Feature Regulatory Compliance
CFPB Section 1033: Effective, Enjoined, and Under Reconsideration
The 2024 Section 1033 rule became effective but is enjoined. A revised proposal was still in OIRA review, not published, on August 17, 2026.
Table of Contents
TL;DR
- The CFPB’s 2024 personal financial data rights rule became effective and appears in 12 CFR part 1033.
- A federal court’s preliminary injunction prevents the CFPB from enforcing it. Do not describe that as “the rule never took effect.”
- The CFPB began reconsideration with a 2025 ANPRM.
- As of August 17, 2026, an action was pending at OIRA, but revised proposed text had not been published. No fee reversal or other detailed change could be verified from the OIRA record alone.
August 17, 2026 Status Update
Section 1033 has four status layers:
| Artifact | Status | What it means |
|---|---|---|
| 2024 final rule | Final and effective | Establishes 12 CFR part 1033 |
| Preliminary injunction | Entered | Prevents CFPB enforcement of the rule while the order applies |
| 2025 ANPRM | Completed information-gathering step | Began reconsideration but did not propose replacement text |
| 2026 OIRA record | Pending review as of cutoff | Shows a regulatory action under review, not a published NPRM |
The official OIRA record did not supply public proposed text. It cannot support claims that the CFPB had already adopted, proposed, or settled a particular fee-for-access rule.
What the 2024 Rule Does
The CFPB’s 2024 final rule implements Dodd-Frank Act Section 1033 through a framework for consumer and consumer-authorized access to covered financial data.
At a high level, the rule addresses:
- covered data providers and products;
- data that must be made available;
- consumer and authorized-third-party access;
- developer interfaces;
- authorization and revocation;
- limits on collection, use, and retention;
- security and recordkeeping; and
- phased compliance dates and exemptions.
The current codified text is available at 12 CFR part 1033. Use that text for the rule’s definitions and requirements, not a forecast about reconsideration.
Effective Does Not Mean Enforceable Today
The 2024 rule reached its effective date. A later preliminary injunction barred CFPB enforcement. Those facts coexist.
Use precise language:
- Correct: “The rule is effective but currently enjoined from CFPB enforcement.”
- Incorrect: “The rule never took effect.”
- Incomplete: “The rule was stayed,” without identifying what the order restrains and whether it remains in force.
For governance reporting, track publication, effective date, original compliance dates, injunction date and scope, litigation posture, and reconsideration separately. Recheck the live docket before a legal or implementation decision.
The 2025 ANPRM Was Not a Replacement Rule
The CFPB’s reconsideration ANPRM asked for information on issues the Bureau might revisit.
An advance notice can identify policy questions and solicit evidence. It does not:
- amend the existing regulation;
- publish proposed replacement text;
- complete notice-and-comment rulemaking; or
- establish a new compliance date.
Treat ANPRM themes as scenarios, not requirements.
OIRA Review Is Not an NPRM
The CFPB’s rule-under-development page and OIRA record are appropriate monitoring sources. As of the cutoff, however, the revised proposal itself was not public in the Federal Register.
That means the following claims were not safe:
- a revised NPRM had already been published;
- OIRA review would finish within a guaranteed period;
- data-access fees would definitely be allowed;
- particular covered data or entities would be added or removed; or
- a final rule and new compliance dates could be forecast with confidence.
When proposed text is published, compare it with both 12 CFR part 1033 and the court record. Until then, maintain alternative scenarios.
What Institutions Can Do Without Betting on Unpublished Text
1. Preserve the status ledger
Assign owners for litigation monitoring, CFPB rulemaking, OIRA status, Federal Register publication, and implementation decisions. Store the source and review date for each status.
2. Map data and systems
Identify covered-product data, source systems, quality constraints, interfaces, authentication, consent, revocation, retention, and deletion. This work supports privacy, security, customer service, and future rule analysis even if scope changes.
3. Inventory third-party access
Document aggregators, screen-scraping, direct APIs, contracts, purposes, data fields, credentials, onward transfers, incidents, and termination. Do not assume the enjoined rule is the only law or contract governing those relationships.
4. Separate reusable work from rule-specific work
Reusable work includes data lineage, API security, consent evidence, vendor inventory, and access logging. Rule-specific work includes exact covered-data fields, performance standards, authorization wording, fee treatment, and compliance dates. Avoid irreversible design choices in the second category until public text exists.
5. Set evidence-based rebaseline triggers
Triggers include a new court order, Federal Register proposal, final rule, changed injunction, or official compliance-date action. OIRA review alone is a monitoring event, not an implementation specification.
So What?
The 2024 rule is effective, enforcement is enjoined, reconsideration is underway, and revised text was not yet public on August 17, 2026. All four facts belong in the compliance record.
Continue low-regret data-governance and interface work, but do not redesign contracts around an unverified fee reversal or treat an OIRA title as proposed law.
The Data Privacy Compliance Kit can organize inventory, retention, third-party, and consumer-rights evidence. Section 1033 implementation still requires current court and rulemaking review.
Primary sources: 2024 final rule | 12 CFR part 1033 | 2025 reconsideration ANPRM | CFPB reconsideration page | OIRA pending-review record
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Is the CFPB's 2024 Section 1033 rule effective?
What did the 2025 reconsideration action do?
Had the CFPB published a revised NPRM by August 17, 2026?
Can an institution rely on the original compliance dates?
What work is appropriate during the uncertainty?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Regulatory Compliance
Transaction Monitoring Data Completeness Testing: Counts, Values, Rejects, and Alert Coverage
Build a transaction monitoring data completeness testing workpaper from source population through ingestion, rules, alerts, rejects, and repair.
Aug 18, 2026
Regulatory Compliance
FINRA's 24 Enforcement Review Recommendations: Read Them as Proposals, Not Rules
FINRA published an external review with 24 recommendations. Here is what the report proposes, what FINRA has said, and what firms should do now.
Aug 12, 2026
Regulatory Compliance
FinCEN Renewed the Minnesota GTO. Banks Have Four Days to Restart $3,000 International Transfer Reporting.
The FinCEN Minnesota GTO starts August 11. Banks and money transmitters need complete data and monthly reporting for covered $3,000 transfers.
Aug 7, 2026