Financial data aggregation is the process of pulling your account information from multiple banks, brokerages, credit card issuers, and lenders into a single digital view through a third-party app or platform. It runs on direct connections between financial institutions and those platforms, and it is governed by a federal framework built on Section 1033 of the Dodd-Frank Act and the Consumer Financial Protection Bureau’s Personal Financial Data Rights Rule, finalized in October 2024. That framework gives you specific rights over who sees your data, what they can do with it, and how you shut off access. Its rollout is currently paused by a federal court order and an ongoing CFPB reconsideration.
What Aggregation Actually Pulls From Your Accounts
Aggregation reaches into checking and savings accounts, brokerage portfolios, retirement funds, credit cards, and outstanding loans. The specific data points include current balances, transaction histories with merchant names and dates, individual stock and mutual fund holdings, and debt balances with interest rates.
The depth matters. A budgeting app doesn’t just know you spent $47 at a grocery store. It knows the date, the exact merchant, and can categorize that purchase against months of similar ones. Investment platforms see individual ticker symbols and share counts. Mortgage lenders can trace twelve months of direct deposits to verify income patterns. That breadth is what makes aggregation useful, and it is also why the rules around it exist.
How the Data Moves: APIs vs. Screen Scraping
Data reaches a third-party app through one of two technical methods, and the difference has real consequences for your security.
API Connections
An Application Programming Interface creates a structured link between your bank’s systems and the aggregator. Your bank shares specific data fields in a standardized format, and the app never sees your login credentials. Companies such as Plaid, MX, Finicity, and Yodlee act as middlemen, maintaining API connections to thousands of banks so individual app developers don’t have to build integrations one at a time.
Screen Scraping
Screen scraping is older and works when no API connection exists. You hand the aggregator your actual bank username and password, and automated software logs into your bank’s website, reads what’s on the screen, and extracts the data. The CFPB has called this “a still common but risky practice that typically involves consumers providing their account passwords to third parties who use them to access data indiscriminately through online banking portals.”1Consumer Financial Protection Bureau. CFPB Finalizes Personal Financial Data Rights Rule Once you share your password, the third party has broad access to your account rather than the narrow slice you meant to share. Moving the industry toward API-based access is a stated goal of the federal data rights framework.
What Aggregated Data Is Used For
Financial management apps use aggregated data to categorize transactions across accounts and track spending over time. Net worth trackers combine brokerage asset values with outstanding loan balances to calculate equity. Automated investment platforms suggest rebalancing based on your actual holdings.
Lenders use aggregation to verify income and liquid assets directly from bank records, replacing paper pay stubs and manual statement uploads. Fannie Mae’s Desktop Underwriter validation service accepts aggregated asset data from approved third-party vendors. The parameters are narrow: only checking and savings accounts qualify, the report must contain at least twelve consecutive months of history, and it can be no older than 45 days at the time of application.2Fannie Mae. DU Validation Service Frequently Asked Questions
How Your Data Is Protected in Transit
Three technical layers protect data during aggregation: encryption, tokenization, and delegated authorization.
The Advanced Encryption Standard with 256-bit keys, known as AES-256, is the standard for securing financial data both in transit and at rest. NIST specifies AES-256 as one of the approved algorithms for protecting electronic data.3National Institute of Standards and Technology. FIPS 197 – Advanced Encryption Standard (AES) Tokenization adds a second layer by replacing sensitive account numbers with unique digital identifiers that have no value if intercepted.
OAuth handles the authorization step. Rather than handing your password to the aggregator, OAuth redirects you to your bank’s own login page. You authenticate directly with your bank, and the bank issues a limited-access token to the aggregator. The aggregator never touches your credentials. This is the core advantage of API connections over screen scraping.
Your Rights Under Federal Law
The legal foundation is Section 1033 of the Dodd-Frank Act, codified at 12 U.S.C. ยง 5533. It requires covered financial institutions to make your account information available to you, on request, in an electronic form you can actually use. That includes transaction data, balances, costs, charges, and usage data.4Office of the Law Revision Counsel. 12 USC 5533 – Consumer Rights to Access Information
Section 1033 sat unused for over a decade until the CFPB’s Personal Financial Data Rights Rule was finalized in October 2024. Codified at 12 CFR Part 1033, the rule requires data providers to share covered data with you and with authorized third parties acting on your behalf, through standardized developer interfaces rather than screen scraping. Covered data includes transaction history, account balances, payment initiation information, terms and conditions, upcoming bill information, and basic account verification data.5eCFR. 12 CFR Part 1033 – Personal Financial Data Rights
Both data providers and third parties must maintain information security programs meeting the standards of the Gramm-Leach-Bliley Act, or the FTC’s Safeguards Rule at 16 CFR Part 314 if they aren’t subject to GLBA.5eCFR. 12 CFR Part 1033 – Personal Financial Data Rights
Limits on What Third Parties Can Do With Your Data
A third party must limit its collection, use, and retention of your data to what is reasonably necessary to provide the product or service you actually requested.5eCFR. 12 CFR Part 1033 – Personal Financial Data Rights Three uses are explicitly prohibited:
- Targeted advertising. A budgeting app that pulls your transaction data cannot use it to serve you ads.
- Cross-selling. The app cannot use your data to market other products or services to you.
- Sale of the data to other parties.
Permitted uses beyond delivering the requested service include complying with legal obligations like subpoenas, preventing fraud or unauthorized transactions, and making reasonable improvements to the service you asked for.5eCFR. 12 CFR Part 1033 – Personal Financial Data Rights
Before touching your data, a third party must give you an authorization disclosure, certify that it agrees to these obligations, and obtain your express informed consent through a signed authorization.6eCFR. 12 CFR 1033.401 – Third Party Authorization; General Data collection is capped at one year from your most recent authorization. To keep collecting past that point, the third party has to come back for a fresh authorization.
You also have the right to ask any third party that accessed your data what it collected and why. On request, it must disclose the categories of data gathered, the reasons for collecting them, the names of any parties it shared data with, and the current status of its authorization.
How to Revoke a Third Party’s Access
You can cut off a third party’s access at any time, and the rule requires that doing so be straightforward. The revocation method must be at least as easy to use as the original authorization process, and you cannot be charged a fee or penalized for revoking.5eCFR. 12 CFR Part 1033 – Personal Financial Data Rights
Once the third party receives your revocation, it must stop collecting your data immediately, notify your bank and any aggregator in the chain, and alert any other parties it shared data with. It must also stop using or retaining data it previously collected, unless retention remains reasonably necessary to deliver a service you already requested.5eCFR. 12 CFR Part 1033 – Personal Financial Data Rights That narrow exception does not cover targeted advertising, cross-selling, or data sales.
You can also revoke through your bank directly. When a data provider receives a revocation, it must cut off the third party’s access and notify that third party in a timely manner. Both your bank and the third party must keep records of the revocation for at least three years.5eCFR. 12 CFR Part 1033 – Personal Financial Data Rights
If Unauthorized Transactions Happen
When aggregated data access leads to unauthorized transfers, federal law caps your liability based on how quickly you report the problem. Under the Electronic Fund Transfer Act, if you notify your bank within two business days of learning about a lost or compromised access device, your liability is capped at $50 or the amount of unauthorized transfers before you gave notice, whichever is less.7Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability
If you wait longer than two business days, the cap rises to $500. If unauthorized transfers appear on your periodic statement and you fail to report them within 60 days of the statement being sent, you can be on the hook for the full amount of transfers occurring after that 60-day window. The statute allows extended reporting periods for circumstances like hospitalization or extended travel.7Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability
No agreement between you and your bank can impose greater liability than these federal limits. Your bank also cannot use your negligence, such as writing a PIN on a card, to charge you more than the statute allows. Reviewing your accounts often and reporting suspicious activity fast is the single most effective way to limit your exposure.
The data rights rule adds one more safeguard. A data provider can deny a third party access to its developer interface if that third party has failed to maintain adequate data security, giving banks a way to cut off aggregators that fall short of security standards before a breach rather than only after one.
Where the Rule Stands Now
The CFPB’s rule was designed to phase in by institution size, with the largest banks and nondepositories originally facing an April 1, 2026 compliance date and smaller institutions following through 2030.8Consumer Financial Protection Bureau. 12 CFR 1033.121 – Compliance Dates
That schedule is not proceeding as planned. Banking industry groups challenged the rule in federal court, arguing it put consumer data at risk and exceeded the CFPB’s authority. The U.S. District Court for the Eastern District of Kentucky stayed the compliance deadline until the CFPB completes a new rulemaking. In August 2025, the CFPB published an Advance Notice of Proposed Rulemaking to reconsider elements of the rule, including whether its privacy protections adequately address financial profiling and aggressive marketing.9Federal Register. Personal Financial Data Rights; Reconsideration
The substantive requirements remain on the books, but enforcement of the earliest compliance deadlines is paused, and the final shape of the rule may shift depending on the outcome of the reconsideration.