Section 1071 of the Dodd-Frank Act amended the Equal Credit Opportunity Act to require financial institutions to collect and report data on credit applications from small businesses, including women-owned and minority-owned businesses. The stated purposes are to help enforce fair lending laws and to identify community development needs. The CFPB issued an implementing rule in 2023, adding a new subpart to Regulation B.

What happened next is the reason this guide is written the way it is. The rule was challenged in litigation, compliance dates were stayed and then extended more than once, and the Bureau opened further reconsideration of the rule's requirements. As of mid-2026, the compliance timeline should be treated as unsettled. Any specific date you find in a secondary source is likely to be superseded; verify the current position on the CFPB's own pages before committing to a build schedule.

The part that is not in dispute

Whatever happens to the implementing rule, the statutory mandate in section 1071 remains on the books, and ECOA's underlying prohibition on discrimination in any aspect of a credit transaction has applied to business credit since long before 2010. A lender that treats the data rule as the whole of its small business fair lending obligation has the analysis backwards. The data collection exists to make the substantive prohibition testable — which means the substantive work described in our guide to ECOA and disparate impact analysis is due now regardless of reporting timelines.

Coverage: three questions in sequence

  1. Are you a financial institution under the rule? The definition is deliberately broad. It is not limited to banks and credit unions; it reaches non-depository lenders, online lenders, commercial finance companies, equipment finance providers, factors in some structures, and merchant cash advance providers. Charter status is not the test.
  2. Did you meet the origination threshold? As issued, an institution becomes covered by originating at least 100 covered credit transactions for small businesses in each of the two immediately preceding calendar years. Both years must be met, which creates a rolling in-and-out possibility for lenders near the line.
  3. Is the specific application covered? A covered application is an oral or written request for a covered credit transaction made in accordance with the lender's procedures, from an applicant that is a small business under the revenue test. Inquiries, prequalifications, and reevaluation or renewal requests are handled under defined rules rather than being automatically included.
Product treatment under the rule as issued
ProductTreatment
Term loans and lines of creditCovered credit transactions
Business credit cardsCovered
Merchant cash advancesCovered, despite not being structured as loans
Other business credit not otherwise excludedGenerally covered
Trade creditExcluded
HMDA-reportable transactionsExcluded, because reported elsewhere
Insurance premium financingExcluded
Public utilities and securities creditExcluded
Credit designated for consumer purposesOutside the rule; consumer credit rules apply instead

The inclusion of merchant cash advances is worth pausing on. MCA providers have historically argued their product is a purchase of future receivables rather than credit. The rule treats it as covered, and several states reach the same conclusion for disclosure purposes. Providers whose entire compliance posture rests on the not-credit characterization should test that assumption against both the federal rule and the state statutes.

What gets collected, and the firewall

The rule as issued calls for a substantial data set — on the order of dozens of fields per application — combining information the lender already has, information from the applicant, and information about the outcome. The categories are:

  • Application and identifying data — unique identifier, application date, method and recipient of the application, and action taken with its date.
  • Credit type and purpose — product type, guarantees, term, and the purpose of the requested credit.
  • Amounts — amount applied for and amount approved or originated.
  • Pricing — interest rate details, total origination charges, broker fees, and other pricing components for originated credit.
  • Denial reasons — the principal reasons for denial, which line up with the adverse action reasons ECOA already requires.
  • Business profile — census tract, gross annual revenue, NAICS code, number of workers, time in business, and number of principal owners.
  • Demographic data — minority-owned, women-owned, and LGBTQI+-owned business status, and the ethnicity, race, and sex of principal owners.

Demographic information is requested from the applicant, and the applicant may decline to provide it. Lenders must state that they cannot discriminate on the basis of the information or on the applicant's decision not to provide it.

Watch out: the rule includes a firewall. Employees and officers involved in making a credit determination generally must not have access to the applicant's demographic responses, unless it is not feasible to limit access and the applicant is notified of that access. Building the collection form and the underwriting screen without designing the firewall into the data architecture is the single most predictable implementation failure.

Reported data is submitted annually to the CFPB, and a version of it is intended for public release with modifications to address privacy risk. Lenders should assume that whatever is published will be analyzed by researchers, journalists, plaintiffs' counsel, and community groups — which is a reason to run internal disparity analysis on your own data before anyone else does.

Why the timeline is unsettled, and how to plan anyway

  1. 2023. The CFPB issued the final rule with tiered compliance dates based on origination volume, largest lenders first.
  2. Shortly after issuance. Trade associations sued. A court order initially stayed compliance dates for the plaintiffs, and the stay was later broadened, decoupling the operative dates from the original schedule.
  3. 2024 into 2025. The Bureau issued interim final rulemaking extending compliance dates, and subsequently indicated it would reconsider aspects of the rule through further rulemaking.
  4. Mid-2026. The statutory mandate stands and some form of data collection remains the expected end state, but the operative compliance dates, and potentially the scope and data fields themselves, are subject to change. Confirm the current position at consumerfinance.gov before setting internal deadlines.

The planning question is what to build when the specification may shift. The answer is to prioritize work that no plausible version of the rule eliminates:

Practical step: the highest-value preparation is not a reporting engine — it is a clean application record. Most lenders discover that they cannot reliably identify when an application was received, what product was requested, what action was taken, and on what date. Fixing that is useful for fair lending testing, adverse action compliance, and litigation defense whether or not a single report is ever filed.

  • Define "application" consistently across channels — branch, phone, broker, online, and partner-originated.
  • Capture action taken and action date reliably, including withdrawals and incomplete files, which are recurring examination findings.
  • Record principal reasons for denial in a form that reflects the actual decision drivers.
  • Map where demographic responses would live and how the firewall would be enforced technically, not by policy alone.
  • Inventory broker, referral, and platform partners who touch applications, since their data becomes your reporting problem.

Partners, platforms, and the data you do not control

Small business credit increasingly originates through embedded channels: software platforms offering financing at checkout, marketplaces referring merchants to lenders, and technology providers running the application experience end to end. Under the rule, the reporting obligation follows the financial institution that originates, not the interface the applicant saw. That makes contractual data rights essential — the lender needs the fields, in the right format, with accuracy commitments and audit rights.

Those arrangements raise the same allocation questions covered in our guide to who owns compliance risk in embedded finance, and the diligence and monitoring expectations in our guide to third-party risk management. Federal banking regulators including the FDIC publish supervisory guidance on third-party relationships that supervised institutions should align to.

If you are the small business, not the lender

Applicants should know two things. Providing demographic information is voluntary, and a lender may not discriminate against you for providing it or for declining. And regardless of the data rule's status, ECOA already gives business applicants the right to be free from discrimination and, in defined circumstances, to receive the specific principal reasons for a denial — a right worth exercising because the stated reasons often reveal a fixable file problem.

Separately, watch the terms rather than the data forms. Personal guarantees, confessions of judgment where permitted, and daily-remittance structures carry real consequences that the application process rarely highlights; our guide to personal guarantees in business deals covers what owners actually put at risk.

Quick answers

Is the section 1071 rule in effect right now?

The statutory mandate is in effect and has been since 2010. The 2023 implementing rule has been through litigation, stays, extended compliance dates, and announced reconsideration. As of mid-2026 the operative compliance timeline is unsettled, and specific dates published earlier should not be relied on. Check the CFPB's current materials rather than any summary, including this one, for the live position.

Does the rule apply to non-banks?

Yes as issued. The definition of financial institution turns on engaging in financial activity and meeting the origination threshold, not on holding a bank charter. Online lenders, commercial finance companies, and merchant cash advance providers can all be covered institutions, and some smaller banks may fall below the threshold while a larger fintech lender falls above it.

What is the firewall requirement?

It restricts underwriters and other decision-makers from seeing the applicant's demographic responses, on the theory that data collected to detect discrimination should not become an input to discrimination. Where limiting access is not feasible, the rule requires notifying the applicant that the information may be accessed. In practice it is a systems-design requirement, not a training point.

If the rule changes, is the preparation wasted?

Mostly not. Consistent application definitions, reliable action-taken data, accurate denial reasons, and partner data rights all serve fair lending testing, adverse action compliance, and examination readiness independent of any reporting obligation. What may be wasted is a reporting pipeline built to fixed field specifications that later change — which argues for building the data layer first and the submission layer last.

Do state commercial financing laws cover the same ground?

They cover related ground differently. Several states have enacted commercial financing disclosure statutes requiring cost and term disclosures for small business financing, with varying thresholds, covered products, and disclosure formats. They are separate obligations from federal data reporting, they differ from one another, and no one state's approach represents a national standard.

Where this leaves you

Run the coverage analysis now — institution status, origination counts for the two preceding years, and which of your products are covered credit — and write the conclusion down with its date and assumptions. Build the application data layer, because it pays for itself in fair lending and adverse action work regardless of the rule's fate. Design the firewall into the architecture rather than the policy manual. Then hold the reporting build until the specification settles, and re-check the CFPB's position on a fixed cadence rather than waiting for news to find you.

Related lending, partnership, and product-structuring guides sit in the banking, payments, and fintech pathway.