Blog Login
Compliance

What Is Open Banking? Section 1033 and What It Means for Fintechs

A

Anzar Dewani

43 minutes ago

The CFPB's Section 1033 rule gives consumers the right to access and share their financial data with third parties. This guide explains what open banking is, what the Section 1033 rule requires, and how it creates both compliance obligations and opportunities for fintechs.

What Is Open Banking? Section 1033 and What It Means for Fintechs

Open banking — the practice of allowing consumers to share their financial data with third parties through secure, standardized interfaces — has been reshaping financial services globally. In the United States, the regulatory framework for open banking is anchored in Section 1033 of the Dodd-Frank Wall Street Reform and Consumer Protection Act, which gives consumers the right to access their financial data in usable electronic form and share it with third parties. The CFPB finalized its Personal Financial Data Rights rule (implementing Section 1033) in 2024, establishing the first federal open banking regulatory framework in the US.

What Is Section 1033?

Section 1033 of Dodd-Frank (12 U.S.C. § 5533) requires covered financial institutions to make consumer financial data available to consumers and authorized third parties upon the consumer's request, in a format that is usable and accessible electronically. The CFPB's implementing rule — sometimes called the "1033 rule" or the "Personal Financial Data Rights rule" — operationalizes this right.

The CFPB finalized this rule in October 2024. The rule establishes requirements for financial institutions (as data providers) and third-party apps and fintechs (as data recipients). Fintechs should review the current rule text and CFPB guidance at consumerfinance.gov for the most current requirements, as the rule is subject to litigation and implementation phased timelines.

Who Is Covered by the Section 1033 Rule?

Data Providers (Obligated Parties)

The 1033 rule applies to "data providers" — financial institutions that hold consumer accounts — including banks, credit unions, credit card issuers, and certain other covered financial service providers. Data providers are required to make consumer financial data available through secure, standardized developer interfaces (APIs) upon a consumer's request.

Large data providers (above a certain asset threshold) have earlier compliance deadlines. Smaller institutions have extended timelines. The CFPB publishes the phased compliance schedule in the rule.

Third Parties (Data Recipients)

Fintechs that access consumer financial data on behalf of consumers — such as personal financial management apps, account aggregators, payment initiation services, and lending platforms — are "third parties" or "data recipients" under the rule. Data recipients have obligations including:

  • Limiting data use to the specific purposes the consumer authorized
  • Not using consumer data for targeted advertising
  • Not selling consumer data
  • Retaining data only as long as necessary for the authorized purpose
  • Maintaining reasonable security practices
  • Providing consumer-facing disclosures about data use

Key Requirements Under the Section 1033 Rule

For Data Providers

  • Provide consumer financial data through developer interfaces (APIs) that meet CFPB performance standards
  • Make available specified data types — including transaction data, account balance, upcoming bill information, and terms and conditions
  • Not charge consumers or authorized third parties for access to this data
  • Not deny or restrict access based on the third party's business model or competitive concerns
  • Implement reasonable security measures for developer interfaces

For Data Recipients (Fintechs)

  • Obtain authorization from consumers before accessing their data — through a standardized authorization mechanism
  • Limit data collection and use to what the consumer authorized
  • Not engage in secondary use of data (advertising, sale, sharing beyond the authorized purpose)
  • Honor consumer revocation of authorization promptly
  • Maintain data security practices appropriate for the sensitivity of the data
  • Provide clear, consumer-facing disclosures about data access and use

How Open Banking Creates Fintech Opportunities

Section 1033 has significant positive implications for fintechs as data recipients. It creates:

  • Standardized data access: Fintechs no longer need to rely on screen scraping or ad hoc data sharing agreements — they can access consumer-consented data through standardized APIs
  • Expanded market opportunity: With consumer-consented access to financial data, fintechs can build more personalized products — credit underwriting using cash flow data, financial management tools, payment initiation services, and more
  • Competitive data portability: Consumers can more easily move their financial data to competing services, reducing switching costs and increasing competition

Open Banking and Data Privacy

The Section 1033 rule intersects with existing data privacy laws. Fintechs accessing consumer financial data must comply with the Gramm-Leach-Bliley Act (which governs the privacy of financial information), applicable state privacy laws including CCPA, and the 1033 rule's own data use limitations. Building a compliant open banking data governance program requires addressing all three frameworks.

Frequently Asked Questions

When do banks have to comply with the Section 1033 rule?

The CFPB's Section 1033 rule includes a phased compliance schedule based on the size of the data provider. Large banks had earlier deadlines; smaller institutions have extended timelines. The specific compliance dates are published in the final rule at consumerfinance.gov and are subject to change as implementation proceeds.

What data must be shared under Section 1033?

The CFPB's rule specifies covered data types, including transaction information, account balance, upcoming bill payment information, and account terms and conditions. The rule does not require sharing all data a financial institution holds — it focuses on data the consumer could use to understand their account and manage their finances.

Can fintechs still use screen scraping after Section 1033?

The 1033 rule establishes standardized API access as the preferred method. The rule does not explicitly prohibit screen scraping, but data providers are not required to facilitate it and may restrict it. As API-based access becomes available, reliance on screen scraping will likely decrease and may become less viable.

Does Section 1033 apply to crypto or digital asset accounts?

The CFPB's current 1033 rule focuses on traditional financial accounts — bank accounts, credit card accounts, and similar products. Whether the rule extends to crypto or digital asset accounts is an evolving question that fintechs in this space should monitor closely.

 

This article is for educational purposes only and does not constitute legal or compliance advice. Section 1033 implementation is ongoing and subject to change. Consult qualified legal counsel and monitor CFPB guidance for current requirements.

 

Talk to the ComplyOne team to get started.

Share this article:

Related Articles