ICBA told the Consumer Financial Protection Bureau that community banks already meet the requirements of Section 1033 of the Dodd-Frank Act by providing consumers with electronic access to their financial data through online banking portals and mobile apps—and the statute only mandates data access directly to consumers, not third parties.
ICBA to CFPB: Section 1033 should not be mandated for community banks
June 24, 2025 / By ICBA
ICBA told the Consumer Financial Protection Bureau that community banks already meet the requirements of Section 1033 of the Dodd-Frank Act by providing consumers with electronic access to their financial data through online banking portals and mobile apps—and the statute only mandates data access directly to consumers, not third parties.
ICBA told the Consumer Financial Protection Bureau that community banks already meet the requirements of Section 1033 of the Dodd-Frank Act by providing consumers with electronic access to their financial data through online banking portals and mobile apps—and the statute only mandates data access directly to consumers, not third parties.
Details: In a letter to CFPB Director Russell Vought following a meeting between ICBA and CFPB officials, ICBA said:
Section 1033 does not require banks to share consumer data with third parties, especially those acting in their own commercial interest without fiduciary duty, and that the CFPB's 2024 rule mandating such sharing exceeds its statutory authority.
It supports a consumer-demand-driven approach to open banking that allows banks to innovate and manage data sharing through contractual relationships rather than prescriptive regulations that mandate specific technologies like developer interfaces.
Recent Court Action: The CFPB earlier this month asked a federal court to vacate its 1033 rule on consumer data security and privacy, saying the rule is unlawful.
ICBA View: ICBA has long expressed concerns about the impact of the rule on consumer data security and privacy. While the rule included an ICBA-advocated provision exempting community banks under $850 million in assets from a provision requiring institutions to create and maintain a third-party developer interface, ICBA has repeatedly called on the CFPB to focus its implementation of Section 1033 on promoting data security at third-party entities.
Ongoing Advocacy: Addressing the 1033 rule is a key priority of ICBA’s “Repair, Reform, and Thrive” plan for the new Congress and Trump administration. ICBA’s Open Banking Guidebook details the rule as well as its advocacy efforts, including securing exemptions for community banks under $850 million in assets.
Subscribe now
Sign up for the Independent Banker newsletter to receive twice-monthly emails about new issues and must-read content you might have missed.
Sponsored Content
Featured Webinars
Join ICBA Community
Interested in discussing this and other topics? Network with and learn from your peers with the app designed for community bankers.
Subscribe Today
Sign up for Independent Banker eNews to receive twice-monthly emails that alert you when a new issue drops and highlight must-read content you might have missed.
News Watch Today
Join the Conversation with ICBA Community
ICBA Community is an online platform led by community bankers to foster connections, collaborations, and discussions on industry news, best practices, and regulations, while promoting networking, mentorship, and member feedback to guide future initiatives.