Skip to content
RiskTemplates · The Daily Brief Tuesday, August 18, 2026
Wire FINRA's 24 Enforcement Review Recommendations: Read Them as Proposals, Not Rules AUG 11

Feature Regulatory Compliance

CFPB Section 1033: Effective, Enjoined, and Under Reconsideration

The 2024 Section 1033 rule became effective but is enjoined. A revised proposal was still in OIRA review, not published, on August 17, 2026.

By Rebecca Leung · June 6, 2026 ·
Table of Contents

TL;DR

  • The CFPB’s 2024 personal financial data rights rule became effective and appears in 12 CFR part 1033.
  • A federal court’s preliminary injunction prevents the CFPB from enforcing it. Do not describe that as “the rule never took effect.”
  • The CFPB began reconsideration with a 2025 ANPRM.
  • As of August 17, 2026, an action was pending at OIRA, but revised proposed text had not been published. No fee reversal or other detailed change could be verified from the OIRA record alone.

August 17, 2026 Status Update

Section 1033 has four status layers:

ArtifactStatusWhat it means
2024 final ruleFinal and effectiveEstablishes 12 CFR part 1033
Preliminary injunctionEnteredPrevents CFPB enforcement of the rule while the order applies
2025 ANPRMCompleted information-gathering stepBegan reconsideration but did not propose replacement text
2026 OIRA recordPending review as of cutoffShows a regulatory action under review, not a published NPRM

The official OIRA record did not supply public proposed text. It cannot support claims that the CFPB had already adopted, proposed, or settled a particular fee-for-access rule.

What the 2024 Rule Does

The CFPB’s 2024 final rule implements Dodd-Frank Act Section 1033 through a framework for consumer and consumer-authorized access to covered financial data.

At a high level, the rule addresses:

  • covered data providers and products;
  • data that must be made available;
  • consumer and authorized-third-party access;
  • developer interfaces;
  • authorization and revocation;
  • limits on collection, use, and retention;
  • security and recordkeeping; and
  • phased compliance dates and exemptions.

The current codified text is available at 12 CFR part 1033. Use that text for the rule’s definitions and requirements, not a forecast about reconsideration.

Effective Does Not Mean Enforceable Today

The 2024 rule reached its effective date. A later preliminary injunction barred CFPB enforcement. Those facts coexist.

Use precise language:

  • Correct: “The rule is effective but currently enjoined from CFPB enforcement.”
  • Incorrect: “The rule never took effect.”
  • Incomplete: “The rule was stayed,” without identifying what the order restrains and whether it remains in force.

For governance reporting, track publication, effective date, original compliance dates, injunction date and scope, litigation posture, and reconsideration separately. Recheck the live docket before a legal or implementation decision.

The 2025 ANPRM Was Not a Replacement Rule

The CFPB’s reconsideration ANPRM asked for information on issues the Bureau might revisit.

An advance notice can identify policy questions and solicit evidence. It does not:

  • amend the existing regulation;
  • publish proposed replacement text;
  • complete notice-and-comment rulemaking; or
  • establish a new compliance date.

Treat ANPRM themes as scenarios, not requirements.

OIRA Review Is Not an NPRM

The CFPB’s rule-under-development page and OIRA record are appropriate monitoring sources. As of the cutoff, however, the revised proposal itself was not public in the Federal Register.

That means the following claims were not safe:

  • a revised NPRM had already been published;
  • OIRA review would finish within a guaranteed period;
  • data-access fees would definitely be allowed;
  • particular covered data or entities would be added or removed; or
  • a final rule and new compliance dates could be forecast with confidence.

When proposed text is published, compare it with both 12 CFR part 1033 and the court record. Until then, maintain alternative scenarios.

What Institutions Can Do Without Betting on Unpublished Text

1. Preserve the status ledger

Assign owners for litigation monitoring, CFPB rulemaking, OIRA status, Federal Register publication, and implementation decisions. Store the source and review date for each status.

2. Map data and systems

Identify covered-product data, source systems, quality constraints, interfaces, authentication, consent, revocation, retention, and deletion. This work supports privacy, security, customer service, and future rule analysis even if scope changes.

3. Inventory third-party access

Document aggregators, screen-scraping, direct APIs, contracts, purposes, data fields, credentials, onward transfers, incidents, and termination. Do not assume the enjoined rule is the only law or contract governing those relationships.

4. Separate reusable work from rule-specific work

Reusable work includes data lineage, API security, consent evidence, vendor inventory, and access logging. Rule-specific work includes exact covered-data fields, performance standards, authorization wording, fee treatment, and compliance dates. Avoid irreversible design choices in the second category until public text exists.

5. Set evidence-based rebaseline triggers

Triggers include a new court order, Federal Register proposal, final rule, changed injunction, or official compliance-date action. OIRA review alone is a monitoring event, not an implementation specification.

So What?

The 2024 rule is effective, enforcement is enjoined, reconsideration is underway, and revised text was not yet public on August 17, 2026. All four facts belong in the compliance record.

Continue low-regret data-governance and interface work, but do not redesign contracts around an unverified fee reversal or treat an OIRA title as proposed law.

The Data Privacy Compliance Kit can organize inventory, retention, third-party, and consumer-rights evidence. Section 1033 implementation still requires current court and rulemaking review.


Primary sources: 2024 final rule | 12 CFR part 1033 | 2025 reconsideration ANPRM | CFPB reconsideration page | OIRA pending-review record

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Is the CFPB's 2024 Section 1033 rule effective?
Yes. The final rule became effective, but a federal court later entered a preliminary injunction that prevents CFPB enforcement. 'Effective' and 'currently enforceable' are different status questions; the injunction did not erase the rule from the Code of Federal Regulations.
What did the 2025 reconsideration action do?
The CFPB published an Advance Notice of Proposed Rulemaking in August 2025 to gather information for reconsideration. An ANPRM seeks input; it is not a proposed replacement rule and does not itself amend 12 CFR part 1033.
Had the CFPB published a revised NPRM by August 17, 2026?
No. The official OIRA record showed a Personal Financial Data Rights reconsideration action under review, but no revised proposed text had been published in the Federal Register. OIRA review is not publication and does not establish a fee policy or other substantive revision.
Can an institution rely on the original compliance dates?
The injunction prevents CFPB enforcement of the 2024 rule while it remains in force. Institutions should not present the original dates as active enforcement deadlines, but should preserve the rule, litigation, injunction, reconsideration, and OIRA review as separate status fields.
What work is appropriate during the uncertainty?
Map relevant data, interfaces, authorizations, third parties, security, retention, and contracts; preserve current-law compliance; and scenario-plan rather than hard-code an unpublished replacement. Rebaseline only after reviewing an official proposed or final rule and the live court orders.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.