The Consumer Financial Protection Bureau's (CFPB) rewrite of its Personal Financial Data Rights rule (sometimes known as "Open Banking") under Section 1033 of the Dodd-Frank Act has garnered the reputation as a FinTech versus banking fight. However, non-bank mortgage lenders should be paying attention. The results of this rule and business incentives it creates will affect how mortgage lenders verify assets, confirm income, detect fraud, support underwriting, and eventually deliver loans to investors.
Recent reporting indicates that the CFPB is on the cusp of releasing a significant reprise of the regulatory regime underpinning the concept of consumer data rights that the Dodd-Frank Act altered. In deciphering the message communicated through the Bureau's August 22, 2025, Advance Notice of Proposed Rulemaking (ANPRM) and court filing in the litigation challenging the rule, it seems clear that the new regime will fundamentally rethink three issues that mortgage lenders should watch: whether data providers may charge access fees, who may act as a consumer's authorized representative, and the changes the rule undertakes to address security risks and privacy.1 For lenders, the practical question is whether borrowers will continue to be able to authorize fast, reliable data access, or whether the process starts moving back toward PDFs of bank statements, paystubs, screenshots, and manual follow-up.
Issue 1: Fees
Current § 1033.301(c)(1) and (2) bars data providers from charging consumers or authorized third parties to establish or maintain access interfaces, receive data requests, or make covered data available. The ANPRM reopened that ban. It asked whether the fee prohibition is the best reading of Section 1033 (Question 9) and whether covered persons should be allowed to recover a reasonable cost for providing access (Question 15). Recent reporting suggests the CFPB may consider a threshold model: free access up to a certain number of requests, with fees allowed after that. That model could hit mortgage files quickly. A single loan may require data from several banks, pulled more than once for underwriting, quality control, investor delivery, or repurchase defense. Small per-request fees could become real costs when routed through aggregators, verification vendors, and loan origination systems. Lenders should watch the proposal for clarity on who may charge, when fees may be imposed, how fees are calculated, and whether/how those costs may be passed through (and potentially disclosed) to borrowers.
The statutory text leaves open the question as to whether or if the CFPB has the power to cap fees in this argument. The potential for unbounded or expensive bank-imposed fees could start to behave like a tax on consumers and undermine the Dodd-Frank right to access their own data.
Issue 2: "Representative" Definitions
Section 1002(4) of the Dodd-Frank Act defines "consumer" to include an individual or an "agent, trustee, or representative acting on behalf of an individual."2 The current Open Banking rule treats authorized third parties as covered representatives if they obtain consumer authorization and meet the rule's obligations. The ANPRM asked whether that reading is correct (Question 1) and whether an agent, trustee, or representative must act in a fiduciary capacity (Question 3), suggesting that a more rigorous standard was under significant consideration. Similarly, a seemingly leading question in the ANPRM asks whether a fiduciary reading would limit consumers' ability to transfer transaction data or reduce competition by third-party service providers (Question 5).
A fiduciary requirement would not suit many mortgage lending data flows. Aggregators, verification providers, point-of-sale platforms, and loan-origination vendors perform limited tasks for a specific transaction; they are not consumer fiduciaries. Furthermore, a decade or so of jurisprudence indicates that lenders are affirmatively not fiduciaries of their borrowers.
If the Bureau narrows the definition, lenders may need new consent language, new vendor structures, direct bank-by-bank arrangements, or new intermediaries controlled by the institutions holding the data.
The rule also needs to account for how mortgage data is used after collection. A lender may rely on the same verification data for underwriting, quality control, investor delivery, repurchase defense, servicing transfers, audits, and examinations. Current 12 Code of Federal Regulations (CFR) 1033.421 governs third-party collection, use, and retention of covered data and requires a signed authorization disclosure. If the CFPB restricts retention, reuse, or transfer too sharply, lenders may have to reauthorize borrowers and rerun verifications for the same loan multiple times during the same lending process. Today, the same verification information may support underwriting, conditions clearance, pre-closing review, Quality Control (QC), investor delivery, repurchase defense, audit response, servicing transfer, and investor relief programs. Changes on the use and reuse of the permissioned data will impact the design of these flows.
Issue 3: Security Controls
Large banks will likely frame the 1033 rewrite as a data-security problem. The ANPRM cited major breaches at Yahoo, OPM, Equifax, Marriott, LinkedIn, Facebook, and the Office of the Comptroller of the Currency (OCC), and asks whether current Gramm-Leach-Bliley Act (GLBA) protections are adequate (Questions 18, 26, and 28). Non-bank mortgage lenders should not accept the premise that they operate in a regulatory vacuum. They are already subject to the Federal Trade Commission (FTC)-administered Safeguards Rule, a GLBA-based security regime that expressly covers mortgage lenders and brokers and now includes federal breach-notification obligations. The CFPB should resist calls to impose a separate bank-grade overlay on authorized third parties. That kind of regime would not merely "raise standards." It would shift liability, increase compliance costs, and give data-holding banks a basis to restrict or ration consumer-permissioned access.
Thoughts on Engagement During the Comment Period
Mortgage lenders should use the comment process to bring evidence of how their flows would be impacted. Useful comments would show how often lenders use permissioned data, how many institutions appear in a typical borrower file, how many pulls occur per loan lifecycle, what manual verification costs, and how automated verification affects cycle times, fraud detection, and (perhaps most importantly) borrower experience. The core message seems to boil down to this: borrower-authorized data access is now part of mortgage infrastructure. If the CFPB makes that access slower or more expensive, lenders and borrowers will feel it in ordinary loan files.
---
1 Consumer Fin. Prot. Bureau, Personal Financial Data Rights Reconsideration, 90 Fed. Reg. 40,986 (Aug. 22, 2025) (advance notice of proposed rulemaking) and Forcht Bank, N.A. v. Consumer Financial Protection Bureau, No. ___, U.S. District Court for the Eastern District of Kentucky (filed Oct. 22, 2024).
2 Codified at 12 U.S.C. § 5481(4).