The Consumer Financial Protection Bureau's Section 1033 open-banking rule is legally in force but not currently enforceable on its original schedule: a federal district court in Kentucky stayed the rule's tiered compliance dates on October 29, 2025, in Forcht Bank, N.A. v. CFPB, while the CFPB itself reconsiders the rule's fee, privacy, and access provisions.
For compliance officers and legal-ops teams tracking the fintech data-access landscape, that split status — a rule that exists on the books but whose deadlines do not currently bind anyone — is the operative fact for planning purposes in 2026. This explainer walks through what the rule requires, why its compliance dates are stayed, and what a reasonable compliance calendar looks like while the reconsideration proceeds.
What Is the Section 1033 Rule, and What Does It Require?

A Section 1033 rule is a Consumer Financial Protection Bureau regulation that implements the data-access provision of the Dodd-Frank Act by requiring covered financial institutions to make consumers' own account and transaction data available to them, and to authorized third parties, on request. The CFPB finalized the rule as "Required Rulemaking on Personal Financial Data Rights," codified at 12 CFR Part 1033, with an effective date of November 18, 2024 (89 FR 90989).
The rule designates two categories of regulated actors. "Data providers" are banks, credit unions, card issuers, and other institutions that hold consumer financial account data — checking and savings accounts, credit cards, and similar products. "Authorized third parties," typically fintech apps and data aggregators, may request that data on a consumer's behalf once the consumer has granted authorization through a standardized process. Data providers must make covered data available through a secure interface, and the rule bars data providers from charging consumers for that access.
The regulation also created a framework for CFPB recognition of standard-setting bodies that can issue technical specifications data providers and third parties use to build compliant interfaces — a mechanism the rule's text separates from the substantive data-access obligations in Subparts B and C.
Is the Rule in Effect in August 2026?
The rule's text remains part of the Code of Federal Regulations, but its compliance dates are currently stayed, so no data provider is presently required to meet a Section 1033 deadline. The stay followed a challenge brought by a bank and banking trade associations in the U.S. District Court for the Eastern District of Kentucky, case number 5:24-cv-304-DCR.
On July 29, 2025, the court granted a stay after the CFPB told the court it intended to "comprehensively reexamine" the rule and develop "a well-reasoned approach," according to the CFPB's own account of the reconsideration proceeding. On October 29, 2025, the court's order specifically stayed the rule's compliance dates set out in 12 CFR 1033.121(b) — the tiered schedule described below — pending the outcome of the bureau's reconsideration.
That leaves the underlying regulatory text technically effective while the operative deadlines that would force institutions to build compliant interfaces are suspended. Compliance teams should not read the stay as a repeal: it is a litigation-driven pause tied to a specific case and a specific reconsideration docket, and it can be lifted, extended, or superseded by a new final rule.
Which Institutions Does the Original Compliance Schedule Cover?
The 2024 final rule set five compliance tiers keyed to institution size, phasing in obligations for the largest data providers first. These are the dates as adopted in the final rule and as currently stayed — not a forecast of when a revised rule might set new dates.
| Tier | Covered Data Providers | Original Compliance Date |
|---|---|---|
| Tier 1 | Depository institutions with at least $250 billion in total assets; nondepository providers with at least $10 billion in total receipts | April 1, 2026 |
| Tier 2 | Depository institutions with $10 billion to $250 billion in assets; smaller nondepository providers above the receipts threshold | April 1, 2027 |
| Tier 3 | Depository institutions with $3 billion to $10 billion in assets | April 1, 2028 |
| Tier 4 | Depository institutions with $1.5 billion to $3 billion in assets | April 1, 2029 |
| Tier 5 | Depository institutions with $850 million to $1.5 billion in assets | April 1, 2030 |
Depository institutions below $850 million in assets fall outside the rule's coverage entirely under the original text. Because the October 29, 2025 stay suspends these dates rather than deleting them, they remain the reference points a revised rule would either keep, shift, or replace — which is why compliance calendars built around this table should carry an explicit caveat rather than a fixed deadline.
What Is the CFPB Reconsidering, and Why?
The CFPB opened a formal reconsideration on August 22, 2025, with an advance notice of proposed rulemaking published in the Federal Register under Docket No. CFPB-2025-0037. An advance notice of proposed rulemaking is a preliminary step in which an agency solicits public input on the substance of a possible rule change before drafting formal proposed regulatory text.
The notice asked for comment on four issues central to how the rule would operate in practice:
- How to define a "representative" authorized to request data on a consumer's behalf, including whether the category should extend beyond fiduciaries to other third parties.
- Whether data providers should be permitted to charge fees to offset compliance costs, given that the 2024 final rule bars charging consumers or authorized third parties for data access.
- Information-security threats associated with data storage and transmission under the rule, and the cost-benefit tradeoffs of the interface requirements.
- Consumer privacy risks, including the possibility that data obtained under the rule could be licensed or sold by third parties without the consumer's informed awareness.
The comment period on the advance notice closed October 21, 2025. The CFPB has indicated it intends to address an extension of the compliance dates through a subsequent notice of proposed rulemaking, according to the bureau's compliance-resources guidance — meaning any new deadlines would themselves go through public notice and comment before taking effect.
What Should Compliance and Legal-Ops Teams Do Now?
Treat the current stay as a planning window, not a reason to stand down entirely. A reasonable interim posture for institutions that would fall under Tier 1 or Tier 2 if the original schedule resumes includes:
- Confirm which tier the institution would occupy under the existing asset and receipts thresholds, since that determines exposure if the stay is lifted with the original dates intact.
- Track the CFPB's reconsideration docket (CFPB-2025-0037) and the Eastern District of Kentucky case docket for the next procedural filing, rather than relying on secondhand summaries of either.
- Hold vendor and interface-build decisions to a scoping stage rather than a full commitment, since the fee and representative-definition questions under reconsideration could change interface requirements materially.
- Flag the stay's case-specific basis to business units that may treat "stayed" as "cancelled" — the distinction matters for budget and staffing conversations tied to any future date.
What this means in practice: institutions should not build to the original April 2026 Tier 1 date as a hard deadline, but they also should not treat the rule as dead, since the CFPB has stated an intent to issue a revised rule rather than abandon rulemaking under Section 1033 altogether. Legal-ops teams tracking data-sharing agreements with fintech partners should revisit those agreements' assumptions about mandated free access, since the fee question is explicitly open. Procurement conversations about interface vendors are better framed as contingent options than locked builds until the reconsideration produces proposed text. This article provides information about the status of federal rulemaking and litigation; it is not legal advice, and institutions should consult qualified counsel about how the rule and its stay apply to their specific circumstances.
Frequently Asked Questions
Does the stay mean Section 1033 has been repealed? No. The stay suspends the rule's compliance dates in a specific case, Forcht Bank, N.A. v. CFPB, while the CFPB reconsiders parts of the rule. The regulatory text at 12 CFR Part 1033 remains on the books, and the CFPB has signaled it plans to issue a revised rule rather than abandon Section 1033 rulemaking.
Can data providers charge consumers for access under the current rule? Under the 2024 final rule as written, no — data providers may not charge consumers or authorized third parties for data access. Whether that prohibition survives is one of the four questions the CFPB is reconsidering in its August 2025 advance notice.
When will a revised rule take effect? No effective date exists yet. The CFPB has indicated any extension of compliance dates would go through a separate notice of proposed rulemaking with its own comment period, so a revised timeline would only become binding after that process concludes.
Which institutions were closest to a compliance deadline before the stay? Tier 1 data providers — depository institutions with at least $250 billion in total assets and nondepository providers with at least $10 billion in total receipts — faced the earliest original date, April 1, 2026, before the October 2025 stay suspended it.
For a related digital perspective, read The Ultimate Guide to Watching the "Star Wars" Series in the Best Order.
For more context, read The Ultimate Guide to Watching the "Star Wars" Series in the Best Order.
