Skip to content
Section 1033 Open Banking in 2026: Inside the CFPB's Injunction, Rewrite, and the Data-Fee Fight
Business & Startups47 min read

Section 1033 Open Banking in 2026: Inside the CFPB's Injunction, Rewrite, and the Data-Fee Fight

Scult Team
47 min read

A Kentucky court froze the CFPB's Section 1033 open banking rule right before its deadline, and a rewrite now underway could let banks charge for consumer data.

Section 1033 Open Banking in 2026: Inside the CFPB's Injunction, Rewrite, and the Data-Fee Fight

Direct answer: US open banking hit a genuine regulatory cliffhanger in 2026. The CFPB finalized its Section 1033 rule in October 2024 with phased compliance beginning April 1, 2026, but a federal court in Kentucky enjoined enforcement, finding the rule likely exceeded the CFPB's statutory authority — so the April 2026 deadline passed without becoming a binding trigger for anyone. The CFPB has since sent a new "Personal Financial Data Rights Reconsideration" proposal to OIRA in August 2026, and the central open question in that rewrite is whether banks will finally be allowed to charge fintechs and data aggregators for access to consumer financial data, a shift that would reshape the economics of the entire fintech ecosystem built on free data access.

What's Actually Happening

For more than a decade, a strange asymmetry has defined how consumers access their own financial data in the United States. A consumer can walk into their bank and ask for a printed statement, but getting that same data into a budgeting app, a lending underwriting tool, or a personal finance dashboard has depended on a patchwork of screen-scraping arrangements, bilateral data-sharing deals, and voluntary standards that banks and fintechs negotiated among themselves with no consistent legal floor underneath them. Section 1033 of the Dodd-Frank Act was written back in 2010 to close that gap by giving consumers a statutory right to access their own financial data and share it with third parties of their choosing, but the CFPB did not actually issue a rule implementing that right until October 2024 — fourteen years after the underlying statute passed.

That October 2024 rule, formally the Personal Financial Data Rights rule, set out a phased compliance schedule. The largest depository institutions and data providers were slated to comply first, with their deadline set for April 1, 2026, and smaller institutions phased in over the following years. On paper, this looked like the moment the United States would finally catch up to open banking regimes that other markets had already built years earlier — a durable, standardized, legally enforceable right for consumers to move their own data between their bank and the fintech apps, aggregators, and lenders of their choosing, replacing the current mix of screen-scraping and bespoke bilateral agreements with something closer to a common, API-based standard.

Then the rule ran into a federal courtroom in Kentucky. According to reporting from Consumer Finance Monitor and the law firm Cozen O'Connor, a federal court there enjoined enforcement of the Section 1033 rule, finding that it likely exceeded the CFPB's statutory authority and was arbitrary and capricious under the standards courts use to evaluate agency rulemaking. An injunction of this kind does not repeal a rule outright, but it does something functionally similar in the near term: it blocks the agency from enforcing the rule while the underlying legal challenge plays out, which means the rule's compliance deadlines stop meaning anything in practice even though they remain on the books. That is precisely what happened here. The April 1, 2026 deadline for the largest data providers arrived and passed, but because the injunction was already in place, it did not trigger the wave of enforcement-driven compliance activity a binding deadline normally would.

Rather than simply defending the enjoined rule in court and waiting for a final judicial resolution, the CFPB has taken a different path in 2026: it started over. PYMNTS.com reported on the CFPB's move to rewrite the rule rather than simply fight for the original text, and Consumer Finance Monitor reported that on August 6, 2026, the agency formally sent a new proposal — titled the "Personal Financial Data Rights Reconsideration" — to the Office of Information and Regulatory Affairs (OIRA) for review. OIRA review is a standard, required step in the federal rulemaking process before a proposed rule can be published for public comment, so this submission signals the CFPB is actively moving toward a formal Notice of Proposed Rulemaking rather than simply litigating the old rule indefinitely.

The single biggest substantive question inside that reconsideration, based on the reporting available, is whether banks will finally be allowed to charge fintechs and data aggregators for access to consumer financial data — something the original 2024 rule effectively prohibited by requiring data access to be provided to authorized third parties without a fee. Lifting that prohibition, even partially, would be a genuinely structural change to how the entire open banking and fintech data ecosystem in the US is financed, because it would convert what has functionally been a free input for thousands of fintech products into a metered, priced one. Alongside the fee question, the reconsideration is also reportedly wrestling with who qualifies as a consumer's "authorized representative" for purposes of requesting data on their behalf, and what privacy and cybersecurity protections should attach to that data once it leaves the bank's systems and enters a third party's.

It is worth being precise about what all of this does and doesn't mean for anyone trying to plan around it right now. It does not mean open banking is dead in the US, and it does not mean Section 1033 has been struck down as unconstitutional or invalid on the merits — the litigation over the original rule's validity is still working through the courts, and the underlying statutory right Congress created in 2010 has not been repealed by anyone. What it does mean is that the specific implementing rule that was supposed to make that right concrete and enforceable starting in April 2026 is currently frozen, and the agency responsible for it has decided the better path forward is a substantially rewritten version rather than a defense of the original text. For banks, fintechs, data aggregators, and the consumers whose data sits at the center of all of it, that leaves 2026 as a year of continued operating under the pre-2024 patchwork of voluntary agreements and bilateral arrangements, with a new rule somewhere on the horizon whose final shape — particularly on the fee question — is still genuinely unresolved.

It's also worth understanding, in general terms, why the mechanics of data access matter as much as the legal right itself. Before any standardized rule existed, the dominant technical method fintechs used to pull a consumer's bank data was screen-scraping: a third-party app would essentially store a consumer's actual online banking username and password, log in on the consumer's behalf using an automated script, and parse the resulting web page to extract balances and transactions. This approach worked well enough to build an entire generation of budgeting and personal-finance products, but it came with real downsides that both banks and security researchers flagged for years — consumers handing their actual bank credentials to a third party, fragile integrations that broke every time a bank redesigned its website, and no clean way for a bank to distinguish a legitimate scraping request from a genuine security threat hitting its login page at scale. The shift toward standardized, authenticated APIs — the approach Section 1033 was designed to formalize and require — was meant to replace that credential-sharing model with a cleaner, more secure, and more auditable one, where a consumer authorizes specific, revocable access without ever handing over their actual login credentials. That transition was already underway voluntarily at many larger banks before the 2024 rule, but the rule was meant to make it universal and consistent rather than optional and bank-by-bank, which is exactly the consistency currently on hold while the rule sits enjoined.

Why It's Trending Now

Several forces are converging to make this a live story in 2026 rather than a settled piece of financial regulatory history. The first is simply timing: April 1, 2026 was supposed to be a real deadline with real consequences, and deadlines that arrive and then visibly fail to bind anything tend to generate more attention than deadlines that quietly pass because compliance already happened. Trade press, compliance consultants, and law firms serving bank and fintech clients all had genuine business reasons to be watching closely for what would happen on and immediately after that date, and what happened — an anticlimactic non-event because of a standing injunction — was itself newsworthy precisely because so many parties had spent the better part of eighteen months preparing as if the deadline would hold.

The second force is the August 2026 OIRA submission, which converted what had been an open-ended, somewhat abstract question ("will the CFPB eventually rewrite this rule?") into a concrete, dated development with an actual document moving through the federal rulemaking pipeline. OIRA review typically precedes a formal proposed rule and public comment period, so this submission is the clearest signal yet that a rewritten rule, with real potential to reshape the fee question, the "authorized representative" definition, and the privacy/security requirements, is not a hypothetical future scenario but an active, near-term regulatory process that stakeholders need to track and potentially weigh in on.

The third force is the substance of the fee question itself, which cuts directly at the commercial model of a large slice of the fintech industry. PYMNTS.com's framing — that the CFPB's open banking rewrite "could put data-access fees at the center of the Section 1033 fight" — captures why this particular issue generates so much more heat than a typical regulatory footnote would. Banks have argued for years that they bear real infrastructure, security, and compliance costs to make consumer data available through secure channels, and that a free-access mandate effectively forces them to subsidize the fintech ecosystem built on top of that data. Fintechs and data aggregators, on the other side, have argued that charging for access to a consumer's own data — data the consumer has a statutory right to share — effectively taxes the exercise of a right Congress created, and that fees would be set unilaterally by the same banks whose competitive interest lies in raising the cost of the fintech products competing with their own offerings. Both positions have real logic behind them, and a final rule that lands closer to one side or the other has direct, calculable revenue implications for thousands of companies on both sides of that divide.

Finally, this is trending because it sits at the intersection of two audiences that don't always overlap in financial regulatory coverage: consumer advocates focused on data rights and control, and a commercial fintech and banking industry focused on unit economics and competitive positioning. A story that genuinely matters to both audiences, for different reasons, tends to generate more sustained coverage than a story that only matters to one.

There's also a broader pattern worth naming: this is the second time in roughly two years that a major CFPB rulemaking effort has been disrupted mid-implementation, following a broader run of litigation and political turnover that has touched much of the agency's post-2024 rulemaking agenda. For an industry that had, in earlier years, grown accustomed to CFPB rules eventually taking effect roughly as written once finalized, the Section 1033 injunction is part of a newer and less predictable pattern where a finalized rule is no longer treated by industry compliance teams as a reliable signal that the described obligations will actually arrive on schedule. That shift in how seriously a "finalized" federal rule should be treated as a planning input is, in its own right, a meaningful part of why this particular story has resonated so widely across the compliance and legal press covering financial services in 2026, well beyond the narrower audience that would normally track a single agency's data-access rule.

Who This Affects / The Business Stakes

The regulatory uncertainty around Section 1033 touches a wide set of players, each with a different stake in how the eventual rewrite lands.

Banks and large depository institutions were the parties who faced the nearest-term compliance deadline under the original rule, and they are also the parties whose commercial interest in the fee question is most direct. A bank that has already invested in building secure, standardized data-access APIs has a real cost basis it can point to when arguing for fee authority, and larger institutions in particular have pushed for the ability to recover some of that infrastructure investment rather than providing it as a mandated, uncompensated service. At the same time, banks that already treat robust data access as a competitive differentiator — a way to keep customers engaged with an ecosystem of connected apps rather than losing them to alternatives — have a countervailing interest in not making that access so expensive that it discourages the fintech partnerships their own customers value.

Fintechs, budgeting apps, and personal finance tools depend on reliable, low-friction access to a user's bank account data as the foundational input for nearly everything they do — categorizing spending, projecting cash flow, flagging unusual transactions, or simply displaying an aggregated balance across accounts. For a fintech, the regulatory uncertainty itself is almost as costly as any specific outcome, because product roadmaps, unit economics, and even fundraising narratives depend on having a reasonably confident answer to a basic question: will access to the data our product runs on remain free, or will it carry a per-user, per-connection, or per-call fee that has to be built into our pricing? A rule that stays frozen for an extended period leaves that question open indefinitely, which is its own kind of business cost even before any fee is actually charged.

Data aggregators — the specialized infrastructure companies, named generically in the brief's evidence sources as the kind of firm that sits between banks and the thousands of individual fintech apps that need bank data — occupy an especially exposed position, because their entire business model is built on standardizing and reselling access to bank data at scale. If banks gain fee authority, aggregators are the most likely first point where those fees get charged, and how those costs then get passed down to the individual fintechs the aggregator serves (and from there, potentially, to end consumers) is one of the more consequential downstream questions the rewrite raises without yet answering.

Consumers are, in principle, the parties Section 1033 was written to protect, and the practical stakes for them are less abstract than they might first appear. Every consumer who currently connects a bank account to a budgeting app, a tax-prep tool, a lending application, or a personal finance dashboard is relying on exactly the kind of data-sharing arrangement this rule governs. A rewrite that meaningfully raises the cost of that access, or narrows who can request it on a consumer's behalf, has a realistic path to showing up eventually as new fees, discontinued integrations, or narrower product features for ordinary users who never followed a single word of the underlying rulemaking process.

Community banks and credit unions face a different version of the same stakes: compliance capacity. Even though the largest institutions were first in line under the original rule's phased schedule, smaller institutions were slated to follow, and building secure, standardized data-sharing infrastructure is a meaningfully larger relative lift for an institution without a large in-house technology function. However the rewrite lands, the compliance burden question for smaller providers remains live and unresolved, and it's reasonable to expect community banking trade groups to keep pushing for longer phase-in periods, simplified technical requirements, or shared industry-utility infrastructure that spreads the build cost across many smaller institutions rather than requiring each one to build a bespoke solution independently.

Software vendors and platforms building on top of financial data — including the vertical SaaS platforms, lending-decision tools, and personal-finance products that treat bank-account connectivity as a feature rather than their core product — face a quieter but equally real version of this uncertainty. A company deciding today whether to build its own direct bank integrations, rely entirely on a third-party aggregator, or build a hybrid approach is effectively making an architectural bet on how this rulemaking resolves, even if that bet isn't always made consciously. Choosing an aggregator-dependent architecture concentrates the fee-pass-through risk in a single vendor relationship that can be renegotiated later; building direct integrations spreads the compliance and maintenance burden internally but keeps more control over eventual cost terms. Neither choice is obviously correct in the abstract, and the right answer depends heavily on a given company's scale, engineering capacity, and risk tolerance for regulatory ambiguity — which is exactly the kind of judgment call worth making deliberately rather than by default.

The Global Picture

United States: The full story above is the US story — the CFPB finalized the Section 1033 rule in October 2024 with an April 1, 2026 compliance deadline for the largest providers, a federal court in Kentucky enjoined enforcement on the grounds the rule likely exceeded the agency's statutory authority, the deadline passed without becoming binding, and the CFPB has now sent a "Personal Financial Data Rights Reconsideration" proposal to OIRA as of August 6, 2026, with the fee question, the "authorized representative" definition, and privacy/cybersecurity protections all reportedly on the table in the rewrite.

UK: No distinct 2026-specific reporting on this surfaced in this research pass. It's worth noting, in general terms available in the brief, that the UK pioneered a version of open banking earlier through the Competition and Markets Authority and the Open Banking Implementation Entity, which is part of why the US situation is so often discussed in comparison to it — but no current, 2026-dated update on the UK framework's status was found in this pass, so nothing region-specific beyond that general context should be assumed.

UAE/Dubai: No distinct regional-specific reporting on this topic surfaced in this research pass. Businesses operating in or serving that market should treat this as an open question rather than assume either a US-style framework or an absence of one.

Australia: No distinct regional-specific reporting on this topic surfaced in this research pass, beyond the general, widely known fact that Australia has its own Consumer Data Right framework that predates the US rule. No 2026-specific development on that framework's current status was returned in this search pass, so it should not be assumed to be static or resolved either.

Germany: Public reporting specific to Germany on this topic is thin so far in this research pass — no distinct regional finding surfaced.

Europe/France: No distinct regional-specific reporting surfaced in this research pass. The EU has its own long-standing open banking and open finance framework building on PSD2, but no 2026-specific update on that framework was directly returned in this search pass, so any comparison to the US situation should stay general rather than assume a specific current EU status.

China: No distinct regional-specific reporting on this topic surfaced in this research pass.

The honest summary of the global picture is that the US situation is unusually well-documented and unusually unsettled right now, while the comparative picture in the other six regions surveyed here is simply thin in this particular research pass — not because those markets lack activity, but because this pass didn't surface 2026-dated, region-specific reporting on open banking or open finance for them. Anyone building a genuinely global view of open banking regulation in 2026 should treat the US detail here as solid ground and the rest as open questions requiring their own dedicated research rather than extrapolation from the US case.

What This Means Going Forward / How to Respond

For any business whose product, underwriting model, or customer experience depends on consumer financial data — a fintech, a bank with an open API strategy, a lender using account data for underwriting, or a software platform embedding financial features — the practical posture right now is to plan for genuine uncertainty rather than betting confidently on either the original rule's terms or a specific rewritten version. That means a few concrete things in practice: maintaining existing bilateral and aggregator-based data-sharing relationships rather than assuming a standardized, free-API future is imminent; building unit economics that can absorb a scenario where data access carries a real per-connection or per-call cost, even if that scenario doesn't fully materialize; and staying close to the CFPB's OIRA-stage rulemaking process, since the formal public comment period that typically follows OIRA review is the most concrete opportunity industry participants get to shape the final rule's treatment of fees, authorized representatives, and security requirements before it's locked in.

For a software or product team building around any of this — whether that's a fintech assembling a new account-aggregation feature, a bank modernizing its data-sharing API layer, or a lender building underwriting tooling on top of consumer-permissioned data — the technical and architectural decisions made now matter regardless of how the rulemaking eventually resolves. A system built with modular, swappable data-access integrations, clear consent and audit trails, and cost-monitoring baked in from the start will adapt far more cheaply to a fee-based future than one that assumed free, unlimited data access as a permanent architectural given. That kind of forward-looking build is exactly the kind of work a custom software partner earns its keep on — designing the underlying data and integration architecture so that a regulatory shift on fees or access rules becomes a configuration change rather than a rebuild. Teams evaluating that kind of build-out can see how this approach plays out in practice through Scult's custom software development work, which is built around exactly this kind of adaptable, standards-aware architecture, and its AI agents and automation practice for the underwriting and data-orchestration layer that increasingly sits on top of these data flows.

The regulatory story here is also, underneath the legal and political detail, a reminder of a broader pattern that shows up constantly in financial technology: rules that take years to finalize can still take years more to become genuinely settled once litigation and reconsideration enter the picture, and the businesses that plan around "the rule as written" without building in flexibility for "the rule as it may eventually be rewritten" tend to be the ones caught out when a court injunction or an agency reversal changes the ground underneath them. For open banking specifically, 2026 looks less like a resolution and more like the middle of a longer negotiation between banks, fintechs, aggregators, and regulators over who bears the cost of making a decade-old statutory right actually work in practice — and that negotiation, on the evidence available right now, is still very much unresolved.

There's a useful discipline in treating this kind of prolonged regulatory limbo as a design constraint rather than a distraction to wait out. Teams that build their data-access layer, consent management, and audit logging as a genuinely modular piece of their architecture — rather than hard-wiring assumptions about a specific fee structure or a specific aggregator's API into their core product logic — put themselves in a position to absorb whatever the CFPB's eventual rule actually says with a configuration change instead of a multi-quarter engineering scramble. That same discipline extends to consent and audit trails specifically: whatever the reconsideration ultimately decides about "authorized representative" status and required privacy protections, a system that already logs consent events, access scope, and revocation requests in an auditable way will be far closer to compliant with whatever lands than one that treated consent as an afterthought. Businesses that got this architecture right before the rule even existed — treating clean data provenance and access control as good practice on its own merits — are, not coincidentally, the ones best positioned to adapt quickly once the rewritten rule finally does land.

Straight Answers on Open Banking, Section 1033, and the Data-Fee Fight

Is the Section 1033 open banking rule currently in effect?

No, not in a binding, enforceable sense as of this research pass. The CFPB finalized the Section 1033 rule in October 2024 with phased compliance beginning April 1, 2026 for the largest data providers, but a federal court in Kentucky enjoined enforcement of the rule, finding it likely exceeded the CFPB's statutory authority and was arbitrary and capricious. That injunction means the April 2026 deadline passed without triggering binding enforcement obligations. The underlying statutory right in Section 1033 of Dodd-Frank still exists, but the specific implementing rule meant to make it concrete and enforceable is currently frozen while litigation continues and the CFPB pursues a rewritten version through its "Personal Financial Data Rights Reconsideration" proposal, sent to OIRA in August 2026. Businesses should treat compliance as currently non-binding but should not assume the underlying right or a future rule has disappeared entirely.

What is the current CFPB Section 1033 open-banking status for lenders?

Lenders relying on consumer-permissioned account data for underwriting are currently operating in a holding pattern. The rule that would have set enforceable standards for how they access that data starting April 1, 2026 is enjoined, so lenders continue to rely on the pre-existing patchwork of bilateral agreements and data-aggregator relationships rather than a standardized, legally mandated framework. The CFPB's August 2026 OIRA submission signals a rewritten rule is coming, but its final terms — including whether data access will carry fees passed through to aggregators and, potentially, to the lenders and fintechs they serve — remain unresolved. Lenders building underwriting products on this data should treat the current arrangement as provisional and build in flexibility for a future where data costs money rather than assuming today's free-access status quo is permanent.

What is Section 1033 of the Dodd-Frank Act?

Section 1033 is a provision of the 2010 Dodd-Frank Wall Street Reform and Consumer Protection Act that gives consumers a statutory right to access information about their own financial accounts and to share that information with third parties of their choosing, such as budgeting apps, lenders, or financial advisors. The provision itself is more than a decade old, but the CFPB did not issue a rule actually implementing it — spelling out the technical and legal mechanics of how that right gets exercised in practice — until October 2024. That implementing rule is the "Personal Financial Data Rights" rule now caught up in litigation and reconsideration. The statute created the right; the rule was supposed to make it operational, and it's the rule, not the underlying statutory right, that is currently enjoined and being rewritten.

What right does Section 1033 give consumers over their financial data?

Section 1033 gives consumers a legal right to obtain information about their own financial accounts held by banks and other financial institutions, and to direct that information be shared with authorized third parties they choose to work with — such as a budgeting app, a comparison-shopping tool, or a lender evaluating a loan application. The intent behind the provision is to prevent consumers from being effectively locked into their existing bank's ecosystem simply because moving or sharing their own financial data was technically or contractually difficult. The October 2024 implementing rule was meant to give this right concrete technical and legal teeth — standardized formats, timelines, and obligations on data providers — but with that rule currently enjoined, the underlying right exists on the books while its practical enforcement mechanism remains unsettled.

When did the CFPB finalize its Section 1033 open banking rule?

The CFPB finalized its Section 1033 rule, formally called the Personal Financial Data Rights rule, in October 2024. The rule set out a phased compliance schedule rather than a single universal deadline, with the largest depository institutions and data providers required to comply first and smaller institutions phased in over subsequent years. The rule's rollout, however, was disrupted well before most of those deadlines arrived: a federal court in Kentucky enjoined enforcement, finding the rule likely exceeded the CFPB's statutory authority, and the agency has since moved to reconsider and rewrite the rule rather than simply defend the original October 2024 text through the litigation.

What was the original compliance deadline for the largest data providers?

Under the CFPB's October 2024 rule, the largest depository institutions and data providers faced a compliance deadline of April 1, 2026 — the first milestone in the rule's phased rollout, with smaller institutions given later deadlines in subsequent years. That April 2026 date became a genuine point of industry focus in the run-up to it, with banks and data providers investing in preparation to meet it. In practice, the deadline arrived and passed without triggering binding enforcement, because a federal court injunction was already in place blocking the CFPB from enforcing the rule while litigation over its validity continued.

Why did a federal court in Kentucky block enforcement of the Section 1033 rule?

According to reporting from Consumer Finance Monitor and the law firm Cozen O'Connor, a federal court in Kentucky enjoined enforcement of the Section 1033 rule after concluding it likely exceeded the CFPB's statutory authority and was arbitrary and capricious — two distinct legal standards courts apply when reviewing whether a federal agency's rule stayed within the bounds of the power Congress actually delegated to it, and whether the agency's reasoning in adopting the rule was sufficiently well-supported. An injunction on these grounds pauses enforcement while the underlying legal challenge proceeds, rather than permanently striking the rule down, which is why the CFPB has been able to pursue a rewritten version rather than treating the matter as closed.

On what grounds did the court find the rule exceeded the CFPB's authority?

The reporting describes the court's finding in two connected parts: that the rule likely exceeded the statutory authority Congress gave the CFPB under Section 1033 of Dodd-Frank, and separately, that the rule was arbitrary and capricious under the administrative law standard courts use to assess whether an agency's rulemaking was reasoned and well-justified. These are the standard legal bases on which federal courts review agency rules, and a finding along either one is generally enough to support an injunction while the case proceeds. The available reporting does not detail the court's full legal reasoning beyond these two findings, so businesses should treat the "likely exceeded authority" framing as the operative legal basis without assuming further specifics not present in the source coverage.

What happened when the April 2026 compliance deadline arrived?

Nothing binding happened, which was itself the notable outcome. Because the federal court injunction was already in place well before April 1, 2026, the deadline for the largest data providers arrived and passed without triggering the enforcement action, compliance audits, or penalty exposure a live deadline would normally carry. Institutions that had invested time and resources preparing for the deadline found themselves in a genuinely unusual position: technically still facing a rule with a passed compliance date, but with no enforcement mechanism currently available to the CFPB to act on it. This is part of why the story generated so much industry attention — an anticlimactic non-event after considerable anticipatory preparation.

What is the CFPB's new "Personal Financial Data Rights Reconsideration" proposal?

The "Personal Financial Data Rights Reconsideration" is a new rulemaking proposal the CFPB sent to the Office of Information and Regulatory Affairs (OIRA) for review on August 6, 2026, according to Consumer Finance Monitor's reporting. Rather than simply continuing to defend the enjoined October 2024 rule in court, the CFPB is pursuing a substantively rewritten version of the open banking rule through this proposal. OIRA review is a standard step that typically precedes a formal Notice of Proposed Rulemaking and public comment period, so this submission signals the agency is actively moving toward a new, revised rule rather than treating the current litigation as the end of the story. The proposal's most closely watched element, per PYMNTS.com's reporting, is whether it will lift the ban on banks charging fintechs and data aggregators for data access.

What is at stake in the debate over whether banks can charge fees for data access?

This question sits at the center of the entire rewrite, because it directly determines the unit economics of the fintech and data-aggregation industries built on top of consumer financial data. Banks argue they bear real infrastructure, security, and compliance costs providing secure data access and should be compensated for it, particularly by third parties building commercial products on top of that access. Fintechs and aggregators argue that charging for access to a consumer's own data effectively taxes a statutory right Congress created, and that fee structures set unilaterally by banks — who often compete directly with the fintechs requesting access — create an obvious conflict of interest. However the reconsideration resolves this, the outcome will directly affect pricing, product viability, and competitive dynamics across the fintech industry, making it the single most consequential open question in the current rulemaking process.

Who qualifies as a consumer's "authorized representative" under open banking rules?

The reconsideration is reportedly still working through the definition of who can validly act as a consumer's "authorized representative" for purposes of requesting their financial data — a question that determines which entities (budgeting apps, aggregators, lenders, financial advisors) can legitimately request and receive a consumer's data on their behalf, and under what consent standards. A narrower definition would reduce the number of entities that can access data without additional friction; a broader one preserves more of the current ecosystem's flexibility but raises questions about consent verification and fraud risk. The available reporting confirms this is an active, unresolved element of the rewrite without specifying exactly where the CFPB currently lands on it, so the practical answer for now is that the definition remains genuinely open.

How does open banking affect budgeting apps and fintechs that rely on account data?

Budgeting apps and similar fintechs depend on reliable, typically free access to a user's linked bank account data as the core input for their entire product — categorizing transactions, tracking spending against budgets, projecting cash flow, and flagging anomalies. The regulatory uncertainty around Section 1033 matters enormously to this category because it directly affects two things: whether that access remains reliable and standardized versus staying dependent on the current patchwork of bilateral agreements, and whether it remains free or starts carrying a cost that has to be passed through in pricing. A rule that finalizes fee authority for banks would represent a genuine cost-structure shift for an entire product category that has, until now, largely treated bank data access as a free input rather than a metered one.

What privacy and cybersecurity protections are being debated for open banking data sharing?

Alongside the fee question and the authorized-representative definition, the CFPB's reconsideration is reportedly also addressing what privacy and cybersecurity protections should govern consumer financial data once it moves from a bank's systems to a third party's. This matters because data leaving a heavily regulated bank environment and entering a fintech or aggregator's systems can, depending on that third party's own security practices, meaningfully change the risk profile of that data — a concern regulators, banks, and consumer advocates all cite as a legitimate reason for some baseline standard rather than leaving security practices entirely to bilateral negotiation. The specific shape those protections will take in the rewritten rule isn't detailed in the available reporting, but the fact that it's an active part of the reconsideration signals it will be a substantive, not cosmetic, element of the final rule.

How does the UK's original Open Banking framework compare to the US Section 1033 approach?

The UK built an earlier version of open banking through the Competition and Markets Authority and the Open Banking Implementation Entity, predating the US CFPB's October 2024 rule by several years, which is part of why US open banking coverage frequently references the UK as an earlier-mover comparison point. No 2026-specific reporting on the UK framework's current status surfaced in this research pass, so a detailed, current comparison isn't possible from the available sourcing. What can be said in general terms is that the US approach has followed a more legally contested path — a statutory right dating to 2010, an implementing rule not finalized until 2024, and that rule then enjoined before its first deadline — a considerably more turbulent path to implementation than a market that established its framework earlier and, as far as general public knowledge goes, with less subsequent litigation disruption.

What is Australia's Consumer Data Right and how does it relate to open banking?

Australia has its own Consumer Data Right framework, a broader data-portability right that includes but isn't limited to banking data, and which predates the US CFPB's 2024 rule. No 2026-specific reporting on the current status of Australia's Consumer Data Right surfaced in this research pass, so a detailed current comparison to the US situation isn't available from this sourcing. In general terms, Australia's framework represents a different regulatory design choice than the sector-specific approach Section 1033 takes in the US — extending data-portability rights across multiple sectors rather than focusing specifically on financial accounts — but readers wanting a precise, current picture of where Australia's framework stands in 2026 should look to dedicated Australian regulatory sources rather than this US-focused research.

Does the EU have its own open-finance framework, and how does it compare to the US rule?

The EU has its own long-standing regulatory foundation for open banking and open finance, built originally on the second Payment Services Directive (PSD2) and subsequent EU-level open finance initiatives, predating the US CFPB's 2024 rule by years. No 2026-specific reporting on the current status of that EU framework surfaced in this research pass, so a detailed, current comparison to the US rewrite isn't available from this sourcing. What can be said generally is that the EU's approach has developed through a more centralized, harmonized regulatory process across member states, in contrast to the US's single-agency, litigation-disrupted path — but businesses wanting a precise 2026 EU status should consult dedicated EU regulatory sources rather than extrapolate from the US case covered here.

How would allowing banks to charge third parties for data access change the fintech ecosystem?

If the CFPB's rewrite ultimately permits banks to charge fintechs and data aggregators for consumer data access, it would convert what has functionally operated as a free input for a large share of the fintech industry into a metered, priced one — a genuinely structural shift in unit economics. Aggregators would likely be the first point where such fees get charged, given their position between banks and the thousands of individual fintech apps they serve, and how those costs then flow downstream to individual fintechs and, potentially, to end consumers is one of the more consequential unresolved questions. Fintechs with thin margins or business models built around free data access as a foundational assumption would face the most direct pressure to adjust pricing or product design; better-capitalized players might absorb the cost as a competitive moat against smaller entrants who can't.

What data-sharing standards (like APIs) are used to implement open banking?

The general practice in open banking implementations, both in markets with mature frameworks and in the more contested US rollout, involves standardized application programming interfaces (APIs) that let authorized third parties request and receive a consumer's account data directly and securely, replacing older, less secure practices like screen-scraping, where a third party would essentially log into a consumer's bank account using their credentials to extract data from the web interface. The October 2024 CFPB rule was designed to push the US financial industry toward exactly this kind of standardized API-based approach rather than the current mixed reality of some standardized APIs alongside continued reliance on screen-scraping and bespoke bilateral integrations. With that rule enjoined, the pace of that shift toward fully standardized APIs has slowed relative to what the rule's timeline had intended.

Are consumers at risk of losing access to their own financial data during this regulatory back-and-forth?

Not immediately, in the sense that the existing data-sharing arrangements consumers currently rely on — the pre-2024 patchwork of bilateral agreements and aggregator relationships — remain in place and aren't being unwound by the injunction or the reconsideration process. What consumers are at some risk of losing, or never fully gaining, is the more standardized, legally guaranteed, cost-free version of that access the October 2024 rule was designed to lock in. The practical risk for consumers is less about a sudden loss of existing app connections and more about the eventual rewritten rule landing in a way that introduces new fees or friction that get passed down over time, changing the terms of access gradually rather than cutting it off abruptly.

How does open banking enable account-to-account payments as an alternative to card networks?

Standardized, consumer-authorized access to bank account data and payment initiation capability is generally understood as a foundation for account-to-account payment methods that can bypass traditional card networks, letting a consumer authorize a direct transfer from their bank account to a merchant or another party without routing through card rails. This kind of payment infrastructure depends on the same underlying data-access and consent mechanisms Section 1033 was designed to standardize, so the pace and terms of open banking's implementation in the US has a direct bearing on how quickly account-to-account payment alternatives can scale domestically. The specific state of account-to-account payment adoption in the US isn't detailed in the available research sourcing for this piece, but the structural connection to open banking's implementation is well established in general terms.

What compliance burden does open banking place on smaller community banks and credit unions?

Under the CFPB's original phased rollout, smaller institutions were given later compliance deadlines than the largest data providers, reflecting an acknowledgment that building secure, standardized data-sharing infrastructure represents a proportionally larger lift for institutions without large in-house technology teams or existing API infrastructure. That relative burden question remains live and unresolved regardless of how the current reconsideration lands, because any eventual rule — whether it closely resembles the original 2024 version or differs substantially on fees and other terms — will still need to address how smaller institutions are expected to build and maintain compliant data-sharing capability without the scale advantages larger banks bring to that same task.

How might a revised Section 1033 rule affect data aggregators like Plaid or MX?

Data aggregators occupy one of the most directly exposed positions in this entire rulemaking process, because their core business model is built on standardizing and reselling access to bank account data at scale across thousands of individual fintech clients. If the rewritten rule grants banks fee authority, aggregators are the most likely first point in the chain where those fees would actually get charged, which would directly affect their own cost structure and, in turn, the pricing they offer to the fintechs relying on their infrastructure. The available research sourcing for this piece doesn't name specific aggregators or detail company-specific impacts, so any assessment of a particular aggregator's exposure should be treated as a general industry-structure observation rather than a company-specific claim grounded in the cited sources.

Why do some banks oppose open banking mandates?

Banks' opposition to mandated, fee-free data access generally centers on the argument that they incur real infrastructure, security, and compliance costs to make consumer data available through secure channels, and that a mandate requiring them to provide that access without compensation effectively forces them to subsidize a fintech ecosystem that, in some cases, competes directly with their own product offerings. There's also a competitive dimension: some banks have expressed concern that fee-free, standardized data access makes it easier for a customer to be poached by a fintech competitor offering a more attractive interface built on top of the bank's own underlying account data and infrastructure, without the bank recovering any of the value created by maintaining that account relationship.

Why do fintechs and consumer advocates generally support strong open banking rules?

Fintechs and consumer advocates generally frame strong, standardized, fee-free open banking rules as a direct extension of a consumer's ownership over their own financial data — the idea that a consumer shouldn't have to pay extra, or navigate inconsistent bilateral agreements, simply to exercise a right to share information about their own accounts with a service provider of their choosing. For fintechs specifically, standardized rules also reduce the operational cost and legal uncertainty of building and maintaining dozens or hundreds of separate bilateral data-sharing agreements with individual banks, replacing that patchwork with a single, predictable regulatory floor that applies across the industry rather than depending on each bank's individual negotiating posture.

What happens to a consumer's connected apps if a bank restricts data-sharing access?

In the current environment, where the standardizing rule is enjoined and providers continue operating under the pre-2024 patchwork of bilateral and aggregator-based arrangements, a bank retains meaningful discretion over how and whether it makes data available to a given third party, which means a consumer's connected apps could in principle lose functionality or access if the underlying bank changes its data-sharing terms or discontinues a particular integration. This is precisely the kind of inconsistency and consumer-facing fragility the CFPB's rule was designed to reduce by creating a more standardized, legally guaranteed baseline. Until a finalized rule is in force, the underlying stability of any given consumer's app connections depends more on the specific bilateral or aggregator relationship in place than on a uniform legal guarantee.

Is open banking data-sharing safe from hacking or misuse?

Security is one of the elements the CFPB's reconsideration is reportedly still actively working through, specifically what privacy and cybersecurity protections should govern data once it leaves a bank's systems and enters a third party's. In general terms, moving from less secure practices like screen-scraping toward standardized, authenticated APIs is broadly understood across the industry as a meaningful security improvement, because it avoids the practice of a third party holding a consumer's actual bank login credentials. That said, any data-sharing arrangement introduces some additional attack surface simply by virtue of more parties handling the same data, which is exactly why security standards are a live, substantive part of the ongoing rulemaking rather than a settled, resolved question.

Can a consumer revoke a third party's access to their bank data once granted?

The general design intent behind open banking frameworks, including the CFPB's original rule, is that consumer authorization should be revocable — a consumer who connects a budgeting app or lending tool to their bank account should be able to withdraw that permission and cut off the third party's ongoing access. The specific mechanics of how revocation works in practice currently depend on the individual bank, aggregator, or app involved, given that a single standardized, legally mandated revocation mechanism is exactly the kind of feature the enjoined rule was meant to guarantee consistently across the industry. Until a finalized rule locks in a uniform standard, consumers should check the specific revocation process offered by their particular bank or connected app rather than assume a single universal mechanism applies everywhere.

How does open banking support switching between banks or financial products?

Standardized, portable access to a consumer's own transaction history and account data is generally understood as a meaningful enabler of switching between financial providers, because a new bank, lender, or financial product provider can more easily verify a consumer's financial history and creditworthiness using data the consumer authorizes them to access, rather than requiring the consumer to manually reconstruct that history or rely solely on traditional credit bureau data. This switching-support function is one of the underlying policy rationales for open banking generally, though the specific degree to which it's currently realized in the US market depends heavily on how much of the industry has adopted standardized data-sharing versus continuing to rely on the older, more fragmented patchwork.

What industries beyond banking are exploring open-finance data-sharing (e.g., insurance, investments)?

The broader "open finance" framing — as opposed to open banking specifically — generally refers to extending similar consumer data-portability principles beyond checking and savings accounts into other financial categories, including insurance policies and investment or brokerage accounts. The research sourcing for this piece centers specifically on the CFPB's Section 1033 rule, which is focused on banking and payment account data rather than insurance or investment accounts, so no specific 2026 US developments on open finance expansion into those adjacent categories are grounded in the available sources. In general terms, the broader open finance concept remains a topic of ongoing industry and policy discussion beyond the banking-specific rule covered here.

How long has the US lagged behind other countries in implementing open banking?

Section 1033 of the Dodd-Frank Act, the statutory basis for the US open banking right, dates back to 2010, but the CFPB did not finalize a rule actually implementing that right until October 2024 — a gap of roughly fourteen years between the underlying legal right and its first implementing regulation. Other markets, including the UK and Australia, are generally understood to have established functioning open banking or open data frameworks earlier than that October 2024 US rule, which is part of why US coverage of this topic frequently frames the country as a comparatively late mover. With the October 2024 rule now enjoined and under reconsideration, the practical gap between the US having a genuinely operative, enforceable open banking framework and other markets' earlier-established frameworks has, if anything, widened rather than closed in 2026.

What is OIRA's role in reviewing the CFPB's new Section 1033 proposal?

The Office of Information and Regulatory Affairs, a part of the Office of Management and Budget, reviews significant federal agency rules before they're formally published as a proposed rule open for public comment — a standard checkpoint in the federal rulemaking process intended to assess a rule's costs, benefits, and consistency with administration priorities before it moves further along the pipeline. The CFPB's submission of its "Personal Financial Data Rights Reconsideration" to OIRA on August 6, 2026 is exactly this kind of standard, required step, and it signals that the agency is actively moving the rewritten rule toward a formal proposal rather than treating the matter as settled by the current litigation. OIRA review doesn't guarantee any particular outcome or timeline for what comes next, but it is a concrete, dated sign of forward motion.

Could the Section 1033 rule be rewritten entirely rather than just delayed?

Yes — and the available reporting suggests this is exactly the path the CFPB has chosen rather than simply defending the original October 2024 rule through litigation or issuing a temporary delay. The "Personal Financial Data Rights Reconsideration" proposal sent to OIRA in August 2026 is described in the sourcing as a genuine reconsideration, with the fee question, the authorized-representative definition, and privacy/security protections all reportedly open for revision rather than simply a schedule adjustment on an otherwise unchanged rule. That framing matters for anyone trying to plan around this: the eventual rule that emerges from this process could differ substantially from the original 2024 version, not just arrive later than originally planned.

How does regulatory uncertainty around open banking affect fintech investment and product planning?

Extended regulatory uncertainty of the kind currently surrounding Section 1033 tends to make it harder for fintechs to plan product roadmaps and unit economics with confidence, because a foundational input to many fintech products — the cost and reliability of accessing consumer bank data — remains genuinely unsettled rather than fixed by a finalized rule. Investors evaluating fintech companies whose business models depend on that data access have to factor in a real, if hard-to-quantify, risk that a future rule could introduce new costs or access restrictions that weren't part of the original business case. This kind of prolonged uncertainty is generally understood across the industry as a drag on investment confidence and product commitment, independent of which specific outcome eventually materializes.

What would "reciprocity" requirements mean for fintechs that want access to bank data?

The concept of reciprocity in open banking rulemaking generally refers to a requirement that third parties requesting access to a consumer's bank data must also make equivalent data available back to the ecosystem under similar terms — intended to prevent a one-way flow where fintechs pull data from banks without any obligation to share comparable data themselves. The specific reporting available for this piece doesn't detail whether or how reciprocity requirements factor into the CFPB's current reconsideration, so any specific claim about reciprocity's role in the rewritten rule should be treated as an open question rather than a confirmed feature, even though the general concept is a recognized element of open banking policy debates more broadly.

How does open banking affect credit-invisible or underbanked consumers?

One of the general policy rationales behind open banking frameworks is that they can help consumers with thin or nontraditional credit histories — sometimes called "credit-invisible" — get evaluated more fairly by lenders willing to consider actual account and transaction data (such as consistent rent or utility payments visible in bank transaction history) rather than relying solely on traditional credit bureau scores that may not reflect that consumer's real financial behavior. The specific research sourcing for this piece is focused on the mechanics of the Section 1033 rulemaking process rather than detailed impact studies on underbanked consumers, so this should be understood as a general policy rationale commonly cited in open banking discussions rather than a claim grounded in specific 2026 US data from the cited sources.

What's the realistic timeline for a finalized, enforceable US open banking rule?

Based on the available reporting, the realistic timeline runs through at least the remainder of 2026 and likely well beyond, given that the CFPB's reconsideration proposal only reached the OIRA review stage in August 2026 — a step that typically precedes, rather than concludes, the formal proposed-rule and public-comment process. From there, a final rule would need to be published, potentially face further legal challenges given the pattern already seen with the original 2024 rule, and then work through its own phased compliance schedule. Businesses and consumers should reasonably expect the current state of regulatory uncertainty to persist for a meaningful stretch of time rather than resolve quickly, and should plan operationally around that extended uncertainty rather than around a specific anticipated resolution date.

Want results like this?

Keep reading