# 90 FR 40986: Personal Financial Data Rights Reconsideration

> Federal · Regulations · In force

URL: https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2025-16139

## Section

- **Citation:** 90 FR 40986
- **Heading:** Personal Financial Data Rights Reconsideration
- **Jurisdiction:** Federal
- **Kind:** Regulations
- **Status:** In force
- **Text as of:** August 14, 2026
- **Source:** Compiled text
- **Location:** Federal Register / Vol. 90 / 90 FR 40986

## Text

C 20552.
Instructions: The CFPB encourages the early submission of comments. All submissions should include the agency name and docket number. Additionally, where the Bureau has asked for specific comment on a topic, commentors should seek to highlight the topic to which its comment is applicable. Because paper mail is subject to delay, commenters are encouraged to submit comments electronically. In general, all comments received will be posted without change to https://www.regulations.gov.
All submissions, including attachments and other supporting materials, will become part of the public record and subject to public disclosure. Proprietary information or sensitive personal information, such as account numbers or Social Security numbers, or names of other individuals, should not be included. Submissions will not be edited to remove any identifying or contact information.
FOR FURTHER INFORMATION CONTACT:
Dave Gettler, Paralegal Specialist, Office of Regulations, at 202-435-7700 or at: https://reginquiries.consumerfinance.gov/. If you require this document in an alternative electronic format, please contact CFPB_Accessibility@cfpb.gov.

SUPPLEMENTARY INFORMATION:
I. Background
Technology has made it possible to store, analyze, and share personal financial data electronically, and interest has grown within the financial services industry and among policymakers in the potential benefits of bolstering consumers' rights to access personal financial data. Consistent with this desire to increase consumers' access to their financial information, section 1033(a) of the Dodd-Frank Act provides that, subject to rules issued by the CFPB, consumers shall have access to requested information in the control or possession of financial entities relating to the products or services obtained from those financial entities.
Section 1033 of the Dodd-Frank Act, codified as 12 U.S.C
consists of the following:
• A general articulation of the scope of the information that may be obtained by the consumer. (Sub-section A)
• An explicit list of exceptions laying out information a covered person is not required to provide. (Sub-section B)
• An explicit statement that section 1033 does not impose any duty on a covered person to maintain or keep any information about a consumer. (Sub-section C)
• Authorization for the CFPB to prescribe standards for how information will be transmitted to consumers. (Sub-section D)
• The inter-agency consultation requirements when prescribing rules implementing section 1033. (Sub-section E)
On November 18, 2024, the Bureau published the Personal Financial Data Rights final rule (PFDR Rule) under section 1033. 1 In general, the PFDR Rule applies to financial institutions, which it describes as “data providers,” that issue credit cards, hold transaction accounts, issue devices to access an 2 On July 29, 2025, the court granted a motion to stay proceedings in the case, following the Bureau's announcement that it “seeks to comprehensively reexamine this matter alongside stakeholders and the broader public to come up with a well-reasoned approach . . . that aligns with the policy preferences of new leadership and addresses the defects in the [PFDR Rule].” 3
1 89 FR 90838 (Nov. 18, 2024). In June 2024, the Bureau finalized a portion of the proposal, regarding attributes a standard-setting body must possess to receive CFPB recognition and establishing the application process for CFPB recognition. 89 FR 49084 (June 11, 2024). The June 2024 rule was then incorporated into the November 2024 final rule.
2 Forcht Bank, N.A. v. CFPB, No. 5:24-cv-00304 (E.D. Ky. 2024).
3 Order Granting Motion to Stay, No. 5:24-cv-00304 (July 29, 2025) (ECF No. 83).
II
ng attributes a standard-setting body must possess to receive CFPB recognition and establishing the application process for CFPB recognition. 89 FR 49084 (June 11, 2024). The June 2024 rule was then incorporated into the November 2024 final rule.
2 Forcht Bank, N.A. v. CFPB, No. 5:24-cv-00304 (E.D. Ky. 2024).
3 Order Granting Motion to Stay, No. 5:24-cv-00304 (July 29, 2025) (ECF No. 83).
II. Executive Order 12866
The Office of Information and Regulatory Affairs within the Office of Management and Budget (OMB) has determined that this action is a “significant regulatory action” under Executive Order 12866, as amended. Accordingly, the OMB has reviewed this action.
III. Questions
Scope of Who May Make a Request on Behalf of a Consumer
As the term is used in section 1033 of the Dodd-Frank Act, a “consumer” is defined as an individual or an agent, trustee, or representative acting on behalf of an individual. 12 U.S.C. 5481(4). At common law, an agent has fiduciary duties such as those of care, loyalty, good faith, and confidentiality. Also at common law, a “trustee” has these fiduciary duties as well as any specific duties that are required by the terms of the trust. The PFDR Rule interpreted the phrase “representative acting on behalf of an individual” to include third parties that access consumers' data pursuant to certain authorization procedures and substantive obligations. 4 The Bureau estimated that “more than 100 million consumers have used consumer-authorized data access” in the U.S. via third parties as of 2024. 5 The Bureau is seeking comments generally on the proper scope of how the term “representative” should be interpreted. Specifically, the Bureau requests comments on the following questions:
4 See 12 CFR part 1033, subpart D.
5 See 89 FR 90838 at 90958.
1
of care, loyalty, good faith, and confidentiality. Also at common law, a “trustee” has these fiduciary duties as well as any specific duties that are required by the terms of the trust. The PFDR Rule interpreted the phrase “representative acting on behalf of an individual” to include third parties that access consumers' data pursuant to certain authorization procedures and substantive obligations. 4 The Bureau estimated that “more than 100 million consumers have used consumer-authorized data access” in the U.S. via third parties as of 2024. 5 The Bureau is seeking comments generally on the proper scope of how the term “representative” should be interpreted. Specifically, the Bureau requests comments on the following questions:
4 See 12 CFR part 1033, subpart D.
5 See 89 FR 90838 at 90958.
1. What is the plain meaning of the term “representative?” Does the PFDR Rule's interpretation of the phrase “representative acting on behalf of an individual” represent the best reading of the statutory language? Why or why not?
2. Are there other provisions in Federal statutes or financial services market practice in which third parties authorized to act on behalf of an individual encompass, on an equivalent basis, both those having fiduciary duties and those who do not?
3. Does the statutory reference to an “agent, trustee, or representative” indicate that “representative” is intended to encompass only those representatives that are serving in a fiduciary capacity? If a “representative” under 12 U.S.C. 5481(4) is interpreted to be an individual or entity with fiduciary duties, what are the distinctions between an “agent” and a “representative” for purposes of section 1033?
4. In seeking the best reading of the statutory language, what evidence or interpretive principles should the Bureau consider with respect to the term “representative?”
5. If a “representative” under 12 U.S.C
red by part 1033. Section 1033 of the Dodd-Frank Act, however, is silent on the question of how the burden of consumers' exercise of the rights it creates should be shared between the consumer and the “covered person.” The Bureau is seeking comments and data generally on how to deal with this omission, and whether costs, benefits, or market forces might justify modifying the PFDR Rule's provisions. Specifically, the Bureau requests comments and data on the following questions:
6 89 FR 90838 at 90884-87.
9. Does the PFDR Rule's prohibition on fees represent the best reading of the statute? Why or why not?
10. Was the PFDR Rule correct to conclude that permitting fees “would obstruct the data access right that Congress contemplated”? Why or why not?
11. What is a reasonable range of estimates regarding the fixed costs to “covered persons” of putting in place the standards required by sub-section D of section 1033 and the operational architecture to intake, document, and process requests made by consumers, including natural persons and persons acting on behalf of a natural person ( i.e., an agent, trustee, or representative)? How do these estimates vary by the size of the covered financial institution?
12. What is a reasonable range of estimates regarding the marginal cost to covered financial institutions of responding to requests made under the auspices of section 1033? How do these estimates vary by the size of the covered financial institution?
13. How is the range above affected by the need of the “covered person” to confirm that an agent, trustee, or representative acting on behalf of an individual has actually been authorized by the consumer to act on their behalf?
14. Is there any legal precedent from other Federal statutes, not involving Federal criminal law or provision of services by the U.S
the covered financial institution?
13. How is the range above affected by the need of the “covered person” to confirm that an agent, trustee, or representative acting on behalf of an individual has actually been authorized by the consumer to act on their behalf?
14. Is there any legal precedent from other Federal statutes, not involving Federal criminal law or provision of services by the U.S. Government, where there is a similar omission of explicit authorization to the agency to set a cost sharing balance in effectuation of a new statutory right and, if so, what principles has the court allowed the agency to use in establishing a proper balance?
15. Absent any legal precedent from other laws, should covered persons be able to recover a reasonable rate for offsetting the cost of enabling consumers to exercise their rights under section 1033? Why or why not?
16. If covered persons should be able to recover a reasonable rate for offsetting the costs of enabling consumers to exercise their rights under section 1033, should the Bureau place a cap on the upper bounds of such rates that can be charged? If so, what should the cap be on such rates, and why? If not, why not?
17. If consumers ought to bear some of the cost in implementing requirements under section 1033, should that be shared by every consumer of a covered person, including those who may not wish to exercise their rights under section 1033?
Information Security Concerns in the Exercise of Section 1033 Rights
One unfortunate byproduct of the transition to a largely digital information architecture is the increased number of threat vectors to the secure storage and transmission of data. In the context of the PFDR Rule, in which several types of covered persons are engaged in the use, retention, and transmittal of consumer financial data, adequate information security standards and controls must be in place to guard against malicious actors, including fraudsters, scammers, and “Business Email Compromise” or “BEC” perpetrators
ion 1033, should that be shared by every consumer of a covered person, including those who may not wish to exercise their rights under section 1033?
Information Security Concerns in the Exercise of Section 1033 Rights
One unfortunate byproduct of the transition to a largely digital information architecture is the increased number of threat vectors to the secure storage and transmission of data. In the context of the PFDR Rule, in which several types of covered persons are engaged in the use, retention, and transmittal of consumer financial data, adequate information security standards and controls must be in place to guard against malicious actors, including fraudsters, scammers, and “Business Email Compromise” or “BEC” perpetrators. 7
7 The Federal Bureau of Investigation has estimated that BEC has caused $55 billion in losses between 2013 and 2023. See Fed. Bureau of Investigation, Business Email Compromise: The $55 Billion Scam, https://www.ic3.gov/PSA/2024/PSA240911 (last visited Aug. 1, 2025).
The existence of data breaches is a constant threat and has affected some of the most sophisticated and well-financed institutions including: Yahoo (2013 and 2014); the Office of Personnel Management (2015); Equifax (2017); Marriott (2018); LinkedIn (2019); Facebook (2019); and OCC (2025). All it takes is a single mistake in compromising internal data security protocols for an enormous amount of personal information, including personally identifiable information (PII), to become available to malign actors and available for sale on the dark web. The risks regarding improper transmission of personal financial data underscore the need to ensure that entities authorized to access that information have appropriate safeguards in place.
The PFDR Rule attempted to address information security in several ways
ormation security standards ought entities adhere when accessing consumer financial data held by a covered person, and who is best positioned to evaluate whether these entities are adhering to such standards?
28. What are the costs and benefits of the PFDR Rule's provisions designed to reduce the use of screen scraping? What changes would better protect the security of consumer credentials?
29. Does the PFDR Rule provide adequate protections for consumers and covered persons to ensure that the request for a consumer's information is in fact knowingly authorized by the individual consumer and that the information is in fact being made available to the consumer as opposed to a malicious actor?
Privacy Concerns in the Exercise of Section 1033 Rights
A consumer's financial transactions reveal an enormous amount of information about their habits and lifestyle. Even for those who are comfortable with the existence of an extensive digital record that can often accurately be used to predict their behavior, there is certain information that few individuals may not want revealed to everyone and anyone, sometimes even those closest to them. Such information includes transaction data that reveals the existence of: (a) medical conditions; (b) financial vulnerability; (c) financial abundance that could make them the target of criminal activity; and (d) substance abuse problems or other high-risk behaviors. So long as the information is
Financial institutions collect, use, and disclose data in many ways that impact consumer privacy. One major privacy threat is when customers are unaware of ongoing licensure or sale of their data. The percentage of service platform users who actually read user agreements is very low. 8 While such individuals are responsible for the consequences of such inattentiveness, it does not reduce the potential annoyance or harm from use of that data to target an individual for financial profiling and aggressive marketing.
8 See, e.g., Pew Rsch
re unaware of ongoing licensure or sale of their data. The percentage of service platform users who actually read user agreements is very low. 8 While such individuals are responsible for the consequences of such inattentiveness, it does not reduce the potential annoyance or harm from use of that data to target an individual for financial profiling and aggressive marketing.
8 See, e.g., Pew Rsch. Ctr., Americans and Privacy: Concerned, Confused and Feeling Lack of Control Over Their Personal Information, at 38 (Nov. 2019) (poll of American adults finding that nine percent reported that they “always” read privacy policies).
Subpart D of the PFDR Rule required third parties to obtain a consumer's express informed consent to access covered data on behalf of the consumer, prescribed what a third party must disclose to a consumer, and limited a third party's collection, use, and disclosure of covered data. 9 The Bureau is seeking comments and data generally on the threats to data privacy as a result of unwitting licensing or sale of sensitive personal financial information, and on any modifications to the PFDR Rule's provisions. Specifically, the Bureau is seeking comments and data on the following questions:
9 See 12 CFR 1033.401(c) (requiring consumer's express informed consent to access covered data on behalf of the consumer by obtaining an authorization disclosure that is signed by the consumer electronically or in writing); 12 CFR 1033.411(b) (specifying content requirements for the authorization disclosure); 12 CFR 1033.421 (explaining a third party's obligations with respect to the collection, use, and retention of covered data). The PFDR Rule also requires third parties to provide the consumer with a copy of the authorization disclosure that the consumer has signed electronically or in writing and that reflects the date of the consumer's electronic or written signature. 12 CFR 1033.421(g)(1).
30. Does the PFDR Rule provide adequate protection of consumer privacy? Why or why not?
31
use, and retention of covered data). The PFDR Rule also requires third parties to provide the consumer with a copy of the authorization disclosure that the consumer has signed electronically or in writing and that reflects the date of the consumer's electronic or written signature. 12 CFR 1033.421(g)(1).
30. Does the PFDR Rule provide adequate protection of consumer privacy? Why or why not?
31. How prevalent is the licensure or sale of consumer financial data by bank and non-bank financial institutions, where customers either have the right to opt into or opt out of having their data licensed or sold? What is the approximate balance between such regimes where the customer is given a choice?
32. How prevalent is the licensure or sale of consumer financial data by bank and non-bank financial institutions where consent to license or sale is part of a standard user agreement or privacy notice?
33. What is the prevalence of licensure or sale of consumer data by companies with a fiduciary duty to their clients?
34. What estimates exist on the percentage of financial service platform users who actually read and/or understand user agreements and privacy notices in their entirety?
Compliance Dates
The PFDR Rule included a series of compliance dates by which data providers would need to comply with the requirements in subparts B and C of the PFDR Rule. 10 These compliance dates were determined by the size of the entity, and ran from April 1, 2026, through April 1, 2030. 11 As part of its reconsideration of the PFDR Rule, the Bureau plans to issue a Notice of Proposed Rulemaking to extend the compliance dates. The Bureau is seeking comments and data generally on the appropriateness of the compliance dates in the PFDR Rule, and what extension may be appropriate
iance dates were determined by the size of the entity, and ran from April 1, 2026, through April 1, 2030. 11 As part of its reconsideration of the PFDR Rule, the Bureau plans to issue a Notice of Proposed Rulemaking to extend the compliance dates. The Bureau is seeking comments and data generally on the appropriateness of the compliance dates in the PFDR Rule, and what extension may be appropriate. Specifically, the Bureau is seeking comments and data on the following questions:
10 The PFDR Rule did not set explicit compliance dates for third parties that receive data on the grounds that their compliance was functionally tied to compliance by data providers.
11 Pursuant to a court order, the compliance dates have been stayed by 90 days. Thus, the first compliance date is now June 30, 2026.
35. Have entities encountered unexpected difficulties or costs in implementing the PFDR Rule to date?
36. If the Bureau were to make substantial revisions to the PFDR Rule, how long would entities need to comply with a revised rule? How would the necessary implementation time vary based on the size of the entity covered by the rule?
Russell Vought, Acting Director, Consumer Financial Protection Bureau.

[FR Doc. 2025-16139 Filed 8-21-25; 8:45 am] BILLING CODE 4810-AM-P

## Nearby sections

- [90 FR 59 Access to Video Conferencing](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2024-30501.md)
- [90 FR 271 Securing the Information and Communications Technology and Services Supply Chain: Unmanned Aircraft Systems](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2024-30209.md)
- [90 FR 283 Air Plan Approval; Ohio; Moderate Attainment Plan Elements for the Cleveland Area for the 2015 Ozone Standard](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2024-30717.md)
- [90 FR 578 Airworthiness Directives; Bombardier, Inc., Airplanes](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2024-31624.md)
- [90 FR 581 Section 30C Alternative Fuel Vehicle Refueling Property Credit; Hearing](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2024-31233.md)
- [90 FR 1050 Modification of Class E Airspace; Battle Mountain Airport, Battle Mountain, NV](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2024-31694.md)
- [90 FR 1054 Endangered and Threatened Wildlife and Plants; Removal of Ute Ladies'-Tresses From the List of Endangered and Threatened Plants](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2024-30380.md)
- [90 FR 1419 Endangered and Threatened Wildlife and Plants; 90-Day Finding on Two Petitions for Gray Wolf](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2024-31754.md)
- [90 FR 1421 Endangered and Threatened Wildlife and Plants; Endangered Species Status for the Bleached Sandhill Skipper](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2024-31761.md)
- [90 FR 1909 Federal Baseline Water Quality Standards for Indian Reservations; Withdrawal of Proposed Rule](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2024-31219.md)
- [90 FR 2550 Amendments to Definitions and Related Provisions Under the Randolph-Sheppard Vending Facility Program](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2025-00124.md)
- [90 FR 3046 Airworthiness Directives; Siam Hiller Holdings, Inc, Helicopters](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2025-00588.md)
- [90 FR 3107 C.I. Pigment Violet 29 (PV29); Regulation Under the Toxic Substances Control Act (TSCA)](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2024-30931.md)
- [90 FR 3720 Oranges and Grapefruit Grown in Lower Rio Grande Valley in Texas; Increased Assessment Rate](https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2025-00193.md)

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/statutes/FR_PRORULE_2025-16139. Check the current official text before relying on it. Not legal advice.
