Skip to content
RiskTemplates · The Daily Brief Thursday, October 1, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature Data Privacy

CFPB's Section 1033 Rewrite Is at OIRA. What the Two Key Substantive Changes Mean for Banks, Fintechs, and Data Aggregators.

The CFPB sent its Section 1033 reconsideration NPRM to OIRA on August 6, 2026. Two proposed changes — allowing data access fees and tightening the 'authorized representative' standard — would reshape how open banking works in the U.S. Here's what each change means for your compliance program.

By Rebecca Leung · September 28, 2026 ·
Table of Contents

TL;DR

  • CFPB submitted its Section 1033 reconsideration NPRM to OIRA on August 6, 2026 — the first concrete step toward a rewritten open banking rule
  • The original 2024 rule is codified but enjoined; the rewrite aims to resolve the substantive disputes that drove the litigation
  • Two changes carry the most operational weight: permitting data access fees (banks want them; fintechs don’t) and tightening the authorized representative standard (potential fiduciary duties for data aggregators)
  • OIRA review typically runs up to 90 days — a proposed rule and public comment period could follow by late 2026 or early 2027

The CFPB’s open banking rule has been in regulatory limbo for nearly two years. The final rule published in October 2024 — establishing consumer rights to share financial data under Section 1033 of the Dodd-Frank Act — became effective and then immediately became the subject of litigation that put the whole thing on hold. On August 6, 2026, the CFPB took the next step: it submitted a reconsideration NPRM to the Office of Information and Regulatory Affairs (OIRA), beginning the formal interagency review process for a rewritten rule.

What comes out of that process will determine how open banking works in the United States for the next decade. And the two substantive issues that generated the most disagreement in the original rulemaking — whether banks can charge fees for data access, and what obligations attach to third parties who handle consumer financial data — are the ones that matter most to compliance programs, data governance functions, and the banks and fintechs building data access infrastructure today.

How We Got Here: The Original Rule, the Lawsuit, and the Reconsideration

The CFPB’s October 2024 final rule implementing Section 1033 gave consumers a codified right to direct financial data about themselves to third parties of their choosing. It applied to depository institutions with more than $850 million in assets plus certain covered nonbanks, required API-based access to certain categories of account data, and prohibited covered entities from charging fees for that access.

Three industry groups — the Bank Policy Institute, the Kentucky Bankers Association, and America’s Credit Unions — challenged the rule in the Eastern District of Kentucky in November 2024. The court issued a preliminary injunction that paused CFPB enforcement of the rule while the merits of the challenge were litigated. That injunction has remained in place.

The CFPB’s August 2025 Advance Notice of Proposed Rulemaking opened a formal record for reconsideration. The CFPB solicited comment on whether to amend or rescind specific provisions, with the fee prohibition and the authorized representative framework drawing the most substantive responses. The NPRM submitted to OIRA on August 6, 2026 is the agency’s first formal proposed response to that record.

What the proposed rule actually says won’t be public until OIRA’s review concludes and the CFPB publishes the NPRM in the Federal Register. But the trajectory of the rulemaking, the ANPRM comments, and reporting on the OIRA submission give a reasonable picture of where the two most contested issues are heading.

Change 1: Data Access Fees

The original rule’s fee prohibition was a major sticking point. Under the 2024 final rule, covered data providers were prohibited from charging third parties — data aggregators, fintechs, account management apps — fees for providing access to consumer financial data. The CFPB’s reasoning was that fee structures could create barriers to consumer data access and allow larger institutions to monetize what is, under Dodd-Frank, essentially the consumer’s own data.

Banks and credit unions pushed back hard. Their argument: providing secure, compliant API infrastructure is not free. Server infrastructure, authentication systems, compliance auditing, fraud monitoring on API access points — all of these have real costs. The original rule required covered entities to absorb those costs while competitors in the data aggregation space built businesses on top of that access. That, the industry argued, was not economically sustainable.

The reconsideration is expected to replace the blanket prohibition with something more nuanced. The options range from a cost-recovery standard (fees permitted up to verifiable infrastructure costs) to a market-rate approach (fees negotiated between parties, with guardrails to prevent anticompetitive pricing). The ANPRM asked specifically about whether a de minimis access threshold — under which fees would not be permitted — was appropriate, and at what level.

For banks and credit unions: if fees are permitted, data APIs become a potential revenue line rather than a pure cost center. The compliance question is what documentation supports a “reasonable cost recovery” fee — infrastructure costs will need to be attributable, auditable, and defensible if regulators or litigants later challenge fee levels.

For fintechs and data aggregators: permitted fees change the economics of open banking fundamentally. Apps that currently access bank data at no marginal cost will face a new cost line. Aggregators like Plaid, MX, and Finicity will need to either absorb those fees or pass them through to downstream fintechs. Either way, business models built on the assumption of free API access need to be stress-tested.

For compliance programs: the shift from a prohibition to a permissive standard with conditions means your vendor contracts need to address this. If you use a data aggregator, your agreement likely doesn’t contemplate a world where the aggregator pays access fees to the bank. Renegotiation clauses, fee pass-through provisions, and pricing transparency terms deserve attention before the NPRM becomes a final rule.

Change 2: The Authorized Representative Standard

The second major substantive issue is the framework for who qualifies as an “authorized representative” — the third-party entity a consumer designates to receive their financial data.

The original rule used a consent-based standard: a consumer authorizes a third party, the third party becomes an authorized representative, and data can flow. The original rule imposed some behavioral obligations on authorized representatives — they had to limit data use to the purposes the consumer authorized, couldn’t sell data except in limited circumstances, and had to provide required disclosures — but the core question of eligibility was consent-based.

The litigation and the ANPRM comment record surfaced a more fundamental challenge: consent alone doesn’t protect consumers if the party they’ve authorized is itself acting against their interests. A fintech app could obtain proper consumer authorization and then use that data in ways that benefit the app at the consumer’s expense — secondary monetization, targeting, sale to data brokers — all technically within the scope of initial consent but potentially inconsistent with what the consumer understood when they clicked “authorize.”

The reconsideration is expected to address whether authorized representatives should be required to meet a higher standard — one that functions more like a fiduciary relationship. Under a fiduciary-like standard, an authorized representative wouldn’t just need initial consumer consent; it would need to demonstrate, on an ongoing basis, that each use of the consumer’s data actually serves the consumer’s interests.

What a Fiduciary Standard Would Change in Practice

The difference between consent-based and fiduciary-based authorization is not theoretical — it’s operational.

Data monetization. Under a consent-based standard, an aggregator that obtains consumer authorization to connect a bank account can potentially use derived data (spending patterns, account balances, income estimates) for its own product development or third-party analytics, if the disclosure authorized it. Under a fiduciary standard, that secondary use would require a showing that it benefits the consumer — not just that the consumer consented.

Partner data sharing. Aggregators routinely pass consumer financial data to downstream fintechs and application developers. Under a fiduciary standard, each downstream use would need to be evaluated for consumer benefit, not just documented in a privacy policy.

The authorized representative verification obligation. The original rule required covered data providers to verify that a third party claiming authorized representative status had actually been authorized by the consumer. A fiduciary standard adds a second-order obligation: even after verification, the data provider may need to evaluate whether the authorized representative is operating within a framework that protects consumer interests.

For data aggregators, a fiduciary standard is a significant business model challenge. The value proposition of aggregation often includes secondary uses of financial data — credit modeling, financial health scoring, advertising. A requirement to demonstrate consumer benefit for each such use changes what aggregation businesses are permitted to do with the data they handle.

For your data privacy compliance program, a fiduciary standard would require updating your authorized third-party framework to include ongoing monitoring — not just initial authorization capture — and potentially establishing a review process for secondary data uses that didn’t previously require compliance sign-off.

Timeline: What “Under OIRA Review” Actually Means

OIRA review is not publication. It is a formal interagency review process in which the Office of Management and Budget evaluates proposed regulations for consistency with administration policy, economic impact, and statutory authority. OIRA review can conclude in as little as a few weeks or take longer than the 90-day review period for significant rules.

The August 6, 2026 OIRA submission means:

  1. The CFPB has completed its internal draft and submitted a formal proposed rule for interagency review
  2. OIRA will coordinate with other agencies and White House offices, potentially requiring revisions before the NPRM is cleared
  3. The CFPB cannot publish the NPRM for public comment until OIRA clears it — or the OIRA review period expires
  4. Once published, the NPRM will open a public comment period (typically 60 days for significant rules)
  5. The CFPB will then analyze comments and publish a final rule

If OIRA clears the NPRM by November 2026, public comments could close in early 2027, with a final rule possible by mid-to-late 2027 — assuming no further litigation and assuming the current administration completes the rulemaking.

The preliminary injunction remains in place through all of this. The injunction doesn’t dissolve when the CFPB publishes a new proposed rule; it will need to be addressed through the litigation, through a new rule that moots the legal challenges, or through a settlement.

What This Means for Your Data Access Program

Most compliance programs have taken one of two approaches to Section 1033 since the injunction: either treating the rule as effectively suspended (doing nothing) or treating the substantive requirements as forward-looking best practice regardless of enforceability (building toward the original rule’s requirements). Neither is adequate for what comes next.

The rewrite doesn’t start over — it revises. The core framework of Section 1033 — covered entities, covered data categories, consumer authorization, API access, data minimization — is not being reconsidered from scratch. The fee and authorized representative provisions are the primary revision targets. Programs that have done nothing should catch up on the non-contested structural requirements. Programs that have built toward the original rule need to track which specific provisions are changing.

Vendor contracts deserve attention now. The permitted fee question will ripple through every data aggregator agreement. If you contract with Plaid, MX, Finicity, or any other aggregator for financial data access, your agreement was written in an environment where banks couldn’t charge the aggregator for access. When that changes, the aggregator’s cost structure changes, and your contract may not allocate that cost clearly. Better to negotiate this now, before the rule is final and the industry is scrambling, than to have it land as a surprise.

Authorized representative documentation should be current. Whether the final rule uses consent-based or fiduciary-based authorization, you will need documentation showing what consumer authorizations you have, for what purposes, and through what mechanism. The data privacy compliance program documentation your GLBA program already requires for information-sharing disclosures provides the foundation — but authorized representative status under Section 1033 goes further, requiring evidence that each authorization was specific, informed, and revocable.

Monitor for OIRA clearance. The OIRA record is publicly available through reginfo.gov. The NPRM’s entry will move from “Under Review” to cleared when OIRA acts. Publication in the Federal Register starts the comment clock — and that’s the window where your institution can shape the final rule, not after it’s done.

The Broader Data Access Stakes

The Section 1033 rewrite isn’t just about open banking in the narrow sense. It’s about the legal architecture that governs whether U.S. consumers can move their financial data to competitors and new entrants — and whether data-based fintech business models operate on a foundation of consumer consent or on infrastructure they don’t control and may soon have to pay for.

For institutions that have built consumer data access programs on the assumption that the original October 2024 rule represented the final framework, the rewrite means that assumption was wrong. The original Section 1033 rulemaking set the structure; the rewrite will determine whether data access is a free infrastructure obligation or a priced service, and whether authorized representatives are consent holders or fiduciaries.

Those aren’t details. They’re the economic model for the next decade of financial data access.

So What?

The NPRM is at OIRA, not the Federal Register. You can’t comment on it yet. The preliminary injunction still blocks the original rule’s enforcement. On the surface, it looks like nothing has changed since August.

What has changed is the certainty of a rewrite. The CFPB has committed — through formal regulatory process — to revising the rule. The fee prohibition and the authorized representative framework are both in play. And the final rule, when it comes, will be built on the record of the ANPRM, the industry comments, and the litigation that has defined what’s contested.

For a data privacy or data governance function managing financial data access, the OIRA submission is the signal to start working: audit your authorized representative relationships, review your aggregator contracts, and update your Section 1033 documentation to reflect the current legal status rather than the original compliance dates. The comment period, when it opens, is the last opportunity to influence what the final rule requires.

The rule is coming. Build your program like it is.

Primary sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the status of the CFPB's Section 1033 rule as of September 2026?
The original October 2024 Section 1033 final rule is codified at 12 CFR Part 1033 but is currently subject to a federal court preliminary injunction that blocks CFPB enforcement while litigation continues. The CFPB submitted a reconsideration NPRM to OIRA on August 6, 2026. OIRA review typically takes up to 90 days, meaning the proposed rule could be published for public comment in late 2026 or early 2027.
What would happen to data access fees under the Section 1033 rewrite?
The original 2024 rule prohibited covered data providers from charging third parties fees for data access. The CFPB's August 2025 ANPRM solicited comments on whether to permit fees above a de minimis threshold. Banks and credit unions argued the fee prohibition prevented recovery of reasonable infrastructure costs. The rewrite is expected to address whether and under what conditions data access fees would be permissible.
What is an 'authorized representative' under Section 1033 and why does the definition matter?
An authorized representative is a third party — such as a data aggregator or fintech app — that a consumer authorizes to access their financial data. The original rule used a consent-based standard: if the consumer said yes, you were an authorized representative. The rewrite is expected to consider whether authorized representatives must meet a higher, fiduciary-like standard requiring them to act in the consumer's interest throughout the data access relationship, not just at the point of initial authorization.
Which institutions are covered entities under Section 1033?
The original rule covers depository institutions with more than $850 million in total assets and certain covered nonbank financial service providers. Smaller institutions have later compliance deadlines. The fee and authorized representative provisions affect all covered entities and their third-party data access relationships regardless of asset size.
What should fintechs do during the OIRA review period?
Three priorities: (1) Map your existing data access arrangements to identify which rely on screen scraping versus API — the rule affects each differently; (2) Review your data aggregator contracts to understand renegotiation rights if access fees become permitted; (3) Update your data governance documentation to reflect the rule's current legal status — enjoined and under reconsideration — rather than treating the 2024 compliance deadlines as active obligations.
What is the practical difference between a consent-based and a fiduciary-based authorized representative standard?
A consent-based standard says: if a consumer authorized you, you're an authorized representative. A fiduciary-based standard would require you to act in the consumer's best interest throughout the data access relationship — including evaluating whether secondary uses, data monetization, or partner data sharing are actually in that consumer's interest. The latter would restrict data practices that currently rest on initial consent alone and could fundamentally alter how aggregators generate revenue.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Which of the 23 state privacy laws apply to your fintech after GLBA, plus the GLBA checklist, request tracker, assessments and vendor terms to comply.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.