Section 1033 of the Dodd-Frank Act — better known lately as CFPB 1033 — is the legal foundation for "open banking" in the United States: the idea that your financial data belongs to you, and that you can authorize a trusted third party (a fintech app, or a service that uses an aggregator like Plaid) to access it on your behalf. The CFPB turned that principle into a rule, the Personal Financial Data Rights Rule, which requires banks and other data providers to share covered account and transaction data with consumers and authorized third parties. For lenders, it's worth understanding — even though, right now, it isn't being enforced.
Where the CFPB 1033 rule stands today
The rule exists on paper but is not currently enforceable by the CFPB. The short version:
- The CFPB finalized the Section 1033 rule in October 2024, with a phased compliance schedule beginning April 1, 2026 for the largest data providers.
- In late October 2025 (Oct. 29), Judge Danny C. Reeves of the U.S. District Court for the Eastern District of Kentucky issued a preliminary injunction halting the CFPB from enforcing the rule while the agency reconsiders it.
- The CFPB had already published an Advance Notice of Proposed Rulemaking in August 2025, seeking comment on four issues: who qualifies as an authorized "representative," whether data providers may charge fees for access, whether data-security standards are adequate, and whether privacy protections (including under GLBA) are adequate.
- A follow-on Notice of Proposed Rulemaking to revise the rule and its dates was anticipated in 2026 and, as of this writing, had not yet published — so the final scope, thresholds, and deadlines could still change.
A note on the "April 1" vs. "June 30, 2026" dates
You may see both cited, and both are legitimate. The rule text codifies all tiered deadlines on April 1 (2026 through 2030), but court orders in the litigation tolled the first operative deadline to June 30, 2026 before the injunction paused enforcement entirely. Either way, no deadline is currently a binding enforcement trigger while the rule is enjoined.
What the rule requires (in plain terms)
When it is in force, Section 1033 requires data providers to make a consumer's covered data available — to the consumer and to authorized third parties — in a secure, standardized, machine-readable form, with obligations around consent, privacy, and data security. It's built to move the market away from screen-scraping and toward permissioned, API-based access.
What it means for lenders
Two things are worth holding in mind at once: the rule isn't enforceable today, and the underlying data-rights direction isn't going away. That argues for readiness rather than a build-out. A short checklist:
- Structured data. Make sure the consumer data you hold can be exported in a clean, structured form — not locked in PDFs or free-text fields.
- Authorization workflows. Use clear, documented consumer-consent steps for any data sharing. This mirrors the permissible-purpose discipline you already apply under the FCRA.
- Audit trails. Log data-access requests and authorizations so you can show who accessed what, and when.
- Watch the LEI question. As written, the rule requires authorized third parties to carry a Legal Entity Identifier (LEI). That requirement is intact in the rule text but stayed and unenforced — and aggregators such as Plaid may still request an LEI contractually during onboarding, regardless of the stay. An LEI is issued to legal entities, not individuals, which is a wrinkle if you operate as a sole proprietor.
- Monitor the reconsideration. The scope and dates may shift with the CFPB's proposed rule. Watch for it before investing in a specific implementation.
For a deeper compliance picture — how 1033 sits alongside FCRA, ECOA, GLBA, and OFAC in a Salesforce lending stack — see our adverse action notice guide and our lending compliance software overview.
Where LASER fits
LASER Credit Access helps you surface and track potential Section 1033 obligations as they develop — it does not fulfill your institution's legal duties for you, and nothing here is legal advice. Because it stores credit and consumer data in structured Salesforce objects, you're better positioned for standardized data access if and when a reconsidered rule takes effect. As the rule moves through reconsideration, we'll update this article when there is a binding change.
This article is for informational and educational purposes only and is not legal advice. Regulatory status reflects the publication date above and may change; confirm current requirements with qualified legal counsel before acting. Next scheduled review: November 2026.
