Pub. 5 2024 Issue 5

performance specifications to receive and respond to data access requests. This approach aims to ensure third parties are acting on behalf of consumers when accessing their data and respect their privacy interests. Rule 1033 also promotes security and reliability, as it would apply a set of consistent standards across the market for sharing data. Third-party access proposals would require these companies to provide an authorization disclosure to inform the consumer of key terms of access and obtain the consumers’ informed consent. According to the CFPB, the proposed rule would “forbid companies that receive data from misusing or wrongfully monetizing the sensitive personal financial data.” What Data Does Rule 1033 Cover? The rule includes a definition of the types of data that providers, such as card issuers and financial institutions, would need to make available upon request. According to the proposed rule, covered data includes: • Transaction information, including historical data (at least 24 months). • Account balances. • Terms and conditions. • Upcoming bill information. • Basic account verification information, such as name, address, email, etc. It excludes confidential commercial information, algorithms, information used to prevent fraud or money laundering or other crimes and information that is required confidential under other laws, as well as other information that the provider cannot retrieve in the ordinary course of business. At the request of a consumer or authorized third party, providers must make covered data available in a machine‑readable format that can be retained by the consumer or authorized by a third party and transferred for processing into separate information systems — all without imposing fees or charges. How Rule 1033 is Accelerating Open Banking So, what does Rule 1033 have to do with open banking? Open banking uses APIs to enable developers to access an institution’s data, which includes customer data. The technological approach enables banks to offer new products or services without building them internally or relying on a single provider. Rule 1033 aims to place data rights in the hands of consumers, expanding the definition of open banking and giving them more control. While that control could make customers less “sticky,” it could be welcome news for institutions that prioritize a relationship‑based approach to customer service, like community banks. As consumers exercise more control over their data, they’re more able to switch to banks that provide personalized service and their desired products instead of remaining with those that hoard all their financial data but provide poor service and lacking products. Data Rights Considerations in Open Banking As with any technology partnership, concerns may arise regarding data sharing and third‑party data breaches. However, there are ways to mitigate risk for your institution. And the opportunities that open banking provides — from improving customer experience to expanding revenue lines — can better position your institution against the competition. As a data steward, your bank should consider several factors to protect your customers and remain compliant. Safeguard your digital services, core platform and any other sectors placed into your open banking ecosystem. Your bank should also ensure you have secure processes in place, including handling file transfers without opening yourself up to any vulnerabilities. To maximize your security and incident preparedness, develop and maintain policies and procedures for preventing and managing a security breach. Additionally, make sure you understand data retention and data deletion obligations. How to Qualify an Open Banking Vendor Partnering with third‑party vendors to enhance your offerings is a key part of open banking, but you must stay vigilant and keep bad actors out of your open banking network. Here are a few considerations your institution should keep in mind when qualifying a vendor: • Qualified Sources: Ensure you’re looking for vendors and applications from reputable industry sources. • Standard Due Diligence: Audit procedures should follow your institution’s established policies. • Adequate Testing Phase: Deploy a testing phase to ensure how your institution’s data is accessed and used through the vendor’s apps. • Security, Audits and Reporting: Verify the vendor uses secure methods to access and store your institution’s data, especially consumer‑related data. Understand what they offer in terms of audit support and reporting capabilities. Sharing Data in the Digital Era When it comes to Rule 1033, your bank has a choice to make. Will you simply implement measures to ensure compliance once required and deliver data upon request? Or will you embrace open banking to better serve current and prospective customers? Developing the right open banking strategy for your institution can provide long‑term benefits for your bank. 19 In Touch

RkJQdWJsaXNoZXIy MTg3NDExNQ==