Guide
Open banking and CFPB Section 1033 obligations
Section 1033 of the Dodd-Frank Act gives consumers the right to access their financial data and, importantly, to authorize third parties to access it on their behalf. The CFPB rulemaking that implements it turns a statutory principle into concrete duties for the institutions that hold the data and the parties that receive it. For any fintech that either exposes data or consumes it, the rule reshapes how access, consent, and security are handled.
Data access and covered information
The rule requires covered data providers to make specified account information available to consumers and their authorized third parties through a machine-readable interface, without charging a fee for access. Covered data typically includes transaction history, account balances, terms, and information needed to initiate payments. The provider has to maintain a reliable developer interface, meet performance and availability expectations, and avoid practices that effectively block access, such as forcing credential sharing instead of a proper interface.
Authorization, third parties, and security
A third party seeking data must obtain informed consumer authorization, limit its collection and use to what the consumer authorized, and honor revocation. Data can only be used for the requested product or service, and secondary uses like targeted marketing are constrained. Everyone in the chain carries data-security obligations. The move away from screen scraping toward tokenized, permissioned access is a central goal, and readiness means both the interface and the governance around consent have to be in place.
Tracking a phasing, evolving rule
Section 1033 obligations phase in over time and depend on an institution size and role, which makes a static checklist unreliable. The Protocol Collective provides this as an owned single-file, regulator-mapped compliance dashboard: paid once, owned outright, updated for life, and built from public regulatory frameworks. Each requirement maps to its source so a provider or third party can see what applies to its role and keep one current view as the rule takes effect.
Explore The Protocol Collective
General information about compliance and program structure, not regulatory, legal, tax or financial advice, and no promise of any examination or audit outcome. Built from public frameworks.