On October 19, 2023, the Consumer Financial Protection Bureau (CFPB) announced its long-awaited proposed rule regulating “Personal Financial Data Rights” (the proposed rule). The proposed rule implements Section 1033 of the Dodd-Frank Act, which provides consumers the right to access and port their financial information between banks and other financial entities. CFPB Director Rohit Chopra stated that the proposal would accelerate the shift towards open banking and jumpstart competition in the U.S. financial service sector by giving consumers “the power to walk away from bad service” and switch providers.

The proposed rule would apply to two main categories of entities: 1) data providers like banks, consumer credit lenders, and payment facilitation companies (e.g., digital wallets); and 2) authorized third parties who can access financial data from data providers on consumer’s behalf, including data aggregators.

Requirements Applicable to Data Providers. Data providers would be subject to three main requirements:

  • Requirement to make consumer data available without fees or charges. The proposed rule would require data providers to make consumer account information available, without fees or charges, both to the consumer about whom the account relates, as well as any entity authorized to act on the consumer’s behalf, such as a data aggregator. The range of covered information required to be provided is broad, and includes account information, transaction history, account balance, and upcoming bill information. The proposed rule does not require the disclosure of confidential commercial information (such as algorithms used to derive credit scores and risk predictors), information collected to prevent fraud or other unlawful conduct, and information the provider cannot retrieve in the ordinary course of its business.
  • Requirement to establish and maintain “developer interfaces.” The proposed rule would require providers to “establish and maintain” an accessible “developer interface” for third parties to access consumer-authorized data (for example, through the use of APIs). The performance of the interface must be “commercially reasonable.” Data providers are also prohibited from imposing unreasonable access caps (i.e., limits on how often a third-party authorization request will be fulfilled). They must implement security safeguards consistent with the Gramm-Leach-Bliley Act and the Safeguards Rule. And they must disclose information about themselves and the developer interfaces to ensure that consumers and authorized third parties have the information necessary to make requests and use the interface.1 
  • Requirement to implement standardized formats. The proposed rule would require consumer data to be made available in both “usable” and “standardized” format by consumers and their authorized third parties. To satisfy the “usable” standard, the data must be available in a machine-readable file that a consumer or authorized third party can retain and transfer into a separate information system. As for “standardization,” data providers may either 1) comply with “qualified industry standards” issued by a CFPB-recognized standard-setting body, or 2) if no such standards exist, make covered data available in a format that is “widely used by the developer interfaces of other similarly situated data providers with respect to similar data and is readily usable by authorized third parties.” The CFPB sets forth a process through which applicants can become a “qualified standard setting body,” which includes the applicant having to show that they develop their standards through a “fair, open, and inclusive” method.

Authorized Third Parties. Third parties would be subject to the following main requirements, among others.

The CFPB proposes to implement the rule in phases, establishing a staggered effective date starting at six months for the largest banks and firms, and extending to four years for the smallest.

Next Steps

The proposed rule is likely to undergo some revision before being finalized sometime in fall 2024. Interested parties may submit public comments to the CFPB on or before December 29, 2023. We encourage businesses interested in and potentially affected by the CFPB’s proposed rule to submit comments. Wilson Sonsini Goodrich & Rosati routinely advises companies on submitting public comments on proposed rules in the fintech, privacy, and security areas. For more information about this alert, please contact Maneesha MithalLibby Weingarten, or any member of the firm’s privacy and cybersecurity or fintech and financial services practices.

Doo Lee contributed to the preparation of this post.


[1] The CFPB details certain risks associated with the practice of screen-scraping and states that “[t]he CFPB expects that third parties would no longer use screen scraping to access covered financial data once data providers have compliant interfaces for third parties.” Notice of Proposed Rulemaking at 213.