The CFPB’s proposed Personal Financial Data Rights Reconsideration was received by OIRA on Aug 4, 2026. The official record checked on Sep 9, 2026 lists it as pending review. The proposal is not yet public, but legal and industry reporting suggests data-access fees and changed obligations may be among the issues under review.
The CFPB’s official personal financial data rights page remains useful background on Section 1033 and consumers’ ability to access and share financial data through standards prescribed by the bureau. For fintechs, that US consumer-permissioned data framework connects directly to API performance, consent management, security, vendor dependency, and contractual liability.
If the rewrite proposes changes to who pays for access, what data providers must support, or how third parties use ‘consumer-permissioned’ data, fintech insurance buyers should revisit technology errors and omissions, cyber, privacy, directors and officers, and contractual indemnity language.
Open Banking Lives In The Operating Model
Open banking sounds like a US policy debate until something breaks. Then it becomes an operational question: who had permission to access the data, which API failed, what the contract said, and which party is responsible to the customer.
That is why the CFPB’s Section 1033 rewrite matters for fintech insurance buyers. The rule governs the infrastructure around consumer-permissioned financial data. Fintechs, banks, aggregators, processors, and service providers may each carry a different part of the risk.
Data Fees Are Also Liability Signals
Recent reporting suggests data-access fees may sit near the center of the rewrite. That sounds commercial, but it also affects risk. If proposed changes alter who can charge for access, how access is priced, or what technical obligations apply, they could change who connects to whom, how often data is pulled, whether commercial API calls are rationed or priced differently, and which contractual duties sit behind the access model.
A fintech that relies on third-party data access should be ready to explain what happens if pricing, availability, access terms, or authentication standards change. The underwriting concern is not only regulatory compliance. It is operational resilience.
Where Insurance Programs Need Updating
Open banking firms should test their cover against the actual data flow.
A buyer can start with three questions for its broker:
- Which data provider or API is essential to the service?
- Which customer losses does the contract make the business responsible for?
- Does the wording address that failure, with what exclusions and limits?
Those answers should inform how the company reviews:
- Technology E&O: whether failed data access, incorrect data, delayed feeds, or API outages create covered service failure.
- Cyber and privacy: how consent, authentication, token management, data minimisation, and breach response are handled.
- Contractual liability: which indemnities apply between banks, aggregators, processors, apps, and enterprise customers.
- D&O: whether management has documented oversight of regulatory change and material dependency risk.
- Business interruption: whether the company understands revenue impact if access is interrupted or repriced.
That evidence can make the difference between a fintech submission that reads like a generic SaaS risk and one that reflects how open banking actually works.
Practical Takeaway
The Section 1033 rewrite should push fintech companies to refresh their insurance story now. Map the data, map the consent, map the vendors, and map the contracts. Then make sure the policies are written around that real operating model rather than around a stale description of the product.
Speak with Relm about fintech insurance for open banking, payments, data access, and technology liability.
Sources