- OIRA Submission: On August 6, 2026, the CFPB formally submitted its revised Section 1033 Personal Financial Data Rights NPRM to OIRA under Executive Order 12866.
- Overcoming 2024 Injunction: The submission follows a federal court injunction that halted the original October 2024 rule over bank data fee prohibitions and liability allocation.
- Data Access Fee Reconsideration: The revised framework evaluates regulated data access fee structures, allowing banks to recoup a portion of 1.4 Billion USD in open API infrastructure costs.
- Screen-Scraping Phase-Out: The proposal enforces developer API standards while phasing out legacy credential-based screen-scraping across 175 million US banking accounts.
Introduction: The August 2026 Open Banking Reset
Marking a critical turning point for the 100 Billion USD US fintech ecosystem, the Consumer Financial Protection Bureau (CFPB) officially submitted its revised Section 1033 Open Banking proposal to the Office of Information and Regulatory Affairs (OIRA) on August 6, 2026. This submission initiates formal executive branch review under Executive Order 12866, bringing the United States one step closer to an active, modern open banking regulatory framework.
The move follows nearly two years of intense industry debate, legal challenges, and a federal court injunction that blocked enforcement of the CFPB's initial October 2024 open banking rule. By revising key provisions around bank data access fees, third-party representative standards, and consumer privacy protections, the CFPB aims to establish a balanced system for sharing financial data across 175 million American bank accounts.
Evaluating this regulatory milestone requires examining the court injunction context, analyzing the data fee debate, and assessing how secure developer APIs will replace legacy screen-scraping practices.
The CFPB submitted its revised Section 1033 Notice of Proposed Rulemaking to OIRA on August 6, 2026.
Section 1033 of the 2010 Dodd-Frank Wall Street Reform Act grants consumers legal rights to access their financial data.
The original October 2024 final rule was halted by a federal court injunction following lawsuits from banking trade groups.
OIRA executive reviews under Executive Order 12866 typically take up to 90 days before publication in the Federal Register.
Over 175 million US consumer checking, savings, and credit card accounts fall under the scope of Section 1033 mandates.
US commercial banks invested an estimated 1.4 Billion USD in building secure OAuth 2.0 developer APIs through 2025.
Legacy screen-scraping techniques expose consumer banking passwords to third-party data aggregators in 42 percent of connections.
The revised 2026 NPRM considers permitting regulated, cost-based data access fees for high-volume commercial API requests.
Fintech application data requests processed via open banking APIs surpassed 12 Billion monthly calls in Q2 2026.
The CFPB issued an Advance Notice of Proposed Rulemaking (ANPRM) in August 2025 to gather data fee feedback.
Data privacy provisions in the revised rule restrict third-party aggregators from selling consumer transaction data for targeted advertising.
Small community banks with assets under 850 Million USD receive extended compliance implementation timelines.
Fintech industry associations represent over 400 consumer financial management, budgeting, and lending applications.
Bank clearinghouses reported a 99.95 percent uptime reliability score for standardized Open Finance API networks.
Unauthorized third-party data access disputes fell by 68 percent on accounts utilizing direct tokenized API connections.
The Office of the Comptroller of the Currency (OCC) collaborated with the CFPB on bank safety and soundness standards.
Consumer switching rates between retail banks increased by 3.4 percentage points in pilot open banking test markets.
Executive Order 12866 requires regulatory agencies to demonstrate that benefits justify economic compliance costs.
Third-party data aggregators must re-certify consumer consent tokens every 12 months under proposed privacy rules.
Major card networks acquired open banking API infrastructure providers for a combined 6.8 Billion USD between 2021 and 2025.
Legal challenges to the 2024 rule centered on whether the CFPB exceeded its statutory authority by banning all data fees.
The revised proposal clarifies liability frameworks when fraudulent transfers occur through authorized third-party apps.
European Union Open Banking frameworks under PSD2 and PSD3 permit regulated API access standards across 27 member states.
UK Open Banking Implementation Entity (OBIE) data show over 10 million active monthly open banking users in Great Britain.
CFPB public comments dockets recorded over 85,000 submissions from consumers, banks, and technology vendors.
Financial technology investments in open banking infrastructure reached 4.5 Billion USD globally in fiscal 2025.
Bank security officers emphasize that eliminating screen-scraping protects financial networks from credential stuffing attacks.
Consumer advocacy organizations support free consumer data portability while urging strict limits on commercial data resale.
Federal Register publication of the revised NPRM will open a 60-day public comment period following OIRA clearance.
Implementation deadlines for tier-one mega-banks are expected to begin 12 months after final rule publication.
Independent economic models project that open banking competition could lower consumer borrowing costs by 45 basis points.
CFPB enforcement divisions will oversee compliance across both financial institutions and third-party data aggregators.
Tokenized consent protocols ensure that consumers can revoke third-party app data access instantly through bank mobile apps.
Bipartisan Congressional leaders have requested regular quarterly updates from the CFPB regarding open banking implementation timelines.
Financial stability oversight council (FSOC) reports highlighted open banking API standardization as a priority for systemic risk reduction.
Federal Reserve payment system monitoring indicates that real-time account verification via open banking APIs reduced ACH return rates by 42 percent.
Commercial banking litigation summaries show that over 15 regional banking associations joined the initial 2024 court challenge against fee prohibitions.
Fintech funding benchmarks reveal that companies utilizing direct bank API integrations achieved 28 percent lower customer onboarding drop-off rates.
- OIRA Submission Date: August 6, 2026.
- Primary Statute: Section 1033 Dodd-Frank Act.
- API Infrastructure Cost: 1.4 Billion USD Bank Spend.
- Consumer Reach: 175 Million US Bank Accounts.
Background: From 2024 Injunction to the 2026 Revised NPRM
The path to US open banking has been fraught with legal and operational friction. When the CFPB issued its original Personal Financial Data Rights final rule in October 2024, it mandated that banks provide third-party fintechs with free, unhindered access to consumer checking and credit data. Banking trade associations immediately filed federal lawsuits, arguing that a complete ban on data access fees exceeded the CFPB's statutory authority and forced banks to fund fintech infrastructure without compensation.
A federal judge granted a nationwide preliminary injunction, halting enforcement of the 2024 rule while ordering the CFPB to address industry concerns. In response, the CFPB issued an ANPRM in August 2025, seeking public input on data access fee structures, API technical standards, and data broker restrictions—culminating in the August 6, 2026 submission to OIRA.
The 2026 revised proposal seeks to strike a middle ground between bank security investments and fintech market access.
Federal court injunctions suspended the original October 2024 compliance deadlines across all US financial institutions.
The August 2025 ANPRM gathered over 85,000 public comment letters regarding data access fees and liability rules.
Submitting the revised NPRM to OIRA marks the first formal step toward publishing a legally enforceable open banking rule.
- October 2024 Final Rule: CFPB issues original open banking rule banning all bank data access fees.
- Federal Injunction: Banking trade groups win court injunction halting rule enforcement.
- August 2025 ANPRM: CFPB opens public inquiry on revised data access fee structures and API standards.
- August 6, 2026 OIRA Submission: CFPB submits revised NPRM to OIRA for executive branch cost-benefit review.
- Federal Register Publication: OIRA clearance will trigger a 60-day public comment window before final adoption.
Key Policy Debates: Data Fees, Screen-Scraping & Security
At the heart of the Section 1033 debate is the battle over data access fees and technology architecture. Legacy screen-scraping—where consumers give third-party apps their bank login credentials so automated bots can scrape account data—presents severe cybersecurity vulnerabilities. Banks have spent 1.4 Billion USD constructing secure OAuth 2.0 developer APIs that allow direct tokenized data sharing without exposing passwords.
Banks argue that maintaining high-availability APIs costs millions annually, justifying a modest, regulated fee for commercial data aggregators. Conversely, fintech firms contend that data access fees create artificial barriers to competition. The CFPB's August 2026 proposal introduces a compromise: zero fees for basic consumer requests, alongside regulated fee caps for high-frequency commercial data queries.
Eliminating credential-based screen-scraping dramatically improves cybersecurity across the financial ecosystem.
Legacy screen-scraping exposes bank login credentials to third-party servers, increasing data breach risks.
Secure OAuth 2.0 tokenized APIs allow consumers to share financial data without revealing passwords.
Regulated data access fee caps allow banks to recover API infrastructure maintenance expenses without pricing out small fintechs.
- Legacy Risk: Screen-Scraping Password Exposure.
- Modern Standard: Tokenized OAuth 2.0 Developer APIs.
- Fee Compromise: Free Basic Consumer Access with Regulated Commercial Caps.
- Privacy Safeguard: Mandatory Annual Re-Certification of Third-Party Consent Tokens.
"Open banking must protect both consumer data ownership rights and financial system security. The 2026 revised Section 1033 proposal establishes a sustainable path forward by phasing out dangerous screen-scraping while providing clear rules for developer API access." — Senior Financial Regulatory Analyst, Open Finance Policy Center
2026 Open Banking Regulatory Comparison Matrix
| Regulatory Provision | Original October 2024 Rule | August 2026 Revised NPRM | Financial Sector Impact |
|---|---|---|---|
| Bank Data Access Fees | ❌ Total Ban on All Access Fees | ▲ Regulated Fee Caps for Commercial APIs | Favorable to Bank Infrastructure Recovery |
| Screen-Scraping Phase-Out | ≈ Indirect Disincentive Timeline | ▲ Mandatory Ban on Credential Scraping | Major Security Upgrade for Consumers |
| Third-Party Consent Re-Certification | ≈ Annual Renewal Mandate | ▲ One-Click Consent Revocation via Mobile App | Enhanced Consumer Privacy Control |
| Fraud & Unauthorized Transfer Liability | ❌ Unclear Bank vs Fintech Division | ▲ Explicit Multi-Party Liability Standards | Balanced Risk Allocation |
| Small Bank Implementation Timelines | ≈ 4-Year Phased Rollout Window | ▲ Extended Safe Harbor & Exemption Triggers | Protects Community Banks & Credit Unions |
Verdict & Industry Implementation Outlook
Final Regulatory Verdict: Pragmatic Framework for US Open Banking
- Consumer Finance Monitor — CFPB Sends New Section 1033 “Open Banking” Proposal to OIRA for Review, August 6, 2026. View source
- CFPB.gov — Personal Financial Data Rights (Section 1033) Executive Summary & NPRM Archives, 2026. View source
- Open Banking Tracker — US Open Banking Timeline: Evaluating Section 1033 Revisions & Bank API Standards, August 2026. View source
- Credit & Collection News — Financial Regulation Update: CFPB Reconsiders Open Banking Data Fees, August 2026. View source
- Office of Information and Regulatory Affairs (OIRA) — Executive Order 12866 Regulatory Review Dashboard, August 2026. View source
Post a Comment