Tucked in the middle of the massive financial services regulatory overhaul that is Dodd-Frank are about 300 words that still aren’t enforced: Section 1033, which provides consumers the right to access and share their financial data. Since Dodd-Frank became law in 2010, banks, fintechs and aggregators have all been striving for a more open system as consumers seek to connect their banking data to third party apps.
“Everyone is realizing that this is the future, and they have a chance to steer the ship,” said Don Cardinal, managing director of the Financial Data Exchange (FDX). The nonprofit pushes its API-based data sharing standard across the financial services industry, and its 130-member organization includes big banks, fintechs and aggregators, such as Bank of America, Chase, Citi, PayPal and Experian. “When you have market demand, and we all work for the customer, you will serve the customer in any way and any channel you can,” Cardinal said.
Even with the market pressure for a more connected world in financial services and Section 1033 of Dodd-Frank, there is still no regulatory framework enforcing open banking in the U.S.
That could all change next year, as the Consumer Financial Protection Bureau (CFPB) issued a statement last month about proposed rulemaking around consumer data sharing.
That said, any regulation is still far in the future, as the statement was announcing an advance notice of proposed rulemaking (ANPR), a sort of redundant pre-ANPR. Some questions remain: What would a regulatory framework around open banking look like? And how would it interact with existing technology standards spearheaded by FDX?
The Bluetooth of financial services
According to FDX, the market forces and consumer expectations around open banking have kept the U.S. as an industry leader despite the lack of a government mandate. Cardinal likened it to the shift to online banking, and pointed out that financial services didn’t need regulation to kickstart that digital shift.
Despite the 10-year wait for any kind of enforced data sharing regulation, the CFPB’s pre-ANPR in July indicates the U.S. might soon have regulations similar to the open banking laws in Europe and Australia. With a regulatory framework, banks would be obligated to share data at consumers’ requests.
If and when these regulations go into effect, Cardinal said FDX’s mission can coexist with a new framework in the U.S. For its part, FDX already works with regulators when developing its tech standards, and standards around security and error codes, for example, are separate from the policy outcomes around consumer rights and privacy.
FDX, in a way, is trying to create in financial services what Bluetooth has done for interoperability among mobile devices, Cardinal said, and FDX’s technology standard can operate within laws that govern privacy rights and accountability. The nonprofit launched in Canada in July, and Cardinal said FDX’s data-sharing API would comply with regulated markets overseas.
The goal to create a Bluetooth-like connection standard began with the U.S. launch of FDX in 2018, with the goal to move the industry away from credential-based data sharing to adopt API-based data sharing, which is seen as more secure than sharing login credentials.
John Pitts, policy lead at Plaid, agreed that market forces have put the U.S. ahead of other countries when it comes to open banking, but there is still a need for regulations that protect consumers and their right to share data. FDX might be developing a Bluetooth-like tech standard, but regulators still need to ensure consumers can share whatever data they like with third parties, Pitts said.
“Bluetooth works when there’s not a disagreement as to whether both jazz and rock should be available over Bluetooth,” Pitts said. “There is, right now, a level of disagreement as to what types of data are available to the consumer to flow over those technical rails.”
According to Brian Costello, vice president of data strategy and strategic solutions at Envestnet Yodlee, a regulatory framework would provide guidance to the interoperability standard FDX’s members are trying to create. Regulators could, for example, create laws governing who is at fault if consumer data is compromised, providing guidance, but not necessarily interfering, with the technology work of FDX members.
Although most parties are embracing secure data sharing, Costello noted there is some reluctance in the industry.
“Some banks believe in the power of data, and they have engaged with aggregators to offer it to their own customers,” Costello said. “But the other side of the house isn’t interested” in their customers giving their data to third parties due to the additional regulatory hurdles banks would need to oversee and manage, he said.
Another reason some banks don’t engage with open banking is because they can’t. Smaller banks cling to credential-based data sharing because their core provider doesn’t provide a plug-and-play API solution, making credential-based sharing the only option, according to Tom Carpenter, FDX’s director of public affairs and marketing.
The delay in rolling out a regulatory framework isn’t just a result of bank pushback. Costello added that regulators themselves have been cautious about creating new laws because the issue is so complex, and any new regulations need to take in existing frameworks.
The 10-year wait
When Dodd-Frank became law in 2010, Section 1033 positioned the U.S. to be a pioneer in open banking regulations. And while the approach thus far has largely been market-driven — which Plaid’s Pitts argues is the right approach since creating regulations too early could be self-defeating — Plaid believes regulations are necessary to create a truly open ecosystem.
Although many banks promote the benefits of open banking, Plaid has seen data-sharing agreements drafted in which banks will only allow certain third parties to receive consumer data, ensuring they don’t have to share coveted information with competitors. Similarly, banks don’t want consumers to share certain proprietary data, like interest rates and fees, for fears competitors will use it to steal customers. “I don’t know what ‘data access’ means if the fees and interest rates that are the core to the product aren’t part of that,” Pitts said.
With Dodd-Frank enacted 10 years ago, many believe there shouldn’t even be a debate around creating a universal mandate around data sharing.
The CFPB hosted a symposium on Section 1033 in February, during which Thomas Brown, a partner with the Paul Hastings law firm, flagged the importance of data sharing regulations. Brown focuses on antitrust and competition and the global banking and payment systems practices.
The CFPB’s pre-ANPR “is a welcome development,” Brown said in an email, noting that “it’s hard to argue with the observation that ‘too much regulation could be cumbersome.’ That’s kind of a truism.”
Still, the regulation doesn’t have to be cumbersome, Brown said, and by issuing a rule the CFPB can make clear that financial institutions are obliged to make information available to consumers and third parties designated by them, while also providing guidance about the information covered by the rule. “Perhaps most importantly, it can do all of that without developing a standard for interconnection,” he added.
Other regulatory experts see existing policies that cover data protection and consumer privacy as sufficient when it comes to facilitating open banking and the secure sharing of consumer data.
“Ultimately, if the banks are confident they can do open banking in a way that maintains the safety, security and protection of the data within the existing highly regulated framework that they operate under, then the reason there’s not more regulation is because the big privacy and data security concerns are already dealt with for financial institutions,” said Robert Savoie, a member at McGlinchey, a law firm specializing in consumer financial services compliance. “It’s not an area where there’s some secretly unregulated product coming out.”
Despite the lack of enforcement around 1033, and pushback due to the regulatory burden, some of the biggest banks are positioning open banking at the center of their long-term innovation strategies.
BMO Financial Group, for example, has been working toward a more open strategy that brings in various tools and expertise from the fintech ecosystem. Most recently, the $739 billion dollar bank partnered with Google to launch co-branded digital bank accounts in 2021.
“Because this is a model that we have been building strategies around and working on with a variety of partners, we were already on track to essentially open up many of the elements of the back end of what we do through technologies — like microservices and API layers — to make it easier to securely share data with a whole host of different providers as the open banking model continues to evolve,” said Brett Pitts, chief digital officer at the Toronto-based bank. “That work has been influencing how we think about our technology implementations and how we build things for internal use and external collaborations.”
PNC Bank, too, is pursuing a platform-based strategy in which the bank can plug into different third parties to provide a broader swath of banking services and tools to customers.
“A platform strategy is a business model that leverages a shared and open digital infrastructure, which we call a platform infrastructure, to connect and enable a marketplace of participants that creates mutual value exchange,” said Ganesh Krishnan, chief information officer of the $410 billion dollar bank’s corporate and institutional banking business. “We want to take banking to our customers how they want to use it, instead of forcing them to come to us.”
This market-driven approach to open banking in the U.S. is a “very healthy” one, BMO’s Pitts said, “because everybody is thinking about it in very customer-centric terms, like who are our customers, what do they care about and what do they need to more effectively manage their financial lives.”
That approach also just means regulators aren’t forcing this change on the financial services industry, rather, it’s the financial services industry that is integrating and adopting that change of its own volition, Savoie said.
Getting every bank, fintech and aggregator to be on the same page is certainly not easy.
“Over the last five years there has been legitimate progress in the market in solving many of the differences between banks, fintechs, aggregators and others,” Plaid’s Pitts said, adding, “1033 is very clear. [Consumers] have a right to access [their data]. The goal of this rulemaking should be to cement and clarify that right so there are no debates about it. Let the market … implement that right technologically.”






