From the original research pack. This draft has not received a complete claim-by-claim review. Fees, product terms, statistics and legal status may have changed. Its preparation date is not a publication date. Use the linked original sources.

Editor note (remove before publishing): Previously tagged items resolved 2026-09-17 (exemption threshold confirmed in 12 CFR 1033.111(d); FTA appeal and bank data-access fee deals could not be confirmed and were hedged or removed). Also re-check the Federal Register for any new 1033 proposed rule published after Aug. 14, 2026.

Last updated September 17, 2026.

Every time you link your bank account to a budgeting app, a payment app, or a mortgage lender, you're using "open banking." In 2024 the Consumer Financial Protection Bureau (CFPB) finalized a rule meant to make that data-sharing a legal right, safer, and free. Nearly two years later, the rule is blocked by a federal court, being rewritten by the agency, and its first compliance deadline has come and gone without taking effect. Here's where things stand and what it means for consumers and developers.

Key takeaways

  • The CFPB finalized its Personal Financial Data Rights rule under Section 1033 of the Dodd-Frank Act in October 2024 (published November 18, 2024) [1][2].
  • It would require banks, card issuers, and some payment providers to share your data with apps you authorize, for free, through secure interfaces instead of screen scraping [2].
  • In August 2025 the CFPB reopened four key issues, including whether banks may charge fees for data access [3].
  • On October 29, 2025, a federal court in Kentucky preliminarily enjoined enforcement of the rule while the CFPB rewrites it [4][5].
  • As of September 17, 2026, no new proposed rule has been published; the CFPB's August 2026 regulatory agenda still lists the reconsideration as pending [6].

What is open banking?

Open banking means letting you share your financial account data (balances, transactions, account and routing numbers) with other companies you choose, such as budgeting apps, lenders, or payment services.

In the U.S., this has mostly run through data aggregators, companies that connect thousands of apps to thousands of banks. Historically, many connections relied on screen scraping: you gave an app your bank username and password, and software logged in as you to copy your data. Banks and aggregators have been moving toward APIs (application programming interfaces), which pass data through secure, token-based connections without sharing your password.

The scale is large. The CFPB said that as of 2022, at least 100 million consumers had authorized a third party to access their account data, with more than 50 billion access attempts a year [2].

What Section 1033 is

Section 1033 of the Dodd-Frank Act (2010) says consumers have a right to access information about their financial accounts in a usable electronic form. For more than a decade, the CFPB didn't write detailed rules to implement it. That changed with the 2024 rule.

What the 2024 rule requires

The final rule, as published [2]:

Topic What the 2024 rule says
Who must share data ("data providers") Banks and credit unions, plus nonbanks that offer checking-type (Regulation E) accounts, credit cards, or payment services such as digital wallets. Depository institutions with total assets at or below the Small Business Administration size standard for their industry are exempt [2].
What data Transactions, balances, information to initiate payments, account terms, upcoming bills, and basic account verification details
Fees Prohibits fees for consumer and third-party data access
Screen scraping Data providers must offer a developer interface and may not rely on third parties using consumers' login credentials to access data
Third parties (apps) Must limit collection, use, and retention to what's reasonably necessary for the product you asked for; authorization lasts up to one year before you must reauthorize
Effective date January 17, 2025
Compliance dates Staggered from April 1, 2026 (largest providers) through April 1, 2030 (smallest covered providers)

The CFPB also set up a process to recognize industry standard-setting bodies to write technical standards for these interfaces; it issued a rule on standard-setter attributes in June 2024 [1].

How the rule got stuck: a timeline

Date Event Status
Oct. 22, 2024 CFPB releases final rule [1] Final
Oct. 2024 Forcht Bank, the Kentucky Bankers Association, and the Bank Policy Institute sue in the Eastern District of Kentucky [5][7] Litigation
Nov. 18, 2024 Rule published in the Federal Register [2] Final
Jan. 17, 2025 Rule's effective date [2] Effective, compliance not yet due
2025 CFPB tells the court it will "comprehensively reexamine" the rule; the court stays the case [3] Under reconsideration
Aug. 22, 2025 CFPB publishes an advance notice of proposed rulemaking (ANPR) on four issues; comments due Oct. 21, 2025 [3] Proposed stage (pre-proposal)
Oct. 29, 2025 Judge Danny Reeves grants a preliminary injunction barring enforcement while the CFPB rewrites the rule [4] Enjoined
Apr. 1, 2026 First compliance date arrives; not enforceable under the injunction [8] Enjoined
Aug. 14, 2026 CFPB regulatory agenda lists reconsideration of the rule as an active rulemaking [6] Pending

The four reopened questions

In the August 2025 ANPR, the CFPB asked for comment on [3]:

  1. Who counts as a consumer's "representative" (for example, whether aggregators and fintech apps qualify).
  2. Fees: "the optimal approach to the assessment of fees" to cover data providers' costs.
  3. Data security risks and costs.
  4. Data privacy risks.

The Bureau also said it planned to extend compliance dates and asked what extension would be appropriate [3].

Why the court blocked it

According to the American Bankers Association's summary of the ruling, Judge Reeves found the plaintiffs "likely to succeed on all four of their claims," including that the rule likely exceeded the CFPB's authority, that the Bureau likely lacked authority to ban data-access fees, and that the fixed deadlines relied on standards that didn't yet exist [4]. A preliminary injunction is not a final decision on the merits.

The Financial Technology Association, which intervened to defend the rule, said it was "exploring all options, including an appeal" [5]. We could not confirm whether an appeal was filed.

The fight over fees

Fees are the most commercially important open question. The 2024 rule banned them. Large banks argue that building and securing data interfaces is expensive and that aggregators profit from bank infrastructure. Fintechs and aggregators argue that fees would tax consumers' access to their own data and favor incumbents.

If the rewritten rule allows fees, expect those costs to be negotiated between banks and aggregators, and possibly passed along to apps and users.

What this means for you

If you're a consumer

  • Nothing breaks today. Linking accounts still works through existing bank–aggregator connections, which don't depend on the rule taking effect.
  • Your legal right is less concrete than the 2024 rule promised. Access terms are set mostly by agreements between banks and aggregators for now.
  • Protect yourself: prefer connections that send you to your bank's own login page (token-based) rather than asking for your bank password inside the app; review and revoke connected apps in your bank's settings; read what data an app requests. Related field note

If you're a developer or fintech

  • Plan for API-first access. Many large banks have already moved to APIs, regardless of the rule.
  • Budget for possible fees. The reopened fee question makes a zero-cost assumption risky.
  • Watch the "representative" definition. It could affect whether aggregators and certain business models qualify.
  • Build to data-minimization norms anyway; they reduce breach risk and match where state privacy laws are going.

If you're a bank or credit union

  • Compliance deadlines are not enforceable while the injunction stands, but the April 2026–2030 schedule may be reset rather than eliminated [3]. Law firms have advised using the pause to test systems and review vendor contracts [8].

How the U.S. compares

The UK and EU built open banking through regulation years earlier, with bank APIs mandated for payment accounts. India and Brazil have pushed data sharing through central-bank or government-backed frameworks. The U.S. remains largely market-driven while the federal rule is on hold. Related field note Related field note

What to watch next

  • A new proposed rule from the CFPB, likely with revised compliance dates, fee provisions, and a narrower or clarified "representative" definition.
  • Court action after any new rule, since the Kentucky case was paused rather than decided.
  • CFPB capacity. Leadership changes and agency restructuring have slowed rulemaking; timing is uncertain [5].

Explore the payment path

FAQ

Is the CFPB's open banking rule in effect? The rule technically became effective January 17, 2025, but a federal court preliminarily enjoined enforcement on October 29, 2025, and compliance deadlines are not being enforced while the CFPB reconsiders it [2][4].

Did the April 1, 2026 compliance deadline apply? No. It arrived while the injunction was in place, so it was not an enforceable deadline [8].

Can banks charge fees for sharing my data? The 2024 rule would ban fees, but the CFPB has reopened that question [3], and the court found the fee ban likely exceeded the Bureau's authority at the preliminary stage [4].

Is screen scraping illegal? No federal ban is in force. The 2024 rule would require data providers to offer interfaces that don't rely on shared passwords [2], but it isn't being enforced.

Is it safe to connect my bank account to apps? It can be, but risk depends on the app and connection method. Use apps that connect through your bank's login page, limit permissions, and revoke access you no longer use.

Sources

  1. Consumer Financial Protection Bureau, "Required Rulemaking on Personal Financial Data Rights," https://www.consumerfinance.gov/personal-financial-data-rights/, accessed 2026-09-17.
  2. Consumer Financial Protection Bureau, "Required Rulemaking on Personal Financial Data Rights" (final rule), Federal Register, https://www.federalregister.gov/documents/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-data-rights, Nov. 18, 2024, accessed 2026-09-17.
  3. Consumer Financial Protection Bureau, "Personal Financial Data Rights Reconsideration" (ANPR), Federal Register, https://www.federalregister.gov/documents/2025/08/22/2025-16139/personal-financial-data-rights-reconsideration, Aug. 22, 2025, accessed 2026-09-17.
  4. ABA Banking Journal, "Kentucky federal court enjoins CFPB from enforcing current 1033 final rule," https://bankingjournal.aba.com/2025/11/kentucky-federal-court-enjoins-cfpb-from-enforcing-current-1033-final-rule/, Oct./Nov. 2025, accessed 2026-09-17. (Trade association publication.)
  5. Payments Dive, "Judge blocks open banking rule enforcement," https://www.paymentsdive.com/news/judge-blocks-open-banking-rule-fintechs-CFPB-crypto/804190/, Oct. 30, 2025, accessed 2026-09-17.
  6. Consumer Financial Protection Bureau, "Regulatory Agenda," Federal Register, https://www.federalregister.gov/documents/2026/08/14/2026-16613/regulatory-agenda, Aug. 14, 2026, accessed 2026-09-17.
  7. Bank Policy Institute, complaint in Forcht Bank, N.A., et al. v. CFPB (E.D. Ky.), https://bpi.com/wp-content/uploads/2024/10/Forcht-Bank-Kentucky-Bankers-Association-BPI-v-CFPB-2024.10.22.pdf, Oct. 22, 2024, accessed 2026-09-17. (Plaintiff filing.)
  8. Cozen O'Connor, "Section 1033 Compliance Date: Open Banking Rule Enjoined and Under Reconsideration," https://www.cozen.com/news-resources/publications/2026/section-1033-compliance-date-open-banking-rule-enjoined-and-under-reconsideration, 2026, accessed 2026-09-17. (Law-firm analysis.)

Disclaimer: This article is for educational purposes only and is not financial, legal, or tax advice. The status of the Section 1033 rule and related litigation may change quickly. Check the CFPB and Federal Register for the latest official documents, and consult counsel about compliance obligations.

KEEP THE THREAD GOINGRevoke an app’s access to your bank data →Build the dispute evidence file while fulfilling the order →Hosted checkout reduces PCI scope; it does not erase the merchant boundary →Return to the library →