Editor note (remove before publishing): Previously tagged items resolved 2026-09-17 (exemption threshold confirmed in 12 CFR 1033.111(d); FTA appeal and bank data-access fee deals could not be confirmed and were hedged or removed). Also re-check the Federal Register for any new 1033 proposed rule published after Aug. 14, 2026.
Last updated September 17, 2026.
Every time you link your bank account to a budgeting app, a payment app, or a mortgage lender, you're using "open banking." In 2024 the Consumer Financial Protection Bureau (CFPB) finalized a rule meant to make that data-sharing a legal right, safer, and free. Nearly two years later, the rule is blocked by a federal court, being rewritten by the agency, and its first compliance deadline has come and gone without taking effect. Here's where things stand and what it means for consumers and developers.
Key takeaways
- The CFPB finalized its Personal Financial Data Rights rule under Section 1033 of the Dodd-Frank Act in October 2024 (published November 18, 2024) [1][2].
- It would require banks, card issuers, and some payment providers to share your data with apps you authorize, for free, through secure interfaces instead of screen scraping [2].
- In August 2025 the CFPB reopened four key issues, including whether banks may charge fees for data access [3].
- On October 29, 2025, a federal court in Kentucky preliminarily enjoined enforcement of the rule while the CFPB rewrites it [4][5].
- As of September 17, 2026, no new proposed rule has been published; the CFPB's August 2026 regulatory agenda still lists the reconsideration as pending [6].
What is open banking?
Open banking means letting you share your financial account data (balances, transactions, account and routing numbers) with other companies you choose, such as budgeting apps, lenders, or payment services.
In the U.S., this has mostly run through data aggregators, companies that connect thousands of apps to thousands of banks. Historically, many connections relied on screen scraping: you gave an app your bank username and password, and software logged in as you to copy your data. Banks and aggregators have been moving toward APIs (application programming interfaces), which pass data through secure, token-based connections without sharing your password.
The scale is large. The CFPB said that as of 2022, at least 100 million consumers had authorized a third party to access their account data, with more than 50 billion access attempts a year [2].
What Section 1033 is
Section 1033 of the Dodd-Frank Act (2010) says consumers have a right to access information about their financial accounts in a usable electronic form. For more than a decade, the CFPB didn't write detailed rules to implement it. That changed with the 2024 rule.
What the 2024 rule requires
The final rule, as published [2]:
| Topic | What the 2024 rule says |
|---|---|
| Who must share data ("data providers") | Banks and credit unions, plus nonbanks that offer checking-type (Regulation E) accounts, credit cards, or payment services such as digital wallets. Depository institutions with total assets at or below the Small Business Administration size standard for their industry are exempt [2]. |
| What data | Transactions, balances, information to initiate payments, account terms, upcoming bills, and basic account verification details |
| Fees | Prohibits fees for consumer and third-party data access |
| Screen scraping | Data providers must offer a developer interface and may not rely on third parties using consumers' login credentials to access data |
| Third parties (apps) | Must limit collection, use, and retention to what's reasonably necessary for the product you asked for; authorization lasts up to one year before you must reauthorize |
| Effective date | January 17, 2025 |
| Compliance dates | Staggered from April 1, 2026 (largest providers) through April 1, 2030 (smallest covered providers) |
The CFPB also set up a process to recognize industry standard-setting bodies to write technical standards for these interfaces; it issued a rule on standard-setter attributes in June 2024 [1].
How the rule got stuck: a timeline
| Date | Event | Status |
|---|---|---|
| Oct. 22, 2024 | CFPB releases final rule [1] | Final |
| Oct. 2024 | Forcht Bank, the Kentucky Bankers Association, and the Bank Policy Institute sue in the Eastern District of Kentucky [5][7] | Litigation |
| Nov. 18, 2024 | Rule published in the Federal Register [2] | Final |
| Jan. 17, 2025 | Rule's effective date [2] | Effective, compliance not yet due |
| 2025 | CFPB tells the court it will "comprehensively reexamine" the rule; the court stays the case [3] | Under reconsideration |
| Aug. 22, 2025 | CFPB publishes an advance notice of proposed rulemaking (ANPR) on four issues; comments due Oct. 21, 2025 [3] | Proposed stage (pre-proposal) |
| Oct. 29, 2025 | Judge Danny Reeves grants a preliminary injunction barring enforcement while the CFPB rewrites the rule [4] | Enjoined |
| Apr. 1, 2026 | First compliance date arrives; not enforceable under the injunction [8] | Enjoined |
| Aug. 14, 2026 | CFPB regulatory agenda lists reconsideration of the rule as an active rulemaking [6] | Pending |
The four reopened questions
In the August 2025 ANPR, the CFPB asked for comment on [3]:
- Who counts as a consumer's "representative" (for example, whether aggregators and fintech apps qualify).
- Fees: "the optimal approach to the assessment of fees" to cover data providers' costs.
- Data security risks and costs.
- Data privacy risks.
The Bureau also said it planned to extend compliance dates and asked what extension would be appropriate [3].
Why the court blocked it
According to the American Bankers Association's summary of the ruling, Judge Reeves found the plaintiffs "likely to succeed on all four of their claims," including that the rule likely exceeded the CFPB's authority, that the Bureau likely lacked authority to ban data-access fees, and that the fixed deadlines relied on standards that didn't yet exist [4]. A preliminary injunction is not a final decision on the merits.
The Financial Technology Association, which intervened to defend the rule, said it was "exploring all options, including an appeal" [5]. We could not confirm whether an appeal was filed.
The fight over fees
Fees are the most commercially important open question. The 2024 rule banned them. Large banks argue that building and securing data interfaces is expensive and that aggregators profit from bank infrastructure. Fintechs and aggregators argue that fees would tax consumers' access to their own data and favor incumbents.
If the rewritten rule allows fees, expect those costs to be negotiated between banks and aggregators, and possibly passed along to apps and users.
What this means for you
If you're a consumer
- Nothing breaks today. Linking accounts still works through existing bank–aggregator connections, which don't depend on the rule taking effect.
- Your legal right is less concrete than the 2024 rule promised. Access terms are set mostly by agreements between banks and aggregators for now.
- Protect yourself: prefer connections that send you to your bank's own login page (token-based) rather than asking for your bank password inside the app; review and revoke connected apps in your bank's settings; read what data an app requests. Related field note
If you're a developer or fintech
- Plan for API-first access. Many large banks have already moved to APIs, regardless of the rule.
- Budget for possible fees. The reopened fee question makes a zero-cost assumption risky.
- Watch the "representative" definition. It could affect whether aggregators and certain business models qualify.
- Build to data-minimization norms anyway; they reduce breach risk and match where state privacy laws are going.
If you're a bank or credit union
- Compliance deadlines are not enforceable while the injunction stands, but the April 2026–2030 schedule may be reset rather than eliminated [3]. Law firms have advised using the pause to test systems and review vendor contracts [8].
How the U.S. compares
The UK and EU built open banking through regulation years earlier, with bank APIs mandated for payment accounts. India and Brazil have pushed data sharing through central-bank or government-backed frameworks. The U.S. remains largely market-driven while the federal rule is on hold. Related field note Related field note
What to watch next
- A new proposed rule from the CFPB, likely with revised compliance dates, fee provisions, and a narrower or clarified "representative" definition.
- Court action after any new rule, since the Kentucky case was paused rather than decided.
- CFPB capacity. Leadership changes and agency restructuring have slowed rulemaking; timing is uncertain [5].
FAQ
Is the CFPB's open banking rule in effect? The rule technically became effective January 17, 2025, but a federal court preliminarily enjoined enforcement on October 29, 2025, and compliance deadlines are not being enforced while the CFPB reconsiders it [2][4].
Did the April 1, 2026 compliance deadline apply? No. It arrived while the injunction was in place, so it was not an enforceable deadline [8].
Can banks charge fees for sharing my data? The 2024 rule would ban fees, but the CFPB has reopened that question [3], and the court found the fee ban likely exceeded the Bureau's authority at the preliminary stage [4].
Is screen scraping illegal? No federal ban is in force. The 2024 rule would require data providers to offer interfaces that don't rely on shared passwords [2], but it isn't being enforced.
Is it safe to connect my bank account to apps? It can be, but risk depends on the app and connection method. Use apps that connect through your bank's login page, limit permissions, and revoke access you no longer use.
Sources
- Consumer Financial Protection Bureau, "Required Rulemaking on Personal Financial Data Rights," https://www.consumerfinance.gov/personal-financial-data-rights/, accessed 2026-09-17.
- Consumer Financial Protection Bureau, "Required Rulemaking on Personal Financial Data Rights" (final rule), Federal Register, https://www.federalregister.gov/documents/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-data-rights, Nov. 18, 2024, accessed 2026-09-17.
- Consumer Financial Protection Bureau, "Personal Financial Data Rights Reconsideration" (ANPR), Federal Register, https://www.federalregister.gov/documents/2025/08/22/2025-16139/personal-financial-data-rights-reconsideration, Aug. 22, 2025, accessed 2026-09-17.
- ABA Banking Journal, "Kentucky federal court enjoins CFPB from enforcing current 1033 final rule," https://bankingjournal.aba.com/2025/11/kentucky-federal-court-enjoins-cfpb-from-enforcing-current-1033-final-rule/, Oct./Nov. 2025, accessed 2026-09-17. (Trade association publication.)
- Payments Dive, "Judge blocks open banking rule enforcement," https://www.paymentsdive.com/news/judge-blocks-open-banking-rule-fintechs-CFPB-crypto/804190/, Oct. 30, 2025, accessed 2026-09-17.
- Consumer Financial Protection Bureau, "Regulatory Agenda," Federal Register, https://www.federalregister.gov/documents/2026/08/14/2026-16613/regulatory-agenda, Aug. 14, 2026, accessed 2026-09-17.
- Bank Policy Institute, complaint in Forcht Bank, N.A., et al. v. CFPB (E.D. Ky.), https://bpi.com/wp-content/uploads/2024/10/Forcht-Bank-Kentucky-Bankers-Association-BPI-v-CFPB-2024.10.22.pdf, Oct. 22, 2024, accessed 2026-09-17. (Plaintiff filing.)
- Cozen O'Connor, "Section 1033 Compliance Date: Open Banking Rule Enjoined and Under Reconsideration," https://www.cozen.com/news-resources/publications/2026/section-1033-compliance-date-open-banking-rule-enjoined-and-under-reconsideration, 2026, accessed 2026-09-17. (Law-firm analysis.)
Disclaimer: This article is for educational purposes only and is not financial, legal, or tax advice. The status of the Section 1033 rule and related litigation may change quickly. Check the CFPB and Federal Register for the latest official documents, and consult counsel about compliance obligations.