Is Open Banking Safe? Protections, Risks, and Liability

Open banking is safe enough for most people to use with reasonable confidence, and in important ways it is safer than the older method of handing a budgeting app your bank username and password. Your login stays with your bank, the connection is encrypted, and federal law caps your liability on unauthorized transfers from personal accounts if you report them promptly. The real risks sit at the edges: the third-party app or data aggregator holding a copy of your transaction data, gaps in the consumer-protection rules for business accounts, and a key CFPB rule whose enforcement is currently on hold.

Why the Connection Itself Is Safer Than It Used to Be

Older budgeting tools relied on screen scraping. You gave the app your bank username and password, and it logged in as you to pull data. That gave the third party the same full access to your account that you have, so any breach at the app exposed your credentials directly.

Open banking replaces that with an Application Programming Interface (API). Your credentials stay with your bank. The bank verifies you, then passes only the specific data the app requested — a balance, a transaction list — through a structured channel. Data moves under Transport Layer Security, the same encryption protocol behind any “https” website, and is typically encrypted at rest on the provider’s servers as well.

Two consequences follow. If the app is breached, attackers get transaction data, not the keys to log in as you and move money. And because most banks now require a second factor — a text code, a biometric check, a push notification — before an API connection is authorized, someone who has stolen your password alone still cannot attach your account to a new service.

The CFPB’s Personal Financial Data Rights rule, finalized in November 2024, treats screen scraping as insufficient and pushes the market toward API access.1Federal Register. Required Rulemaking on Personal Financial Data Rights Some providers may still fall back on credential-based access where an API is not available, so it is worth checking how a specific app connects before signing up.

What Actually Protects You Right Now

Two federal laws are already doing the work, regardless of what happens with the newer CFPB rule.

The Gramm-Leach-Bliley Act requires every financial institution to maintain administrative, technical, and physical safeguards for customer records, to guard against anticipated threats, and to prevent unauthorized access that could cause substantial harm.2SEC. Gramm-Leach-Bliley Act Third parties reaching your data through open banking are generally expected to meet the same standard.

The Electronic Fund Transfer Act, implemented through Regulation E, caps your liability for unauthorized electronic transfers from personal accounts. That cap is the single most important consumer protection in this area, and it is covered in detail below.

The CFPB’s Section 1033 rule would add more: hard limits on how third parties use your data, mandatory disclosures naming any data aggregator involved, and one-year authorization windows. But a federal court in the Eastern District of Kentucky stayed the rule’s compliance deadlines after the CFPB announced it would reconsider the rule, and the agency plans to issue a new proposal extending those dates.3Federal Register. Personal Financial Data Rights Reconsideration For now, treat the rule’s protections as promised rather than enforceable.

Where the Real Risks Sit

Most of the exposure in open banking is not at your bank. It is at the companies sitting between your bank and the app.

In most cases, the app you use does not connect directly to your bank. A data aggregator — Plaid, Finicity, and similar services — maintains API connections with thousands of institutions and reformats your data for the app.4Federal Reserve Bank of Kansas City. Data Aggregators: The Connective Tissue for Open Banking Your data passes through an additional company before reaching the app, and that company holds records of what it moved.

Under the CFPB’s finalized framework, aggregators would have to certify to you that they follow the same data-use restrictions as the app itself, and the aggregator’s name and role would have to appear in the authorization disclosure you see.5Consumer Financial Protection Bureau. Regulation 1033.431 – Use of Data Aggregator The rule also draws a hard line against three secondary uses of your data: targeted advertising, cross-selling the app’s other products, and selling the data to anyone else.1Federal Register. Required Rulemaking on Personal Financial Data Rights Until the compliance dates land, those limits are not enforceable, so the app’s own privacy policy is what governs what happens to your data.

One way to gauge a provider’s security posture before you connect is to check whether it holds a current SOC 2 report. Developed by the American Institute of Certified Public Accountants, a SOC 2 evaluates a company’s controls for security, availability, processing integrity, confidentiality, and privacy. Reputable aggregators and apps publish or share these on request.

Your Liability If an Unauthorized Transfer Happens

For personal accounts, Regulation E caps what you can be forced to eat when someone moves money without your permission. The cap depends on how fast you report:

  • Report within two business days of learning about the problem, and your liability is limited to $50 or the total unauthorized amount, whichever is less.
  • Report after two business days but within 60 days of the statement date, and your liability can rise to as much as $500 for the transfers that occurred after the two-day window.
  • Wait more than 60 days after the statement date, and there is no cap on transfers that occurred after that 60-day window.

The clock runs from when the bank sends the periodic statement showing the unauthorized transfer, not from when the transfer happened.6eCFR. 12 CFR 1005.6 – Liability of Consumer for Unauthorized Transfers Once you report, the bank must investigate and reach a determination within 10 business days, or provisionally credit your account and take up to 45 days.7Consumer Financial Protection Bureau. Regulation E – 1005.11 Procedures for Resolving Errors

Business Accounts Do Not Get These Caps

Regulation E defines a consumer as a natural person and covers only accounts held primarily for personal, family, or household purposes. Business accounts are excluded.6eCFR. 12 CFR 1005.6 – Liability of Consumer for Unauthorized Transfers

Commercial transfers fall under Article 4A of the Uniform Commercial Code instead. If your bank followed commercially reasonable security procedures and accepted a payment order in good faith, the loss from an unauthorized transfer can land on the business, even where the business did not authorize it. The specific allocation depends on your account agreement. If you connect a business account to any open banking service, read that agreement, look closely at how security procedures and liability are described, and consider whether additional insurance is appropriate.

How to Reduce Risk Before You Connect

Read the authorization screen before you tap through it. It should identify the third party and any data aggregator, list exactly what data will be accessed, explain the purpose, and state how long access lasts. Where the screen lets you narrow what is shared — say, balances but not transaction detail — narrow it.

Under the CFPB’s framework, authorizations would last no longer than one year and would require a fresh authorization to continue. Even outside that rule, most banks now maintain a screen inside their app or website where you can see every active third-party connection and disconnect any of them instantly. Check that screen periodically. Disconnect anything you no longer use. Revoking access stops the flow of new data; under the CFPB’s rule, it would also require the third party to stop retaining previously collected data unless retention is still reasonably necessary for a service you use.

Turn on multi-factor authentication at your bank if it is not already the default, and use a unique password there. The API model protects your credentials from the app, but your credentials still matter for every other way someone might try to reach your account.

What to Do If Something Goes Wrong

If you see a transaction you did not make, or you learn that a third-party app or aggregator has been breached, move quickly.

  • Contact your bank first, and ask for written confirmation of your report with the date and time. The sooner you report, the lower your Regulation E liability.
  • Revoke the third-party connection through your bank’s app or website. This stops any further data sharing.
  • Check every account, not just the one linked to the app, for other unauthorized activity.
  • If personal information was exposed, file a report at IdentityTheft.gov to generate a recovery plan and a formal FTC Identity Theft Report, which helps in disputing fraudulent accounts.8Federal Trade Commission. IdentityTheft.gov
  • Save copies of everything: correspondence with the bank, notices from the app, any police or FTC filings. If a reimbursement dispute follows, documentation of prompt reporting is what protects you.

A credit freeze at the major bureaus can stop someone from opening new accounts in your name, but it does not sever open banking connections; those are account-level data flows, not credit inquiries. Freeze your credit anyway after a breach, and revoke the specific connection to shut the data channel.

Most states require companies to notify affected residents within 30 to 60 days of discovering a data breach, so if an app or aggregator holding your data is compromised, you should hear about it. That notice is the trigger to start working through the steps above.