When a budgeting app connects to your bank account without asking for your bank password directly, that’s “open banking” (sometimes called open finance) at work — a shift in how financial data moves between institutions, driven as much by federal rulemaking as by the apps themselves. The rule behind that shift in the U.S. has a specific name, a specific history, and, as of this writing, an unsettled future.
What the rule actually says
In October 2024, the Consumer Financial Protection Bureau finalized the Personal Financial Data Rights rule, activating Section 1033 of the Consumer Financial Protection Act — a legal authority Congress had enacted back in 2010 but that had never been implemented. The rule requires banks, credit card issuers, and other financial providers to give consumers free access to their own data (transaction history, account balances, information needed to initiate payments) and to let them authorize a third party, like a budgeting app or a competing bank, to access that same data on their behalf.
Two mechanical details matter more than they sound like they would. First, the rule is explicitly meant to move providers away from screen scraping — the older, riskier practice where a third-party app asks for your actual bank username and password and logs in as you to grab your data — toward secure, purpose-built data connections that don’t require handing over your real credentials. Second, it created a right to revoke access: when you revoke a third party’s access, the rule requires that access to end immediately, with data deletion as the default, and access can’t be extended past one year without you actively reauthorizing it. It also bars a “bait-and-switch”: a third party can only use your data for what you actually asked it to do, not for unrelated purposes like targeted advertising.
The rule set a phased compliance schedule based on institution size, with the largest providers required to comply starting April 1, 2026, and the smallest covered institutions given until April 1, 2030. Some small banks and credit unions were exempted entirely.
Why its status matters right now
None of that is settled law in practice. The CFPB reopened the rule for reconsideration through an Advance Notice of Proposed Rulemaking in August 2025, and reporting through mid-2026 indicates a federal court has enjoined enforcement of parts of the rule while that reconsideration plays out. In plain terms: the rule was finalized, but whether it survives in its 2024 form, gets rewritten, or gets rolled back is an open question as of this writing, and the compliance dates above may not hold. Anyone relying on this rule for a specific legal right — a business building around it, or a consumer expecting a specific protection — should check the CFPB’s current rulemaking status rather than assume the 2024 version is fully in force.
What this means for someone linking their own accounts today
Regardless of where the rule ends up, the underlying practical guidance for individuals doesn’t change much. When connecting a budgeting app, investment tracker, or lending app to your bank:
- Prefer apps that connect through your bank’s own secure login flow (often shown as a redirect to your bank’s actual site) rather than ones that ask you to type your online banking password directly into a third-party app — that’s the screen-scraping pattern the rule was written to move away from.
- Check what data an app is requesting access to, and for how long, rather than accepting a broad, indefinite grant by default.
- Periodically review which third parties still have access to your accounts and revoke anything you no longer use — an old, forgotten connection is one more thing that can be compromised without your noticing.
These are reasonable habits whether or not the federal rule survives reconsideration in its current form, because they follow directly from how the underlying technology works, not from the specific legal requirement.
The competitive argument behind the rule
The CFPB’s own framing for the rule leaned heavily on competition: easier data portability was meant to make it simpler to switch banks or lenders without losing transaction history, and to let lenders extend credit based on income and spending data held elsewhere — a potential benefit for people with thin credit files, including younger borrowers. Whether that plays out depends on the rule’s final form, which, again, is not yet decided.
This article is educational and describes a regulatory rule and its status as understood at the time of writing; rulemaking status changes, and this isn’t legal or financial advice for your specific situation. See our Financial Disclaimer, and check consumerfinance.gov directly for the current, authoritative status of this rule before relying on it.