The CFPB has sent a new Section 1033 open banking proposal to the White House Office of Information and Regulatory Affairs, according to legal and industry reporting. The content is not yet public, but data-access fees are expected to be one of the most contested issues.
The CFPB’s official personal financial data rights page explains that Section 1033 concerns consumers’ ability to access and share financial data through standards prescribed by the bureau. For fintechs, that regulatory foundation connects directly to API performance, consent management, security, vendor dependency, and contractual liability.
If the rewrite changes who pays for access, what data providers must support, or how third parties use consumer-permissioned data, fintech insurance buyers should revisit technology errors and omissions, cyber, privacy, directors and officers, and contractual indemnity language.
Open Banking Lives In The Operating Model
Open banking sounds like a policy debate until something breaks. Then it becomes an operational question: who had permission to access the data, which API failed, what the contract said, and which party is responsible to the customer.
That is why the CFPB’s Section 1033 rewrite matters for fintech insurance buyers. The rule governs the infrastructure around consumer-permissioned financial data. Fintechs, banks, aggregators, processors, and service providers may each carry a different part of the risk.
Data Fees Are Also Liability Signals
Recent reporting suggests data-access fees may sit near the centre of the rewrite. That sounds commercial, but it also affects risk. Fees can change who connects to whom, how often data is pulled, whether commercial API calls are rationed or priced differently, and which contractual duties sit behind the access model.
A fintech that relies on third-party data access should be ready to explain what happens if pricing, availability, access terms, or authentication standards change. The underwriting concern is not only regulatory compliance. It is operational resilience.
Where Insurance Programmes Need Updating
Open banking firms should test their cover against the actual data flow.
- Technology E&O: whether failed data access, incorrect data, delayed feeds, or API outages create covered service failure.
- Cyber and privacy: how consent, authentication, token management, data minimisation, and breach response are handled.
- Contractual liability: which indemnities apply between banks, aggregators, processors, apps, and enterprise customers.
- D&O: whether management has documented oversight of regulatory change and material dependency risk.
- Business interruption: whether the company understands revenue impact if access is interrupted or repriced.
That evidence can make the difference between a fintech submission that reads like a generic SaaS risk and one that reflects how open banking actually works.
Practical Takeaway
The Section 1033 rewrite should push fintech companies to refresh their insurance story now. Map the data, map the consent, map the vendors, and map the contracts. Then make sure the policies are written around that real operating model rather than around a stale description of the product.
Speak with Relm about fintech insurance for open banking, payments, data access, and technology liability.
Sources