Section 1033 of the Dodd-Frank Act, codified at 12 U.S.C. § 5533, says a consumer financial services provider must make information about a consumer's own account available to that consumer, subject to rules the CFPB writes. For fourteen years the statute sat mostly dormant. In October 2024 the CFPB issued its Personal Financial Data Rights final rule, the first comprehensive U.S. open-banking regulation.
The short version for anyone planning around it: the rule was immediately challenged in court, and during 2025 the Bureau opened a reconsideration of key provisions. The statutory right in Section 1033 is not going anywhere, but the implementing details — fees, timelines, standard-setting, scope — should be treated as evolving until the litigation and any replacement rulemaking resolve.
What the 2024 rule actually built
The final rule converted a one-sentence statutory right into an operating system for data sharing. Its central moves, as issued:
- Covered data. Transaction history (generally at least 24 months), account balances, information needed to initiate payments (such as account and routing data or a tokenized substitute), upcoming bill information, and basic account verification data such as name and contact details.
- Developer interfaces. Data providers must maintain a machine-readable interface for authorized third-party access, meeting performance expectations, rather than forcing credential-based screen scraping.
- No access fees. As issued, the rule barred data providers from charging consumers or authorized third parties for covered data access — one of the most contested provisions in the litigation and reconsideration.
- Authorization discipline for third parties. Companies receiving data must obtain informed consumer authorization, limit collection to what the consumer's requested product reasonably needs, honor revocation, cap authorization duration with re-authorization requirements, and restrict secondary uses such as unrelated advertising or sale of the data.
- Standard-setting bodies. The rule created a process for the CFPB to recognize industry standard-setting organizations whose consensus standards can serve as evidence of compliance for interface formats and performance.
Screen scraping deserves its own sentence: the rule's design pushes the market from shared login credentials toward tokenized, permissioned access, which is both a security upgrade and a significant engineering project for smaller institutions.
Who does what: three roles, three duty sets
Data providers
Banks, credit unions, card issuers, and certain payment-product providers holding covered accounts must build and maintain the access interface, respond to consumer and authorized third-party requests, publish documentation, and apply reasonable request-denial standards (for example, genuine risk-management concerns) rather than blanket refusals. Denials aimed at suppressing competition are exactly what the rule was written to prevent.
Third parties
Fintech apps that use bank data — budgeting tools, lending underwriters, pay-by-bank services — carry the authorization, data-minimization, retention, and deletion duties. If your product agreement promises more than the rule requires, the contract governs; our guide to data and security terms in software contracts explains how those private commitments interact with regulatory floors.
Data aggregators
Aggregators sit in the middle, contractually bound in both directions. The rule requires that consumers see and understand the aggregator's role during authorization. Aggregator agreements are also where liability for breaches, outages, and misuse gets allocated — the same risk-allocation discipline described in our article on who owns compliance risk in embedded finance.
The timeline, and why it keeps moving
- October 2024. Final rule issued with compliance phased by institution size — the largest data providers on the earliest date, additional tiers following over several years, and depositories under an asset threshold (set at $850 million in the rule as issued) exempt as data providers.
- Immediately after issuance. Banking trade groups sued, arguing the Bureau exceeded its statutory authority on points including the fee ban and the scope of third-party access.
- 2025. The CFPB, under new leadership, told the court it intended to reconsider the rule and opened a new rulemaking process examining core provisions — fees, the pace of compliance dates, standard-setting, and data-security expectations among them.
- 2026 and beyond. Some form of Section 1033 implementation remains the stated goal across administrations, but the binding details await the outcome of reconsideration and litigation. Track the CFPB's rules-and-policy page for the operative version.
Watch out: do not build a compliance calendar from secondary summaries of the 2024 rule. Several widely cited compliance dates have been stayed, extended, or reopened since issuance. The only reliable source is the current docket itself.
Planning work that survives the uncertainty
Institutions and fintechs keep asking the same question: what is worth building now if the rule may change? A defensible answer focuses on components no plausible final version eliminates.
- Inventory covered accounts and data fields. Every version of the rule requires knowing what data you hold, where it lives, and how fresh it is. This work is never wasted.
- Move off screen scraping where feasible. Tokenized access is the direction of travel in every draft, in industry standards, and in examiner expectations about credential security.
- Build authorization and revocation plumbing. Consent capture, consent records, and a working revocation path are foundational under any final rule — and are already good UDAAP hygiene.
- Paper the aggregator relationships. Access agreements should address security standards, liability for unauthorized transactions, outage responsibilities, and audit rights, because contract law fills whatever gaps the regulation leaves.
- Coordinate privacy compliance. Financial data flows also implicate Gramm-Leach-Bliley safeguards and, for some data uses, the state statutes mapped in our guide to U.S. state consumer privacy laws.
Practical step: if you are a fintech that initiates payments using bank-account data, run the money-movement analysis separately from the data-access analysis. Data rights under Section 1033 do not answer whether your funds flow needs licensing — that question is covered in our money-transmission guide.
What consumers can demand right now
Independent of the rule's implementation schedule, the statute itself entitles consumers to information about their own accounts, and most major institutions already support connecting third-party apps through permissioned channels. Consumers should authorize apps through the bank's connection flow rather than handing over login credentials, review connected-app lists periodically, and revoke access for tools they no longer use. If an institution stonewalls a reasonable data request, a complaint to the CFPB creates a documented record.
Quick answers
Is the Section 1033 rule currently in effect?
The statute is in effect and has been since 2010. The 2024 implementing rule was finalized but promptly challenged in court, and the CFPB opened a reconsideration in 2025 that put key provisions and compliance dates in flux. As of mid-2026, treat specific deadlines and technical requirements as provisional and verify them on the CFPB's rule page.
Does the rule cover mortgage, investment, or payroll data?
Not as issued. The 2024 rule reached Regulation E asset accounts, Regulation Z credit cards, and products facilitating payments from them. Mortgages, auto loans, brokerage accounts, and payroll data were left for potential future rulemakings, though some of that data already moves through the market under private agreements.
Can my bank charge a fintech app for accessing my data?
The 2024 rule prohibited fees for covered data access, and that ban became one of the most disputed issues in the litigation and reconsideration. Whether some cost-recovery pricing will be permitted in a revised rule is an open question. What you pay the app itself is a matter of your contract with the app.
Are small banks and credit unions exempt?
The rule as issued exempted depository institutions below an asset threshold — $850 million as written — from the data-provider obligations, and it gave the smallest covered tiers the latest compliance dates. Exempt institutions can still choose to offer permissioned access, and many do through their core-banking vendors.
Does open banking data sharing waive my privacy rights?
No. The rule's design limits authorized third parties to the data reasonably needed for the product you requested, restricts unrelated secondary uses, and requires a revocation path. Gramm-Leach-Bliley safeguards and applicable state privacy statutes continue to apply to companies holding your financial data.
Where this leaves you
Section 1033 created the right; the fight is over the machinery. Data providers should keep building the durable components — data inventories, secure interfaces, consent records — while tracking the docket before spending on contested specifics. Fintechs should paper their access chains carefully and treat authorization discipline as permanent. Consumers can use permissioned connections today and should prune them like any other account access. For the wider context of how these products are regulated, see the banking, payments, and fintech pathway.