As the CFPB reconsiders Section 1033, financial firms face an operational question behind the rulemaking: how do you keep consumer authorization disclosures controlled, current and consistent across digital channels?
The U.S. framework for consumer financial data access is moving again.
On 4 August 2026, the Consumer Financial Protection Bureau submitted its reconsideration of the Personal Financial Data Rights rule, commonly associated with Section 1033 of the Dodd-Frank Act, to the Office of Information and Regulatory Affairs for review.[1]
The proposal remains under review, and its text has not yet been published.
That distinction matters.
It would be premature to say that the CFPB has introduced new disclosure, consent or data-sharing requirements. What we know is that the Bureau is reconsidering parts of the rule it finalized in 2024, after previously seeking public comment on four areas: who may act as a consumer's representative, potential fees for data access, information security and privacy.[2]
Within the privacy questions, the CFPB also asked specifically about practices such as licensing or selling consumer-authorized data without the consumer's knowledge.[2]
For firms building or operating open banking journeys, that creates an unusual position: the direction of travel is visible, but the exact destination is not.
And behind that regulatory uncertainty sits a practical communications problem.
The rule already says a great deal about consumer authorization
The 2024 Personal Financial Data Rights rule established detailed requirements around how third parties obtain authorization to access consumer financial data.
Under the existing regulatory text, a third party seeking access must obtain the consumer's express informed consent through an authorization disclosure that is signed electronically or in writing.[3]
That disclosure must be clear, conspicuous and separated from other material.
It must also provide information including the identity of the third party, the data provider, the product or service the consumer has requested, and the categories of data the third party intends to access.[3]
The framework goes beyond the first authorization screen.
The existing rule also includes requirements relating to providing the consumer with a copy of the authorization disclosure, identifying the date on which it was signed, and making information available about the status of the authorization, the categories of data collected, the reasons for collecting them and how authorization can be revoked.[3]
These requirements illustrate something important about open banking.
Consent is not simply a button.
It is a chain of communications.
A consumer may encounter information about data access during onboarding, inside a mobile application, on a web page, within an authorization disclosure, through a third-party interface and later through communications about continuing or revoking access.
Each of those touchpoints can contain regulated wording.
The rule is still there, but the compliance timetable is not currently running
There is another layer to the story.
The compliance dates associated with the 2024 rule are currently suspended following a court order issued on 29 October 2025 in Forcht Bank, N.A. v. CFPB.[4]
That suspension concerns when firms must comply.
It should not be confused with the content of the rule itself.
The regulatory text describing authorization disclosures, consent and related obligations remains part of the existing rule, while the timetable for mandatory compliance is suspended as litigation and the CFPB's reconsideration continue.[3][4]
Even before that suspension, implementation dates had already moved.
The original framework contemplated phased compliance dates running from 2026 through 2030, depending on the size and type of institution. Those dates were subsequently postponed before the broader judicial suspension took effect.[2][4]
For financial institutions and third parties preparing open banking programmes, that means the regulatory environment has already gone through several stages before the reconsidered proposal has even been published.
Regulatory change creates a communications problem
This is where a rulemaking exercise becomes an operational issue.
Imagine a consumer connecting a bank account to a fintech application.
The journey might involve:
- an onboarding screen;
- an explanation of the service;
- an authorization disclosure;
- categories of data that will be accessed;
- privacy information;
- information about the third party receiving the data;
- confirmation of the authorization;
- later communications about continuing access or revocation.
Those pieces may not live in one system.
The mobile application may contain one set of wording. The website may use another template. A data aggregator may control part of the journey. Confirmation emails may be generated from a separate communications platform.
Now introduce a regulatory change.
One disclosure is updated.
Then another.
Legal approves revised wording. Product updates the web journey. Engineering schedules the application change for the next release. A third-party integration is updated separately.
Without strong controls, the result can be version drift.
The website displays one version.
The mobile application displays another.
An automated email still contains wording approved under an earlier process.
The problem is no longer simply whether the organization has written the correct disclosure.
It is whether the organization knows which approved wording is live at each customer touchpoint.
The difficult question comes later
Operational weaknesses around communications are often invisible while everything is working normally.
They become visible months later.
A consumer challenges a data-sharing authorization.
An internal compliance review asks how a particular disclosure changed.
A regulator wants to understand what information was presented at a specific point in the customer journey.
The organization then has to reconstruct the past.
Which disclosure was approved at that time?
When did the new version become effective?
Was the same wording deployed to web and mobile?
Was an older email template still active?
Which version was presented when that particular consumer gave authorization?
Not every one of these questions represents an explicit Section 1033 requirement.
They are operational questions that arise when regulated communications change across multiple systems.
That distinction is important.
The regulation defines the legal requirements. Firms still have to decide how they will control the communications used to meet them.
Open banking makes version control a business issue
Historically, communication templates have often been treated as implementation detail.
A piece of wording sits in application code. Another lives in a content management system. Another sits with a third-party provider.
That approach becomes harder to defend as communications become part of the mechanism through which regulated decisions and consumer permissions are obtained.
If a disclosure must be clear, conspicuous and presented separately from other material, then its wording and placement matter.
If authorization depends on informed consumer consent, then the information supporting that consent matters.
And if a rule changes, knowing where that information is used becomes important too.
This makes communication governance more than an editorial concern.
It becomes part of operational control.
Teams need to know what wording has been approved, what version is currently in use, where it appears, when it changed and how previous versions can be reconstructed if necessary.
The technology used to achieve that can vary.
The control objective is simpler: regulated communications should not quietly diverge across channels.
What firms should be watching next
The immediate regulatory milestone is the CFPB's reconsidered proposal.
Until the proposal is published, firms should be cautious about predicting how Section 1033 will change.
The Bureau's earlier consultation gives an indication of the areas under review, but it does not tell us what the final proposal will contain.
Once the new text appears, financial institutions, fintechs, data providers and third parties will need to compare it carefully against the 2024 rule.
The legal analysis will matter.
So will a more operational question:
If the wording supporting consumer consent has to change, how quickly can the organization identify every place where that wording appears, approve the replacement and demonstrate which version was in use at any particular point in time?
Open banking is usually discussed as a problem of APIs and access to data.
Increasingly, it is also a problem of communication control.