than 1033

Section 1033 is not the only consumer financial data rights obligation your institution may face. The California CCPA/CPRA gives California residents rights to access and delete personal data, including financial transaction data. State-level financial privacy laws (like the new state privacy law landscape) are expanding beyond what GLBA covers.

DSAR (Data Subject Access Request) workflows under CCPA, GDPR, and state privacy laws are already operational obligations for institutions with the relevant consumer populations. The data inventory, format standardization, and response infrastructure you build for those obligations overlaps significantly with what Section 1033 will require.

The institutions that navigate this well are treating these as a unified consumer data rights program — not three separate compliance projects happening in parallel.

So What?

The temptation when a rule is enjoined and under reconsideration is to defer everything until the dust settles. The problem is that the underlying infrastructure work — API development, data architecture, governance frameworks — takes 12–24 months even after the regulatory picture is clear. If you wait for the final revised rule to start, you will almost certainly face a compressed implementation timeline.

The current period — where compliance dates are suspended but the regulatory direction is clear — is the best time to:

  • Understand what your data architecture looks like against the rule’s requirements
  • Identify the biggest gaps (usually the API infrastructure)
  • Update data governance and third-party data sharing agreements
  • Build the institutional knowledge your compliance team needs to respond quickly when the revised rule drops

The Data Privacy Compliance Kit includes DSAR response workflow templates, data retention policy frameworks, and data governance documentation structured for GDPR, CCPA, GLBA, and applicable state privacy laws — the same data rights infrastructure that Section 1033 compliance will build on.

The rulemaking is uncertain. The obligation — in some form — is not.


Sources: CFPB Personal Financial Data Rights Final Rule (October 2024); 12 CFR Part 1033; Federal Register Vol. 89, No. 222 (November 18, 2024); Forcht Bank, N.A., et al. v. CFPB, No. 5:24-cv-304-DCR (E.D. Ky.); CFPB Section 1033 ANPR on Reconsideration (August 2025).

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the CFPB's Section 1033 rule and what does it require?
Section 1033 of the Dodd-Frank Act gives consumers the right to access their financial data in usable electronic form. The CFPB finalized its implementing rule (12 CFR Part 1033) on October 22, 2024. The rule requires covered data providers — primarily depository institutions with $850 million or more in assets — to make available to consumers upon request their transaction history (24 months), account terms and conditions, payment initiation information, and upcoming payments. Consumers can authorize regulated third parties to access this data on their behalf. Data providers cannot charge fees for access.
Is the Section 1033 rule currently in effect?
No — enforcement is currently stayed. On October 29, 2025, the U.S. District Court for the Eastern District of Kentucky issued a preliminary injunction preventing the CFPB from enforcing the rule (Forcht Bank, N.A., et al. v. CFPB). The CFPB subsequently initiated reconsideration of the rule through an Advance Notice of Proposed Rulemaking in August 2025. As of June 2026, the rule's compliance dates remain suspended pending litigation resolution and expected rulemaking revisions. Institutions should monitor CFPB rulemaking announcements and track the court proceedings.
Which financial institutions are covered by Section 1033?
The final rule covers depository institutions (banks, credit unions, savings associations) with $850 million or more in total assets that offer covered financial products: transaction accounts, credit cards, and similar accounts that allow consumers to make payments or hold funds. Institutions below $850 million in assets are exempt under the final rule. Certain nondepository entities with $10 billion or more in annual receipts from covered financial products are also covered. Mortgage loans, auto loans, investment accounts, and retirement accounts were not included in this first rulemaking.
What are an institution's obligations regarding third-party data access?
Third parties that receive consumer financial data under Section 1033 must limit their data collection, use, and retention to what is reasonably necessary to provide the service the consumer requested. They are prohibited from using the data for targeted advertising, cross-selling, or selling consumer data to others without separate authorization. Third parties must maintain information security programs meeting GLBA Section 501 standards (or FTC Safeguards Rule standards if not subject to GLBA), and retain compliance records for at least three years after the consumer's most recent authorization. Consumer authorization expires after one year and must be renewed.
What should financial institutions do now given the litigation uncertainty?
The litigation uncertainty does not mean institutions should stop preparing. The fundamental regulatory direction — toward consumer-permissioned data sharing — is not in dispute. A revised rule will almost certainly emerge. Institutions should treat the current period as implementation runway: assess current API capabilities, map what data would need to be made available, audit third-party access agreements, and review data governance policies for the additional data flows the rule will require. The gap between where most institutions are today and what a Section 1033 program requires is substantial — and the compliance timeline will be compressed if you wait for the final revised rule to begin.
How does Section 1033 interact with existing GLBA and state privacy law obligations?
Section 1033 adds obligations on top of GLBA's existing data governance framework. GLBA Regulation P governs privacy notices and sharing with affiliated and nonaffiliated third parties. Section 1033 creates a new affirmative obligation to share data upon consumer request through permissioned APIs — a distinct mechanism from Regulation P's consent model. State privacy laws (California CCPA/CPRA, state-level consumer financial data rights) may layer additional obligations in specific jurisdictions. Institutions need a unified data governance framework that addresses all three simultaneously, not siloed compliance programs for each.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.