The CFPB's Personal Financial Data Rights Rule: The Text of Part 1033 and the Injunction That Froze It
Key Takeaways
- Section 1033 of the Consumer Financial Protection Act, 12 U.S.C. § 5533, obliges a covered person to make account and transaction information available to a consumer on request, subject to CFPB rules and statutory exceptions
- The final rule, published at 89 FR 90838 on November 18, 2024, covers Regulation E accounts, Regulation Z credit cards and payment facilitation, and staggered compliance from April 1, 2026 to April 1, 2030
- Authorized third parties are limited to what is reasonably necessary for the product the consumer requested, which the rule states excludes targeted advertising, cross-selling and sale of covered data
- On October 29, 2025 the Eastern District of Kentucky enjoined the CFPB from enforcing the rule until it completes its reconsideration, after the Bureau had told the court it viewed the rule as unlawful
- The Sixth Circuit appeals are held in abeyance, and no proposed rule appears in the Federal Register's index for part 1033 after the August 2025 advance notice
What Section 1033 Says
12 U.S.C. § 5533(a) provides that, "[s]ubject to rules prescribed by the Bureau, a covered person shall make available to a consumer, upon request, information in the control or possession of the covered person concerning the consumer financial product or service that the consumer obtained from such covered person," including information about transactions, costs, charges and usage, and that the information "shall be made available in an electronic form usable by consumers."
Subsection (b) lists categories a covered person may not be required to provide, including confidential commercial information such as algorithms used to derive credit or risk scores, information collected to prevent fraud or money laundering or to detect or report unlawful conduct, and information that cannot be retrieved in the ordinary course of business. Subsection (c) imposes no duty to maintain records. Subsection (d) directs the Bureau to prescribe standards promoting standardized formats, "including through the use of machine readable files," and subsection (e) requires consultation with the federal banking agencies and the Federal Trade Commission.
The statute's operative word is "consumer." Whether it reaches a fintech or data aggregator acting for a consumer is the question that has driven the litigation. As the Eastern District of Kentucky noted, the Dodd-Frank Act defines consumer in 12 U.S.C. § 5481(4) as "an individual or an agent, trustee, or representative acting on behalf of an individual."
What the 2024 Rule Built
The CFPB released the final rule on October 22, 2024, according to its rulemaking page, and it was published at 89 FR 90838 on November 18, 2024 with an effective date of January 17, 2025. A separate final rule in June 2024 had set the attributes a standard-setting body needs for CFPB recognition. Part 1033 has four subparts: general provisions and compliance dates, the obligation to make covered data available, requirements for consumer and developer interfaces, and obligations of authorized third parties.
Under § 1033.111, a data provider is a covered person that is a Regulation E financial institution, a Regulation Z card issuer, or any other person that controls or possesses information about a covered product the consumer obtained from it, and the rule's own example is that "[a] digital wallet provider is a data provider." The covered products are Regulation E accounts, Regulation Z credit cards, and facilitation of payments from either, excluding products that merely facilitate first party payments. Subparts B and C do not apply to a depository institution whose total assets are at or below the Small Business Administration size standard for its industry code.
Section 1033.211 defines covered data in six categories:
- transaction information, with at least 24 months of history deemed sufficient
- account balance information
- information to initiate payment to or from a Regulation E account, including an account and routing number usable for an ACH transaction, with tokenized account numbers permitted
- terms and conditions, such as the fee schedule, APR or APY, credit limit, rewards terms, overdraft opt-in status and whether the consumer has entered into an arbitration agreement
- upcoming bill information
- basic account verification information, limited to name, address, email address and phone number, plus a truncated account number where the provider holds the account
Section 1033.221 carries the statutory exceptions into the rule and narrows them: information does not become confidential commercial information "merely because it is an input to, or an output of, an algorithm, risk score, or predictor." Section 1033.301 requires both a consumer interface and a developer interface, and § 1033.301(c) prohibits any fee or charge to a consumer or authorized third party for establishing or maintaining those interfaces or for responding to requests. Section 1033.311(c)(1) sets a minimum response rate of 99.5 percent in each calendar month for the developer interface.
Conditions on Authorized Third Parties
A third party becomes an authorized third party under § 1033.401 by giving the consumer an authorization disclosure, certifying in it that the third party agrees to the obligations in § 1033.421, and obtaining the consumer's express informed consent through an electronic or written signature. Section 1033.411 requires the disclosure to name the third party and the data provider, briefly describe the requested product, list the data categories, describe the expected duration of collection, and explain how to revoke.
Section 1033.421(a)(1) limits the third party's "collection, use, and retention of covered data to what is reasonably necessary to provide the consumer's requested product or service," and paragraph (a)(2) states that targeted advertising, cross-selling of other products or services, and the sale of covered data "are not part of, or reasonably necessary to provide, any other product or service." Collection is capped at one year after the consumer's most recent authorization, after which a new authorization is required. The listed permitted uses include uses required by other law, fraud prevention, servicing the requested product and improving it. For data security, § 1033.421(e) applies the Gramm-Leach-Bliley Act safeguards rules or, for a third party outside section 501 of that Act, the FTC's Safeguards Rule at 16 CFR part 314.
The Compliance Dates as Written
Section 1033.121(b) staggered compliance with subparts B and C by size, measured for depository institutions by average total assets across call reports from the third quarter of 2023 through the second quarter of 2024, and for other data providers by total receipts:
| Original compliance date | Data providers |
|---|---|
| April 1, 2026 | Depository institutions with at least $250 billion in total assets; nondepository institutions with at least $10 billion in total receipts in calendar year 2023 or 2024 |
| April 1, 2027 | Depository institutions with at least $10 billion but less than $250 billion; nondepository institutions that did not reach $10 billion in receipts in both years |
| April 1, 2028 | Depository institutions with at least $3 billion but less than $10 billion |
| April 1, 2029 | Depository institutions with at least $1.5 billion but less than $3 billion |
| April 1, 2030 | Depository institutions with more than $850 million but less than $1.5 billion |
None of those dates now operates as written. The district court first extended the compliance deadlines by 90 days, moving the first to June 30, 2026, which the CFPB acknowledged in a footnote to its August 2025 advance notice. The injunction described below then barred enforcement altogether.
From Defending the Rule to Asking a Court to Set It Aside
Forcht Bank, N.A., the Kentucky Bankers Association and the Bank Policy Institute sued in the Eastern District of Kentucky, No. 5:24-cv-304, on the day the rule was finalized, alleging that it exceeds the CFPB's statutory authority and is arbitrary and capricious. The Financial Technology Association intervened to defend it. The court's October 29, 2025 memorandum opinion and order recounts what followed. After the change of administration the CFPB determined that "the Rule is unlawful and should be set aside" and moved for summary judgment seeking vacatur. Then, on July 29, 2025, instead of filing a reply, it moved to stay the case because it had "decided to initiate a new rulemaking to reconsider the Rule."
The advance notice of proposed rulemaking, published August 22, 2025 at 90 FR 40986, sought comment on four issues: who can serve as a "representative" making a request on a consumer's behalf, the approach to fees defraying a covered person's costs, the data security threat and cost-benefit picture, and the data privacy threat picture. On timing it stated that "the Bureau plans to issue a Notice of Proposed Rulemaking to extend the compliance dates." Comments were due October 21, 2025.
Ruling on the banks' motion, Judge Danny C. Reeves found them likely to succeed on the argument that "representative" in § 5481(4) should be read in harmony with "agent" and "trustee," which describe fiduciary relationships, and on the argument that the CFPB failed to consider the cumulative effect on data security of four provisions, including the payment initiation data requirement and the limits on denying access. He treated unrecoverable compliance costs as irreparable harm and ordered that "[t]he Consumer Financial Protection Bureau is ENJOINED from enforcing the Personal Financial Data Rights Rule until it has completed its reconsideration of the Rule," describing the relief as a temporary stay under 5 U.S.C. § 705 pending final rulemaking.
Where the Rule Stands in September 2026
Appeals from the injunction are pending in the Sixth Circuit as No. 25-6164, brought by the Financial Technology Association, and No. 26-5005, brought by the CFPB. According to the plaintiffs' July 28, 2026 status report, the Sixth Circuit on March 30, 2026 granted a motion to hold briefing in abeyance while the Bureau conducts its new rulemaking and directed status reports every 60 days. The report quotes the CFPB's statement that it "is continuing to conduct the rulemaking to reconsider the Personal Financial Data Rights Rule (Rule), with a view to substantially revising it," and is still considering the comments received on the August 2025 advance notice.
The Bureau's 2026 regulatory agenda, published August 14, 2026 at 91 FR 53082, lists "a rulemaking to reconsider certain aspects of the Bureau's November 2024 personal financial data rights rule." The Federal Register's index of documents affecting 12 CFR part 1033 lists four: the October 2023 proposal, the June 2024 standard-setting rule, the November 2024 final rule and the August 2025 advance notice. No proposed rule to extend the compliance dates or revise part 1033 appears there. The regulatory text has not been withdrawn; the agency responsible for it is enjoined from enforcing it and has told both courts that it intends to substantially revise it.
Background
For the underlying law rather than this development: Financial Services privacy law.
Frequently Asked Questions
Is the CFPB's personal financial data rights rule in effect?
What were the original Section 1033 compliance dates?
Can a bank charge an authorized third party for data access under Part 1033?
Can an authorized third party use Part 1033 data for advertising?
What is Forcht Bank v. CFPB?
Has the CFPB proposed a replacement for the 1033 rule?
Sources
Everything above is reported from these documents. Follow them to verify.
- 12 U.S.C. § 5533, Consumer rights to access information (September 14, 2026) statute
- CFPB, Required Rulemaking on Personal Financial Data Rights, final rule, 89 FR 90838 (Nov. 18, 2024), full text (November 18, 2024) regulation
- CFPB, Personal Financial Data Rights Reconsideration, advance notice of proposed rulemaking, 90 FR 40986 (Aug. 22, 2025), full text (August 22, 2025) regulation
- CFPB, Regulatory Agenda, 91 FR 53082 (Aug. 14, 2026), full text (August 14, 2026) agency release
- Federal Register API, documents affecting 12 CFR part 1033 (September 14, 2026) registry
- CFPB, Required Rulemaking on Personal Financial Data Rights (rulemaking page) (August 27, 2025) agency release
- Forcht Bank, N.A. v. CFPB, No. 5:24-cv-304 (E.D. Ky. Oct. 29, 2025), memorandum opinion and order (Doc. 90) (October 29, 2025) court opinion
- Forcht Bank, N.A. v. CFPB, Nos. 25-6164, 26-5005 (6th Cir.), plaintiffs-appellees' status report filed July 28, 2026 (July 28, 2026) docket
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.