Your Financial Data Should Stay Protected
Chances are, you've already benefited from a little-known part of the Dodd-Frank Act that supports open banking without thinking much about it. Maybe you connected your bank account to Venmo or PayPal to pay a friend back after dinner, linked it to Robinhood to fund an investment account, or gave Rocket Money access to automatically set money aside or cancel unwanted subscriptions.
If so, you're one of the 100 million consumers who have already authorized an app or other third party to access their financial-account data.
Section 1033 of the Dodd-Frank Act was passed in 2010 to establish Americans' right to access information about their financial accounts. That right underpins an ecosystem in which people can authorize financial apps and services to access their data.
But as this ecosystem has expanded, so have questions about where that information goes, how it is used, and who is responsible when something goes wrong.
Open banking gives everyone more choice
Secure data sharing allows consumers to connect their financial accounts to the tools that work best for them—whether that means viewing multiple accounts in one place, tracking spending, automating savings, making payments, comparing products, or applying for credit.
In the FDIC's 2023 household survey, nearly half of U.S. households reported using a nonbank online payment service such as PayPal, Venmo, or Cash App. And as more apps help people manage their financial lives, secure data sharing has enabled companies to offer simpler, more convenient services.
But consumer choice only works when people can trust the system behind it.
Protections should follow the data
You've connected an app like Rocket Money to your bank account. But what happens next? Who can access that information, how long is it stored, and can it be shared again?
That uncertainty is widespread. A 2025 national survey found that fewer than half of Americans were confident their personal data—including financial information—was private and not distributed without their knowledge.
As financial data moves across a growing ecosystem, Americans may have limited visibility into how it is used or who is responsible if it is exposed, misused, or involved in fraud. You should not face weaker or less consistent protections simply because your data moves from one financial provider to another.
Clear consent and accountability matter
Consumers should be able to understand what information they are sharing, why it is needed, who will receive it, and how to withdraw access. That clarity is often missing today. A survey of more than 4,000 U.S. banking consumers found that 78% did not know financial apps could continue accessing their personal data even when the app was closed or deleted.
Consent should be clear, specific, and easy to manage—not buried in lengthy terms or treated as permanent permission to collect more information than a service requires.
Accountability must also extend across the full ecosystem. Every company that accesses or holds sensitive financial data should be responsible for protecting it and responding when something goes wrong.
Security and choice should go hand in hand
Open banking can support broader access to useful financial tools and encourage continued innovation. Strong safeguards do not have to stand in the way of that progress. They are what allow everyone to participate in the system with confidence.
Any implementation of Section 1033 should pair people’s ability to use the services they choose with consistent data-security standards, meaningful privacy protections, clear consent rules, and shared accountability across the marketplace.
Americans should not have to choose between convenience and security.
For more updates like this, sign up for The Ledger Project’s emails here.