The CFPB's Personal Financial Data Rights rule, the agency's implementation of Section 1033 of the Dodd-Frank Act, has cleared its first compliance checkpoint despite a pending legal challenge. For community banks and credit unions, the headline is simple. Open banking is no longer a future scenario to monitor. It is something you have to build.
At its core, §1033 gives consumers the right to access and share their financial data with third parties of their choosing. It also obligates the institutions that hold that data to make it available through secure, standardized interfaces. The rule deliberately steers the market away from credential-based screen scraping toward authenticated, permissioned APIs.
The tiered timeline
Compliance phases in by asset size. The largest institutions go first, and smaller depositories get more runway. That runway is not idle time. The build, vendor selection, and authorization plumbing all need to start well ahead of your own deadline.
- Tier 1Largest depositories · > $250B in assets✓ Active
- Tier 2Mid-size institutions · $10B–$250B⚠ 2027
- Tier 3Community banks & credit unions · < $10B2028
- ExemptSmallest institutions below the CFPB thresholdN/A
The model provider behind your new data-access layer is now a vendor you must risk-rate. Examiners are already treating it that way.
What tier one requires
Even institutions still years from their own deadline should treat the tier-one requirements as the reference architecture. The capabilities below are what a compliant data-sharing program looks like in practice.
- Consumer data-access APIs. Provide standardized, authenticated endpoints for the covered data fields, with no credential sharing.
- Authorization & consent logging. Keep a durable, scoped and time-bound record of who was granted access, to what, and when.
- Third-party sharing governance. Apply diligence and ongoing oversight to the data recipients and aggregators in your ecosystem.
- Revocation on demand. Consumers can withdraw access at any time, and your systems must honor it promptly and verifiably.
What to do now
The litigation creates uncertainty about the edges of the rule, but its direction is clear. Treating a delay as a reprieve is the expensive mistake. Inventory the covered data you hold, map it to your core and digital-banking vendors, and put the third-party providers who will touch consumer data into your formal risk-rating process today. That is the work that takes the longest and that examiners will ask about first.
Zovos maps your §1033 covered-data inventory to your vendor stack automatically and flags every data recipient that belongs in your third-party risk program. The longest part of the build can then start on day one.
This is for information only and is not legal advice. Confirm your institution's tier and obligations against the final rule and counsel before acting.