Skip to content
Monday, August 24, 2026
3G TIMESFINTECH LAW · LEGAL TECH · COMPLIANCE
Home / Regulation
Regulation

CFPB Finalizes Open-Banking Rule Under Section 1033, Mandating Secure Financial Data Access

Analyze the CFPB final rule under Section 1033 of the Consumer Financial Protection Act, establishing developer data access standards.

William Elliott · August 24, 2026 · 2 min read
ShareXFacebookLinkedInTelegramEmail
CFPB Finalizes Open-Banking Rule Under Section 1033, Mandating Secure Financial Data Access

The Consumer Financial Protection Bureau (CFPB) finalized its Personal Financial Data Rights rule under Section 1033 of the Consumer Financial Protection Act, requiring covered financial institutions to provide consumers and authorized third parties secure access to financial data without screen scraping. Compliance deadlines begin in 2026 for the largest depository institutions under CFPB Docket No. CFPB-2023-0052.

This analysis is published for informational purposes and does not constitute legal advice. Covered entities should consult regulatory compliance counsel for institutional implementation strategies.

Which entities are subject to the CFPB Section 1033 mandate?

The rule applies to depository institutions, credit unions, and non-bank financial entities offering consumer checking, savings, credit card, and digital wallet accounts. According to the official rulemaking release published by the CFPB, implementation is phased across five tiers based on institution asset size.

TierEntity Asset Size ThresholdCompliance Mandate Deadline
Tier 1Depository institutions with $250B or more in assetsApril 2026
Tier 2Depository institutions between $10B and $250BApril 2027
Tier 3Depository institutions between $850M and $10BApril 2028
Tier 4Depository institutions between $250M and $850MApril 2029
Tier 5Depository institutions under $250MApril 2030

What technical standards govern developer interfaces?

Covered institutions must build secure developer APIs that eliminate reliance on consumer credential sharing and screen scraping. Authorized third parties must obtain explicit, re-certified annual consent and restrict data usage strictly to providing the requested financial product.

What this means in practice