Open Banking and the Battle for the Financial Data Layer
Open Banking and the Battle for the Financial Data Layer
Beneath every budgeting app, every instant loan decision, every "connect your bank account" button lies a quiet, contested question: who controls a consumer's financial data, and who pays to move it? The answer is being fought out right now in courtrooms, rulemakings, and boardrooms — and whoever controls the data layer controls the foundation on which modern finance is built. This is a structural analysis of that battle.
In this report
The core thesis
Data is the substrate of modern financial services. A lending decision is only as good as the data behind it; a payment is only as smart as the account information that routes it; a budgeting tool is worthless without a live feed of transactions. For most of banking's history, that data sat locked inside the institution that held the account. Open banking is the project of unlocking it — letting consumers permission their own data out to whichever provider serves them best.
The central argument of this report is that open banking is less a feature than a contest over infrastructure. The question is not really whether consumers can share their data — that genie left the bottle a decade ago — but who controls the pipes, who sets the terms, and crucially, who pays. That contest pits incumbent banks, which built and hold the data, against fintechs and aggregators, which want frictionless access to it, with regulators caught between competition and security. How it resolves will shape the economics of nearly every data-dependent business in finance — and the resolution is currently anything but settled.
The fight isn't over whether financial data gets shared — that's already happening. It's over who owns the rails, who sets the rules, and who pays the toll. That is a fight over the foundation of modern finance.
What open banking actually is
Strip away the jargon and open banking describes a simple flow with three parties. Data providers — usually the banks where consumers hold their primary accounts — hold the raw data. Data aggregators sit in the middle, verifying information and connecting it to the apps consumers want to use. Authorized third parties — the budgeting app, the lender, the payments company — receive the permissioned data and turn it into a service.
A concrete example: a consumer with a checking account at one bank, a credit card at another, and investments at a third can authorize a single app to pull balances and transactions from all three and show them in one place. That capability — consumer-permissioned, cross-institutional data sharing — is the engine behind account switching, personal financial management, income and cash-flow verification for lending, and pay-by-bank payments. It is, increasingly, the connective tissue of the entire fintech ecosystem, and the natural foundation for the kind of embedded finance now woven into non-financial products.
Section 1033: the rule and its reversal
In the United States, the legal foundation for open banking is Section 1033 of the Dodd-Frank Act, enacted in 2010 — and then left largely dormant for over a decade. The framework gives consumers a right to access data about the financial products they hold, subject to rules the Consumer Financial Protection Bureau was directed to write.
Those rules finally arrived. In October 2024, the CFPB finalized the Personal Financial Data Rights rule, a landmark attempt to turn Section 1033 into a working system. As finalized, it required covered data providers — banks above an asset threshold and certain nonbanks — to make consumer data available, electronically and at no cost, to consumers and authorized third parties; it covered roughly 24 months of transaction data; it set a phased compliance schedule running from 2026 through 2030; and it sought to move the industry off risky screen-scraping toward secure APIs. The CFPB also recognized the Financial Data Exchange (FDX) as the first standard-setting body for the framework.
Then the politics turned. The same day the rule was finalized, a coalition of banks — Forcht Bank, the Bank Policy Institute, and the Kentucky Bankers Association — sued, arguing the CFPB had overstepped its statutory authority. Under new leadership, the CFPB reversed its own position: in 2025 it told the court the rule was unlawful and should be set aside, then pivoted to issuing an Advance Notice of Proposed Rulemaking to rewrite the rule rather than simply vacate it. A federal court enjoined enforcement and stayed the case pending reconsideration. The result, as of mid-2026, is a regulatory regime in suspension: the first compliance deadline passed without becoming a binding enforcement trigger, and the rule exists on paper but not in practice — paused, contested, and being rewritten.
The fight over who pays
Here lies the most consequential — and least appreciated — battle. The 2024 rule effectively barred data providers from charging for access: banks would have to hand over consumer data for free. Strike that provision, and the entire economics of open banking changes.
This is not hypothetical. Large banks have signaled they intend to charge aggregators and fintechs for data access, with reports that the highest fees would fall on payments-focused companies — precisely those whose business models depend on high-frequency data calls. The banks' logic is straightforward: they built and maintain the infrastructure, they bear the security burden, and they argue third parties should not profit for free from systems banks paid for — particularly when much of the call volume comes not from individual consumer requests but from standing permissions that ping the bank's systems continuously. The fintech counterargument is equally clear: charging for access raises a toll on competition, entrenching incumbents and raising costs that ultimately reach consumers, undermining the entire purpose of open banking.
The resolution of this single question — free access versus paid access, and at what price — will do more to shape the fintech landscape than almost anything else. A pay-per-call regime would reward scale and squeeze thin-margin, data-hungry models; free access would keep the field open to challengers. It is, in the most literal sense, a fight over who pays the toll on the rails of modern finance.
The screen-scraping problem
Lurking beneath the policy debate is a genuine security issue that open banking, done right, solves. The legacy method of moving financial data is screen scraping: a consumer hands their banking username and password to a third party, which logs in as the consumer to retrieve data. This is risky on every axis — it exposes credentials, grants broad and indiscriminate access, and offers little control over what's taken or how it's used.
The promise of API-based open banking is to replace this entirely: instead of surrendering credentials, a consumer grants a permission that shares only specific, authorized data through a secure channel, revocable at will. On this point banks and fintechs largely agree — screen scraping should die. The disagreement is about everything around it: the terms, the liability, the standards, and the price. That an industry can agree on the destination while fighting bitterly over the road reveals just how high the stakes of the data layer have become.
Why the data layer is the prize
Why does any of this matter so much? Because control of the financial data layer is leverage over everything built on top of it. Consider what permissioned data enables:
- Lending. Cash-flow and transaction data allow lenders to assess borrowers — especially thin-file ones — far more accurately than legacy credit data alone, the foundation of the shift we examine in the new architecture of credit.
- Payments. Direct account access enables pay-by-bank and account-to-account payments that can bypass card rails entirely.
- Switching. Portable data lowers the cost of changing providers, the precise mechanism that forces incumbents to compete on rate and service.
- Financial management. Aggregated, real-time data powers the budgeting and advice tools consumers increasingly expect.
Each of these is a multi-billion-dollar arena, and each rests on the data layer. Whoever sets the terms of access — through rules, pricing, or sheer control of the pipes — holds a position of structural power over all of them. That is why a seemingly technical fight over data-sharing standards has drawn in the largest banks, the entire fintech industry, and the federal government at once.
The US versus the world
The American approach is distinctive in its messiness. Much of the developed world mandated open banking through regulation years ago — the United Kingdom and the European Union built standardized, government-directed frameworks that compelled banks to open their data on common terms. The US, by contrast, developed open banking largely market-first, through private aggregators and bilateral arrangements, and is only now — fitfully, and amid litigation — attempting to layer a regulatory framework on top. The contrast matters: a mandated regime delivers consistency and certainty but less flexibility, while a market-led one delivers innovation and fragmentation in equal measure. The US is, in effect, trying to decide how much of the European model it wants — and discovering that the question is politically and economically explosive.
Where this goes
Three things can be said with reasonable confidence even amid the uncertainty. First, the direction of travel is durable: regardless of the specific rule's fate, the underlying statutory mandate persists, the technology has matured, and consumer-permissioned data sharing is not going away. Second, the access-pricing question is the variable that matters most — whether banks can charge, and how much, will reshape which business models are viable, and it remains genuinely unresolved. Third, the API transition will continue regardless of the regulatory timeline, because screen scraping's risks are unacceptable to everyone and secure permissioned access is the agreed endpoint.
For anyone building in finance, the strategic implication is to treat the data layer as contested, not settled — to plan for a world where access may carry a price, to build on secure permissioned channels rather than fragile scraping, and to recognize that the institutions which control or can reliably access the data layer hold a durable advantage. The plumbing, as ever, is where the power is. And as data-driven models increasingly read consumer financial health in real time, that plumbing will determine who can see the borrower clearly — a theme that runs through the entire consumer credit cycle.
Frequently asked questions
A system in which consumers permission the sharing of their financial data with third-party apps and services. Data flows from providers (often banks) through aggregators that verify and connect it to authorized third parties, typically via APIs. It underpins account switching, budgeting tools, payments, and data-driven lending.
Section 1033 of the Dodd-Frank Act (2010) is the statutory basis for US open banking. The CFPB finalized an implementing rule in October 2024 requiring covered institutions to share consumer data with consumers and authorized third parties electronically and free of charge. It was challenged in court and, under new leadership, enjoined and reopened for reconsideration rather than taking effect as written.
Fintechs favor free, mandated access because it lowers switching costs and fuels competition. Banks oppose the rule as finalized, citing security, liability, and infrastructure cost. A central flashpoint is whether banks can charge aggregators and fintechs for data access — with some large banks signaling they intend to, which could reshape data-dependent business models.
An older data-access method in which a consumer shares banking login credentials with a third party that logs in to retrieve data. It's risky because it exposes credentials and grants broad access. A core goal of open banking is to replace it with secure, permissioned APIs that share only the specific data a consumer authorizes.
Key takeaways
- Open banking is a contest over infrastructure — who controls and prices the financial data layer.
- The CFPB's 2024 Section 1033 rule was finalized, then enjoined and reopened under new leadership.
- The decisive battle is whether banks can charge fintechs and aggregators for data access.
- All sides agree screen scraping should give way to secure permissioned APIs.
- Control of the data layer is leverage over lending, payments, switching, and financial tools alike.
Keep reading
This report is for general information only and does not constitute financial, legal, or investment advice. Regulatory status is evolving and described as of mid-2026; consult primary sources for the current state of the rule.