What's Happening?
The Consumer Financial Protection Bureau (CFPB) has submitted a new Section 1033 open banking proposal to the White House Office of Information and Regulatory Affairs. While the content of this rewrite is not yet public, data-access fees are anticipated
to be a central and highly contested issue. Section 1033 concerns consumers' ability to access and share their financial data through bureau-prescribed standards. For fintech companies, this regulatory foundation directly impacts API performance, consent management, security, vendor dependency, and contractual liability. If the rewrite alters who pays for data access, what data providers must support, or how third parties use consumer-permissioned data, fintech insurance buyers will need to re-evaluate their technology errors and omissions, cyber, privacy, directors and officers, and contractual indemnity language. The rewrite is significant because open banking, while appearing to be a policy debate, quickly becomes an operational question when issues arise, determining responsibility for data access, API failures, and contractual obligations.
Why It's Important?
This regulatory rewrite is critical for the fintech industry as it will define the infrastructure surrounding consumer-permissioned financial data. The potential changes to data-access fees are not merely commercial; they directly influence risk allocation and operational resilience within the open banking ecosystem. Fees can dictate who connects to whom, the frequency of data pulls, whether commercial API calls are rationed or priced differently, and the contractual duties underpinning the access model. For fintechs relying on third-party data access, understanding the implications of changes in pricing, availability, access terms, or authentication standards is paramount. The underwriting concern extends beyond regulatory compliance to operational resilience, as disruptions or repricing of data access can significantly impact a company's revenue and service delivery. This makes it imperative for open banking firms to align their insurance coverage with their actual data flow and operational model, rather than relying on generic risk assessments.
What's Next?
Fintech companies operating in the open banking space are advised to proactively review and update their insurance programs in anticipation of the CFPB's Section 1033 rewrite. This involves mapping their data flows, consent processes, vendor relationships, and contracts to ensure their policies adequately cover potential risks. Specific areas for review include technology errors and omissions (E&O) for issues like failed data access or API outages, cyber and privacy insurance for consent management and breach response, contractual liability for indemnities between various parties, and Directors and Officers (D&O) insurance for oversight of regulatory change and dependency risk. Companies should also assess business interruption coverage to understand the revenue impact if data access is disrupted or repriced. The goal is to ensure that insurance submissions accurately reflect the unique operational model of open banking, moving beyond generic SaaS risk profiles. The release and finalization of the CFPB's new rule will be a pivotal moment, requiring immediate adaptation from all stakeholders.
Beyond the Headlines
The CFPB's Section 1033 rewrite underscores the complex and evolving regulatory landscape surrounding data privacy and financial innovation. Beyond the immediate commercial and risk implications, this initiative touches upon fundamental questions of consumer rights in the digital age, particularly the right to access and control personal financial data. The debate over data-access fees highlights the tension between fostering an open, competitive market and ensuring fair compensation for data providers, while also protecting consumers from potential exploitation. The outcome of this rewrite could set a precedent for how data is valued and exchanged across various industries, influencing future regulations on data portability and interoperability. It also brings to light the ethical responsibility of financial institutions and fintechs to manage sensitive consumer data securely and transparently, emphasizing that regulatory compliance is not just about avoiding penalties but about building trust and ensuring the long-term sustainability of digital financial services.











