Privacy & Security

CFPB Data Rights Rule: What It Means for Your Budget App (2026)

The CFPB's financial data rights rule was supposed to change how budget apps access your bank data by April 2026. That date passed with the rule blocked in court and being rewritten. Here's what the rule says, what happened, and what you can do right now.

You open your budgeting app. You tap "Connect Bank." A login screen appears β€” looks just like your bank's website. You type in your username and password. And somewhere between your bank and the app, a company you've never heard of now has your credentials, your transaction history, and permission to access your account whenever it wants.

That's still how many budgeting apps work in September 2026. And a federal rule was supposed to change it.

The CFPB's Personal Financial Data Rights Rule β€” built on Section 1033 of the Dodd-Frank Act β€” was finalized in October 2024 with the promise of giving consumers real control over their financial data. The right to move it. The right to revoke access. The right to know who has it. The largest banks were supposed to comply by April 1, 2026.

That date has passed, and the rule never took effect. A federal court blocked it in October 2025, the CFPB under new leadership called its own rule unlawful, and a rewritten version has been under White House review since August 2026. The protections you were promised haven't arrived, and the version that eventually does may look quite different.

Here's what the rule actually says, what went wrong, and what it means for how you manage your money right now.

πŸ“‹

What you'll learn

  • What the CFPB financial data rights rule actually requires β€” in plain language
  • Why the April 2026 compliance date passed without the rule taking effect, and where it stands now
  • How Section 1033 would change the way budget apps access your bank data
  • The Plaid $58M settlement and why it matters to this conversation
  • What you can do right now instead of waiting for regulators

What Is the CFPB Financial Data Rights Rule?

Section 1033 of the Dodd-Frank Wall Street Reform and Consumer Protection Act β€” passed in 2010 β€” gave the CFPB authority to establish rules about consumer access to financial data. For fourteen years, there was no rule to go with it. Then, in October 2024, the CFPB finalized the Personal Financial Data Rights Rule.

The rule does several concrete things.

It gives you the right to your data. Banks, credit card companies, and other financial institutions must make your transaction history, account balances, payment information, and upcoming bill details available to you β€” electronically, in a usable format. Not locked in a PDF buried behind three menus. Actually portable.

It lets you authorize third parties to access that data. If you want a budgeting app or financial advisor to pull your transactions, the rule creates a standardized process for that. Your bank can't block it or make it unnecessarily difficult.

It kills screen scraping. This is the part that matters most for budget app users. Right now, when you "connect your bank" through an app, the app (or its middleware provider, usually Plaid) often logs into your bank using your actual credentials. The rule mandates a shift to secure APIs β€” meaning your login credentials would never need to leave your bank. Third parties get the data they need through a regulated pipeline, not by impersonating you.

It sets limits on data use. Third parties can only use your financial data for the specific purpose you authorized. No side deals. No selling your transaction patterns to advertisers. No building shadow credit profiles from your spending habits. When you revoke access, it ends immediately. Deletion becomes the default. Access expires after one year unless you explicitly reauthorize.

It bans fees for data access. Your bank can't charge you β€” or a third party you authorized β€” for accessing your own data.

On paper, this is significant. It's the first federal regulation that directly addresses how financial data aggregators operate. And a Visa consumer survey (conducted in 2022, published in 2023) found that 87% of U.S. consumers already use open banking to connect their accounts to third-party services, so it would change the ground rules for most people.

What Happened to the Rule: Timeline Through September 2026

The final rule set compliance dates by institution size:

  • Largest depository institutions ($250B+ in assets) and large non-depository institutions ($10B+ in receipts): April 1, 2026
  • Smaller institutions phased in through April 1, 2030

That first date has come and gone without the rule taking effect. Here's the sequence of events that derailed it.

Immediate legal challenge (October 2024). The same day the rule was finalized, Forcht Bank, the Bank Policy Institute, and the Kentucky Bankers Association filed suit in the Eastern District of Kentucky (Forcht Bank v. CFPB), arguing the CFPB overstepped its authority. They claimed the rule compromised data security rather than protecting it and that the agency lacked statutory authority to ban data-access fees.

Early stays (February–March 2025). The court paused the case twice, for 90 days in total, and pushed the compliance dates back by the same amount. That moved the first deadline from April 1 to June 30, 2026.

The CFPB turns on its own rule (May 2025). Under new leadership, the CFPB's chief legal officer, Mark Paoletta, told the court that "Bureau leadership has determined that the Rule is unlawful and should be set aside," Payments Dive reported. The agency that wrote the rule was now arguing against its own work. In July 2025 it asked the court to pause the lawsuit while it reconsidered the rule, and the court agreed but left the compliance deadlines in place.

Advance Notice of Proposed Rulemaking (August 2025). The CFPB published an ANPR on August 22, 2025, asking for public comment on four issues: who can act as a consumer's "representative," whether banks may charge fees for data access, data security, and data privacy. That signaled a rewrite, not a tweak.

Court injunction (October 29, 2025). Judge Danny Reeves granted a preliminary injunction: the CFPB "is ENJOINED from enforcing the Personal Financial Data Rights Rule until it has completed its reconsideration of the Rule." He found the banks likely to succeed on the merits, including their argument that the rule was arbitrary and capricious. The ABA Banking Journal summarized the ruling as finding the plaintiffs "likely to succeed on all four of their claims."

Funding crisis (November–December 2025). The Justice Department's Office of Legal Counsel concluded that the CFPB could not draw funds from the Federal Reserve while the Fed has no "combined earnings," and the CFPB told a court it could not lawfully request new funds and had enough to operate "until at least December 31, 2025." In December the CFPB said it would issue an interim final rule for Section 1033, citing its funding situation; none has been published. Later that month a federal judge rejected the Justice Department's reading in NTEU v. Vought, and the CFPB has since made its funding requests to the Fed in order to comply with that court's order.

The deadlines pass (April and June 2026). April 1, 2026 came and went, and so did the court-extended June 30 date. The deadlines are still written into the rule, but with enforcement blocked, no bank has had to meet them. Law firm Cozen O'Connor summed it up in April 2026: the rule exists "on paper, but not in practice."

A new proposal goes to the White House (August 2026). On August 4, 2026, the CFPB sent a proposed rule titled "Personal Financial Data Rights Reconsideration" to the White House Office of Information and Regulatory Affairs for review, according to American Banker and Ballard Spahr's Consumer Finance Monitor. That is usually one of the last steps before a proposal is published for comment.

Where it stands (September 25, 2026). The 2024 rule is still on the books but can't be enforced. The replacement proposal has not been published in the Federal Register, and its text isn't public; PYMNTS reported the CFPB has considered letting banks charge for data access after a set number of free requests. You can follow the rewrite on the CFPB's reconsideration page.

Here's the thing about regulatory timelines: even when they hold, implementation takes years. When they don't hold, as this one didn't, the gap between "announced" and "enforced" can stretch indefinitely. Any new version still has to go through public comment and a final rule before it can take effect.

Why This Rule Exists: The Data Sharing Problem

The rule didn't emerge from nowhere. It's a response to a specific, documented pattern of problems in how financial data gets shared.

The screen scraping model. Most budgeting apps don't connect directly to your bank. They use middleware β€” Plaid, Yodlee, Finicity β€” that logs into your bank account using your credentials. This is called screen scraping. It means a third party stores your bank username and password, logs in as you, and pulls whatever data it can access. Your bank can't distinguish between you and the middleware company. There's no granular permission β€” it's all-or-nothing access.

If this sounds like a security problem, it is. The CFPB specifically cited screen scraping as a risk to consumers, and the rule was designed to end the practice by mandating API-based access instead.

The Plaid settlement. Plaid, the dominant middleware provider used by YNAB, Copilot, Monarch Money, Venmo, and dozens of other apps, agreed to pay $58 million to settle a class action lawsuit, and a judge approved the settlement in July 2022. The allegations: Plaid collected far more financial data than the connected apps required, and designed its login screens to mimic users' actual bank portals, obscuring the fact that users were handing credentials to Plaid rather than their bank. Plaid denied the allegations and didn't admit wrongdoing. The $58 million check spoke for itself. (For the full breakdown of what Plaid does and which apps depend on it, see our explainer on what Plaid is and why budget apps want your bank login.)

The breach numbers. The U.S. saw a record 3,322 data compromises in 2025, according to the Identity Theft Resource Center's annual report. Financial services was again the most-hit sector, with 739. And the number of organizations affected by supply chain attacks, where attackers compromise a vendor to reach its clients, nearly doubled, from 660 in 2024 to 1,251 in 2025.

When a single middleware company like Plaid holds the bank credentials of tens of millions of users, it becomes an extraordinarily high-value target. The question isn't if there will be incidents. It's how bad they'll be when they happen.

Data sharing as a business model. A 2023 Incogni study of 20 popular Android budgeting apps found that 60% share user data with third parties. Apps that share data collect an average of 12 data points per user, double the 6 collected by apps that don't share. One in four apps shares users' financial information with third parties.

The CFPB financial data rights rule was supposed to address all of this. Standardized APIs instead of credential sharing. Explicit consumer consent. Purpose limitation. Mandatory deletion. It was, genuinely, a strong framework.

And right now, it's sitting in legal limbo.

What the Rule Would Change for Budget App Users

If the rule eventually takes effect β€” in some form β€” here's what would actually change for people who use budgeting apps.

No more sharing bank passwords with apps. Budget apps would connect through your bank's API. Your bank would authenticate you directly (think OAuth β€” the "Log in with Google" model, but for your bank). The app gets the data it needs. It never sees your credentials. This alone would eliminate the largest single attack surface in the current system.

You'd know exactly what data is being accessed. The rule requires explicit disclosure of what data a third party is requesting and for what purpose. No more blanket access. No more "we need your login to see your balance" when what they actually want is your full transaction history for the past three years.

Revoking access would actually work. Right now, disconnecting a bank in a budgeting app doesn't necessarily mean the middleware provider deletes your data or stops accessing your account. Under the rule, revocation would be immediate, simple, and come with data deletion as the default.

Switching apps would get easier. Data portability means you could move from one budgeting app to another without re-linking everything from scratch. Your data belongs to you, and you can take it wherever you want.

Sound familiar? If you've followed the EU's PSD2 (Payment Services Directive) or open banking initiatives in the UK and Australia, this is the U.S. version β€” arriving roughly five to eight years later. And currently stalled in court.

The Privacy Paradox: More Access Can Mean More Risk

Here's where it gets complicated. And where most coverage of the CFPB rule stops being honest.

Open banking rules are designed to give consumers more control over their data. But they also create a standardized, regulated pipeline for third parties to access that data. More access points. More companies requesting data. More APIs to secure.

The Bank Policy Institute β€” one of the plaintiffs in the lawsuit β€” argued that the rule would actually increase data security risks by multiplying the number of entities with access to consumer financial data. Judge Reeves took the concern seriously: his opinion says the CFPB's "failure to consider the cumulative impact" of the rule's provisions affecting data security "renders the rulemaking likely arbitrary and capricious."

This isn't a fringe argument. The UK's open banking implementation, while broadly considered successful, has seen ongoing challenges with API security, consent management, and the practical difficulty of monitoring dozens of authorized third parties with access to your accounts.

Let's be honest about what this means for someone who just wants to track their spending without their data ending up somewhere unexpected.

The CFPB rule, if implemented well, would be significantly better than the current screen-scraping free-for-all. API access is objectively more secure than sharing passwords. Explicit consent is better than buried terms of service. Mandatory deletion is better than hoping companies do the right thing.

But "better" isn't the same as "safe." The rule regulates how third parties access your data through the financial system. It doesn't eliminate the fundamental fact that your data is being transmitted, stored, and processed by companies you may not fully trust.

There's a simpler approach that no regulation can improve upon: don't share the data in the first place.

What You Can Do Right Now (Without Waiting for the CFPB)

Regulations take years. Courts take longer. You can protect your financial data today.

Option 1: Use any budget app with manual entry β€” no bank sync.

Most budgeting apps work fine without connecting a bank. YNAB, Monarch Money, Goodbudget β€” they all support manual entry. You type in your income and expenses yourself. No Plaid. No credentials shared with anyone. Your bank account stays between you and your bank. We compared the apps built for this in our list of budget apps that don't connect to your bank.

The friction is real: you're spending two to five minutes a day entering transactions instead of having them imported automatically. But there's a strong argument β€” backed by behavioral research β€” that the manual process actually produces better financial outcomes. When you have to consciously record every purchase, you're more aware of what you're spending. Automatic imports create passive record-keeping. Passive record-keeping rarely changes behavior.

(We've written about this trade-off extensively in our guide to tracking expenses without compromising privacy.)

Option 2: Export CSV from your bank and import it.

Your bank's online portal almost certainly lets you download your transaction history as a CSV file. Many budget apps accept CSV imports. You get bank-accurate records without sharing credentials with any third party. It's not glamorous. It genuinely works.

Option 3: Use a local-first app where data never leaves your device.

This is the architectural solution. Local-first apps store everything on your device β€” in the browser's IndexedDB database, on your hard drive, wherever β€” and never send your financial data to a server. There's no credential sharing because there's no connection to your bank. There's no data breach risk because there's no central server holding millions of users' financial data. There's no policy change to worry about because the company never has your data in the first place.

BudgetVault works this way. Everything lives in your browser's local storage. No account. No bank sync. No server holding your financial data. You enter your transactions manually, set up category budgets, track recurring expenses, and export to CSV whenever you want. If you're interested in how the underlying technology works, our comparison of IndexedDB vs cloud storage goes deep on the technical side. For other apps that keep your data off company servers, see our guide to privacy-focused finance apps.

The trade-offs are real and worth being honest about. You lose automatic bank sync. You lose multi-device access (your data is on one browser, on one device). If you clear your browser data without exporting first, it's gone β€” no recovery, no backup server. That's the cost of a genuine privacy guarantee.

For a lot of people, especially those who watched Mint shut down in March 2024 and take years of financial data with it, that trade-off is exactly right.

The Bigger Picture: Privacy by Architecture vs. Privacy by Regulation

The CFPB financial data rights rule represents the regulatory approach to financial privacy. It says: we'll create rules about how companies handle your data, and we'll enforce those rules. When it works, it raises the floor for everyone.

But regulation has structural limitations.

Rules can be challenged in court (as this one has been). Agencies can reverse course under new leadership (as this one has). Enforcement requires funding and political will (both currently in question). Even well-enforced rules allow data to flow β€” they just regulate the flow. Your financial data still moves from your bank to a third party to their servers. It's more controlled, but it's not private in any architectural sense.

Privacy by architecture takes the opposite approach. Instead of regulating what companies do with your data, it eliminates the data flow entirely. If your budget app never connects to your bank and never sends your financial data to a server, there's nothing to regulate. No consent form to manage. No API to secure. No breach to disclose.

These two approaches aren't in competition. The CFPB rule, if it ever takes effect, would make cloud-based budget apps safer. That's worth fighting for. But if your priority is keeping your financial data private right now, you don't need to wait for a regulation that may or may not arrive.

The tools already exist. You just have to be willing to enter your expenses manually. (For a broader look at where the local-first movement is heading, see our article on why local-first apps are replacing cloud storage for personal finance.)

What to Watch For

The CFPB's reconsideration process is ongoing. Here's what to monitor.

The new proposed rule. The proposal sent for White House review in August 2026 is the next concrete step. Once it appears in the Federal Register, there will be a public comment period, and the details that matter most for budget app users will be visible: whether banks can charge for data access, who counts as a consumer's "representative," and how data security and privacy are handled. A final rule comes after that.

The funding situation. The CFPB's recent requests for money from the Federal Reserve have been made to comply with the court order in NTEU v. Vought. Its request for July through September 2026 was $51.7 million, a figure its acting director wrote "does not reflect the amount that I believe to be reasonably necessary." Without stable funding, the agency's ability to complete rulemaking, let alone enforce it, is limited, and the funding fight is being litigated separately from the 1033 case.

State-level action. California, Colorado, and Virginia already have consumer data privacy laws that provide some financial data protections. If the federal rule stalls indefinitely, state laws may become the de facto standard β€” creating a patchwork that's hard for consumers to navigate and for apps to comply with.

Industry moves. Data aggregators like Plaid and Finicity are pushing toward API-based access regardless of regulation, partly because banks prefer it (less liability) and partly because the writing is on the wall. Some of the rule's effects may happen through market forces even if the rule itself never takes effect.

FAQ

What is Section 1033 of the Dodd-Frank Act?

Section 1033 gives the CFPB authority to require financial institutions to make consumer data available in electronic form. The CFPB used this authority to finalize the Personal Financial Data Rights Rule in October 2024, which would require banks and financial companies to share consumer data through secure APIs rather than screen scraping. As of September 2026, the rule is enjoined by a federal court and under reconsideration.

Will the CFPB financial data rights rule take effect in 2026?

Not as written. The first compliance date (April 1, 2026, later extended to June 30, 2026) passed while a preliminary injunction from the Eastern District of Kentucky, issued in October 2025, barred the CFPB from enforcing the rule. The CFPB is rewriting it: a new proposal went to White House review in August 2026 but had not been published as of September 25, 2026. Any revised rule still needs a public comment period and a final version before it can take effect.

Does the rule affect my current budgeting app?

Not yet β€” the rule isn't being enforced. When (and if) it takes effect, it would primarily change how apps that use bank sync connect to your financial institution. Apps using Plaid or similar middleware would shift to secure API connections, and you'd have more explicit control over what data they access and for how long. Apps that don't connect to your bank β€” like spreadsheets, manual-entry apps, or local-first tools β€” would be unaffected.

How can I protect my financial data without waiting for regulation?

Use a budgeting app with manual entry instead of bank sync. This eliminates the need to share credentials with any third party. For maximum privacy, use a local-first app that stores data only on your device β€” no server, no account, no breach surface. You can also export CSVs from your bank and import them into your budgeting tool. See our complete guide to financial privacy in 2026 for a thorough action plan.

What was the Plaid $58M settlement about?

Plaid agreed in 2021 to pay $58 million to settle a class action, and a federal judge approved the settlement in July 2022. The lawsuit alleged that it collected more financial data than necessary, designed its login screens to mimic bank portals (making users think they were logging into their bank when they were giving credentials to Plaid), and retained data beyond reasonable expectations. Plaid denied the allegations and did not admit wrongdoing. The settlement required business practice changes including new disclosures and a user portal for managing data connections.

BudgetVault is a personal budgeting tool, not a financial advisor. This article is for informational purposes only and should not be treated as professional financial advice. We have no affiliation with the CFPB, and this article reflects publicly available information as of September 25, 2026.

See how it works, without signing up

Open BudgetVault with six months of sample data. Free, no account, no bank login, and your numbers stay on your device.