By Ray Birch
WASHINGTON—The CFPB’s withdrawal of its contested consumer financial data rights rule is the right decision, say analysts, who shared concerns about the rule adding to fraud concerns, increasing FI costs, and simply being a regulation the U.S. banking system was not yet ready to fully adopt.
Most agreed the rule was overly complex and riddled with uncertainties.
As CUToday.info reported, in a filing submitted to the U.S. District Court for the Eastern District of Kentucky, the CFPB stated the agency intends to withdraw the rule, citing a lack of legal foundation. The agency plans to request summary judgment this week, asking the court to formally invalidate the regulation. The rule was to be phased in during 2026.
J.V. Proesel, president of Moebs $ervices, told CUToday.info the open banking rule was designed with good intentions to give consumers more rights over their personal data and protect privacy.
“Overall, the rule included many positive consumer-centric protections that was received well by financial users,” Proesel said. “However, since the final rule was issued last fall, the implementation was clearly going to be complex and fraught with uncertainties and more questions than answers.”
Even with the exclusion of FIs less than $850 million in assets, the regulatory cost for banks and credit unions cannot be understated, emphasized Proesel.
“The CFPB’s intent was the rule would increase competition and lower prices on financial services. This was always doubtful, too,” said Proesel. “So, while well intentioned, it is hard to see the benefits outweigh the costs and the reversal is appropriate.”
Proesel, like others, believes the CFPB’s latest move does not signal the end for key components of the soon-to-be defunct rule.
“Data privacy and protection is extremely important, and so is the portability of your financial service data between providers,” Proesel said. “Another key aspect that still needs to be addressed is the oversight of fintechs. Simply put, what is the regulatory definition of a fintech? There isn’t one.”
As reported by CUToday.info, banks and credit unions raised concerns about the rule’s requirement to share sensitive consumer data with largely unregulated fintechs. Many experts emphasized that stronger data security measures must be in place before open banking can become standard practice in the U.S.
Unintended Consequences
The Defense Credit Union Council noted that throughout the open banking rulemaking process, it had consistently expressed concerns regarding the potential unintended consequences of the Section 1033 rule on credit unions and their members.
“While the rule aimed to enhance consumer access to financial data and promote competition, DCUC cautioned that it could inadvertently expose credit unions to increased reputational and operational risks, particularly if third-party entities mishandle shared data,” said DCUC Chief Advocacy Officer Jason Stverak. “The cooperative nature of credit unions, built on trust and member relationships, could be compromised by such vulnerabilities.”
Stverak said DCUC had highlighted the rule’s implementation could impose significant compliance burdens on credit unions, especially smaller institutions, without commensurate benefits.
“The requirement to share data with third parties, coupled with the potential for increased fraud and data breaches, raised substantial concerns about member privacy and the security of sensitive financial information,” he said. “Given these considerations, DCUC views the CFPB’s proposed rescission of the Section 1033 rule as a prudent step toward ensuring that consumer financial data rights are protected without compromising the integrity and operational viability of credit unions.”
Stverak said DCUC, instead, advocates for a “balanced approach” that safeguards consumer interests while recognizing the unique structure and mission of credit unions in serving their members.
In addition to increased fraud concerns, analysts were concerned over the cost and time that will be required by FIs to address open banking—possibly having to create a new area within the financial institution.
For banks and credit unions, the rule would require the development of secure, real-time systems for data access and sharing, said Dennis Irwin, chief compliance officer at Alkami, a cloud-based digital banking solutions provider for financial institutions.
America’s Credit Unions Chief Advocacy Officer Carrie Hunt told CUToday.info that ACU had many questions about the CFPB’s rule.
“And one now is will we see this rule eventually be reissued,” she said. “This may just mean credit unions are going to perhaps have a little more time (to prepare for open banking’s growth in the U.S.).
Hunt, too, acknowledged the many data security and privacy concerns the open banking rule raised.
“America’s Credit Unions believes there needs to be greater protections in place,” Hunt concluded.
