Startup

Open Banking: Who Owns Your Financial Data

A rule finalized in 2024 was supposed to settle whether your bank data belongs to you. In 2026 it sits frozen in court while banks, fintechs, and regulators fight over the answer.

Nathan Xiang·March 28, 2026

The Question Under Every Fintech App

Open banking It's the principle that your financial data your balances transactions and payment history belongs to you and should go at your direction to a budgeting app to a lender that evaluates you to a rival bank that offers a better rate. Every fintech product this site covers depends on that data flow and for two decades it has flowed through a gray zone at first screen-scraping with shared passwords then formal data channels negotiated between banks and aggregators like Plaid the middleware companies that connect thousands.of applications to thousands of banks. The underlying legal question was never resolved: access is a courtesy that banks grant or a right that customers have. The United States finally tried to respond and the response is currently frozen in court

The Rule and the Freeze

Congress planted the seed in 2010 Section 1033 of the Dodd Frank Act which directs regulators to grant consumers access to their own financial data. The CFPB finally finalized the implementing rule in October 2024 requiring banks to provide data through secure interfaces free of charge at the customer's direction. The banks sued almost immediately arguing that the bureau overstepped its authority and that mandatory free access ignores the costs.real estate and responsibility for operating pipelines. A federal court banned the rule the CFPB under new leadership opted to rewrite it rather than defend it reopening the core issues in 2025 and the rule's April 2026 compliance date passed and passed without enforcement. Most importantly the rewrite puts data access fees Whether banks can charge fintechs for connections that the original rule made free is on the table and several large banks have already announced their intention to do exactly that

Free mandatory access and negotiated price access produce two different industries. One treats your data as if it were your property and moves at your command. The other treats it as a product that your bank wholesales to the companies you want to use

Why Password Sharing Was the Real Problem

The phrase screen scraping with shared passwords passes by quickly and is worth stopping because technical history explains why the security issue and the rights issue became intertwined

In the original agreement a customer handed over their banking username and password to a third-party app. That app then logged in as a customer and read everything it could see

Consider what that actually granted. Not access to a defined set of data but access to everything the client could do since the application was indistinguishable from the client. No scope because credentials have no limits. No expiration because a password works until it is changed. And there is no clean revocation because removing access meant changing the password and therefore breaking all other services that used it

It also trained an entire generation of customers to enter their banking credentials into apps that weren't from their bank which is the precise behavior every fraud awareness campaign aims to prevent

Tokenized interfaces solve all four problems at once. The customer authenticates with the bank itself the bank issues a token to the application and that token can be limited to specific data have an expiration date and be revoked individually without altering anything else

That's why the industry continued to migrate to them even with the rule frozen. Banks wanted fraud exposure to go away and aggregators wanted reliability so both sides had reasons independent of any regulation

The complication is that building the interface also creates the toll booth. In the case of sharing passwords there was nothing to charge because the bank was not providing anything not preventing something. A specially designed interface is the infrastructure that the bank operates and the infrastructure can have a price. The security solution and the question about the price came in the same box

The Economics of the Fight

Follow the incentives and litigation will make a lot of sense. For banks data portability is a demolition of the switching cost the customer who can transfer five years of transaction history to a competitor with a single tap is a customer that the deposit franchise no longer owns by inertia and the deposit rigidity that this site's banking coverage describes is the industry's main asset. Charging fees recovers infrastructure costs which are truly non-zero and conveniently taxes hunting competitorsfurtively.For fintechs free access to data is existence itself a lender that backs cash flow instead of credit scores a robo-advisor that sees the entire balance sheet account-to-account payments that avoid the card rails covered in our exchange article all of this runs down the pipes.For consumers what's at stake is simpler: prices and frictions decide whether data moves in practice regardless of what the law says in principle

What a Data Fee Does to Competition

The question of tariffs is often posed as if the only question is how much money changes hands. The most important effect is which companies can still operate. Illustrative and round

Let's say access is priced at fifty cents per linked customer per month. For a large bank that's a rounded-up item. For apps on the other side it depends entirely on what they earn per user

A budgeting tool that monetizes at three dollars a month per user would be paying about seventeen percent of its revenue for the data on which the product is based. A lender making hundreds of dollars on a completed loan would barely notice the same fifty cents

Therefore an identical fee is almost fatal for one business model and irrelevant for another and the pattern is consistent. It falls more on low-revenue-per-user consumer tools and less on high-value transactional products

Now let's ask which category is really threatening a deposit franchise. They are the everyday consumer tools the ones that show the customer their complete financial picture across all institutions show a better savings rate and make moving money seem normal. Those are precisely the products that the fee structure would lock in the price

There is a second effect that works in the same way. A charge per customer is the closest thing to a fixed cost and fixed costs favor scale. A large aggregator with millions of connections can absorb and spread it. A new entrant with a better product and few users cannot and has to pay before earning revenue

None of this shows that the fee is unjustified since operating a secure interface actually costs money and someone has to fund it. What it does mean is that the fee is not a neutral cost recovery mechanism. Whatever level it is set at it orders the market and it happens to order it in the direction of whichever party you prefer

The Liability Question Nobody Has Answered

Buried in the banks' argument along with cost is liability and it's the part of their case that's hardest to dismiss

Ask what happens when data leaves a bank at a customer's direction lands in a third-party application and that application is compromised. The customer's transaction history is now exposed. Who is responsible?

By sharing passwords a bank had an uncomfortable but available answer: that the customer had revealed their credentials in violation of the account terms

A mandatory interface eliminates that response completely and deliberately. The entire design is for the customer to order and the bank to comply. The bank does not select the recipient may not have evaluated it and cannot reject it on the grounds that it would prefer not to deal with it

Therefore the bank is ordered to hand over data to a party it did not choose and then has a reasonable expectation of being blamed when something goes wrong because it is the institution with which the customer has a relationship and which has the balance worth suing

This is a genuine problem and is separable from the stakeholders' position of the banks. It also explains why they want a fee which funds research and monitoring of who receives data or a right to refuse which is a control and is exactly what the rule was written to avoid

Any lasting agreement has to respond directly defining who is responsible for a subsequent breach and setting standards that recipients must meet. Leaving it unresolved means that banks will continue to push for control through whatever mechanism is available to them and the fee is currently that mechanism

Meanwhile, the Market Moved On

The strange reality of 2026 is that open banking is thriving commercially while legally frozen. Tens of millions of Americans link accounts through aggregators each year banks and aggregators have continued to sign bilateral data deals because customers demand apps work and the industry's security upgrade replacing password sharing with tokenized interfaces continued for self-interested fraud reasons. States have begun drafting their own data rights rules in the federal vacuumthreatening the patchwork that national rules are intended to prevent. And abroad the experiment has already been carried out: the UK and EU imposed open banking years ago producing real account changes and payments innovation and its lesson is instructive: the pipelines were built when regulators forced the issue and stalled when incentives were left up for debate. Currently the United States is testing the alternative hypothesis: that the markets themselves build the pipelines if the government does not participate collecting the toll

A Bilateral Deal Is Not a Right

That commercial health is real and it is easy to draw the wrong conclusion from it which would be that the legal issue no longer matters because the market resolved it

The difference between a negotiated agreement and a right only manifests itself under pressure which is precisely the circumstance that has not yet occurred

A bilateral agreement has a counterparty a term and a price. Its price can be changed at renewal its scope reduced or rejected entirely. It is available on terms that the stronger party finds acceptable and persists as long as that is true

A right does not have any of those conditions attached. It does not require that the bank consider the agreement to be commercially acceptable

Right now those two look identical from the outside because banks have strong reasons to keep data flowing. Customers want apps to work and a bank that broke them would face complaints and attrition. So access continues and continues because interests align

The test comes when they stop lining up. A bank facing a competitor built specifically on that data or a category of app it sees as a threat to its own products has to decide whether to continue providing them. Under a bilateral agreement that's a business decision. Under a right it's not a decision at all

That's why the fact that the current agreement is agreeable is weak evidence about the underlying issue. It simply hasn't been tested and the value of a right is entirely in what makes the day that the counterparty would rather say no

What the European Experiment Actually Showed

The international comparison is the closest thing to the evidence available and is worth reading precisely and not as a blanket endorsement of regulation

The observation in the previous section is that pipelines were built when regulators forced the issue and stalled when incentives were left to be argued among themselves. This is a specific conclusion about coordination rather than a claim that mandates always work

The reason is that data access is structured as a problem that no single participant can solve. Standard interfaces are only valuable if enough institutions implement them in a compatible way and the institutions that are asked to implement them have the least to gain. Each bank would prefer that the others go first and the party best placed to break that deadlock is the one that can require everyone to act together

This is a limited statement and it is one supported by the European experience. It says nothing about whether access should be free and it does not say that a mandate produces good results in general. It says that where the barrier is coordination waiting for the market to be resolved slowly or not at all

Which puts the American position in a specific light. The country has not chosen between free access and priced access but has postponed the decision and what fills the void is a set of private agreements plus a growing patchwork of state rules. A patchwork is the worst outcome available in a coordination problem since it hands over the burden of regulatory compliance without the standardization that is its goal

The Bottom Line

Open banking asks who controls the record of your financial life and America's answer is a mid-rewrite of a 2024 rule ensuring free portability banned in court that is being redrafted by an office recently open to allowing banks to charge for the pipes. Look at the decision on rewrite fees determining whether data rights arrive as rights or as a wholesale market and with them the cost structure of each fintech on your phone. Your transactionsThey are the most honest bio you have. The fight is over who gets paid when you read it. And keep in mind that a fee here is never just a fee because a per-customer charge falls more on the low-margin consumer tools that make switching banks look easy which is the competition that fee recipients would most like to slow down

Explore Teen Biz News →