Data protection protocols were among the top concerns raised after the Consumer Financial Protection Bureau gave consumers and the industry until Dec. 29 to respond to its October open banking proposal.
Sharing data securely is the most important thing when it comes to open banking adoption, Lee Wetherington, senior director of corporate strategy at tech provider Jack Henry, told Bank Automation News.

“Open banking in its simplest terms is just the sharing of financial data,” Wetherington said.
Today, some third-party vendors look to screen-scraping to collect data, which has proven to be a “nightmare” for FIs due to its unreliable nature, Wetherington said. Screen-scraping is the automated data collection used by some third-party vendors who mirror a consumer’s screen and collect consumers’ credentials to log into their accounts.
Financial institutions and third-party vendors are looking to APIs to remove screen-scraping from the data-collection process, Paige Pidano Paridon, senior vice president and senior associate general counsel at Banking Policy Institute, previously told BAN.
However, whether FIs and fintechs are using APIs or screen-scraping methods for data collection, the question is who is liable if data is stolen or hacked. That’s where the CFPB’s proposal can present clarity, Wetherington said.
Determining liability
As financial institutions look to APIs to securely transfer data for open banking purposes, the CFPB must make it clear who is responsible for the data throughout the transfer process, Wetherington said.
Liability depends on where the data is in the transfer, how the breach happens, if the data is in motion and when the breach happened, he said.
“If the API is somehow compromised or hacked, there’s going to be an argument to be made that whoever owns the API has the liability for it being compromised or hacked,” Wetherington said. “If that data has already made its way to that third party that is collecting or aggregating the data, now the third party has liability for that data.”
“It’s hard to parse the liability without specifics of a particular scenario,” Wetherington said. “The design of the rule is to make sure that everybody who has a hand in the process of sharing financial data also shares in the liability for the protection and security of that data and the privacy of that data relative to its account holders.”
As Jack Henry raised concerns about liability, others in the industry, including American Bankers Association and American Fintech Council, also came forward with suggestions with a common theme that the CFPB should have given more time for the industry to comment on the proposal.
Get ready for the Bank Automation Summit U.S. 2024 in Nashville on March 18-19! Discover the latest advancements in AI and automation in banking. Register now.






