ConceptioArchiveCode of Federal Regulations (eCFR)
Code of Federal Regulations (eCFR)public full text

12 CFR Part 1033 — Personal Financial Data Rights

Office of the Federal Register (NARA) · Code of Federal Regulations (eCFR, Office of the Federal Register)
Code of Federal Regulations (eCFR) · Legal · License: Public Domain
Open Source ↗
united states, us regulation, us federal regulation, code of federal regulations, cfr, federal regulation, 12, 1033, part 1033, 12 cfr 1033, 12 cfr part 1033, banks, and, banking, consumer financial protection bureau

PART 1033—PERSONAL FINANCIAL DATA RIGHTS Authority: 12 U.S.C. 5512; 12 U.S.C. 5514; 12 U.S.C. 5533. Source: 89 FR 90989, Nov. 18, 2024, unless otherwise noted. Subpart A—General § 1033.101 Authority, purpose, and organization. (a) Authority. (b) Purpose. (c) Organization. (1) Subpart A establishes the authority, purpose, organization, coverage of data providers, compliance dates, and definitions applicable to this part. (2) Subpart B provides the general obligation of data providers to make covered data available upon the request of a consumer or authorized third party, including what types of information must be made available. (3) Subpart C provides the requirements for data providers to establish and maintain interfaces to receive and respond to requests for covered data. (4) Subpart D provides the obligations of third parties that would access covered data on behalf of a consumer. (5) Appendix A to this part provides instructions for how a standard-setting body would apply for CFPB recognition. § 1033.111 Coverage of data providers. (a) Coverage of data providers. (b) Definition of covered consumer financial product or service. Covered consumer financial product or service (1) A Regulation E account, (2) A Regulation Z credit card, (3) Facilitation of payments from a Regulation E account or Regulation Z credit card, excluding products or services that merely facilitate first party payments. For purposes of this part, a first party payment is a transfer initiated by the payee or an agent acting on behalf of the underlying payee. First party payments include payments initiated by loan servicers. (c) Definition of data provider. Data provider (1) A financial institution, (2) A card issuer, (3) Any other person that controls or possesses information concerning a covered consumer financial product or service that the consumer obtained from that person. Example 1 to paragraph (c): (d) Coverage threshold—Certain depository institutions. (1) Determining SBA size standard. (2) Calculating total assets. (3) Merger or acquisition—coverage of surviving depository institution when there are not four quarterly call report submissions. § 1033.121 Compliance dates. (a) Determining assets and revenue for purposes of initial compliance dates. (1) With respect to a depository institution data provider, total assets are determined by averaging the assets reported on its 2023 third quarter, 2023 fourth quarter, 2024 first quarter, and 2024 second quarter call report submissions to the Federal Financial Institutions Examination Council or National Credit Union Administration, as applicable, or its submissions to the appropriate oversight body to the extent it does not submit such reports to the Federal Financial Examination Council or National Credit Union Administration. If, as a result of a merger or acquisition, a depository institution data provider does not have the named four quarterly call report submissions, the depository institution data provider shall use the process set out in § 1033.111(d)(3) to determine total assets for the time period named in this paragraph (a)(1). (2) With respect to a nondepository institution data provider, total receipts are calculated based on the SBA definition of receipts, as codified in 13 CFR 121.104(a). (b) Initial compliance dates. (1) April 1, 2026, for depository institution data providers that hold at least $250 billion in total assets and nondepository institution data providers that generated at least $10 billion in total receipts in either calendar year 2023 or calendar year 2024. (2) April 1, 2027, for data providers that are: (i) Depository institutions that hold at least $10 billion in total assets but less than $250 billion in total assets; or (ii) Nondepository institutions that did not generate $10 billion or more in total receipts in both calendar year 2023 and calendar year 2024. (3) April 1, 2028, for depository institution data providers that hold at least $3 billion in total assets but less than $10 billion in total assets. (4) April 1, 2029, for depository institution data providers that hold at least $1.5 billion in total assets but less than $3 billion in total assets. (5) April 1, 2030, for depository institution data providers that hold less than $1.5 billion in total assets but more than $850 million in total assets. (c) Compliance dates for depository institution data providers that subsequently cross coverage threshold. § 1033.131 Definitions. For purposes of this part, the following definitions apply: Authorized third party Card issuer Consensus standard Consumer Consumer Consumer interface Covered consumer financial product or service Covered data Data aggregator Data provider Depository institution Developer interface Financial institution Recognized standard setter Regulation E account Regulation Z credit card Third party § 1033.141 Standard-setting bodies. (a) Recognition of a standard-setting body. (1) Openness. (2) Balance. (3) Due process and appeals. (4) Consensus. (5) Transparency. Subpart B—Making Covered Data Available § 1033.201 Availability and prohibition against evasion. (a) Obligation to make covered data available General. (2) Prohibition against evasion. (i) With the intent of evading the requirements of subparts B and C of this part; (ii) That the data provider knows or should know is likely to render unusable the covered data that the data provider makes available; or (iii) That the data provider knows or should know is likely to prevent, interfere with, or materially discourage a consumer or authorized third party from accessing covered data consistent with this part. (b) Current data. § 1033.211 Covered data. Covered data (a) Transaction information, including historical transaction information in the control or possession of the data provider. A data provider is deemed to make available sufficient historical transaction information for purposes of § 1033.201(a)(1) if it makes available at least 24 months of such information. Example 1 to paragraph (a): (b) Account balance information. (c) Information to initiate payment to or from a Regulation E account directly or indirectly held by the data provider. This category includes an account and routing number that can be used to initiate an Automated Clearing House transaction. (1) In complying with its obligation under § 1033.201(a)(1), a data provider is permitted to make available a tokenized account number instead of, or in addition to, a non-tokenized account number, as long as the tokenization is not used as a pretext to restrict competitive use of payment initiation information. (2) This paragraph (c) does not apply to data providers who do not directly or indirectly hold the underlying Regulation E account. For example, a data provider that merely facilitates pass-through payments would not be required to make available account and routing number for the underlying Regulation E account. (d) Terms and conditions. For purposes of this section, terms and conditions are limited to data in agreements evidencing the terms of the legal obligation between a data provider and a consumer for a covered consumer financial product or service, such data in the account opening agreement and any amendments or additions to that agreement, including pricing information. Example 2 to paragraph (d): (e) Upcoming bill information. Example 3 to paragraph (e): (f) Basic account verification information, which is limited to the name, address, email address, and phone number associated with the covered consumer financial product or service. If a data provider directly or indirectly holds a Regulation E or Regulation Z account belonging to the consumer, the data provider must also make available a truncated account number or other identifier for that account. § 1033.221 Exceptions. A data provider is not required to make available the following covered data to a consumer or authorized third party: (a) Any confidential commercial information, including an algorithm used to derive credit scores or other risk scores or predictors. Information does not qualify for this exception merely because it is an input to, or an output of, an algorithm, risk score, or predictor. For example, annual percentage rate and other pricing terms are sometimes determined by an internal algorithm or predictor but do not fall within this exception. (b) Any information collected by the data provider for the sole purpose of preventing fraud or money laundering, or detecting, or making any report regarding other unlawful or potentially unlawful conduct. Information collected for other purposes does not fall within this exception. For example, name and other basic account verification information do not fall within this exception. (c) Any information required to be kept confidential by any other provision of law. Information does not qualify for this exception merely because the data provider must protect it for the consumer. For example, the data provider cannot restrict access to the consumer's own information merely because that information is subject to privacy protections. (d) Any information that the data provider cannot retrieve in the ordinary course of its business with respect to that information. Subpart C—Data Provider Interfaces; Responding to Requests § 1033.301 General requirements. (a) Requirement to maintain interfaces. (b) Machine-readable files upon request. (1) Consumer interface. (i) The requirements of this paragraph (b) for the covered data described in § 1033.211(c) (payment initiation information) and (f) (account verification information); and (ii) The requirement of this paragraph (b) to provide in a file that is machine-readable the covered data described in § 1033.211(d) (terms and conditions). (2) Developer interface. (c) Fees prohibited. (1) Interfaces. (2) Requests. § 1033.311 Requirements applicable to developer interface. (a) General. (b) Standardized format. (1) Meaning of format. format (2) Meaning of standardized. standardized (c) Commercially reasonable performance. (1) Response rate; quantitative minimum performance specification. (i) Any responses by and requests to the interface during scheduled downtime for the interface must be excluded respectively from the numerator and the denominator of the calculation. (ii) In order for any downtime of the interface to qualify as scheduled downtime, the data provider must have provided reasonable notice of the downtime to all third parties to which the data provider has granted access to the interface. Indicia that the data provider's notice of the downtime may be reasonable include that the notice conforms to a consensus standard. (iii) The total amount of scheduled downtime for the interface in a calendar month must be reasonable. Indicia that the total amount of scheduled downtime may be reasonable include that the amount conforms to a consensus standard. (iv) A proper response is a response, other than any message provided during unscheduled downtime of the interface, that meets all of the following criteria: (A) The response either fulfills the request or explains why the request was not fulfilled; (B) The response is consistent with the reasonable written policies and procedures that the data provider establishes and maintains pursuant to § 1033.351(a); and (C) The response is provided by the interface within a commercially reasonable amount of time. Indicia that a response is provided in a commercially reasonable amount of time include conformance to an applicable consensus standard. (2) Indicia of compliance Indicia. (A) Whether the interface's performance conforms to a consensus standard that is applicable to the data provider; (B) How the interface's performance compares to the performance levels achieved by the developer interfaces of similarly situated data providers; and (C) How the interface's performance compares to the performance levels achieved by the data provider's consumer interface. (ii) Performance specifications. (A) The interface's response rate as defined in paragraphs (c)(1) through (iv) of this section; (B) The interface's total amount of scheduled downtime; (C) The amount of time in advance of any scheduled downtime by which notice of the downtime is provided; (D) The interface's total amount of unscheduled downtime; and (E) The interface's response time. (d) Access caps. (e) Security specifications Access credentials. (2) Security program. (ii) If the data provider is not subject to section 501 of the Gramm-Leach-Bliley Act, the data provider must apply to its developer interface the information security program required by the Federal Trade Commission's Standards for Safeguarding Customer Information, 16 CFR part 314. § 1033.321 Interface access. (a) Denials related to risk management. (1) Granting access would be inconsistent with policies and procedures reasonably designed to comply with: (i) Safety and soundness standards of a prudential regulator, as defined at 12 U.S.C. 5481(24), of the data provider; (ii) Information security standards required by section 501 of the Gramm-Leach-Bliley Act, 15 U.S.C. 6801; or (iii) Other applicable laws and regulations regarding risk management; and (2) The denial is reasonable pursuant to paragraph (b) of this section. (b) Requirements for reasonable denials. (1) Directly related to a specific risk of which the data provider is aware, such as a failure of a third party to maintain adequate data security; and (2) Applied in a consistent and non-discriminatory manner. (c) Indicia bearing on reasonable denials. (1) Whether the denial adheres to a consensus standard related to risk management; (2) Whether the denial proceeds from standardized risk management criteria that are available to the third party upon request; and (3) Whether the third party has a certification or other identification of fitness to access covered data that is issued or recognized by a recognized standard setter or the CFPB. (d) Conditions sufficient to justify a denial. (1) The third party does not present any evidence that its information security practices are adequate to safeguard the covered data; or (2) The third party does not make the following information available in both human-readable and machine-readable formats, and readily identifiable to members of the public, meaning the information must be at least as available as it would be on a public website: (i) Its legal name and, if applicable, any assumed name it is using while doing business with the consumer; (ii) A link to its website; (iii) Its Legal Entity Identifier (LEI) that is issued by: (A) A utility endorsed by the LEI Regulatory Oversight Committee, or (B) A utility endorsed or otherwise governed by the Global LEI Foundation (or any successor thereof) after the Global LEI Foundation assumes operational governance of the global LEI system; and (iv) Contact information a data provider can use to inquire about the third party's information security and compliance practices. § 1033.331 Responding to requests for information. (a) Responding to requests—access by consumers. (1) Authenticate the consumer's identity; and (2) Identify the scope of the data requested. (b) Responding to requests—access by third parties. (i) Authenticate the consumer's identity; (ii) Authenticate the third party's identity; (iii) Document the third party has followed the authorization procedures in § 1033.401; and (iv) Identify the scope of the data requested. (2) The data provider is permitted to confirm the scope of a third party's authorization to access the consumer's data by asking the consumer to confirm: (i) The account(s) to which the third party is seeking access; and (ii) The categories of covered data the third party is requesting to access, as disclosed by the third party pursuant to § 1033.411(b)(4). Example 1 to paragraph (b): (c) Covered data not required to be made available. (1) The data are withheld because an exception described in § 1033.221 applies; (2) The data are not in the data provider's control or possession, consistent with the requirement in § 1033.201(a)(1). (3) The data provider's interface is not available when the data provider receives a request requiring a response under this section. However, the data provider is subject to the performance specifications in § 1033.311(c); (4) The request is for access by a third party; and (i) The consumer has revoked the third party's authorization pursuant to paragraph (e) of this section; (ii) The data provider has received notice that the consumer has revoked the third party's authorization pursuant to § 1033.421(h)(2); or (iii) The consumer has not provided a new authorization to the third party after the maximum duration period, as described in § 1033.421(b)(2). (5) The data provider has not received information sufficient to satisfy the conditions in paragraph(a) or (b) of this section. (d) Jointly held accounts. (e) Method to revoke third party authorization to access covered data. § 1033.341 Information about the data provider. (a) Requirement to make information about the data provider readily identifiable. (1) Readily identifiable to members of the public, meaning the information must be at least as available as it would be on a public website; and (2) Available in both human-readable and machine-readable formats. (b) Identifying information. (1) Its legal name and, if applicable, any assumed name it is using while doing business with the consumer; (2) A link to its website; (3) Its LEI that is issued by: (i) A utility endorsed by the LEI Regulatory Oversight Committee, or (ii) A utility endorsed or otherwise governed by the Global LEI Foundation (or any successor thereof) after the Global LEI Foundation assumes operational governance of the global LEI system; and (4) Contact information that enables a consumer or third party to receive answers to questions about accessing covered data under this part. (c) Developer interface documentation. (1) Be maintained and updated as reasonably necessary for third parties to access and use the interface in accordance with the terms to which data providers are subject under this part; (2) Include how third parties can get technical support and report issues with the interface; and (3) Be easy to understand and use, similar to data providers' documentation for other commercially available products. (d) Performance disclosure. § 1033.351 Policies and procedures. (a) Reasonable written policies and procedures. (b) Policies and procedures for making covered data available. (1) Making available covered data. (2) Denials of developer interface access. (i) Creates a record substantiating the basis for denial; and (ii) Communicates in a timely manner to the third party, electronically or in writing, the reason(s) for the denial. (3) Denials of information requests. (i) Creates a record substantiating the basis for the denial; and (ii) Communicates in a timely manner to the consumer or third party, electronically or in writing, the type(s) of information denied, if applicable, and the reason(s) for the denial. (c) Policies and procedures for ensuring accuracy In general. (2) Elements. (i) Implementing the format requirements of § 1033.311(b); and (ii) Addressing information provided by a consumer or a third party regarding inaccuracies in the covered data made available through its developer interface. (3) Indicia of compliance. (d) Policies and procedures for record retention. (1) Retention period. (2) Certain records retained pursuant to policies and procedures. (i) Records documenting requests for a third party's access to an interface, actions taken in response to such requests, and reasons for denying access, if applicable, for at least three years after the data provider has responded to the request; (ii) Records providing evidence of fulfillment of requests for information, actions taken in response to such requests, and reasons for not making the information available, if applicable, for at least three years after the data provider has responded to the request; (iii) Records documenting that the third party has followed the authorization procedures in § 1033.401 to access data on behalf of a consumer, for at least three years after such records are generated; (iv) Records providing evidence of actions taken by a consumer and a data provider to revoke a third party's access pursuant to any revocation method made available by a data provider, for at least three years after the revocation; (v) Records providing evidence of commercially reasonable performance described in § 1033.311(c)(2)(ii), for at least three years after the period recorded; (vi) Written policies and procedures required under this section for three years from the time such material was last applicable; and (vii) Disclosures required under § 1033.341, for three years from the time such material was disclosed to the public. Subpart D—Authorized Third Parties § 1033.401 Third party authorization; general. To become an authorized third party, the third party must seek access to covered data from a data provider on behalf of a consumer to provide a product or service the consumer requested and: (a) Provide the consumer with an authorization disclosure as described in § 1033.411; (b) Provide a statement to the consumer in the authorization disclosure, as provided in § 1033.411(b)(5), certifying that the third party agrees to the obligations described in § 1033.421; and (c) Obtain the consumer's express informed consent to access covered data on behalf of the consumer by obtaining an authorization disclosure that is signed by the consumer electronically or in writing. § 1033.411 Authorization disclosure. (a) In general. (b) Content. (1) The name of the third party that will be authorized to access covered data pursuant to the third party authorization procedures in § 1033.401. (2) The name of the data provider that controls or possesses the covered data that the third party identified in paragraph (b)(1) of this section seeks to access on the consumer's behalf. (3) A brief description of the product or service the consumer has requested from the third party identified in paragraph (b)(1) of this section and a statement that the third party will collect, use, and retain the consumer's data only as reasonably necessary to provide that product or service to the consumer. (4) The categories of data that will be accessed. Categories must have a substantially similar level of specificity as the categories in § 1033.211. (5) The certification statement described in § 1033.401(b). (6) A brief description of the expected duration of data collection and a statement that collection will not last longer than one year after the consumer's most recent reauthorization. (7) A description of the revocation method described in § 1033.421(h)(1). (c) Language access In general. (2) Additional languages. § 1033.421 Third party obligations. (a) General limitation on collection, use, and retention of consumer data In general. (2) Specific purposes. (i) Targeted advertising; (ii) Cross-selling of other products or services; or (iii) The sale of covered data. (b) Collection of covered data In general. (2) Maximum duration. (3) Reauthorization after maximum duration. (c) Use of covered data. (1) Uses that are specifically required under other provisions of law, including to comply with a properly authorized subpoena or summons or to respond to a judicial process or government regulatory authority; (2) Uses that are reasonably necessary to protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability; (3) Servicing or processing the product or service the consumer requested; and (4) Uses that are reasonably necessary to improve the product or service the consumer requested. (d) Accuracy. (1) Flexibility. (2) Periodic review. (3) Elements. (i) Accepting covered data in a format required by § 1033.311(b); and (ii) Addressing information provided by a consumer, data provider, or another third party regarding inaccuracies in the covered data. (4) Indicia of compliance. (e) Data security. (2) If the third party is not subject to section 501 of the Gramm-Leach-Bliley Act, the third party will apply to its systems for the collection, use, and retention of covered data the information security program required by the Federal Trade Commission's Standards for Safeguarding Customer Information, 16 CFR part 314. (f) Provision of covered data to other third parties. (g) Ensuring consumers are informed. (2) The third party will provide contact information that enables a consumer to receive answers to questions about the third party's access to the consumer's covered data. The contact information must be readily identifiable to the consumer. (3) The third party will establish and maintain reasonable written policies and procedures designed to ensure that the third party provides to the consumer, upon request, the information listed in this paragraph (g)(3) about the third party's access to the consumer's covered data. The third party has flexibility to determine its policies and procedures in light of the size, nature, and complexity of its activities, and the third party will periodically review its policies and procedures and update them as appropriate to ensure their continued effectiveness. The policies and procedures must be designed to ensure that the third party provides the following to the consumer, upon request: (i) Categories of covered data collected; (ii) Reasons for collecting the covered data; (iii) Names of parties with which the covered data was shared. The names must be readily understandable to the consumer; (iv) Reasons for sharing the covered data; (v) Status of the third party's authorization; (vi) How the consumer can revoke the third party's authorization to access the consumer's covered data and verification the third party has adhered to requests for revocation; and (vii) A copy of any data aggregator certification statement that was provided to the consumer pursuant to § 1033.431(c)(2). (h) Revocation of third party authorization Provision of revocation method. (2) Notice of revocation. (i) Effect of maximum duration and revocation on collection, use, and retention. (1) No longer collect covered data pursuant to the most recent authorization; and (2) No longer use or retain covered data that was previously collected pursuant to the most recent authorization unless use or retention of that covered data remains reasonably necessary to provide the consumer's requested product or service under paragraph (a) of this section. § 1033.431 Use of data aggregator. (a) Responsibility for authorization procedures when the third party will use a data aggregator. (b) Disclosure of the name of the data aggregator. (c) Data aggregator certification. (1) The third party seeking authorization under § 1033.401 must include the data aggregator's certification in the authorization disclosure described in § 1033.411; or (2) The data aggregator must provide its certification to the consumer, electronically or in writing, separate from the authorization disclosure. The certification must be in the same language as the authorization disclosure and must be clear, conspicuous, and segregated from other material. The name of any data aggregator in the certification must be readily understandable to the consumer. If, after the consumer has completed the authorization procedures, the authorized third party retains a data aggregator to assist with accessing covered data on behalf of the consumer, this data aggregator must provide its certification in accordance with this paragraph (c)(2). § 1033.441 Policies and procedures for third party record retention. (a) General requirement. (b) Retention period. (c) Flexibility. (d) Periodic review. (e) Certain records retained pursuant to policies and procedures. (1) A copy of the authorization disclosure that is signed by the consumer electronically or in writing and reflects the date of the consumer's signature and a record of actions taken by the consumer, including actions taken through a data provider or another third party, to revoke the third party's authorization; and (2) With respect to a data aggregator covered under paragraph (a) of this section, a copy of any data aggregator certification statement that was provided to the consumer pursuant to § 1033.431(c)(2). Appendix A to Part 1033—Personal Financial Data Rights Rule: How to Apply for Recognition as a Standard Setter If you want the CFPB to designate your organization as a recognized standard setter, you should follow the steps described below. We may amend this process from time to time. Step One: Requesting Recognition Submit a written request for recognition. 1 1 This should include key contact information, evidence of your organization's policies and practices, 2 3 2 3 In advance of filing your request, you can seek a pre-filing meeting with us. We can walk you through the application process and help you make a complete submission. Send formal submissions, as well as requests for pre-filing meetings, to: [email protected]. Step Two: Additional Information and Public Comment After reviewing your submission, we may request additional information to ensure that your application is complete. We may publish your application. We may also seek public input on your application and invite your responses to any information we receive on that basis. Step Three: Our Review When reviewing your application, we consider whether your policies and practices meet all the requirements for recognition. We also evaluate whether your application is accurate and complete. We prioritize and review applications based on the extent to which recognizing your organization helps us to implement open banking. 4 4 Step Four: Application Decision CFPB recognition will be publicly disclosed on our website, along with the applicable terms and conditions of such recognition, such as its duration. If the CFPB declines to recognize your organization, we will notify you. You may withdraw your application at any time or for any reason. If we determine that your organization is close to meeting, but does not yet meet, the requirements for CFPB recognition, we may ask you to provide a written plan specifying how and when you will take the steps required for full recognition. If that plan is satisfactory, we may state on our website that your organization has received contingent recognition. Once you provide us with evidence that you have successfully executed on that plan (or otherwise addressed the relevant contingences), the CFPB may extend full recognition. Step Five: Recognition There are several points to keep in mind about recognition. As a recognized standard setter, you agree that the CFPB may monitor your organization and that you will provide information that we request. You must also provide us, within 10 days, written explanation of any material change to information that was submitted with your application or during recognition, as well as any reason your organization may no longer meet underlying requirements for recognition. In addition, you must meet any other specified terms and conditions of your recognition, which may include our reserving the right to observe or participate in standard setting. If your recognition is set to expire, you can apply for re-recognition by re-starting at Step One at least 180 days before expiration. We may temporarily extend your recognition while we consider your request for re-recognition. We may modify or revoke your recognition. The CFPB expects to notify you of the reasons it intends to revoke or modify recognition, and to provide your organization with an opportunity to address the CFPB's concerns.

Related documents

Record · ID 505525 · SHA-256 6574ac10c88b2d3c
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.