The federal push toward open banking is stuck between a stayed rule, a planned rewrite and an intensifying fight over whether banks may charge for data access. The Consumer Financial Protection Bureau’s personal financial data rights rule was designed to let consumers authorize secure transfers of account information to budgeting apps, payment services and competing financial institutions. Its core principle is simple: the customer’s data should move at the customer’s direction.
Implementation is not simple. A federal court stayed the rule’s compliance dates in October 2025. The CFPB had already announced that it was considering amendments and a separate proposal to extend deadlines. As of the bureau’s current compliance page, the stay remains in place. That means firms should not treat the original April 2026 deadline for the largest providers as an active nationwide switch-on date.
The technical dispute concerns application programming interfaces, security standards, consent and cost. APIs can replace risky screen scraping, in which a customer gives an outside service bank-login credentials. A standardized connection can limit what data moves and make revocation easier. But building and operating interfaces costs money. Banks argue that high-volume commercial users should help pay. Fintech companies respond that access fees can become a toll gate that defeats the consumer right Congress created in Section 1033 of the Dodd-Frank Act.
OffThePress.com highlighted a report about that fee fight. The primary record is the CFPB rule and its updated compliance page; public comments in the rulemaking show both sides’ claims. None of those comments proves a particular fee is reasonable or anticompetitive. The evidence needed is measurable: actual interface cost, request volume, security performance, small-firm impact and whether consumers can move data without surrendering passwords.
Truth. Logic. Freedom. No spin. Just signal. The signal is that consumer control, privacy and competition must be engineered together. Free unlimited access with weak authentication is unsafe. Unlimited provider discretion to price access can lock customers in. A durable rule needs narrow data scopes, revocable consent, transparent uptime requirements, liability rules and a fee standard that cannot be gamed by either side.
Confirmed: the rule is stayed and CFPB revision remains possible. Disputed: who should bear interface costs and what charges the statute permits. Expected next: a revised proposal, more comments and further court action. Until then, consumers should verify what data each connected app receives, how long access lasts and how to revoke it without deleting the underlying bank account.
Sources
- Consumer Financial Protection Bureau — Personal Financial Data Rights (01-06-2026)
- Consumer Financial Protection Bureau — CFPB Finalizes Personal Financial Data Rights Rule (10-22-2024)
- U.S. Court of Appeals for the Sixth Circuit — Forcht Bank v. CFPB docket (08-17-2026)
- OffThePress.com — Open banking rule puts consumer data access fees in dispute (08-16-2026)
