The Consumer Financial Protection Bureau (CFPB) finalized its Personal Financial Data Rights rule under Section 1033 of the Consumer Financial Protection Act, requiring covered financial institutions to provide consumers and authorized third parties secure access to financial data without screen scraping. Compliance deadlines begin in 2026 for the largest depository institutions under CFPB Docket No. CFPB-2023-0052.
This analysis is published for informational purposes and does not constitute legal advice. Covered entities should consult regulatory compliance counsel for institutional implementation strategies.
Which entities are subject to the CFPB Section 1033 mandate?
The rule applies to depository institutions, credit unions, and non-bank financial entities offering consumer checking, savings, credit card, and digital wallet accounts. According to the official rulemaking release published by the CFPB, implementation is phased across five tiers based on institution asset size.
| Tier | Entity Asset Size Threshold | Compliance Mandate Deadline |
|---|---|---|
| Tier 1 | Depository institutions with $250B or more in assets | April 2026 |
| Tier 2 | Depository institutions between $10B and $250B | April 2027 |
| Tier 3 | Depository institutions between $850M and $10B | April 2028 |
| Tier 4 | Depository institutions between $250M and $850M | April 2029 |
| Tier 5 | Depository institutions under $250M | April 2030 |
What technical standards govern developer interfaces?
Covered institutions must build secure developer APIs that eliminate reliance on consumer credential sharing and screen scraping. Authorized third parties must obtain explicit, re-certified annual consent and restrict data usage strictly to providing the requested financial product.
What this means in practice
- Build standardized APIs: Transition developer access protocols from legacy screen-scraping portals to secure OAuth-based developer interfaces.
- Implement annual consent management: Build consumer-facing access portals allowing users to view and revoke third-party data access permissions.
- Restrict secondary data monetization: Update third-party vendor agreements to prohibit data reselling or secondary marketing use.

