The Consumer Financial Protection Bureau's Personal Financial Data Rights rule requires covered financial institutions to release consumers' account data — balances, transactions, and bill-payment information — to authorized third parties on request, with the first compliance deadline of April 30, 2026 applying to banks with $250 billion or more in assets. The rule was published in final form on October 22, 2024 under Section 1033 of the Dodd-Frank Act, codified as Regulation P. 3G Times publishes information, not legal advice; firms should take jurisdiction-specific questions to qualified counsel.
The rule is a final rule, not a proposal, and it takes effect in stages: institutions with $250 billion or more in total assets must comply by April 30, 2026, per the compliance-date table in the final rule as published on consumerfinance.gov; institutions between $10 billion and $250 billion follow by April 30, 2027; and those below $10 billion have until April 30, 2028. Nothing in this explainer should be read as a prediction about how the CFPB will enforce the rule in any particular year — that is an open question, and this piece confines itself to what the instrument itself says.
Which institutions does the rule cover?
Coverage turns on two tests in the final rule: the entity must be a "covered person" under Dodd-Frank Section 1002, and it must control or maintain covered data about a consumer. The largest banks, the largest credit-card issuers, and the largest digital wallets and payment apps are inside the perimeter because the rule reaches account providers generally, not just depository institutions. Smaller institutions remain covered but enjoy later compliance dates under the $10 billion threshold built into the rule's phase-in. Providers that only process data without controlling it — pure processors acting on a bank's behalf — sit outside the obligation, per the definitions section of the final rule.
Covered data categories are enumerated, and the enumeration matters more than the marketing term "open banking." It includes historical transaction information, account balances and terms, upcoming bill payments, and the account-verification data that fintech onboarding flows consume.
What must a covered institution actually do?
The operational core is an obligation to establish and maintain an interface — an application programming interface in practice — through which authorized third parties can request and receive covered data. The final rule sets out the sequence a compliance program has to run:
- Build or contract for a data-access interface that meets the rule's performance and availability expectations.
- Authenticate third-party requests against consumer authorization the third party must obtain and document.
- Release the covered data the consumer authorized, in a usable form, without charging the consumer for it.
- Monitor authorization revocations and cut off access when a consumer withdraws consent.
The rule also restricts how the receiving third party may reuse data it collects under an authorization: the recipient must limit secondary use to what the consumer consented to, and it may not use covered data obtained through the interface for targeted advertising or to build cross-institution profiles the consumer did not agree to.
How does the rule treat screen scraping?
The final rule declines to ban screen scraping outright, and that choice is the provision most general coverage skipped. What the rule does instead is create conditions under which scraping should wither: once a bank's interface is live and a third party has authorized access, the bank is permitted to block scraping of the same data by the same third party. Compliance officers should read this as a sequencing problem — the right to block arrives only when the compliant alternative exists, and blocking earlier invites complaints.
This is also where the practical friction will concentrate. Third parties that have relied on credential-based scraping for a decade will need authorization workflows, and banks will need revocation plumbing that actually cuts access off. Neither is a weekend project.
What does the rule say about liability and supervision?
The rule allocates duties asymmetrically: data providers are responsible for the interface and for honoring authorizations, while third parties bear the obligations attached to what they collect — the limits on secondary use, the consent disclosures, and the security duties. Both sides of a data-sharing arrangement can therefore be examined on the same transaction. The CFPB has stated in material accompanying the final rule that it expects to supervise third parties accessing covered data, and firms that are already CFPB-supervised should expect open-banking questions to appear in exam scopes after their compliance date passes.
One boundary worth stating plainly: the rule governs data access, not the underlying product. A fintech that receives data lawfully under the rule is not thereby licensed, and a bank that provides data is not vouching for the recipient's product.
What should compliance and legal-ops teams do now?
Read against the instrument, the practical implications are narrow and concrete:
- Institutions above $250 billion in assets have the shortest runway to the April 30, 2026 date and should already be testing third-party authorization and revocation flows, not just the interface itself.
- Contracts with data aggregators need review against the secondary-use limits, because legacy aggregator agreements routinely permit uses the rule now restricts.
- Fintechs on the receiving side should refresh consent disclosures to match what the rule requires the recipient to state, separate from what the bank states.
- Legal-ops teams should track whether Congress or the Bureau amends or delays the phase-in; as of this explainer's writing, the compliance dates in the published final rule stand.
What the evidence establishes is a final rule with staggered dates, enumerated data categories, and reciprocal duties on providers and recipients. What remains unknown is enforcement posture in the years after each date — that will be set by examination and enforcement practice, not by the text.
For more context, read What to Know About Federal Recreation Fees Before You Book.
