Where Section 1033 Actually Stands: A Plain-Language Guide for Financial Institutions
If you lead compliance, product, or data strategy at a bank or credit union, you have probably asked some version of this question in the last few months: is Section 1033 happening or not?
The honest answer is that it is happening, but not on the timeline anyone expected two years ago. Here is what is confirmed, what is still unsettled, and what it means for your institution right now.
At its core, Section 1033 is a rule about consumer-permissioned data: who can access it, who can charge for it, and what standards govern how it moves. What Is Consumer-Permissioned Data? If you need a refresher on the term itself, that is the fastest place to start.
A quick recap of how we got here
Section 1033 of the Dodd-Frank Act gives consumers a right to access their own financial data and to direct that data, as consumer-permissioned data, to third parties they authorize. The Consumer Financial Protection Bureau finalized its rule implementing that right in October 2024. The rule set a phased compliance schedule, with the largest data providers facing an April 1, 2026 deadline.
Trade groups sued the same day the rule was finalized. A federal court later enjoined the CFPB from enforcing it while the Bureau reconsiders key parts of the framework. In August 2025, the CFPB opened that reconsideration formally with an Advance Notice of Proposed Rulemaking, asking for public input on how the rule should change.
What just happened
On August 6, 2026, the CFPB submitted a new Notice of Proposed Rulemaking to the Office of Information and Regulatory Affairs (OIRA) for review. This is a required step before any new rule can be published for public comment. It signals that the Bureau has finished drafting its revised approach and is ready to move toward publication.
OIRA review under Executive Order 12866 is typically expected to wrap up within 90 days, though it often finishes faster when an agency is treating a rule as a priority. Industry analysts tracking similar CFPB rulemakings under the current administration have noted that recent significant rules have moved from OIRA submission to Federal Register publication in as little as two to three weeks. Given how many times the Bureau has called this reconsideration a priority, a faster timeline would not be a surprise.
Once OIRA clears the rule, it moves to the Federal Register and opens for public comment. That comment period, not the OIRA review, is when the substance of the new rule becomes public and financial institutions can weigh in directly.
What is actually up for debate
The 2025 ANPR laid out the issues the CFPB is reconsidering, and they are the same ones still in play today:
- Data access fees. Should banks and other data providers be allowed to charge third parties for access to consumer-permissioned data? The original 2024 rule prohibited this. Reversing it would be one of the most consequential changes on the table, and it is the piece getting the most attention from trade groups on both sides.
- Who counts as an authorized representative. The rule needs a workable definition of which third parties can request and receive a consumer’s permissioned data on their behalf.
- The balance between competition, privacy, and security. The CFPB has signaled it wants a framework that supports innovation and consumer choice without loosening the standards that protect account holders’ data.
- Compliance burden. Community banks and credit unions raised real concerns about the cost and complexity of the original technical requirements for handling consumer-permissioned data. Expect the revised rule to address this directly.
Why the compliance date confusion is so widespread
The April 1, 2026 deadline for the largest institutions technically still exists on paper. It is just not enforceable right now because of the injunction. That is an unusual place for a rule to sit: written into the Code of Federal Regulations, but not something an examiner can currently cite you for.
This is exactly why so many financial institutions are unsure what to do. Some have paused their open banking work entirely. Others are treating the pause as a planning window rather than a reason to stop. Legal counsel tracking the rulemaking have suggested the second approach is the safer one. The concepts behind Section 1033, consumer-permissioned data sharing and third-party access controls, are showing up in state-level legislation and private litigation even while the federal rule is in flux. Waiting for total certainty before building anything is not really an option.
What this means for your institution this week
- Do not treat this as dead. The rule is moving again, and the OIRA submission suggests publication could come faster than the 90-day maximum window.
- Watch the fee question closely. If data access fees become permissible, it changes the economics of every data-sharing relationship your institution has or is building.
- Use the pause to get your house in order. Review vendor agreements, confirm your data access architecture does not depend on legacy credential sharing, and make sure your team understands where accountability sits if something goes wrong.
- Do not wait for the final rule to modernize your data infrastructure. Whatever the CFPB decides on fees or authorized representatives, the underlying expectation, that account holders can access and share their own consumer-permissioned data securely, is not going away.
Built for consumer-permissioned data, regardless of how the rule lands
“The specifics of the final rule will matter a lot to the industry, but the direction has been clear for years. Consumers expect their financial data to move with them, safely and on their terms. We built Bloom’s consumer-permissioned data infrastructure around that expectation rather than around any single version of the rule. Whatever the CFPB finalizes on fees or authorized representatives, our financial institution partners are not starting over.” – Christa Degnan, Chief Product Officer, Bloom Credit
The bottom line
Section 1033 is not stalled. It is in a specific, well-defined stage of the federal rulemaking process, and the next real milestone is Federal Register publication and the start of a public comment period. For financial institutions, the smartest move right now is to keep building toward the outcome that was always coming: secure, consumer-permissioned data access, whether that arrives through this rule, a revised version of it, or the state laws filling the gap in the meantime.
Want the fuller definition of consumer-permissioned data and how it fits into Bloom’s platform? [Link to: What Is Consumer-Permissioned Data term page]
Sources:
Consumer Financial Protection Bureau. Required Rulemaking on Personal Financial Data Rights. Retrieved August 2026, from https://www.consumerfinance.gov/personal-financial-data-rights/
Consumer Bankers Association. Main Street Ledger: What’s at Stake as the CFPB Reconsiders Its Personal Financial Data Rights Rule. https://consumerbankers.com/blog/main-street-ledger-whats-at-stake-as-the-cfpb-reconsiders-its-personal-financial-data-rights-rule/
Berry, K. American Banker. What We Know About the CFPB’s Forthcoming Open-Banking Rule. https://www.americanbanker.com/news/what-we-know-about-the-cfpbs-forthcoming-open-banking-rule
Cozen O’Connor. Section 1033 Compliance Date: Open Banking Rule Enjoined and Under Reconsideration. https://www.cozen.com/news-resources/publications/2026/section-1033-compliance-date-open-banking-rule-enjoined-and-under-reconsideration
Consumer Finance Monitor. CFPB Sends New Section 1033 “Open Banking” Proposal to OIRA for Review. https://www.consumerfinancemonitor.com/2026/08/06/cfpb-sends-new-section-1033-open-banking-proposal-to-oira-for-review/