2. Concepts and architecture
- Screen scraping vs. APIs; credential storage risks; OAuth and tokenized access
- Data aggregators, data access platforms (Akoya), bank-direct APIs (e.g., JPMorgan Chase, Wells Fargo, Capital One — verify), and data recipients
- Account information vs. payment initiation
- Open banking vs. open finance (investments, pensions, insurance, mortgages) vs. open data (utilities, telecom, payroll)
- Consent lifecycle: capture, scope, duration, reauthorization, revocation, deletion
- Liability chains: who pays when data is misused or accounts are drained after data sharing (Reg E interpretations, contracts, indemnities)
- Use cases: account verification for ACH, PFM, underwriting (cash-flow data — link to Part 06), income/employment verification, tax, pay-by-bank (link to Part 03), wealth aggregation, KYC and fraud signals
3. United States
3.1 Section 1033 of the Dodd-Frank Act
Build a detailed regulation record and timeline (verify every date):
- Statutory text and early CFPB principles (2017), ANPR (2020), SBREFA outline (2022), proposed rule (October 2023)
- Final Personal Financial Data Rights rule (October 2024): covered data providers, covered data, developer interfaces, prohibition on fees for access, secondary-use limits, standard-setter recognition, tiered compliance dates beginning 2026 for largest institutions (verify)
- Litigation filed immediately by bank trade groups; court stays; the CFPB's 2025 decision to reconsider the rule, stated intent to vacate or revise, Advance Notice of Proposed Rulemaking (August 2025 — verify), compliance-date extensions, and any new proposal or final action through September 2026 (verify)
- Key contested issues: fees for data access, liability for unauthorized transactions, screen-scraping sunset, secondary data use, security obligations, scope (crypto, EWA, BNPL?), standard-setter role
- Stakeholder positions (bank trade associations, fintech coalitions such as the Financial Technology Association, consumer groups) with dated sources
3.2 Bank data access fees and disputes
- JPMorgan Chase's plan (reported July 2025) to charge aggregators for data access and subsequent agreements with Plaid and other aggregators (verify terms as reported, dates, and whether other banks followed)
- Prior bank–aggregator bilateral agreements (Chase–Plaid 2020, Wells Fargo, Capital One cutoffs — verify)
- Implications for fintechs' unit economics and consumers
3.3 Privacy law
- GLBA Privacy Rule (Reg P) and FTC Safeguards Rule (amended 2021; breach notification amendment effective 2024 — verify)
- State comprehensive privacy laws (CCPA/CPRA and others) and their GLBA exemptions (entity-level vs. data-level — verify per state)
- State financial-privacy and data-broker laws; California Delete Act/DROP platform (verify dates)
- CFPB proposed rule on data brokers under FCRA (December 2024 — verify withdrawal status)
- FCRA implications of aggregated data used for underwriting
- NYDFS Part 500 cybersecurity amendments (verify phased dates)
- Federal privacy legislation proposals (verify status)
3.4 Industry standards
- FDX API specification versions, adoption metrics (FDX-reported — Tier 4/5), CFPB recognition
- Akoya network and bank-owned data access
- Tokenized account numbers (TANs) and their effects on ACH verification (verify)
4. United Kingdom
- CMA Order (2017) and the CMA9; Open Banking Implementation Entity (OBIE) and transition to Open Banking Limited and a future regulator-led entity (verify status and naming)
- JROC recommendations; Data (Use and Access) Act 2025 enabling smart data schemes (verify)
- Adoption statistics: API calls, active users, payment volumes (verify latest)
- Variable recurring payments (sweeping mandates; commercial VRP phases — verify)
- FCA's open finance roadmap and sector pilots (verify)
- UK GDPR and ICO enforcement relevant to fintech
5. European Union
- PSD2 (in force 2018): AIS and PIS, SCA, RTS on SCA and secure communication, 90-day reauthorization (changed to 180 days — verify)
- PSD3 and the Payment Services Regulation (PSR): Commission proposal (June 2023), Parliament position (April 2024), Council position (2025), provisional political agreement (verify date and content: dashboards for consent management, fraud liability, IBAN/name check, access to payment systems for non-banks, open banking API performance requirements)
- Financial Data Access Regulation (FiDA): proposal (June 2023), negotiations, reports of possible withdrawal or narrowing in the Commission's 2025 work program and subsequent outcome (verify)
- GDPR enforcement relevant to fintech (e.g., fines on payment or banking apps — verify), EU Data Act (application September 2025 — verify), EU AI Act interactions (link to Part 11)
- Berlin Group NextGenPSD2 and SEPA Payment Account Access (SPAA) scheme (verify)
- Adoption evidence and API quality problems
6. Other markets
- India — Account Aggregator framework: RBI NBFC-AA licensing, Sahamati, FIPs/FIUs, consent artifacts, volume growth (verify figures), use in lending; Digital Personal Data Protection Act 2023 and Rules (verify notification and phased dates)
- Brazil — Open Finance: phases 1–4, mandatory participation, Pix initiation via Open Finance (Pix por Aproximação, Jornada sem Redirecionamento — verify), consent statistics, LGPD
- Australia — Consumer Data Right: banking, energy; non-bank lending expansion (verify); government review and 2024–2026 changes to scope and costs; low adoption critiques (verify); action initiation (verify)
- Canada: consumer-driven banking framework legislation (2024 Budget Implementation Act), Bank of Canada oversight role, phased timeline (verify)
- Singapore, Hong Kong, Japan, South Korea (MyData), Saudi Arabia, UAE, Nigeria, Colombia, Mexico (Fintech Law Article 76 — verify)
7. Data providers and aggregators
7.1 Company records (seed list — verify ownership and status)
Plaid, MX, Finicity (Mastercard Open Banking), Akoya, Envestnet | Yodlee (sale to STG — verify), Morningstar ByAllAccounts, Stripe Financial Connections, Teller, Method Financial, Pinwheel, Argyle, Atomic (payroll connectivity), Truv, TrueLayer, Tink (Visa), GoCardless (acquired Nordigen), Yapily, Token.io, Salt Edge, Belvo (LatAm), Pluggy, Finvu/OneMoney/CAMSfinserv (India AAs), Basiq, Frollo, Flinks (Canada), Visa's acquisition attempt of Plaid (abandoned 2021), Mastercard's acquisition of Aiia and Finicity
Record fields to add: connectivity method mix (API vs. scraping, if disclosed), bank coverage claims (label), security certifications (SOC 2, ISO 27001), data-use policy (resale/aggregate analytics), consumer portal for managing connections (e.g., Plaid Portal), litigation and enforcement.
7.2 Litigation and enforcement
- In re Plaid Inc. Privacy Litigation settlement ($58M, 2021–2022 — verify)
- FTC and state actions involving aggregators or data resale (verify)
- CFPB actions on data practices (verify)
- Notable bank vs. aggregator disputes
8. Privacy and security evaluation protocols
8.1 App privacy-policy review protocol
For each fintech app reviewed (50+ target):
- Capture privacy policy, terms, and any GLBA privacy notice (archived, dated).
- Record data categories collected (identity, device, location, contacts, transactions, credit, biometrics).
- Record sharing with affiliates, service providers, marketing partners; whether data is sold or used for targeted ads; opt-out mechanisms.
- Record data aggregator used (from connection flow or disclosures).
- Record retention periods and deletion rights; test documented deletion request process (describe steps; no fabricated outcomes).
- Compare app-store privacy labels to the policy; note mismatches.
- Record security features (MFA, passkeys, device binding).
- Score transparency using a published rubric; present as research, not endorsement.
8.2 Connection and revocation test (documented, with test accounts only)
- Steps to connect via OAuth vs. credential entry; permissions shown; whether scope is adjustable
- Where to see connected apps at the bank and at the aggregator portal
- Revocation steps and confirmation evidence
- Never use real customer data; redact screenshots
9. Breaches and incidents
Build incident records (seed list — verify): Evolve Bank & Trust breach (2024), Patelco Credit Union ransomware (2024), Finastra breach (2024), Snowflake-linked breaches affecting financial firms (2024), Coinbase customer data theft via bribed support contractors (2025 — verify), Cash App former-employee data access (2021–2022), Robinhood social-engineering breach (2021), Flagstar Bank breaches, MOVEit-related financial breaches (2023), Dave breach (2020), Revolut breach (2022), Capital One (2019 background), others through 2026.
For each: data types, number affected (official notifications to state AGs where available), root cause, notifications, regulatory response, litigation, consumer remedies.
10. Workflows
Use the master workflow format for:
- Connecting a bank account to an app safely (OAuth vs. credentials; checking the aggregator)
- Auditing and revoking app access (bank dashboards, aggregator portals, app deletion requests)
- Exercising data-deletion and access rights (CCPA/CPRA, GDPR, UK GDPR, DPDP) with a financial app
- Responding to a breach notice from a fintech (credit freeze, fraud alerts, monitoring, password/passkey changes)
- Building on open banking APIs as a developer (sandbox, consent UX, token storage, compliance with 1033 and PSD2 where applicable)
- A small business choosing an account-verification method for ACH (instant verification vs. micro-deposits vs. tokenized account numbers)
11. Timeline 2020–2026
- 1033 ANPR, proposal, final rule, litigation, reconsideration milestones
- Bank data-access fee announcements and agreements
- PSD3/PSR and FiDA legislative milestones
- UK Data (Use and Access) Act and open finance roadmap
- India AA growth and DPDP Rules
- Brazil Open Finance phases
- Australia CDR changes
- Canada consumer-driven banking legislation
- Major breaches and settlements