"cfpb 36795" by Ted Eytan is licensed under CC BY-SA 2.0
In a rare admission of its missteps, the Consumer Financial Protection Bureau (CFPB) is planning on unwinding its finalized rule on section 1033 of the Dodd-Frank Act. The move is ultimately a win for consumer data privacy as it will prevent data-sharing risks from endangering consumers and placing undue liability on banks.
The CFPB’s change comes in the wake of its litigation with the Bank Policy Institute and the Kentucky Bankers Association in court, where the two aforementioned parties sought injunctive relief, arguing the bureau had exceeded the bounds of its statutory authority. The CFPB filed to vacate the rule in May, conducting a complete 180 by acknowledging the rule exceeds the original intent of the statute as intended to be implemented in statute. 1033 was never meant to mandate data sharing for third parties on behalf of bank customers.
The finalized rule, which was promulgated under the Biden administration, would have established an open banking regime. The term open banking is misleading and disguises the implications of the rule with an innocuous-sounding label.
If implemented, it would have compelled banks to share customer account data free of charge to third parties if authorized by the customer. This would enable third-parties such as fintech companies and other financial institutions to access account records, transaction data, and contact information.
Banks would also be responsible for the establishment and maintenance of a developer interface such as an API to facilitate data access.
The CFPB’s prohibition on fee collection to offset compliance costs associated with the rule defied logic. It would have set a harmful precedent infringing upon banks and other depository institutions’ ability to charge fees for services.
The agency finally resigned to the fact its attempt to curb fee collections was ultra vires. The CFPB argued in its memorandum of support that the silence on fees within the statute does not confer a reasonable justification for a blanket fee prohibition within the rule.
Another danger embedded in the rule emerged regarding the ability of third-parties to engage in screen-scraping. The final rule would have permitted customers to voluntarily disclose their login credentials to third parties, allowing them direct access to highly sensitive data through the customer’s user interface. The rule would even classify account and routing numbers as data that must be shared by banks with third parties.
In other jurisdictions where comparable measures have been implemented, such as the U.K. and the EU, rules are set in place designating liability risks among relevant parties when a third party suffers a data breach. The CFPB’s rule offered no such equivalent protection. This meant that banks could be held liable if a third party data recipient suffered a data breach, even if a customer authorized data sharing permission.
The current system for third-party data sharing by financial institutions involves individual bilateral agreements on how data is shared and what that data can be used for. Government agencies should not attempt to upend private contracts and set data-sharing agreements.
Section 1033 never intended to establish an open banking regime. The CFPB’s reversal on 1033 demonstrates the agency’s acknowledgement that its interpretation of the statute was far too overreaching. Federal agencies must respect consumer data privacy and avoid intervening to open a pandora’s box of safety issues financial institutions already keep well contained.