Hero background
Compliance Updates4 min read

CFPB 1033 Explained: Open Banking Status for Lenders (2026)

By Michael Dunleavey
August 4, 2026
section 1033personal financial data rightsopen banking

Section 1033 of the Dodd-Frank Act — better known lately as CFPB 1033 — is the legal foundation for "open banking" in the United States: the idea that your financial data belongs to you, and that you can authorize a trusted third party (a fintech app, or a service that uses an aggregator like Plaid) to access it on your behalf. The CFPB turned that principle into a rule, the Personal Financial Data Rights Rule, which requires banks and other data providers to share covered account and transaction data with consumers and authorized third parties. For lenders, it's worth understanding — even though, right now, it isn't being enforced.

Where the CFPB 1033 rule stands today

The rule exists on paper but is not currently enforceable by the CFPB. The short version:

  • The CFPB finalized the Section 1033 rule in October 2024, with a phased compliance schedule beginning April 1, 2026 for the largest data providers.
  • In late October 2025 (Oct. 29), Judge Danny C. Reeves of the U.S. District Court for the Eastern District of Kentucky issued a preliminary injunction halting the CFPB from enforcing the rule while the agency reconsiders it.
  • The CFPB had already published an Advance Notice of Proposed Rulemaking in August 2025, seeking comment on four issues: who qualifies as an authorized "representative," whether data providers may charge fees for access, whether data-security standards are adequate, and whether privacy protections (including under GLBA) are adequate.
  • A follow-on Notice of Proposed Rulemaking to revise the rule and its dates was anticipated in 2026 and, as of this writing, had not yet published — so the final scope, thresholds, and deadlines could still change.

A note on the "April 1" vs. "June 30, 2026" dates

You may see both cited, and both are legitimate. The rule text codifies all tiered deadlines on April 1 (2026 through 2030), but court orders in the litigation tolled the first operative deadline to June 30, 2026 before the injunction paused enforcement entirely. Either way, no deadline is currently a binding enforcement trigger while the rule is enjoined.

What the rule requires (in plain terms)

When it is in force, Section 1033 requires data providers to make a consumer's covered data available — to the consumer and to authorized third parties — in a secure, standardized, machine-readable form, with obligations around consent, privacy, and data security. It's built to move the market away from screen-scraping and toward permissioned, API-based access.

What it means for lenders

Two things are worth holding in mind at once: the rule isn't enforceable today, and the underlying data-rights direction isn't going away. That argues for readiness rather than a build-out. A short checklist:

  • Structured data. Make sure the consumer data you hold can be exported in a clean, structured form — not locked in PDFs or free-text fields.
  • Authorization workflows. Use clear, documented consumer-consent steps for any data sharing. This mirrors the permissible-purpose discipline you already apply under the FCRA.
  • Audit trails. Log data-access requests and authorizations so you can show who accessed what, and when.
  • Watch the LEI question. As written, the rule requires authorized third parties to carry a Legal Entity Identifier (LEI). That requirement is intact in the rule text but stayed and unenforced — and aggregators such as Plaid may still request an LEI contractually during onboarding, regardless of the stay. An LEI is issued to legal entities, not individuals, which is a wrinkle if you operate as a sole proprietor.
  • Monitor the reconsideration. The scope and dates may shift with the CFPB's proposed rule. Watch for it before investing in a specific implementation.

For a deeper compliance picture — how 1033 sits alongside FCRA, ECOA, GLBA, and OFAC in a Salesforce lending stack — see our adverse action notice guide and our lending compliance software overview.

Where LASER fits

LASER Credit Access helps you surface and track potential Section 1033 obligations as they develop — it does not fulfill your institution's legal duties for you, and nothing here is legal advice. Because it stores credit and consumer data in structured Salesforce objects, you're better positioned for standardized data access if and when a reconsidered rule takes effect. As the rule moves through reconsideration, we'll update this article when there is a binding change.


This article is for informational and educational purposes only and is not legal advice. Regulatory status reflects the publication date above and may change; confirm current requirements with qualified legal counsel before acting. Next scheduled review: November 2026.

Frequently Asked Questions

What is CFPB Section 1033?

Section 1033 of the Dodd-Frank Act is the statutory basis for open banking in the United States — the principle that consumers own their financial data and can authorize trusted third parties to access it. The CFPB's Personal Financial Data Rights Rule implements it, requiring data providers such as banks to share covered account and transaction data with consumers and their authorized third parties.

Is the Section 1033 rule in effect?

Not in practice. The CFPB finalized the rule in October 2024, but a federal court enjoined the CFPB from enforcing it in October 2025 while the Bureau reconsiders it. The rule is final on paper but not currently enforceable by the CFPB.

When is the Section 1033 compliance deadline?

The rule set tiered deadlines starting April 1, 2026 for the largest data providers. Court orders during the litigation tolled that first operative deadline to June 30, 2026, and the October 2025 injunction has since paused enforcement — so no deadline is currently a binding trigger. A proposed rule to revise the dates and scope was anticipated in 2026.

What should lenders do about Section 1033 now?

The rule requires no action while it is enjoined, but the direction of travel is clear. Prepare by making sure your systems can produce structured data exports, using clear consumer-authorization workflows for any data sharing, keeping audit trails of data-access requests, and monitoring the CFPB's reconsideration for a binding change.

Michael Dunleavey

Founder — LASER Credit Access

Michael Dunleavey brings over 15 years of experience in credit infrastructure and lending compliance, helping financial institutions streamline operations on Salesforce.

Ready to Transform Your Credit Operations?

Discover how LASER Credit Access streamlines compliance and decisioning natively inside Salesforce — unified in a single app, ready from day one.