It came as no surprise this week when the Consumer Financial Protection Bureau (CFPB) finalized implementation of Dodd-Frank Section 1033, commonly known as the open banking rule.
But with that action complete, a period of uncertainty and challenges kicks off. Both fintech operators and traditional financial institutions are adjusting to the scope and timing of a years-in-the-making ruling that regulators argue will return more control of financial data to consumers, but that banking trade groups and some industry participants say is too cumbersome to promote competition. Plus, the ruling itself included a few changes from its proposal, such as what types of operators — digital wallets, for instance — are considered data providers.
For the financial services industry, an open banking era potentially ushers in a period of shifting competition, consolidation and new data-focused partnerships. And it churns up even bigger questions yet to be tested, such as whether the rule creates an advantage for fintech expansion, is a boon for larger institutions with presumably greater data and technology resources, or if it creates a market equalizer that allows regional and community banks and their fintech partners to compete against larger names. Fintech consultants have long argued that financial data remains so fragmented that all financial institutions, even the largest competitors, are at a disadvantage without a uniform approach.
At its broadest, the rule grants consumers the right to access their financial data and to authorize third parties’ access on their behalf, all via standardized electronic disclosures. Third parties, in these instances, are often neobank and nonbank platforms whose presence has grown in the financial services space. Proponents of the rule argue that it allows consumers to change financial services providers more readily when they are unhappy.
Mixed response
Already, banking trade groups, including the Washington-focused American Bankers Association and select state bodies, have launched a court challenge against the CFPB for overreach under the powers granted by Dodd-Frank.
Rob Nichols, president and CEO of the ABA, said in part that his group welcomed cooperation with regulators in promoting privacy, security and consistency to data sharing, but he expressed concern for the scope, liability and cost inherent in the final language.
“Surveys consistently show that Americans trust banks more than any other industry to protect their data, and America’s banks remain committed to that mission. At the same time, our industry remains committed to responsible innovation, and the last thing we need is a rulemaking that puts both at risk,” he said.
Some advocates for the change say that creating a fuller picture of a consumer’s financial history, especially a data snapshot that is uniformly shared and read, will actually provide neobanks, traditional banks and credit unions with expansive information to make decisions on loan qualifications and more.
“We are very excited about 1033 and believe that it’s only going to accelerate the adoption of open banking,” said Misha Esipov, CEO and co-founder of Nova Credit, a nonbank financial services partner. “It is now imperative for bank leaders to have a concrete strategy for how their institutions are going to adapt.”
Esipov, for example, sees further adoption of open banking as key to speeding up what’s been slower acceptance of cash flow underwriting.
“Incorporating cash flow data into the underwriting process has allowed banks to approve 20%-40% of marginal declines, depending on their risk tolerance,” he says. “For many years, we’ve seen people denied access to financial products because they are misunderstood by traditional credit bureaus because they have a thin file, just arrived from another country, etc. More Americans have bank accounts than have a credit score, and if banks can leverage the data within those accounts, they can approve more people, gaining them more customers while expanding financial access.”
Who is covered in the 1033 Rule and key changes to the final
The rule applies to “data providers,” which include depository institutions such as banks and credit unions, as well as non-depository institutions that issue credit cards, hold transaction accounts, issue devices to access an account, or provide payment facilitation services and specific “authorized third parties.”
There were a couple of notable changes from the proposal phase. Small depository institutions, those with $850 million or fewer in assets, are exempt from the rule.
Attorneys at Husch Blackwell LLP, in a note, also emphasized another surprise to the industry in the final wording. The CFPB included digital wallet providers and payment apps as data providers. And importantly, these platforms are still considered “data providers” even when they are only facilitating pass-through payments.
“This means that many of the most popular fintech payment platforms and wallet providers will be subject to the open banking regime,” the attorneys wrote in their note.
Which transactions fall under the 1033 Rule?
“Covered data” encompasses information about transactions, costs, charges and usage related to consumer financial products and services.
These include account balances, historical transaction information (going back 24 months) in the control or possession of the data provider, terms and conditions, upcoming bills and Regulation E payment initiations.
Consumers can authorize third parties to access this data, although security and data use limitations will also apply.
How does 1033 impact data providers?
The final rule mandates that data providers make covered data accessible to consumers and authorized third parties upon request, ensuring the process is reliable, secure and competitive, according to the CFPB.
Data must be provided in a standardized, machine-readable format and data providers are required to meet a minimum response rate for data requests.
Restrictions on request frequency are prohibited, and data providers generally are prohibited from utilizing “screen scraping” as a method for granting data access to third parties under the rule. Screen scraping, which isn’t unique to financial services, is a technique to extract data from websites or web applications by automating user interactions and visual recognition. Its reputation as “data stealing” has bubbled up among consumer-activist groups in recent years.
Additionally, the rule prohibits any fees or charges related to consumer and third-party data access. And the rule calls for specific written policies, procedures and record retention to accompany data access.
What does 1033 mean for third parties?
The rule puts greater authority in the hands of consumers. For third parties to become “authorized,” they must seek data access on behalf of consumers to provide requested products or services, furnish an authorization disclosure with key terms and obtain the consumer’s express consent.
Third parties must limit the collection, use and retention of data to what is necessary for the requested services, excluding targeted advertising and cross-selling. The rule sets a maximum data collection duration of one year, requiring renewed consumer authorization after that point.
Data aggregators can assist third parties with authorization procedures but must certify compliance with third-party obligations. The rule also sets exact terms for record keeping.
Nova Credit’s Esipov sees this inclusion as beneficial to growth in key areas such as underwriting model training, anti-fraud tools and research-driven product development.
It’s not too soon for banks and credit unions to respond
Compliance with the rule will be implemented in phases, with larger providers subject to the rule sooner than smaller counterparts. The compliance target for the largest institutions is April 1, 2026, while the smallest covered institutions is April 1, 2030. Certain small banks and credit unions are not subject to this rule.
“The April 1, 2026, date for larger providers does not give these organizations a lot of time,” says Chris Boersma, product manager, compliance, with BAI.
“I suggest they start with developing a committee that will oversee the implementation of the new rule. The committee needs to identify all tasks that will need to be addressed, prioritize them and set a realistic timeline for completion,” he says. “The institutions that are successful at early planning will have the best chance at a successful implementation.”
In June, the CFPB finalized a rule outlining the qualifications to become a recognized industry standard setting body, which can issue standards that companies can use to help them comply with the CFPB’s Personal Financial Data Rights Rule.
Read the regulatory text of the final Personal Financial Data Rights rule .
Read the notice of the final Personal Financial Data Rights rule.
Rachel Koning Beals is Senior Editor at BAI.