Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy Open Banking topic
No spam. Unsubscribe anytime.
House subcommittee hears clash over open-banking rule, GLBA modernization and small‑bank impacts
Summary
Members of the House Financial Services Subcommittee on Financial Institutions and five witnesses debated whether to modernize the Gramm‑Leach‑Bliley Act, preserve the CFPB’s open‑banking rule under Dodd‑Frank section 1033, and how a patchwork of state privacy laws, API costs and liability rules affect consumers, fintechs and small banks.
Get email alerts on the Data Privacy Open Banking topic
No spam. Unsubscribe anytime.
The House Financial Services Subcommittee on Financial Institutions convened a hearing to review data privacy in the financial system, focusing on whether to modernize the Gramm‑Leach‑Bliley Act (GLBA) and how the Consumer Financial Protection Bureau’s (CFPB) recently finalized personal financial data rights rule under Dodd‑Frank section 1033 should be treated.
The hearing matters because technological change has multiplied the volume and sensitivity of consumer financial data, raising tradeoffs between consumer privacy protections, fraud prevention and continued innovation in payments and fintech services.
Chairman Andy Barr, chair of the subcommittee, opened the hearing by framing the policy tradeoffs: lawmakers must “balance robust privacy protections with innovation, access, and reduced regulatory burden,” and asked whether GLBA remains fit for purpose in a data‑driven era. Ranking Member Bill Foster urged preserving the CFPB rule implementing section 1033, calling it “significant because it gives consumers greater rights, privacy, and the security over their personal financial data.”
Five witnesses gave five‑minute statements and answered members’ questions. Scott Talbot, executive vice president of the Electronic Transactions Association, emphasized the scale of modern payments and the industry’s reliance on existing GLBA and state rules. “In fact, during the minute the 5 minutes I will speak today, this morning, roughly 1,500,000 transactions will be processed in The US,” Talbot said, arguing that payments firms need clarity and a uniform national standard to avoid costly state divergence.
Andrew Morris, director of innovation and technology at America’s Credit Unions, urged an entity‑level exemption for depository institutions already subject to GLBA and other bank regulations, and said federal preemption would reduce burdens on credit unions. Rebecca Keane, partner at Hudson Cook and a former FTC assistant director, described GLBA as the “cornerstone of the financial privacy regulation,” noting its privacy‑notice, opt‑out and safeguards rules and warning that some CFPB proposals (such as reclassifying certain data under the Fair Credit Reporting Act) could reduce institutions’ ability to prevent fraud.
Jennifer Huddleston, senior fellow at the Cato Institute, and Zoe Strickland, senior fellow at the Future of Privacy Forum, both argued that open banking and consumer‑driven data portability can expand competition and consumer choice but need careful drafting to avoid imposing static rules that stifle innovation or create disproportionate litigation risk. Strickland said open banking “represents enormous consumer value,” while Huddleston cautioned that private rights of action with statutory damages can chill innovation and create outsized litigation exposure for small firms.
On the key issues raised during questioning, witnesses and members highlighted three recurring fault lines:
- Preemption and state patchwork: industry witnesses said about two dozen state privacy laws have produced inconsistent definitions and obligations (for example, some states apply only a data‑level exemption while others, like California, treat GLBA data differently), creating compliance complexity for firms operating nationwide. Multiple witnesses urged a uniform federal standard and clearer preemption rules to avoid duplicated costs.
- Scope of coverage and third‑party liability: witnesses and members debated whether laws should extend GLBA‑style obligations to nonbank data recipients and whether data holders can be allowed to charge for API access. Talbot and Morris said some entities that possess consumer financial data but are not currently covered should be included; they also flagged unaddressed questions in the CFPB rule about liability allocation when downstream third parties mishandle data.
- Enforcement and private rights of action: industry witnesses uniformly warned that a broad private right of action would invite class actions and high litigation costs that could disproportionately harm small banks and credit unions. Keane said historical enforcement of GLBA by regulators has been limited and argued regulatory enforcement may be sufficient; Huddleston and others reiterated concerns about statutory damages and private suits.
Members from both parties exchanged questions that reflected differing priorities. Several Republicans, including Representative Pete Sessions and others, stressed protecting depository institutions from duplicative state requirements and limiting private rights of action; Democratic members, including Representative Carolyn Maloney and Representative Lou Correa, emphasized the consumer benefits of the CFPB rule and urged the agency not to rescind or vacate it.
Witnesses also discussed specific operational matters: industry witnesses called for rules that preserve permissible data uses for fraud prevention, questioned the CFPB’s prohibition on charging fees for API access (which they said shifts development costs to data providers), and supported phasing out screen‑scraping. Strickland and others urged that any final approach should vet and impose obligations on data recipients and enable portability that is meaningful for consumers (not forcing them to act as intermediaries to transfer their own records).
No formal votes or committee actions were taken at the hearing. Members said they would submit additional written questions for the record and the chair noted a deadline for witnesses to respond to any submitted questions.
The hearing highlighted both overlap and disagreement: witnesses largely agreed on the value of consumer‑directed data sharing and fraud‑prevention exceptions, but split on whether Congress should enact a sectoral preemption and on the role of private litigation versus agency enforcement. The committee signaled continued attention to how GLBA, state privacy laws and the CFPB’s rule interact, and to refinements — on liability allocation, API cost allocation, and the scope of permitted uses — that stakeholders say are necessary before any statutory overhaul or final rule changes are implemented.
There being no further business, the subcommittee adjourned; members were given five legislative days to submit additional materials for the record and witnesses were asked to reply to written questions by 2025‑07‑10, per the committee’s request.

