Bank data & compliance
Consumer-Permissioned Data: Definition & Example

What Is Consumer-Permissioned Data?
Consumer-permissioned data is financial information a consumer actively authorizes a third party to access, such as bank transactions shared through an open banking connection.
What does consumer-permissioned data mean?
The consumer chooses which institution and accounts to connect, sees what data will be shared and for what purpose, and approves the connection. That is different from data that a bureau collects about a consumer without their direct involvement.
Consumer-permissioned data is the foundation of open banking and cash-flow underwriting. The CFPB’s Section 1033 rulemaking addresses how authorized third parties may collect, use, and retain this data and how consumers can revoke access.
Permissioned access should be limited to what is needed for the stated purpose, and good practice is to keep data only as long as necessary.
Consumer-permissioned data example
A tenant applying for an apartment is asked to connect her bank. The consent screen explains that the service will read her account balances and 12 months of transactions to estimate income and share a report with the property manager. She approves, and the access ends after the report is generated.
Related terms
- Open BankingOpen banking is the practice of letting consumers securely share their bank account data, such as balances and transactions, with third-party apps and services they choose, usually through APIs.
- Section 1033Section 1033 of the Dodd-Frank Act gives consumers a right to access their own financial account data. The CFPB’s rule implementing it sets requirements for sharing that data with authorized third parties.
- Read-Only Bank ConnectionA read-only bank connection lets an app view account data, such as balances and transactions, without being able to move money, make payments, or change anything in the account.
- Alternative DataAlternative data is information used to evaluate applicants that is not in a traditional credit report, such as bank account cash flow, rent and utility payments, and employment or education records.
- Gramm-Leach-Bliley ActThe Gramm-Leach-Bliley Act (GLBA) is a 1999 federal law that requires financial institutions to explain how they share customers’ nonpublic personal information and to safeguard that information.





