blog

Main Street Ledger: What’s at Stake as the CFPB Reconsiders Its Personal Financial Data Rights Rule

On August 4, the Consumer Financial Protection Bureau (CFPB) submitted its reconsideration of the Personal Financial Data Rights Rule to the White House Office of Information and Regulatory Affairs, commonly known as OIRA. The submission marks another step toward publication of a proposed rule revisiting the CFPB’s framework for implementing Section 1033 of the Dodd-Frank Act.

The timing makes it worth revisiting what CBA told the CFPB last October, when the Bureau asked the public for input on how it should reconsider the rule.

CBA’s starting point was straightforward: consumers should have access to their own financial information. At the same time, CBA urged the CFPB to remain anchored to the text Congress actually enacted. Section 1033 requires covered institutions to make certain information available to consumers and directs the Bureau to promote standardized formats. CBA has consistently argued that the statute does not itself establish the broader open-banking framework the prior rule attempted to create.

Against that backdrop, CBA focused its October 2025 comments on four issues the CFPB itself identified for reconsideration: who can request a consumer’s information, fees, information security and data privacy.

Who counts as a consumer’s representative? Section 1033 requires covered financial institutions to make information available “to a consumer.” Yet, the prior rule extended that framework to certain third parties and data aggregators, reasoning that they acted on a consumer’s behalf. CBA urged the CFPB to reconsider that interpretation, arguing that commercial companies using consumer data to provide their own products and services are not “consumers,” nor are they “representatives acting on behalf of an individual,” due to the fact they are operating with the consumer in a business relationship, rather than a fiduciary relationship.  More broadly, CBA cautioned against using that language as a basis for regulatory obligations that Congress did not expressly include in Section 1033.

Who pays for data access? Secure data sharing has real costs. Banks must build, maintain and continually improve the technology that allows consumer information to move safely. The prior rule prohibited data providers from charging third parties and data aggregators for access to those systems. CBA urged the CFPB to reverse that prohibition and allow market participants to negotiate fees as part of their business relationships. The October letter emphasized that Section 1033 does not expressly prohibit fees and warned that a one-sided restriction could discourage continued investment in the technology that supports secure data sharing.

How should consumer information be protected? CBA urged the CFPB to explicitly prohibit screen scraping, a method of accessing account information that can require consumers to provide banking credentials to third parties. CBA also called for clearer guidance on banks’ responsibilities when managing risks associated with third parties, consistent with expectations imposed by prudential regulators. The letter separately reiterated concerns about requiring the sharing of payment-initiation information without adequate safeguards because compromised information could increase fraud risks for consumers.

What happens to data after it is shared? CBA supported retaining limits on how third parties can use consumer information for purposes beyond the service the consumer actually requested. We also called for clearer rules governing consent and revocation and stronger limits on how data aggregators access and use financial information. Consumers should understand who has their data, why they have it and how to stop that access when they choose.

The CFPB’s forthcoming proposal will show how the agency has weighed those questions. As CBA emphasized last fall, a durable approach should protect consumers’ ability to access their financial information while keeping security, privacy, competition and the limits Congress established at the center of the rule.

Consumer access matters. So does accountability. Any final framework should give consumers meaningful control over their information while staying faithful to what Section 1033 actually says.


Wall Street Journal Editorial: Changes Still Needed on Clarity Act

What Happened: In a new piece published this week, The Wall Street Journal Editorial Board urged Senators to consider changes to the Clarity Act, such as closing the loophole that allows stablecoin issuers to pay interest by letting crypto exchanges offer “rewards” for what are essentially banking services and establishing stricter ethics guidelines on federal officials issuing and promoting cryptocurrencies while in office.

Why It Matters: Senate Majority Leader John Thune (R-S.D.) this week had to decide whether to bring the Clarity Act to the Senate floor for a cloture vote, a procedural hurdle the Senate must clear before it can begin formal debate on a bill. It is not a vote on whether the bill becomes law, but on whether the Senate should move forward with considering it.

  • Leader Thune ended up not bringing the Clarity Act to the floor for a cloture vote after a number of Senators signaled they would not support the legislation as is.

What They’re Saying: As The Wall Street Journal Editorial Board said in its piece:

  • “Congress often passes legislation riddled with policy land mines because the Members don’t want to do the hard work of defusing them. A case in point is the crypto regulation bill now in the Senate that Republicans are rushing to pass before they leave town this week.”
  • “The problem is the bill also includes regulatory loopholes that could cause problems in the financial system. One provision would undermine the Genius Act’s prohibition on stablecoin issuers paying interest by letting crypto exchanges offer “rewards” for what are essentially banking services […] This is a particular risk for small banks that use interest payments to attract deposits. Big banks don’t have to pay as much in interest since they benefit from their too-big-to-fail imprimatur. The Clarity Act would bless a workaround to the Genius Act by letting issuers arrange deals with crypto exchanges to pay “rewards” to customers that hold stablecoins.”

Dive Deeper: To read the full piece, click HERE.

Report: CFPB Open Banking Rule Heads to White House for Review 

What’s Happening: As POLITICO reports, the CFPB transmitted its highly-anticipated proposal to rewrite rules governing access to consumers’ financial data to the White House Office of Management and Budget’s (OMB) Office of Information and Regulatory Affairs (OIRA) for review, indicating the proposal will soon be released to the public. 

  • While the timeframe between submission of a rule to OIRA and release to the public in the Federal Register can vary, similar significant rulemakings by the CFPB under the current Administration have taken between two and three weeks from receipt by OIRA to publication. 

Why It Matters: The proposal, which would implement Section 1033 of the Dodd-Frank Act, is intended to reconsider a Biden-era rule that would require banks to make consumer data available to data aggregators and fintech companies.

  • That rule prohibited banks from charging data aggregators and fintech companies for access to customers’ financial information but allowed those data aggregators and fintech companies themselves to subsequently charge fees.

Looking Back: The Biden-era rule was challenged in court, and is not currently in effect until the CFPB completes its ongoing efforts to revise it. To that end, the CFPB last year issued an Advance Notice of Proposed Rulemaking asking questions about several aspects of the rule, including fee limitations, information security, and data privacy.  

Between the Lines: Acting Director Russ Vought’s tenure as Acting CFPB director ended Aug. 1. He remains director of OMB, whose office is now reviewing the proposal. Mark Paoletta is serving as Acting CFPB Director while the Senate considers Brian Johnson’s nomination to lead the Bureau.

Dive Deeper: To read more, click HERE.

Impostor Scams Have Already Defrauded Americans of $1.8B This Year. Here’s How to Spot One. 

What Happened: As Washington Post columnist Michelle Singletary details in a new column, the increased sophistication and prevalence of impostor scams continue to plague hardworking Americans out of their money.

Why It Matters: Impostor scams – or schemes that criminals use to impersonate an official from a trusted organization, such as a government, law enforcement agency or bank – topped the nation’s fraud reports last year, with more than one million complaints filed and $3.5 billion in losses, according to the Federal Trade Commission (FTC). 

  • In the first half of this year, people have already reported losing $1.8 billion to impostor scams.

What They’re Saying: As the FTC said earlier this year: 

  • “These scams lured consumers through text, phone, email, social media, search engine results and other means […] Some of the costliest impersonation scams start with a fake security alert, often from a bank. People are convinced to move money to ‘protect’ it, with their losses often limited only by their available funds.”

Yes, and: M&T Bank’s Retail Market Leader for Greater Washington Rob Wehner said this of the impostor scam that Singletary details in her column:

  • “We’re pleased that the quick actions of our branch team, bank fraud specialists and layered safeguards helped to prevent this scam […] Fraudsters are becoming increasingly sophisticated, often creating a false sense of urgency and impersonating trusted organizations to convince people to move their money. Our employees are trained to ask thoughtful questions, recognize warning signs, and escalate suspicious activity for immediate review.”

Between the Lines: In the column, Singletary details immediate steps to take if you or a loved one falls victim to an impostor scam:

  • Contact your financial institution by calling the fraud department directly using the number printed on your physical card.
  • Freeze all compromised accounts and ask for new account numbers.
  • Change your passwords and enable two-factor authentication using an authenticator app.
  • Disconnect remote access.
  • Don’t answer calls you don’t recognize.
  • Report the crime and contact local police.
  • Freeze your credit file
  • Monitor your credit history.
  • Get support.

Dive Deeper: To read the full column, click HERE.

Stay
Connected

    Sign up to receive our updates.