Feature Regulatory Compliance
CFPB Section 1033 Open Banking Rule: What Financial Institutions Need to Know While the Litigation Plays Out
CFPB finalized its Section 1033 open banking rule in October 2024, requiring covered institutions to share consumer financial data via permissioned APIs. Then a federal court enjoined enforcement in October 2025. Here's what the rule requires, where the litigation stands, and why your compliance team should be building toward it anyway.
Table of Contents
TL;DR:
- The CFPB finalized its Section 1033 “personal financial data rights” rule on October 22, 2024, requiring covered institutions to share consumer financial data via permissioned APIs. A federal court enjoined enforcement in October 2025; the CFPB is now reconsidering the rule.
- The rule covers depository institutions with $850 million or more in assets. Required data: 24 months of transaction history, account terms and conditions, payment initiation information, and upcoming payments. No fees permitted.
- Third parties accessing data have strict use limitations: no targeted advertising, no cross-selling, no data sales. They must maintain GLBA-equivalent information security programs and retain authorization records for three years.
- The litigation uncertainty is real — but the direction isn’t. Build toward a Section 1033-compliant data sharing architecture during the current window rather than waiting for a final rule to begin.
The Right to Your Own Financial Data
The premise of Section 1033 is deceptively simple: you generated the transaction data in your bank account, you should be able to access it. In a format you can actually use. Without calling a branch or waiting for a PDF export.
That premise has been in the Dodd-Frank Act since 2010. It took the CFPB 14 years to finalize implementing rules. The October 2024 rule was immediately challenged in federal court. By October 2025, a Kentucky federal judge had issued an injunction preventing enforcement. By June 2026, the CFPB was in active rulemaking reconsideration.
And yet the rule matters — not only for what it requires when it does take effect, but for what it reveals about where financial data regulation is heading and how much infrastructure work lies between here and compliance.
This is the version for compliance teams who need to understand the rule’s actual requirements, the current litigation status, and what to actually do in the meantime.
What the Rule Requires
The CFPB’s final rule under 12 CFR Part 1033 establishes a framework for consumer-permissioned financial data access with four core components.
Data Providers Must Make Data Available
Covered data providers — primarily depository institutions with $850 million or more in assets — must make available to consumers upon request the following categories of data:
- Transaction information: Account balance and at least 24 months of transaction history
- Terms and conditions: Fee schedules, interest rates, annual percentage rates applicable to the account
- Payment initiation information: Information sufficient to facilitate payment transactions from the account
- Account information: Basic account identification data
- Upcoming bills and payments: Where the data provider has this information
The data must be provided in a standardized electronic format — not PDFs or manual exports. Institutions cannot charge consumers fees for data access.
Notably, the rule explicitly does not require data providers to maintain data they don’t already maintain. The obligation runs to data you have, in the ordinary course of your business. There is no duty to create new data systems to satisfy a Section 1033 request.
Consumers Can Authorize Third Parties
This is the open banking core: consumers can instruct their data provider to share their data with a regulated third party of their choosing — a financial planning app, a lending platform, a money management service.
The authorization process requires:
- The third party provides the consumer an authorization disclosure before accessing data
- The consumer grants express informed consent (written or electronic signature)
- Authorization is limited to a maximum of one year — after which new authorization is required
Third parties must also agree, through a certification process, to comply with the rule’s data use limitations and security obligations before accessing any data.
Third-Party Obligations Are Strict
The rule’s obligations on data-receiving third parties are more prescriptive than many institutions anticipate. A third party accessing consumer data under Section 1033 must:
Limit data collection and use to what is “reasonably necessary” to provide the specific product or service the consumer requested. Three use cases are explicitly prohibited regardless of consumer authorization:
- Targeted advertising
- Cross-selling other products or services
- Selling consumer data to any other party
Maintain information security standards. Third parties subject to GLBA must comply with Section 501 information security requirements. Those not subject to GLBA must comply with the equivalent FTC Safeguards Rule standards. This brings fintech data aggregators — even those that wouldn’t otherwise be GLBA-covered — into a GLBA-equivalent security posture.
Retain compliance records for at least three years after the consumer’s most recent authorization, including signed authorization disclosures and any data aggregator certifications.
Limit retention of data received. Third parties may not retain data beyond what is reasonably necessary for the service — and must have written policies for data retention and purge.
The Developer Interface Requirement
Data providers must maintain a “developer interface” — essentially a customer-permissioned API — through which third parties can securely request and receive consumer data. The rule does not specify a particular API standard (like the UK’s Open Banking Implementation Entity specifications), but does require the interface to be secure, standardized, and available.
Building and maintaining a developer interface is the most significant infrastructure obligation in the rule — and the primary reason large institutions would need several years of implementation time.
Who Is and Isn’t Covered
Covered data providers under the final rule include:
- Depository institutions with $850 million or more in total assets offering transaction accounts or credit cards
- Nondepository covered persons with $10 billion or more in annual receipts from covered financial products
Exempt:
- Depository institutions with less than $850 million in assets (explicitly exempt)
- Most community banks and credit unions
- Mortgage loans, auto loans, payday loans, investment accounts, retirement accounts — these were excluded from the first rulemaking
Practical implication: The rule in its current form primarily targets the largest banks and fintechs. But that’s also who sets the consumer expectation. When the biggest players are required to offer permissioned API access, consumer-facing fintechs and smaller institutions feel competitive pressure to match — regardless of regulatory obligation.
Original Compliance Timeline
The final rule established a phased compliance schedule based on asset size:
| Tier | Institution Size | Original Deadline |
|---|---|---|
| 1 | ≥$250B assets or ≥$10B nondepository receipts | April 1, 2026 |
| 2 | $10B–$250B assets | April 1, 2027 |
| 3 | $3B–$10B assets | April 1, 2028 |
| 4 | $1.5B–$3B assets | April 1, 2029 |
| 5 | $850M–$1.5B assets | April 1, 2030 |
Those timelines are currently stayed.
Where the Litigation Stands
The rule was challenged on the day it was finalized. A national bank and two bank trade associations filed suit in the U.S. District Court for the Eastern District of Kentucky (Forcht Bank, N.A., et al. v. Consumer Financial Protection Bureau, No. 5:24-cv-304-DCR).
On October 29, 2025, the court issued a preliminary injunction preventing the CFPB from enforcing the rule, finding the plaintiffs had demonstrated a likelihood of success on their statutory authority claims.
In August 2025, before the injunction, the CFPB under new leadership had already begun signaling reconsideration — publishing an Advance Notice of Proposed Rulemaking and indicating that the rule as written may need to be revised for alignment with the CFPB’s statutory authority under Dodd-Frank Section 1033.
As of June 2026: the rule’s compliance dates are suspended. The CFPB is expected to issue a revised proposed rule, but the timeline and scope of revisions are not yet clear. The litigation also continues on the merits.
What does this mean practically? The rule will not be enforced as written. A revised version is likely — but may be narrower in scope, different in implementation requirements, or have materially different compliance timelines.
What Institutions Should Do Now
The uncertainty is real. The direction is not.
The fundamental regulatory objective — consumer access to their own financial data via permissioned APIs — has bipartisan support and strong industry acceptance from large fintech players who benefit from data access. Whatever a revised rule looks like, the infrastructure obligation (developer interfaces, authorization frameworks, data governance) will remain.
Here’s what to build during the current window:
1. Map Your Data Architecture
Understand what data you currently maintain that would be covered: transaction histories by account type, account terms, payment information. Many institutions discover during this mapping that data they “have” is scattered across legacy systems in formats that aren’t easily standardized or API-accessible.
2. Assess Developer Interface Readiness
Do you have any consumer-permissioned API capability today? If not, what would it take to build one? This is typically the longest lead-time item — 12–24 months for institutions starting from scratch. The gap between “we have no API” and “we have a standardized, secure, consumer-permissioned developer interface” is a multi-year infrastructure project.
3. Audit Existing Third-Party Data Sharing Arrangements
Section 1033 will introduce new formalized third-party access. Audit your existing data sharing arrangements — through screen-scraping aggregators, data broker relationships, existing API partnerships — against the use limitation, security, and retention requirements the rule imposes. Relationships that don’t meet the standard will need to be renegotiated or terminated.
4. Review Data Governance and Retention Policies
The GLBA Regulation P privacy framework governs how you share with third parties today. Section 1033 adds an affirmative obligation to share. Your data governance policies need to address both the “when you must share” obligation (Section 1033) and the “how you limit sharing in other contexts” obligations (Regulation P, state privacy laws). Building a unified framework now — rather than three separate compliance programs — is significantly more efficient.
5. Monitor the Rulemaking
Subscribe to CFPB notices and Federal Register alerts for Section 1033 rulemaking activity. The comment period on any revised proposed rule will be the primary opportunity to shape what the final compliance requirements actually look like. Track the litigation: if the court rules on the merits in the plaintiffs’ favor, it may constrain what a revised rule can require.
The Consumer Data Rights Landscape Is Broader Than 1033
Section 1033 is not the only consumer financial data rights obligation your institution may face. The California CCPA/CPRA gives California residents rights to access and delete personal data, including financial transaction data. State-level financial privacy laws (like the new state privacy law landscape) are expanding beyond what GLBA covers.
DSAR (Data Subject Access Request) workflows under CCPA, GDPR, and state privacy laws are already operational obligations for institutions with the relevant consumer populations. The data inventory, format standardization, and response infrastructure you build for those obligations overlaps significantly with what Section 1033 will require.
The institutions that navigate this well are treating these as a unified consumer data rights program — not three separate compliance projects happening in parallel.
So What?
The temptation when a rule is enjoined and under reconsideration is to defer everything until the dust settles. The problem is that the underlying infrastructure work — API development, data architecture, governance frameworks — takes 12–24 months even after the regulatory picture is clear. If you wait for the final revised rule to start, you will almost certainly face a compressed implementation timeline.
The current period — where compliance dates are suspended but the regulatory direction is clear — is the best time to:
- Understand what your data architecture looks like against the rule’s requirements
- Identify the biggest gaps (usually the API infrastructure)
- Update data governance and third-party data sharing agreements
- Build the institutional knowledge your compliance team needs to respond quickly when the revised rule drops
The Data Privacy Compliance Kit includes DSAR response workflow templates, data retention policy frameworks, and data governance documentation structured for GDPR, CCPA, GLBA, and applicable state privacy laws — the same data rights infrastructure that Section 1033 compliance will build on.
The rulemaking is uncertain. The obligation — in some form — is not.
Sources: CFPB Personal Financial Data Rights Final Rule (October 2024); 12 CFR Part 1033; Federal Register Vol. 89, No. 222 (November 18, 2024); Forcht Bank, N.A., et al. v. CFPB, No. 5:24-cv-304-DCR (E.D. Ky.); CFPB Section 1033 ANPR on Reconsideration (August 2025).
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the CFPB's Section 1033 rule and what does it require?
Is the Section 1033 rule currently in effect?
Which financial institutions are covered by Section 1033?
What are an institution's obligations regarding third-party data access?
What should financial institutions do now given the litigation uncertainty?
How does Section 1033 interact with existing GLBA and state privacy law obligations?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Regulatory Compliance
Effective Challenge in Model Risk Management: Document the Disagreement
Model risk management effective challenge needs a decision trail. Build a challenge memo that preserves evidence, responses, conditions, and escalation.
Jul 24, 2026
Regulatory Compliance
FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now
FinCEN's student aid fraud alert gives banks nine red flags, a SAR keyword, and a clear transaction-monitoring task for ACH refunds.
Jul 23, 2026
Regulatory Compliance
Magnolia Diagnostics False Claims Act Settlement: Why Investors Paid Part of the $24 Million
The Magnolia Diagnostics False Claims Act settlement reached investors, requisition controls, and $24M in payments. Here is what to fix.
Jul 23, 2026