How to Build Open Banking So Consumers Actually Win
By Maisie Clark Bilotti, VP, External Relations, Policy & Regulatory at MX
Simple Subscribe
Subscribe Now!
Americans now manage their financial lives across more apps, accounts, and institutions than ever before. Section 1033 is the rule that decides whether that increasingly connected ecosystem works for consumers or against them. As the CFPB reconsiders the rule, much of the debate has been framed as a series of trade-offs: access versus security, innovation versus trust, consumers versus financial institutions.
But those don’t have to be opposing forces. Open banking is one of those rare opportunities where protecting consumers and growing competition pull in the same direction. The only question is whether we build it that way. Here’s what doing it right looks like across the issues that matter most.
Need to Know:
- Section 1033 works when it treats a consumer’s data as the consumer’s own, meaning it is free to access, portable, and protected by consent and security obligations that every participant meets.
- The fee debate is where the “old” rule gets it exactly right. Per-call tolls on data access don’t create a more competitive market; they risk advantaging the largest incumbents, raising barriers for smaller players, and reviving less secure methods of moving data.
- Pair free data access with sensible secondary-use rules, shared standards, strong security, and real privacy protections, and open banking delivers the thing everyone claims to want: a market where consumers win and competition thrives.
Start From the Right First Principle: The Data Belongs to the Consumer
Every hard question in open banking gets easier once you settle the first one: who does the data belong to? Section 1033 of the Dodd-Frank Act starts from the right premise. A consumer’s financial data is the consumer’s own, and the institution holding it at any given moment is its custodian, not its owner.
From there, the rest of the framework follows. Consumers should be able to access their data and share it with the providers they choose. They should be able to do this directly, in a usable electronic form, through a representative acting on their behalf.
That last point matters more than it might seem. Raw data a consumer can technically download isn’t necessarily “usable.” The real value of open banking comes when consumer-permissioned data can be securely connected, made understandable, and turned into action —whether that’s better budgeting, smarter lending decisions, fraud monitoring, personalized guidance, or a more complete financial picture.
The Current Rule Gets One Thing Exactly Right: Keep Data Access Free
If any single provision is worth protecting, it is the ban on data access fees. And it is facing the fiercest opposition.
The argument in favor of fees has been packaged persuasively: financial institutions invest in infrastructure to make consumer-permissioned data sharing possible, while other companies build products and businesses using those connections. It has been argued a “modest, market-based” charge is a fair way to distribute these costs.
But that framing misses an important part of the equation: Data providers benefit from open banking infrastructure too.
That’s one reason sophisticated financial institutions began investing in APIs years ago without charging for access. Moving customers from credential-based screen scraping to tokenized APIs can reduce fraud risks, give greater visibility into who is accessing data, provide mechanisms to shut off bad actors, and create opportunities to serve customers across their broader financial lives.
Open banking infrastructure shouldn’t be viewed simply as a cost center. Done well, it’s an industry-wide investment in security, customer experience, and growth.
Fees also create a fundamental competition problem. When an aggregator must accept a provider’s terms or lose access to a significant portion of their customers’ financial data, there isn’t a traditional competitive market setting the price. And today’s “modest” fees are a starting figure, not a ceiling. Large institutions may be able to absorb these costs, but startups and smaller providers may not. Allowing individual data providers to set varying access fees could ultimately give the institutions holding the most data significant influence over the economics of the companies competing to serve their customers.
Consumers already pay for the infrastructure required to access their accounts, just as they support branches, call centers, ATMs, websites, and mobile apps. Open banking is simply another channel to a consumer’s own data; singling it out for a per-use charge risks converting a statutory right into a metered product, and, predictably, pushes cost-sensitive players back toward screen scraping to avoid the meter — reintroducing the exact security risk the industry has spent years trying to retire. The better approach is the way the rule already has it: keep consumer-permissioned data access free, and build trust through strong security, privacy, and accountability requirements.
Make Data Genuinely Useful Through Sensible Use Rules and Shared Standards
Protecting consumers and enabling innovation are not opposing goals, but the current rule occasionally treats them that way. Getting the balance right requires thoughtful rules around how data can be used once a consumer chooses to share it.
First, secondary use. Value should be created for the consumer, not extracted behind their back. But the current rule’s “reasonably necessary” limit is drawn so tightly that it can prevent consumers from choosing services they actually want and affirmatively consent to: Sharper fraud models built on a fuller financial picture, genuinely tailored offers, and privacy-preserving aggregate research that can improve products and outcomes for thin-file borrowers. Improvements in this section of the rule would be of great benefit for ethical marketers looking to curate their campaigns to customers in ways that would benefit them. The answer isn’t a blanket ban or a free-for-all; it’s letting an informed consumer authorize and easily revoke uses that add value for them.
Second, standards. The U.S. data ecosystem is larger and more fragmented than any other, and it only works if participants speak the same technical language. Consensus standards, like those developed through the Financial Data Exchange, are what help an institution of any size connect securely without reinventing the plumbing — and what could, through certification and safe harbors, shrink the compliance burden for smaller players and regulators alike. Shared standards are how a complex market scales while remaining open instead of splintering into a collection of private terms dictated by whoever holds the most data.
Build Trust the Way That Actually Earns It: Security and Privacy
One of the strongest concerns about open banking is ultimately a case about trust. MX research shows that 55% of consumers aren’t sure what companies or providers have access to their financial data. That concern is fair, and it’s exactly what a well-built rule answers directly.
Section 1033 already does. It requires express, informed consent through a clear, standalone disclosure of who is accessing data, what they’ll collect, and why. It mandates an easy, real revocation mechanism for consumers to turn access off, and in most cases the recipient must stop collecting and delete what it holds. It holds data providers and third parties to the same GLBA-grade security standard, and it moves the whole market off screen scraping and onto secure APIs. On privacy, it prohibits selling consumer data and pushes the industry toward a true opt-in norm: data is shared because a consumer chose to share it, not because they failed to find an obscure opt-out.
There are opportunities to make those protections even stronger. Security compliance should be verifiable through recognized frameworks (SOC 2, ISO 27001, or NIST CSF) assessed by accredited auditors. Appropriate safe harbors for participants that reasonably rely on those certifications could help trust scale without creating a regulatory bottleneck. And liability should follow the data, with accountability resting on whoever holds it when something goes wrong. A clear and consistent liability framework creates stronger incentives for every participant to protect consumers. That’s a more durable way to build trust than assuming risk belongs to one category of participant or using that risk to justify charging for access.
The Choice in Front of Us
Open banking is one of the rare policy opportunities where consumer protection and market competition genuinely point in the same direction. The version that works keeps consumer-permissioned data free to access and move, allows informed consumers to authorize uses that benefit them, runs on shared standards, and earns trust through consent, security, and clear liability. And when we get those pieces right, open banking becomes infrastructure for a more competitive ecosystem — one where consumers choose the products that work best for them, new entrants have a fair opportunity to compete, and financial institutions can build better experiences, drive growth, and deepen customer relationships.
The alternative is a system where access to consumer data comes with a toll, handing the certain players a new lever, and calling it fairness.
We can build an open banking ecosystem where consumers actually win and competition actually thrives. Updating Rule 1033 in the right ways is how we make it happen.
