The Data Access Fight: Who Controls Your Financial Information

The Data Access Fight: Who Controls Your Financial Information | HL Hunt
Institutional Outlook

The Data Access Fight: Who Controls Your Financial Information

Every product that reads your bank account to do something useful — verify income, underwrite a loan, move money, budget your spending — depends on a question American law has never definitively answered: does the consumer control that data, or does the institution holding it? Section 1033 of Dodd-Frank was supposed to settle it. A rule implementing it was finalized in October 2024 with compliance beginning April 2026. Instead, a federal court enjoined enforcement in October 2025, the Bureau told that court it considered its own rule unlawful, and a replacement went to regulatory review in August 2026. The first deadline passed without binding anyone. This report examines what's actually at stake — including the reopened fee question, which quietly determines whether any of it happens.

By the HL Hunt Research Desk · 24 min read · Updated August 2026

The core thesis

Open banking gets discussed as a technology question — APIs, standards, integrations. Our thesis is that it's a property question wearing technical clothing: whether financial data about you is your asset that institutions hold, or their asset generated by serving you. Every provision in the rule, and every contested point in the reconsideration, follows from that.

The commercial stakes explain the intensity. A bank's most valuable asset is the primary relationship — the low-beta deposit franchise our deposit analysis values at a meaningful share of assets, built on customer inertia and switching friction. Data portability attacks that directly: a customer whose transaction history and account data can move freely is a customer who can be underwritten, served, and courted by anyone. Open banking is, in substantial part, a policy about reducing switching costs, which is why fintechs favored the final rule and banks opposed it.

The second half of the thesis concerns who bears the cost of the uncertainty. The population that gains most from consented data access is the one our credit invisibility report describes — applicants whose bureau files are thin or absent and whose bank accounts contain the evidence that a credit report doesn't. A regime where data access is expensive, restricted, or legally uncertain hits that group hardest, because for everyone else the conventional file already works.

Open banking is a policy about switching costs. That's why the technical debate is so heated, and why the fee question decides more than the access question.

What data access actually enables

Before the legal mechanics, what the capability does:

  • Cash flow underwriting. Observing income arriving and obligations leaving is the mechanism by which a lender can assess an applicant with no credit file — the discipline our cash flow guide describes, and the main route out of the unscoreable problem.
  • Income and employment verification without documents, which removes the largest source of manual work in lending operations.
  • Account ownership verification, which is simultaneously an identity control and a fraud control — and the prerequisite for the ACH programs our bank payments guide covers.
  • Pay-by-bank, where a payment is initiated from the account directly rather than over card rails.
  • Account switching, where a customer's direct deposits and recurring payments can be moved to a new institution without reconstructing them manually.
  • Personal financial management — budgeting and aggregation tools that require a complete picture across institutions.
  • Ongoing monitoring for the early warning our portfolio management guide describes, within the scope a customer consented to.

Notice the pattern: most of these already happen. The market built around this capability before the rule existed, using a mix of institution-provided APIs, bilateral agreements, and — where neither was available — screen scraping with the customer's credentials. The rule wasn't creating a new capability. It was trying to standardize, secure, and make non-optional something already in widespread use on terms set by whichever institution held the data.

What the rule required

The Personal Financial Data Rights rule finalized in October 2024 established, in outline:

ElementRequirement
Who's coveredDepository institutions above an asset threshold and certain nonbank data providers
What dataTransactions from the prior 24 months, account terms and conditions, and personal account information
To whomThe consumer, and third parties the consumer authorizes
HowElectronically, in a usable form, through developer interfaces rather than credential sharing
FeesNot permitted for consumer-directed access
Third-party obligationsLimits on use, retention, and secondary purposes beyond what the consumer authorized
StandardsRecognition of standard-setting bodies to define technical specifications
TimelinePhased by institution size, largest first from April 1, 2026

Two design features are worth flagging as the contested ones. The no-fee provision made access a compliance obligation rather than a product — banks would bear the cost of building and maintaining interfaces without recovering it from the parties consuming the data. And the third-party obligations attempted to solve the problem that portability creates: once data leaves the institution, the consumer's protection depends entirely on what the recipient does with it, which is a harder thing to police than access itself.

A rule on paper, not in practice
Finalized October 2024, compliance from April 1, 2026, enjoined October 29, 2025, defended by nobody — the agency that wrote it told the court it considered the rule unlawful. The first deadline passed binding no one.

The timeline

The sequence is unusual enough to state precisely, because the shape of it is the story.

October 2024: the CFPB finalizes the Personal Financial Data Rights rule, with phased compliance beginning April 1, 2026 for the largest data providers and running through 2030 for smaller ones.

Immediately after: the rule is challenged in the Eastern District of Kentucky by bank plaintiffs including the Bank Policy Institute, the Kentucky Bankers Association, and Forcht Bank.

Early 2025: following a change in Bureau leadership, the CFPB tells the court it now views its own rule as unlawful and that it should be vacated — siding with the plaintiffs against the rule the agency wrote.

August 2025: the CFPB issues an Advance Notice of Proposed Rulemaking seeking comment on four areas, and announces it will propose extending the compliance dates.

October 29, 2025: Judge Danny C. Reeves issues a preliminary injunction halting CFPB enforcement while the agency reconsiders, finding the rules likely exceeded statutory authority and were arbitrary and capricious.

April 1, 2026: the first compliance deadline passes without becoming a binding enforcement trigger.

August 6, 2026: the CFPB submits a Notice of Proposed Rulemaking titled Personal Financial Data Rights Reconsideration to the Office of Information and Regulatory Affairs for review — generally one of the final steps before publication for public comment.

Two observations. An appeal is stayed in the Sixth Circuit while the reconsideration proceeds, on the theory that revised rules would nullify the dispute. And the pattern here matches what this desk documented in the subscription rulemaking and the medical debt rule: a finalized rule undone without the substantive question being adjudicated, leaving the conduct governed by whatever existed before. The difference here is that what existed before was nothing — Section 1033 sat dormant for over a decade — so the fallback is a market operating on private arrangements.

The fee question

Of the four areas the reconsideration reopened, this is the one that determines the practical outcome, and it deserves to be understood clearly.

The advance notice asked for comment on the optimal approach to assessing fees to defray the costs incurred by a covered person in responding to a request. The original rule permitted none.

The case for permitting fees: building and maintaining secure developer interfaces at scale is genuinely expensive, and requiring institutions to provide that infrastructure for free means they subsidize competitors who monetize the data. A bank absorbing the cost of an interface that a fintech uses to sell a product to that bank's customer has a legitimate complaint about the allocation.

The case against: if the data belongs to the consumer, charging for access is charging for delivery of the consumer's own property — and a fee set by the party with an incentive to discourage access is not really a cost-recovery mechanism. The practical concern is that even modest per-call fees, applied across the volume that data-dependent products require, can make categories of product uneconomic.

The structural point worth carrying: the fee level is the access level. A regime that grants a right and permits the obligated party to price it has granted something considerably less than a right, because pricing determines volume. That's why this question rather than the coverage question is where the outcome sits — and why the answer will be argued about in cents per call rather than in principle.

The population affected most, again, is the one relying on cash flow evidence rather than a bureau file. Bureau data has a price that lenders already pay; if account data acquires a comparable price, the cost advantage of alternative data narrows — and the thin-file underwriting our underwriting guide describes becomes more expensive precisely where margins are thinnest.

Who counts as a representative

The second reopened question is the proper understanding of who may serve as a representative of the consumer — and it sounds technical while being substantively enormous.

Section 1033 gives the consumer a right to their data. The final rule extended that to third parties the consumer authorizes, which is what makes the right practically usable — a consumer receiving a data file personally can do very little with it, while a consumer authorizing a lender or an aggregator to receive it gets a product.

A revised rule could narrow the definitions of consumer and representative, limiting who may access data on a consumer's behalf. Depending on where the line falls, that could:

  • Exclude data aggregators operating between the institution and the end product, which is how most access actually works.
  • Restrict access to regulated entities, which would be a meaningful security improvement and a meaningful competitive restriction simultaneously.
  • Limit the chain of authorization, affecting arrangements where a consumer authorizes a provider that uses a subprocessor.

The honest assessment: there is a real security argument here and a real competitive one, and they point the same direction, which makes the provision hard to read cleanly. Narrowing who may hold consumer financial data reduces the surface area for breaches and also reduces the number of firms able to compete for the relationship. Both effects are real, and the framing chosen usually reveals the framer's position.

Security and the screen scraping problem

The remaining two reopened questions concern data security and privacy, including how existing financial privacy frameworks interact with the rule.

Underneath them sits the practice the rule was partly designed to eliminate: credential-based screen scraping, where a consumer gives a third party their online banking username and password and the third party logs in as them to retrieve data.

Why it's bad, plainly:

  • The consumer surrenders full credentials, granting access far beyond the data actually needed.
  • The institution can't distinguish the scraper from the customer or from an attacker, which defeats fraud controls.
  • Credentials get stored by parties whose security posture the consumer can't assess — which is the synthetic and account takeover exposure our fraud analysis covers.
  • Access can't be scoped or revoked cleanly by the consumer.

Tokenized API access solves all four, which is the strongest technical argument for the rule's approach and one both sides largely accept. The disagreement was never really about whether APIs are better than scraping — it was about who must build them, on what terms, and for whom. Which returns to the fee question.

The uncomfortable interim consequence: with the rule enjoined, the practice it was designed to replace continues in the corners where API access isn't available. A regulatory pause doesn't pause the market; it leaves the market on the older arrangement.

States in the vacuum

Predictably, states have begun legislating into the federal uncertainty — New York among the first movers.

The observed pattern in early state open banking legislation:

  • Substantially shorter than the federal rulemaking record, which addressed data element scope, exceptions, denial standards, and technical requirements in depth.
  • Gaps left to implementing regulation or, more likely, to litigation — precisely the ambiguities the federal record had worked through.
  • Preemption as a live threshold question, since a federal framework, once revised, may or may not leave room for state variation.

This is the same dynamic our regulatory map traces repeatedly and the same one playing out in the medical debt reporting fight and in earned wage access: federal action stalls, states move, and the preemption question becomes the operative one. The outcome for a national business is the least efficient version of both — uncertainty about the federal rule and divergent state obligations arriving before it resolves.

What it means for a household

Stripped of the institutional argument, what does a consumer actually get or lose?

What data access gives you: the ability to be assessed on evidence rather than on absence of evidence, if your credit file is thin; lower-friction verification when applying for things; the practical ability to switch institutions without rebuilding your financial life manually; and tools that see across your accounts rather than one at a time.

What it costs you: your transaction history is among the most revealing data that exists about you — where you go, what you buy, who you pay, what you earn, what you're treated for. Every additional party holding it is additional exposure, and the consumer's protection depends on obligations placed on recipients rather than on the consumer's ability to monitor them.

What to do in the meantime, since the regime is unsettled:

  • Prefer connections that don't require your banking password. If a service asks for your online banking credentials rather than routing you through your bank's own authorization screen, that's the older and worse mechanism.
  • Review what you've connected. Most people have authorized more services than they remember, and most banks now provide a screen listing active connections.
  • Revoke what you don't use. An abandoned connection is standing access with no benefit.
  • Read what you're authorizing — the scope, the duration, and whether the data can be used for purposes beyond the one you wanted.
  • Understand the trade you're making when a lender asks for account access: it frequently produces a better decision for you, particularly on a thin file, and it is genuinely a disclosure.

Scenarios and what we're watching

ScenarioShape of the worldSignposts
Base case — narrowed rule with feesA revised rule permits cost-recovery fees and narrows representative definitions; access continues at higher cost and lower volume; data-dependent products consolidate toward larger playersNPRM contents; fee provisions; representative definitions; aggregator consolidation
Portability caseA durable rule preserves free consumer-directed access with strong recipient obligations; switching costs fall and cash flow underwriting expandsFinal rule fee treatment; compliance timelines; API coverage by institution size
Fragmentation caseFederal reconsideration stalls; states legislate divergently; screen scraping persists where APIs don't exist; preemption litigation followsState enactments; Sixth Circuit activity; credential-sharing prevalence

What we're watching: the fee provisions in the proposed rule, which are the whole outcome; the representative definition, which determines who can compete; API coverage below the largest institutions, since a right that exists only at large banks reaches the wrong population; state enactments and the preemption question; and credential-sharing prevalence, which is the honest measure of whether the security objective is being met regardless of what the rulebook says.

A statutory right written in 2010 has still not been operationalized. In the meantime, the data moves anyway — on terms set by whoever holds it.

Frequently asked questions

What is open banking and what is Section 1033?

The principle that consumers control their financial data and can authorize third parties to access it. Section 1033 of Dodd-Frank is its statutory basis, dormant for over a decade until the CFPB finalized the Personal Financial Data Rights rule in October 2024.

Is the open banking rule in effect?

No. A federal court in Kentucky enjoined enforcement on October 29, 2025 while the Bureau reconsiders, and the April 1, 2026 deadline passed without binding anyone. A replacement proposal went to regulatory review in August 2026.

Can banks charge fees for sharing your financial data?

The original rule said no; the reconsideration reopened it. This is the question that determines the practical outcome, because the fee level effectively sets the access level.

How does data access affect getting credit?

Directly for thin-file applicants — consented account data is what allows a lender to see income and obligations when a credit report shows nothing. Restricted or expensive access hits that population hardest.

Key takeaways

  • Open banking is a property question about who controls financial data, and functionally a policy about reducing switching costs.
  • The rule was finalized October 2024, enjoined October 29, 2025, and the first compliance deadline passed without binding anyone — a replacement went to OIRA review August 6, 2026.
  • The CFPB told the court it considered its own rule unlawful, so the substantive question was never adjudicated.
  • The reopened fee question determines the outcome: a right the obligated party may price is substantially less than a right.
  • Narrowing who counts as a consumer representative has genuine security merit and genuine competitive effect simultaneously.
  • With the rule paused, credential-based screen scraping continues where API access doesn't exist — the practice the rule was meant to replace.

This report is for general information only and does not constitute legal advice. The regulatory position described is actively changing, including pending rulemaking and litigation; verify current requirements with qualified counsel before relying on any description here.