Consumer Access to Financial Data Under Dodd-Frank

How Dodd-Frank Section 1033 and CFPB rules are reshaping consumer access, data sharing, and privacy in modern finance.

By Sneha Tete, Integrated MA, Certified Relationship Coach
Created on

Consumer financial lives increasingly depend on digital data. Bank accounts, credit cards, and payment apps all generate detailed records of how people save, spend, and borrow. U.S. law has begun to recognize that this information is not only about consumers, but also for consumers. Section 1033 of the Dodd-Frank Wall Street Reform and Consumer Protection Act created a legal framework for consumer access to their own financial records, and the Consumer Financial Protection Bureau (CFPB) is now implementing that framework through detailed rules.

1. Background: Why Consumer Access to Financial Data Matters

Digital financial records used to be controlled almost entirely by banks and other institutions. Consumers could see limited information—often only through paper statements—but they had little control over how that data could be reused to obtain better services elsewhere.

As financial technology (fintech) firms emerged, they began building tools for budgeting, payments, and credit comparison that rely on access to consumer account data. This raised two core policy questions:

  • How can consumers use their own financial data to find better products and manage money more effectively?
  • How can the law protect privacy, security, and fair competition while allowing data to move safely?

Section 1033 addresses these questions by giving consumers a statutory right to obtain information about financial products and services they use, subject to rules set by the CFPB. More recently, the CFPB’s Personal Financial Data Rights rule has begun implementing these rights in practice, with a focus on competition and privacy in markets like bank accounts and credit cards.

2. The Legal Foundation: Dodd-Frank Act Section 1033

Section 1033 of the Consumer Financial Protection Act (CFPA), part of Dodd-Frank, establishes that a covered financial company must provide consumers with access to certain information about their accounts when requested.

Key Element What Section 1033 Provides
Right of access Consumers may request information about a financial product or service they obtained, including transaction and account information.
Scope of information Covers data relating to transactions, costs, charges, and usage of the account or product.
Format Information must be provided in an electronic form that is usable by consumers, as defined through CFPB rules.
Rulemaking authority The CFPB is directed to write rules, including standards for standardized formats of data access and transmission.

Section 1033 does not operate in isolation. It interacts with other federal laws that govern financial privacy and data sharing with government agencies, such as the Right to Financial Privacy Act (RFPA), which imposes procedures federal agencies must follow to obtain customer records from financial institutions.

3. From Statute to Practice: CFPB’s Personal Financial Data Rights Rule

To make Section 1033 work in the real world, the CFPB has finalized a Personal Financial Data Rights rule that requires certain financial providers to allow consumer-authorized access to financial data in a structured electronic form.

According to the CFPB, this rule is designed to:

  • Give consumers more power to switch providers and obtain better rates and services.
  • Promote competition in markets such as bank accounts, credit cards, mobile wallets, and payment apps.
  • Enhance privacy and security by limiting how third parties may use and retain consumer data.

Compliance timelines are staggered. Larger institutions must comply first, with smaller entities following on later schedules, so that operational and technical changes can be phased in.

4. What Information Must Be Shared With Consumers?

The CFPB’s rule defines a category of covered data that must be made available to consumers and, when authorized, to third-party firms acting on a consumer’s behalf.

4.1 Types of covered data

  • Transaction history: Typically up to 24 months of account transactions, including amounts, dates, and counterparties.
  • Account balance information: Current and, in some cases, historical balances.
  • Account terms and conditions: Key product terms, such as fees, interest rates, and other pricing details.
  • Payment initiation details: Information needed to initiate payments, such as account identifiers, routing information, and scheduled payments.
  • Upcoming bill or obligation information: Data on scheduled payments and billing cycles where relevant.
  • Basic account verification data: Limited information confirming account ownership and status.

By defining specific data elements and time ranges, the rule aims to create predictable interfaces between financial institutions and authorized third parties, benefiting both consumers and technology providers.

4.2 Products and services in scope

The rule primarily applies to common retail financial products, including:

  • Checking and savings accounts
  • Credit cards
  • Prepaid cards
  • Digital wallets and payment apps

The CFPB indicates that ensuring data access for these products can meaningfully improve consumer choice and reduce switching frictions in highly concentrated markets.

5. How Consumers Exercise Their Access Rights

Under Section 1033 and the CFPB rule, consumers have both a direct and an indirect way to obtain and use their financial information.

5.1 Direct access by the consumer

Consumers can request data directly from their financial providers. At a high level, institutions must:

  • Provide specified covered data electronically and in a form that people can actually use.
  • Offer this access without charging a fee for data sharing required under the rule.
  • Maintain records of how they responded to requests for a defined retention period (for example, three years under some interpretations of the rule).

5.2 Authorization of third parties

Consumers may also direct their financial institutions to share data with a third party, such as:

  • Budgeting and personal finance management apps
  • Credit comparison and refinancing tools
  • Alternative payment providers or neobanks that need transaction history to onboard customers

The CFPB’s rule sets conditions for this third-party access, including:

  • Clear consumer authorization: Third parties must obtain explicit permission from the consumer before collecting data.
  • Limited duration: Data access is generally capped at one year unless the consumer explicitly reauthorizes continued access.
  • Revocation rights: Consumers can revoke access at any time, and data collection must stop immediately when they do so.

6. Privacy and Security: Guardrails on Data Sharing

Greater data access also carries risk. Section 1033 and the CFPB’s rule therefore place strong emphasis on privacy and security protections, building on other laws that govern financial privacy and government access to records.

6.1 Limits on how third parties may use data

Third parties receiving consumer financial data under the rule are constrained in several ways:

  • They may generally use the data only for purposes directly related to the service the consumer requested.
  • They are restricted from repurposing data for unrelated advertising, profiling, or other uses that primarily benefit the third party.
  • If a consumer revokes access or fails to reauthorize after the allowed period, third parties must stop using or retaining most data, subject to narrow exceptions (such as records needed to fulfill existing obligations or comply with law).

6.2 Moving away from risky “screen scraping”

The CFPB has highlighted the risks of screen scraping, where consumers provide login credentials to third parties, which then log in and copy data directly from online banking portals. Problems include:

  • Excessive data collection beyond what is necessary
  • Increased exposure from storing or transmitting passwords
  • Unclear responsibility when misuse or security incidents occur

The rule supports a shift toward safer, permissioned data access methods via standardized interfaces and formats, in line with Section 1033’s direction to promote standardized data formats.

6.3 Interaction with the Right to Financial Privacy Act

While Section 1033 governs consumer access and sharing with third parties, the Right to Financial Privacy Act of 1978 (RFPA) regulates when and how federal government agencies may obtain financial records from institutions.

  • Federal agencies usually must use a subpoena, summons, formal written request, or warrant to obtain customer financial records.
  • They generally must give notice to the customer and an opportunity to challenge the request, subject to specific exceptions.

This structure underscores that consumer access rights under Section 1033 do not diminish privacy protections against government access; separate statutory safeguards continue to apply.

7. Obligations and Opportunities for Financial Institutions

For banks, credit card issuers, and other covered entities, Section 1033 and the CFPB’s implementing rule create both compliance responsibilities and strategic opportunities.

7.1 Core compliance expectations

Covered institutions typically must:

  • Build or adapt systems to provide required data in standardized, machine-readable formats.
  • Implement processes for secure third-party connections, authentication, and authorization management.
  • Maintain internal policies to ensure that data sharing practices adhere to privacy, security, and record-retention requirements.
  • Train staff and update customer communications to explain new rights and procedures.

7.2 Strategic implications

Beyond compliance, institutions can use the new framework to:

  • Develop partnerships with fintech firms that offer value-added services to shared customers.
  • Differentiate themselves with transparent data practices and innovative digital tools.
  • Leverage standardized data flows for improved risk management, analytics, and customer service.

8. Consumer Benefits and Practical Use Cases

When implemented effectively, data access rights can yield tangible benefits for households and small businesses. Examples include:

  • Smarter budgeting and financial planning: Apps can analyze transaction histories to categorize spending, highlight trends, and suggest savings goals.
  • Faster account switching: Consumers can authorize a new provider to import recent transactions and account details, simplifying onboarding and reducing the friction of moving away from high-fee institutions.
  • More accurate credit assessments: Alternative lenders may use bank transaction data, with consent, to assess cash flow and repayment capacity, potentially expanding access to credit.
  • Improved payment services: Payment apps can access up-to-date account and balance information to reduce failed transactions and overdrafts.

These benefits depend on strong safeguards, clear disclosures, and user-centric design so that consumers understand what they are authorizing and how to revoke access if they change their minds.

9. Key Challenges and Open Questions

Even with Section 1033 and the CFPB’s rule in place, several challenges remain for policymakers, industry, and consumer advocates.

  • Standardization and interoperability: Developing widely adopted technical standards for data formats and interfaces is critical to making data access reliable and secure across many different institutions and third parties.
  • Data minimization: Policymakers and firms must continue to refine which data elements are truly necessary for a given service, to avoid excessive sharing.
  • Oversight of third-party data handlers: Monitoring compliance by fintech and other data recipients requires ongoing supervision and, if needed, enforcement.
  • Consumer understanding: Legal consent is not enough; genuine informed choice requires plain-language disclosures and tools that make data permissions easy to see and manage.

10. Frequently Asked Questions (FAQs)

Q1: What is Dodd-Frank Section 1033 in simple terms?

Section 1033 gives you the right to request information about financial products and services you use—such as transactions, costs, and account usage—and requires covered providers to give that information to you in an electronic, usable format, subject to CFPB rules.

Q2: Can I make my bank share data with a budgeting or payment app?

Yes, if the app is properly authorized, you can direct your bank or card issuer to share defined categories of financial data with that app. The CFPB’s rule explains how third parties must obtain your permission and what they can do with your data.

Q3: Do financial institutions have to provide this data for free?

For the data categories covered by the CFPB’s Personal Financial Data Rights rule, institutions generally must provide access without charging consumers a fee for the required sharing.

Q4: How long can a third party keep accessing my data?

Authorization is typically limited to one year unless you proactively renew it. You may revoke access at any time, and once you do, data collection must stop, with limited exceptions for data needed to complete existing services or legal obligations.

Q5: Does this change how the government can obtain my financial records?

No. Government access to financial records is still governed by laws like the Right to Financial Privacy Act, which generally require subpoenas or similar legal process and notice to customers, subject to some exceptions.

References

  1. 12 U.S. Code § 5533 – Consumer rights to access information — U.S. Office of the Law Revision Counsel. 2024-01-01. https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title12-section5533
  2. CFPB Finalizes Personal Financial Data Rights Rule to Boost Competition, Protect Privacy, and Give Families More Choice in Financial Services — Consumer Financial Protection Bureau. 2024-10-22. https://www.consumerfinance.gov/about-us/newsroom/cfpb-finalizes-personal-financial-data-rights-rule-to-boost-competition-protect-privacy-and-give-families-more-choice-in-financial-services/
  3. Personal Financial Data Rights Rule: Consumer Financial Protection Bureau Compliance — Barclay Damon LLP. 2024-11-06. https://www.barclaydamon.com/alerts/personal-financial-data-rights-rule-consumer-financial-protection-bureau-compliance
  4. Navigating the CFPB’s Personal Financial Data Rights Rule — Venable LLP. 2024-10-30. https://www.venable.com/insights/publications/2024/10/navigating-cfpb-personal-financial-data-rights
  5. Right to Financial Privacy Act — Federal Deposit Insurance Corporation, Consumer Compliance Examination Manual. 2023-06-01. https://www.fdic.gov/resources/supervision-and-examinations/consumer-compliance-examination-manual/documents/8/viii-3-1.pdf
Sneha Tete
Sneha TeteBeauty & Lifestyle Writer
Sneha is a relationships and lifestyle writer with a strong foundation in applied linguistics and certified training in relationship coaching. She brings over five years of writing experience to waytolegal,  crafting thoughtful, research-driven content that empowers readers to build healthier relationships, boost emotional well-being, and embrace holistic living.

Read full bio of Sneha Tete