How Open Banking Can Protect Consumers and Strengthen Financial Competition

15948

Americans are managing their money across more banking apps, financial institutions, lending platforms, and budgeting tools than ever before. As the Consumer Financial Protection Bureau reviews Section 1033 of the Dodd-Frank Act, policymakers face a central question: can open banking expand consumer choice without creating new security and privacy risks?

The answer depends on how the system is designed. Consumer protection and financial innovation do not have to be competing priorities. With the right framework, open banking can give people greater control over their financial information while encouraging banks, fintech companies, and other providers to compete on better products and services.

Key Principles for a Consumer-Friendly Open Banking System

  • Consumers should control their financial data and be able to access, transfer, and share it securely.
  • Consumer-authorized data access should remain free to prevent larger institutions from gaining excessive control over market economics.
  • Clear consent rules, shared technical standards, strong cybersecurity, and meaningful privacy protections are essential for building trust.
  • Responsible data use can help improve fraud detection, financial guidance, lending decisions, and personalized services.

Financial Data Should Remain Under Consumer Control

The most important question in open banking is who owns a consumer’s financial information. Section 1033 begins with a straightforward principle: financial data belongs to the consumer. A bank or other institution holding that information should be viewed as its custodian rather than its owner.

This principle gives consumers the ability to access their information and share it with financial providers they choose. Data should be available in a usable electronic format, either directly to the consumer or through an authorized representative acting on the consumer’s behalf.

Simply allowing someone to download a file is not enough. The real value of open banking comes from turning financial information into useful services. Secure data connections can support more accurate budgeting tools, improved lending decisions, better fraud monitoring, tailored financial advice, and a clearer view of a person’s complete financial position.

Why Consumer-Authorized Data Access Should Stay Free

One of the most important elements of the current framework is the principle that providers should not charge fees every time a consumer-authorized service accesses financial data.

Supporters of data access fees argue that financial institutions invest heavily in the technology required to support secure data sharing. They contend that companies building products on top of those connections should contribute to the cost through market-based charges.

However, this argument overlooks the benefits that financial institutions receive from modern open banking infrastructure. Secure application programming interfaces, commonly known as APIs, can help banks move customers away from less secure credential-based screen scraping. APIs can also improve visibility into data access, make it easier to disable unauthorized connections, and reduce certain fraud risks.

Open banking infrastructure is therefore more than an expense. It can serve as an industry-wide investment in stronger security, improved customer experiences, and long-term growth.

Fees also raise serious competition concerns. If a data aggregator must accept the terms set by a financial institution or risk losing access to information from many customers, the arrangement may not reflect a genuinely competitive market. The largest institutions could potentially set terms that smaller fintech companies and startups would struggle to afford.

Large providers may be able to absorb per-use charges, while emerging companies may not. Over time, different access fees imposed by individual data holders could give institutions with the largest customer bases significant influence over the businesses competing to serve those same customers.

Consumers already help fund the infrastructure used to reach their bank accounts, including branches, call centers, ATMs, websites, and mobile applications. Open banking is another channel for accessing a consumer’s own information. Applying a separate charge to every data connection could turn a legal right into a metered service.

Such a system could also encourage cost-conscious companies to return to screen scraping to avoid access fees. That would undermine years of work aimed at moving the financial industry toward safer, more transparent data-sharing methods.

Make Financial Data Useful Through Clear Rules

Consumer privacy and financial innovation can work together, but the rules governing data use must be carefully designed. Consumers should understand how their information will be used, and they should be able to authorize services that provide genuine value.

Set Practical Rules for Secondary Data Use

Financial data should not be used in ways that surprise consumers or benefit companies at their expense. At the same time, overly restrictive rules may prevent people from accessing services they knowingly want and approve.

With informed consent, broader financial data could support stronger fraud detection, more accurate financial recommendations, improved product offers, and privacy-conscious research. Aggregated information may also help financial providers develop better services for people with limited credit histories or fewer traditional banking options.

The best approach is neither unrestricted data use nor an absolute ban on additional uses. Consumers should be able to approve specific uses, understand the benefits and risks, and easily withdraw permission when they no longer want a service to access their information.

Adopt Shared Technical Standards

The United States has a large and fragmented financial data ecosystem. For open banking to work efficiently, banks, fintech companies, data networks, and regulators need common technical standards.

Industry standards can help organizations connect securely without building separate systems for every partner. Certification programs and carefully designed safe harbors could also reduce compliance costs for smaller financial institutions and technology companies.

Shared standards would allow the market to expand while avoiding a patchwork of private rules controlled by the companies that hold the most consumer data.

Security and Privacy Are Essential to Consumer Trust

Consumer concern about financial data privacy remains a major challenge for open banking. Many people are uncertain about which companies can access their information, what data is being collected, and how that information may be used.

A strong Section 1033 framework should address those concerns directly. Consumers should receive clear, standalone disclosures explaining who is accessing their data, what information will be collected, and why it is needed.

They should also have a simple way to revoke access. When permission is withdrawn, data recipients should generally stop collecting information and delete data they no longer need to retain.

Strong cybersecurity obligations should apply across the ecosystem, including to banks, data aggregators, fintech providers, and other companies handling consumer information. Moving away from screen scraping and toward secure APIs can improve transparency and reduce certain vulnerabilities.

Privacy rules should also limit the sale of consumer financial data and support an informed opt-in model. Data should be shared because a consumer deliberately approved the connection, not because the person failed to locate a difficult-to-find opt-out setting.

Strengthen Compliance, Verification, and Liability

Open banking protections could be reinforced through recognized cybersecurity frameworks such as SOC 2, ISO 27001, and the NIST Cybersecurity Framework. Independent assessments by accredited auditors could help demonstrate that participants meet established security expectations.

Appropriate safe harbors may also encourage companies to maintain strong certifications without creating unnecessary regulatory delays. At the same time, responsibility should remain with the organization that controls the data when a security or privacy failure occurs.

A consistent liability framework would give every participant a clear incentive to protect consumers. Accountability should not be assigned solely based on whether a company is a bank, fintech provider, data aggregator, or another type of participant.

The Future of Open Banking Depends on Getting the Framework Right

Open banking presents a rare opportunity for consumer protection and competition to reinforce each other. A successful system would allow consumers to access and move their financial data without unnecessary fees, authorize useful services, and withdraw permission with minimal effort.

It would also rely on common technical standards, strong security requirements, clear privacy rules, and transparent liability policies. These safeguards could create a more competitive financial marketplace where consumers can choose the products that best meet their needs.

Financial institutions could benefit as well. Better data connections may help banks improve customer experiences, develop more relevant services, strengthen fraud controls, and build deeper relationships with account holders.

The alternative is a system where access to consumer data carries a toll, giving the largest data holders another way to influence the companies competing for customers. That approach could limit innovation, raise costs, and weaken consumer choice.

Updating Section 1033 with a focus on free consumer-authorized access, responsible data use, shared standards, security, and accountability can help create an open banking ecosystem in which consumers and competition genuinely benefit.

About the author: Maisie Bilotti is a vice president of external relations at MX, where she focuses on financial data policy and consumer advocacy. She previously held several roles at Google involving congressional relations, privacy, competition policy, and partnership strategy.

Source: TheFinancialBrand.com