Fintechs, aggregators and banks may agree on data sharing, but accountability should be equally assigned to all parties, according to JPMorgan Chase. At an industry forum in Washington, D.C., Natalie Williams, general counsel for responsible banking and data at Chase, said each party should be held to the same standards as banks.
“Our customers, because they have trust in us, will come to us to make them whole in the event of losses,” Williams said at a Consumer Financial Protection Bureau symposium on Wednesday. “Aggregators and fintechs may not have sufficient skin in the game here because someone else — banks — are going to be underwriting and insuring those losses.”
In a panel titled “Considerations for Policymakers,” attendees examined whether banks are obligated to share data with third-party apps, even if they think those third parties might not be secure or legitimate. According to Williams, other financial institutions should follow Chase’s model and hold third parties to similarly high standards.
Williams mentioned three policies the bank has in place for third parties that request banking data on behalf of customers. First, Chase ensures third parties are safely and securely accessing data through application programming interfaces (APIs). In fact, the bank put a ban on “screen scraping” last month to ensure third parties are using APIs, not customer login information, to access banking data. Next, Chase ensures that third parties are following bank-like information security requirements. Lastly, the bank requires fintechs and aggregators to enforce these same requirements with clients.
See also: Inside the Chase plan to ‘ban’ screen scraping
The symposium focused on Section 1033 the Dodd-Frank Act, which grants consumers the right to access their banking data in an electronic format. Many advocates interpret this legislation, enacted in 2017, to mean banks must share data with all third parties, including fintechs and aggregators, at the request of consumers. A major point of contention in the forum was whether banks have any recourse to block data if they feel a third party is fraudulent or unsafe.
Brian Knight, director of innovation and governance at the Mercatus Center, brought up a situation in which a customer demanded that the bank share data with a questionable entity.
“Does [Section] 1033 mandate access in that scenario?” Knight asked. “These are unresolved questions.” If the law is flawed, he added, it is the job of Congress to make changes.
Thomas Brown, a partner who focuses on antitrust in global banking and payments system practices at Paul Hastings LLP, argued that the financial services industry has been dragging its feet on Dodd-Frank. Although he said he doesn’t necessarily agree with Supreme Court’s interpretation of the Second Amendment, he said there are parallels between the right to bear arms and the right for consumers to access their banking data.
“I think 1033 is effective today,” Brown said. “Banks and financial institutions have an obligation to provide access to third parties.”
Bank Innovation Ignite, which will take place on March 2-3 in Seattle, is a must-attend industry event for professionals overseeing financial technologies, product experiences and services. This is an exclusive, invitation-only event for executives eager to learn about the latest innovations. Request your invitation.




