The Consumer Financial Protection Bureau’s Section 1033 open banking rule remains legally unenforceable more than two years after it was finalised, and lenders waiting for a settled cfpb 1033 compliance timeline will have to keep waiting. A federal court in Kentucky has enjoined the CFPB from enforcing the rule, and the Bureau itself is now rewriting it under a proposal that could reverse one of the original rule’s central protections: the ban on banks charging for data access.
What the 1033 rule was supposed to require
Congress created the underlying data-rights authority in the 2010 Dodd-Frank Act, but the dodd frank 1033 provision sat dormant for more than a decade until the CFPB used it to finalise the Personal Financial Data Rights rule in October 2024. That rule gives consumers a legal right to their own financial data and requires banks, credit unions and other data providers to make it available, free of charge, to authorised third parties such as budgeting apps, lenders and payment platforms the consumer chooses to use.
The rule set a phased compliance schedule running from 2026 to 2030, with the largest banks and data providers facing the earliest deadlines, starting in April 2026, and smaller institutions given until the end of the decade to build compliant data-sharing infrastructure. That timeline never held.
Litigation has kept the cfpb open banking rule unenforceable
Forcht Bank, N.A., the Bank Policy Institute and the Kentucky Bankers Association sued the CFPB the same day the rule was finalised, arguing it exceeded the Bureau’s statutory authority under Dodd-Frank. In March 2025, the parties agreed to pause the case and toll the rule’s compliance deadlines while the CFPB, under new leadership, reconsidered its position. Months later, the Bureau’s own chief legal officer told the court it now viewed its rule as unlawful and should be set aside.
In November 2025, the US District Court for the Eastern District of Kentucky granted the bank plaintiffs a preliminary injunction, finding them likely to succeed on the merits and barring the CFPB from enforcing the rule while it reconsiders. The case is now on appeal before the Sixth Circuit as Forcht Bank, N.A. v. CFPB, but that appeal is stayed pending the outcome of the rulemaking, and the parties continue to file joint status reports with the court roughly every six weeks.
A rewritten rule is now with the White House
The CFPB opened a formal reconsideration in August 2025 with an advance notice of proposed rulemaking covering 36 questions, including data-security standards, the definition of an authorised third party and, critically, the fee ban. On 6 August 2026 the Bureau sent a revised proposal, styled the Personal Financial Data Rights Reconsideration, to the White House Office of Information and Regulatory Affairs for review, one of the final steps before a rule publishes for public comment.
Reporting on the submission indicates the reconsidered version would reverse the original fee prohibition, letting banks charge fintechs and other third parties for data access, and would revisit who qualifies as an authorised recipient. Neither the proposal’s exact text nor a new compliance timeline has been made public as this article was drafted, and OIRA review carries no fixed deadline.
What it means for lenders and data aggregators now
For banks, the practical effect is that the original 1033 compliance obligations they spent 2025 preparing for are on hold, not cancelled. Because the original schedule graduated obligations by institution size, larger banks that had already built application programming interfaces to meet the since-enjoined April 2026 deadline are furthest ahead, while smaller banks and credit unions, originally given until 2030, have less sunk cost in the outgoing framework and more reason to wait for the rewritten rule’s final terms before building.
Several institutions continue to offer data access voluntarily or through existing bilateral agreements with aggregators such as Plaid, MX and Akoya, which broker permissioned data flows between banks and third-party apps. A fee-based model, if it survives the final rule, would change the economics for those aggregators and for the fintechs relying on free data access to build lending, budgeting and account-verification products. Lenders assessing whether to invest now in 1033-style infrastructure face a genuine forecasting problem: build to the enjoined rule’s original terms, wait for the reconsidered version, or rely on the bilateral agreements already in place. Fintechly’s guide to the difference between regtech and compliance technology sets out how compliance teams are structuring that kind of build-versus-wait decision more broadly.
State regulators add a further wrinkle. Because the injunction binds only the CFPB, some state attorneys general and financial regulators have signalled they could use independent enforcement powers under Dodd-Frank to pursue open banking claims regardless of the federal Bureau’s position. New York lawmakers introduced Assembly Bill A10640 and companion Senate Bill S9483 in March 2026, which would create state-level open banking data-sharing rights that would apply irrespective of what the CFPB eventually decides.
What to watch next
The next concrete step is publication of the CFPB’s revised proposal for public comment once OIRA review concludes, which will show whether the fee ban reversal survives in the form reported so far. Until then, US lenders operate in the same position they have been in since the injunction: the 1033 rule remains on the books, but not enforceable, and the timeline for a durable federal standard is unresolved. A fuller list of infrastructure providers building for this environment, including the aggregators and compliance vendors affected by the rule’s outcome, sits on Fintechly’s infrastructure sector directory.