
The Consumer Financial Protection Bureau announced a comprehensive reconsideration of its Personal Financial Data Rights rule on August 22, 2025, signaling potential significant changes to how financial institutions handle consumer data access requests under section 1033 of the Dodd-Frank Act. This advance notice of proposed rulemaking addresses four fundamental issues that have generated substantial concern among banks and financial service providers since the original rule's publication in November 2024.
The reconsideration follows a lawsuit filed by a bank, a national trade association representing banks, and a state trade association in the United States District Court for the Eastern District of Kentucky. On July 29, 2025, the court granted a motion to stay proceedings after the Bureau announced its intention to comprehensively reexamine the rule alongside stakeholders to develop an approach that addresses identified defects.
The first major issue under reconsideration concerns who qualifies as a "representative" authorized to access consumer financial data. Under the Dodd-Frank Act, a consumer includes an individual or an agent, trustee, or representative acting on behalf of an individual. At common law, agents and trustees carry fiduciary duties including care, loyalty, good faith, and confidentiality.
The original Personal Financial Data Rights rule interpreted "representative acting on behalf of an individual" broadly to include third parties accessing consumer data pursuant to certain authorization procedures and substantive obligations, without requiring fiduciary duties. The Bureau estimated that more than 100 million consumers have used consumer-authorized data access through third parties as of 2024.
The CFPB is now questioning whether this interpretation represents the best reading of statutory language. If "representative" is interpreted to require fiduciary duties similar to agents and trustees, it would substantially limit which third parties could access consumer financial data under section 1033. This distinction carries enormous implications for financial technology companies and other service providers that have built business models around accessing consumer financial data without establishing formal fiduciary relationships.
For banks and financial institutions, this reconsideration could dramatically reduce the number and types of entities requesting consumer data, potentially simplifying compliance obligations while limiting consumer options for financial management tools.
The original rule prohibited data providers from imposing fees or charges on consumers or authorized third parties for establishing or maintaining required interfaces, receiving requests, or making available covered data. Section 1033 of the Dodd-Frank Act remains silent on how the burden of consumers' exercise of data access rights should be shared between consumers and covered persons.
The Bureau is seeking comments and data on whether costs, benefits, or market forces might justify modifying this prohibition. Questions under consideration include reasonable estimates of fixed costs for implementing required standards, marginal costs of responding to individual requests, and how these costs vary by institution size.
Financial institutions have consistently argued that complying with section 1033 requirements imposes substantial costs without corresponding revenue streams. The reconsideration creates opportunity for banks to provide detailed cost data supporting their position that some fee recovery mechanism is necessary and statutorily permissible.
The Bureau is also examining whether there is legal precedent from other federal statutes where agencies have established cost-sharing balances for new statutory rights without explicit congressional authorization. This analysis could determine whether the CFPB has authority to permit reasonable fee recovery even if the statute doesn't explicitly address the issue.
Information security represents perhaps the most critical concern for financial institutions facing section 1033 compliance. The advance notice acknowledges that data breaches have affected sophisticated and well-financed institutions including Yahoo, the Office of Personnel Management, Equifax, Marriott, LinkedIn, Facebook, and even the Office of the Comptroller of the Currency in 2025.
The original rule attempted to address security concerns by prohibiting reliance on screen scraping, requiring adherence to Gramm-Leach-Bliley Act information security standards, and allowing data providers to deny access when granting it would be inconsistent with GLBA-compliant security policies and procedures.
The Bureau is seeking detailed information about fixed costs of establishing adequate information security architecture, how these costs relate to institution size and customer base, and whether the market provides reasonably priced solutions for smaller covered persons. Questions also address whether fiduciary relationships affect cost-benefit analysis regarding information security investments and whether security levels materially vary between businesses with and without fiduciary duties.
Banks and financial institutions should consider how existing legal obligations regarding risk management, Bank Secrecy Act requirements, and Anti-Money Laundering regulations intersect with section 1033 data access requirements. The reconsideration provides opportunity to explain how the original rule's interface access provisions may conflict with these established regulatory frameworks.
The Bureau is also reconsidering whether its reliance on existing GLBA information security standards provides adequate protection and whether additional standards should apply to entities accessing consumer financial data from covered persons.
Consumer financial transaction data reveals extensive information about habits and lifestyle, including sensitive details about medical conditions, financial vulnerability, substance abuse problems, and other high-risk behaviors. The original rule required third parties to obtain express informed consent, prescribed disclosure requirements, and limited third-party collection, use, and disclosure of covered data.
The advance notice acknowledges that very few service platform users actually read user agreements in their entirety. One poll found that only nine percent of American adults reported that they "always" read privacy policies. While individuals remain responsible for the consequences of such inattentiveness, the Bureau recognizes that this creates potential harm from data use for financial profiling and aggressive marketing.
Questions under reconsideration include the prevalence of consumer financial data licensure or sale by bank and non-bank financial institutions, differences in data practices between companies with and without fiduciary duties to clients, and whether the original rule provides adequate privacy protection.
Financial institutions with strong privacy practices and limited data monetization should provide detailed information about their approaches to demonstrate how robust privacy protection can coexist with section 1033 compliance obligations.
The original rule included compliance dates from April 1, 2026, through April 1, 2030, based on entity size. A court order has already stayed these dates by 90 days, pushing the first compliance date to June 30, 2026. The Bureau plans to issue a Notice of Proposed Rulemaking to further extend compliance dates as part of its reconsideration.
Banks and financial institutions should provide detailed information about unexpected difficulties or costs encountered in implementation efforts to date and how long they would need to comply with a substantially revised rule. Implementation timelines should reflect the reality that major revisions may require a complete redesign of compliance systems rather than incremental adjustments to existing work.
This reconsideration represents a critical opportunity for banks and financial institutions to shape the final regulatory framework governing consumer access to financial data. Comments submitted during the 60-day comment period will directly influence the Bureau's approach to fundamental issues, including who can access data, whether fees can offset compliance costs, what security standards apply, and how privacy protection is balanced against data portability.
Financial institutions should coordinate with trade associations and legal counsel to provide comprehensive, data-supported responses addressing the Bureau's specific questions. Particular emphasis should be placed on documenting actual costs of compliance, security challenges specific to regulated financial institutions, and how existing regulatory obligations create complexity for section 1033 implementation.
The reconsideration also highlights the importance of maintaining comprehensive documentation systems that track data access requests, security protocols, cost allocation, and privacy protection measures. As regulations continue evolving, institutions with robust quality management systems will be better positioned to demonstrate compliance and adapt to changing requirements.
Need help maintaining comprehensive compliance documentation as financial data regulations evolve? Contact Qredible to learn how Q-Trust can help your financial institution track data access requests, document security measures, and demonstrate regulatory compliance across multiple frameworks.