A research agenda, not completed reporting. These are the original topic questions and leads. Named companies, dates and outcomes require verification. Editorial operations and internal schemas remain private.

2. Concepts and architecture

  • Screen scraping vs. APIs; credential storage risks; OAuth and tokenized access
  • Data aggregators, data access platforms (Akoya), bank-direct APIs (e.g., JPMorgan Chase, Wells Fargo, Capital One — verify), and data recipients
  • Account information vs. payment initiation
  • Open banking vs. open finance (investments, pensions, insurance, mortgages) vs. open data (utilities, telecom, payroll)
  • Consent lifecycle: capture, scope, duration, reauthorization, revocation, deletion
  • Liability chains: who pays when data is misused or accounts are drained after data sharing (Reg E interpretations, contracts, indemnities)
  • Use cases: account verification for ACH, PFM, underwriting (cash-flow data — link to Part 06), income/employment verification, tax, pay-by-bank (link to Part 03), wealth aggregation, KYC and fraud signals

3. United States

3.1 Section 1033 of the Dodd-Frank Act

Build a detailed regulation record and timeline (verify every date):

  • Statutory text and early CFPB principles (2017), ANPR (2020), SBREFA outline (2022), proposed rule (October 2023)
  • Final Personal Financial Data Rights rule (October 2024): covered data providers, covered data, developer interfaces, prohibition on fees for access, secondary-use limits, standard-setter recognition, tiered compliance dates beginning 2026 for largest institutions (verify)
  • Litigation filed immediately by bank trade groups; court stays; the CFPB's 2025 decision to reconsider the rule, stated intent to vacate or revise, Advance Notice of Proposed Rulemaking (August 2025 — verify), compliance-date extensions, and any new proposal or final action through September 2026 (verify)
  • Key contested issues: fees for data access, liability for unauthorized transactions, screen-scraping sunset, secondary data use, security obligations, scope (crypto, EWA, BNPL?), standard-setter role
  • Stakeholder positions (bank trade associations, fintech coalitions such as the Financial Technology Association, consumer groups) with dated sources

3.2 Bank data access fees and disputes

  • JPMorgan Chase's plan (reported July 2025) to charge aggregators for data access and subsequent agreements with Plaid and other aggregators (verify terms as reported, dates, and whether other banks followed)
  • Prior bank–aggregator bilateral agreements (Chase–Plaid 2020, Wells Fargo, Capital One cutoffs — verify)
  • Implications for fintechs' unit economics and consumers

3.3 Privacy law

  • GLBA Privacy Rule (Reg P) and FTC Safeguards Rule (amended 2021; breach notification amendment effective 2024 — verify)
  • State comprehensive privacy laws (CCPA/CPRA and others) and their GLBA exemptions (entity-level vs. data-level — verify per state)
  • State financial-privacy and data-broker laws; California Delete Act/DROP platform (verify dates)
  • CFPB proposed rule on data brokers under FCRA (December 2024 — verify withdrawal status)
  • FCRA implications of aggregated data used for underwriting
  • NYDFS Part 500 cybersecurity amendments (verify phased dates)
  • Federal privacy legislation proposals (verify status)

3.4 Industry standards

  • FDX API specification versions, adoption metrics (FDX-reported — Tier 4/5), CFPB recognition
  • Akoya network and bank-owned data access
  • Tokenized account numbers (TANs) and their effects on ACH verification (verify)

4. United Kingdom

  • CMA Order (2017) and the CMA9; Open Banking Implementation Entity (OBIE) and transition to Open Banking Limited and a future regulator-led entity (verify status and naming)
  • JROC recommendations; Data (Use and Access) Act 2025 enabling smart data schemes (verify)
  • Adoption statistics: API calls, active users, payment volumes (verify latest)
  • Variable recurring payments (sweeping mandates; commercial VRP phases — verify)
  • FCA's open finance roadmap and sector pilots (verify)
  • UK GDPR and ICO enforcement relevant to fintech

5. European Union

  • PSD2 (in force 2018): AIS and PIS, SCA, RTS on SCA and secure communication, 90-day reauthorization (changed to 180 days — verify)
  • PSD3 and the Payment Services Regulation (PSR): Commission proposal (June 2023), Parliament position (April 2024), Council position (2025), provisional political agreement (verify date and content: dashboards for consent management, fraud liability, IBAN/name check, access to payment systems for non-banks, open banking API performance requirements)
  • Financial Data Access Regulation (FiDA): proposal (June 2023), negotiations, reports of possible withdrawal or narrowing in the Commission's 2025 work program and subsequent outcome (verify)
  • GDPR enforcement relevant to fintech (e.g., fines on payment or banking apps — verify), EU Data Act (application September 2025 — verify), EU AI Act interactions (link to Part 11)
  • Berlin Group NextGenPSD2 and SEPA Payment Account Access (SPAA) scheme (verify)
  • Adoption evidence and API quality problems

6. Other markets

  • India — Account Aggregator framework: RBI NBFC-AA licensing, Sahamati, FIPs/FIUs, consent artifacts, volume growth (verify figures), use in lending; Digital Personal Data Protection Act 2023 and Rules (verify notification and phased dates)
  • Brazil — Open Finance: phases 1–4, mandatory participation, Pix initiation via Open Finance (Pix por Aproximação, Jornada sem Redirecionamento — verify), consent statistics, LGPD
  • Australia — Consumer Data Right: banking, energy; non-bank lending expansion (verify); government review and 2024–2026 changes to scope and costs; low adoption critiques (verify); action initiation (verify)
  • Canada: consumer-driven banking framework legislation (2024 Budget Implementation Act), Bank of Canada oversight role, phased timeline (verify)
  • Singapore, Hong Kong, Japan, South Korea (MyData), Saudi Arabia, UAE, Nigeria, Colombia, Mexico (Fintech Law Article 76 — verify)

7. Data providers and aggregators

7.1 Company records (seed list — verify ownership and status)

Plaid, MX, Finicity (Mastercard Open Banking), Akoya, Envestnet | Yodlee (sale to STG — verify), Morningstar ByAllAccounts, Stripe Financial Connections, Teller, Method Financial, Pinwheel, Argyle, Atomic (payroll connectivity), Truv, TrueLayer, Tink (Visa), GoCardless (acquired Nordigen), Yapily, Token.io, Salt Edge, Belvo (LatAm), Pluggy, Finvu/OneMoney/CAMSfinserv (India AAs), Basiq, Frollo, Flinks (Canada), Visa's acquisition attempt of Plaid (abandoned 2021), Mastercard's acquisition of Aiia and Finicity

Record fields to add: connectivity method mix (API vs. scraping, if disclosed), bank coverage claims (label), security certifications (SOC 2, ISO 27001), data-use policy (resale/aggregate analytics), consumer portal for managing connections (e.g., Plaid Portal), litigation and enforcement.

7.2 Litigation and enforcement

  • In re Plaid Inc. Privacy Litigation settlement ($58M, 2021–2022 — verify)
  • FTC and state actions involving aggregators or data resale (verify)
  • CFPB actions on data practices (verify)
  • Notable bank vs. aggregator disputes

8. Privacy and security evaluation protocols

8.1 App privacy-policy review protocol

For each fintech app reviewed (50+ target):

  1. Capture privacy policy, terms, and any GLBA privacy notice (archived, dated).
  2. Record data categories collected (identity, device, location, contacts, transactions, credit, biometrics).
  3. Record sharing with affiliates, service providers, marketing partners; whether data is sold or used for targeted ads; opt-out mechanisms.
  4. Record data aggregator used (from connection flow or disclosures).
  5. Record retention periods and deletion rights; test documented deletion request process (describe steps; no fabricated outcomes).
  6. Compare app-store privacy labels to the policy; note mismatches.
  7. Record security features (MFA, passkeys, device binding).
  8. Score transparency using a published rubric; present as research, not endorsement.

8.2 Connection and revocation test (documented, with test accounts only)

  • Steps to connect via OAuth vs. credential entry; permissions shown; whether scope is adjustable
  • Where to see connected apps at the bank and at the aggregator portal
  • Revocation steps and confirmation evidence
  • Never use real customer data; redact screenshots

9. Breaches and incidents

Build incident records (seed list — verify): Evolve Bank & Trust breach (2024), Patelco Credit Union ransomware (2024), Finastra breach (2024), Snowflake-linked breaches affecting financial firms (2024), Coinbase customer data theft via bribed support contractors (2025 — verify), Cash App former-employee data access (2021–2022), Robinhood social-engineering breach (2021), Flagstar Bank breaches, MOVEit-related financial breaches (2023), Dave breach (2020), Revolut breach (2022), Capital One (2019 background), others through 2026.

For each: data types, number affected (official notifications to state AGs where available), root cause, notifications, regulatory response, litigation, consumer remedies.


10. Workflows

Use the master workflow format for:

  • Connecting a bank account to an app safely (OAuth vs. credentials; checking the aggregator)
  • Auditing and revoking app access (bank dashboards, aggregator portals, app deletion requests)
  • Exercising data-deletion and access rights (CCPA/CPRA, GDPR, UK GDPR, DPDP) with a financial app
  • Responding to a breach notice from a fintech (credit freeze, fraud alerts, monitoring, password/passkey changes)
  • Building on open banking APIs as a developer (sandbox, consent UX, token storage, compliance with 1033 and PSD2 where applicable)
  • A small business choosing an account-verification method for ACH (instant verification vs. micro-deposits vs. tokenized account numbers)

11. Timeline 2020–2026

  • 1033 ANPR, proposal, final rule, litigation, reconsideration milestones
  • Bank data-access fee announcements and agreements
  • PSD3/PSR and FiDA legislative milestones
  • UK Data (Use and Access) Act and open finance roadmap
  • India AA growth and DPDP Rules
  • Brazil Open Finance phases
  • Australia CDR changes
  • Canada consumer-driven banking legislation
  • Major breaches and settlements