{"article":{"id":26586096919063,"url":"https://plaid.zendesk.com/api/v2/help_center/en-us/articles/26586096919063.json","html_url":"https://support.plaid.com/hc/en-us/articles/26586096919063-What-should-I-know-about-Section-1033","author_id":1507745258722,"comments_disabled":true,"draft":false,"promoted":false,"position":0,"vote_sum":0,"vote_count":0,"section_id":15991413068951,"created_at":"2024-09-24T13:18:08Z","updated_at":"2026-06-03T17:44:57Z","name":"What should I know about Section 1033?","title":"What should I know about Section 1033?","source_locale":"en-us","locale":"en-us","outdated":false,"outdated_locales":[],"edited_at":"2026-06-03T17:44:57Z","user_segment_id":null,"permission_group_id":1121774,"content_tag_ids":[],"label_names":[],"body":"<p>The status of the Section 1033 rule is currently in flux. Plaid will enforce any 1033 related requirements as necessary when the rule becomes effective, but at this time is not proactively enforcing 1033-related requirements. As clarity develops on the future of Section 1033, Plaid will provide more information on 1033-related requirements.</p>\n<p>The CFPB has released the final <a href=\"https://www.consumerfinance.gov/about-us/newsroom/cfpb-finalizes-personal-financial-data-rights-rule-to-boost-competition-protect-privacy-and-give-families-more-choice-in-financial-services/\">Section 1033</a> rule for the U.S., which establishes stronger financial data rights for consumers. Section 1033 also introduces new compliance requirements for authorized third parties who access consumer data (i.e. data recipients), such as capturing authorization from the consumer to share their data.</p>\n<h2>FAQs</h2>\n<p><strong>What are the regulatory requirements from Section 1033 that Plaid can help my business with?</strong></p>\n<ol>\n<li>\n<strong>Authorization management:</strong> This requirement governs how consent should be captured, and how often, to maintain access to consumer data. It can be broken down into three parts: initial authorization capture, revocation, and reauthorization.</li>\n<li>\n<strong>Record retention:</strong> Authorized third parties will need to be able to prove that they’re compliant. This includes providing evidence that you are following the authorization management requirements outlined above. Also, you’ll need to show that your data usage is limited only to what Section 1033 permits and that you received consent from the consumer during authorization.</li>\n<li>\n<strong>Onboarding:</strong> Third parties accessing consumer data will need to provide certain company details to data providers to help verify you are a legitimate entity.</li>\n</ol>\n<p>You may also have obligations as a data provider if you offer covered financial accounts. <a href=\"https://plaid.com/resources/compliance/section-1033-data-providers/\">Learn more</a>.</p>\n<p><strong>How can Plaid help my business comply with Section 1033?</strong></p>\n<p>Plaid’s solutions can simplify compliance so you can focus on growing your business. Please review our <a href=\"https://view-su2.highspot.com/viewer/a28391b5577027178f61d40b03f9c466\">readiness guide</a> for a summary of all the solutions available now to help you easily comply with the new regulation.</p>\n<ul>\n<li>\n<strong>Data Transparency Messaging (DTM):</strong> Plaid can <a href=\"https://plaid.com/docs/link/data-transparency-messaging-migration-guide/\">manage authorization capture</a> on your behalf by showing the 1033-required information such as use cases and data scopes in Link for a consumer to review and authorize.</li>\n<li>\n<strong>Compliance Center:</strong> Review and input all your required business details in the <a href=\"https://dashboard.plaid.com/settings/company/compliance?tab=companyProfile\">Compliance Center</a> of the Dashboard. Plaid will provide the information on your behalf to data providers as needed to verify that you’re a legitimate entity.</li>\n<li>\n<strong>Consent Logs:</strong> This is a <a href=\"https://plaid.com/docs/api/consent/\">new API</a> that enables you to access the authorization records for each Item, which can be used to show compliance with 1033’s authorization capture requirements if you were to be audited.</li>\n</ul>\n<p><strong>If my customers are businesses (B2B), is my business expected to comply with Section 1033?</strong></p>\n<p>Section 1033 compliance applies to the data that you may be accessing from personal consumer accounts. While your products and services are for businesses, we often find that businesses like sole proprietors may be connecting their personal accounts to share data with you. In this example, you would be subject to the requirements from Section 1033.</p>\n<h2>Authorization Management</h2>\n<p><strong>What is Data Transparency Messaging and how do I configure it?</strong></p>\n<p>Data Transparency Messaging (DTM) is a feature of Link that can help manage authorization capture on your behalf to help comply with Section 1033. To learn how to configure Data Transparency Messaging, please review our <a href=\"https://plaid.com/docs/link/data-transparency-messaging-migration-guide/?utm_source=p2_product&amp;utm_medium=email&amp;utm_campaign=2024_08_product_us_p2_1033_reminder_customers&amp;utm_term=us&amp;utm_content=data-transparency-messaging-migration-guide\">API docs</a>.</p>\n<p>When DTM is enabled for your traffic, Plaid will show in Link the <a href=\"https://plaid.com/docs/link/data-transparency-messaging-migration-guide/#data-scopes-and-consent\">data scopes</a> and use cases for a consumer to review and authorize. To review and update your use cases, go to the <a href=\"https://dashboard.plaid.com/link/data-transparency-v5\">Plaid Dashboard</a> - navigate to Link Customization and then Data Transparency. You can select up to 3 use cases from the provided list for each Link customization. Data scopes are based on the products you initialize Link with.</p>\n<p><strong>Which countries are available for testing Data Transparency Messaging?</strong></p>\n<p>Data Transparency Messaging is available in both Sandbox and Production for the United States and Canada.</p>\n<p><strong>Are there minimum SDK / client library versions in order to enable Data Transparency Messaging?</strong></p>\n<p>To use the <code style=\"border:none;background:#f1f3f5;padding:1px 4px;border-radius:3px;font-size:0.9em;\">additional_consented_products</code> configuration field, the following minimum client library versions are required:</p>\n<ul>\n<li>Python: 9.3.0</li>\n<li>Node: 10.4.0</li>\n<li>Ruby: 15.5.0</li>\n<li>Java: 11.3.0</li>\n<li>Go: 3.4.0</li>\n</ul>\n<p><strong>Will my conversion rate be impacted by Data Transparency Messaging?</strong></p>\n<p>Plaid has been testing Data Transparency Messaging for two years to ensure a seamless user experience while making it easier for consumers to understand their data sharing. Conversion will vary by customer, but we don’t anticipate significant impact to your conversion. You can test Data Transparency Messaging now to monitor for any impact to conversion before DTM is enabled for your business to assist with the regulatory requirements.</p>\n<p><strong>My business offers multiple products and services: which use cases should I choose for Data Transparency Messaging?</strong></p>\n<p>Plaid has preselected default use cases for customers based on both billable and enabled products. You can view and make changes to your use cases at any time from the <a href=\"https://dashboard.plaid.com/link/data-transparency-v5\">Plaid Dashboard</a>. In general, you should configure DTM to show the use case(s) that the consumer is requesting and the data scopes needed to provide that use case (product/service). If your users are requesting multiple use cases then you can show up to 3 use cases for each Link customization. Please note that more use cases and data scopes will result in a longer disclosure for consumers to review in Link. You can also create separate Link customizations for each use case if you prefer requesting consent separately.</p>\n<p><strong>How will a customer know if an Item requires additional data authorization?</strong></p>\n<p>If a customer wants to pull data from an existing Item that they did not yet obtain consent for, we will return <a href=\"https://plaid.com/docs/errors/invalid-input/#additional_consent_required\"><code style=\"border:none;background:#f1f3f5;padding:1px 4px;border-radius:3px;font-size:0.9em;\">additional_consent_required</code></a>. The customer should put the user through <a href=\"https://plaid.com/docs/link/update-mode/#requesting-additional-consented-products\">update mode</a> to consent to additional data scopes.</p>\n<p><strong>What happens if we add a new Plaid product to access additional data?</strong></p>\n<p>If a consumer has already connected their account and you require additional authorization for other data scopes and/or use cases, you can use <a href=\"https://plaid.com/docs/link/update-mode/#requesting-additional-consented-products\">update mode</a> to obtain and capture authorization.</p>\n<p>To see the currently authorized and consented products on an Item, first use the <a href=\"https://plaid.com/docs/api/items/#itemget\"><code style=\"border:none;background:#f1f3f5;padding:1px 4px;border-radius:3px;font-size:0.9em;\">/item/get</code></a> endpoint. If the Item does not have consent for the desired product, create a Link token for update mode with the <code style=\"border:none;background:#f1f3f5;padding:1px 4px;border-radius:3px;font-size:0.9em;\">link_customization_name</code> field set to a customization with <a href=\"https://plaid.com/docs/link/data-transparency-messaging-migration-guide/\">Data Transparency Messaging</a> enabled.</p>\n<p><strong>What Plaid products are covered and which are not covered by Data Transparency Messaging?</strong></p>\n<p>Section 1033 requirements apply to all Plaid products that require Plaid to access data from a Regulation E account, Regulation Z credit card, or an account that facilitates payments from a Regulation E account or Regulation Z credit card. This includes Auth, Balance, Identity, Transactions, Assets, and more. The following Plaid products are excluded from the 1033 requirements:</p>\n<ul>\n<li><a href=\"https://plaid.com/products/identity-verification/\">Identity Verification</a></li>\n<li><a href=\"https://plaid.com/products/monitor/\">Monitor</a></li>\n<li><a href=\"https://plaid.com/docs/income/bank-income/\">Payroll Income</a></li>\n<li><a href=\"https://plaid.com/docs/income/document-income/\">Document Income</a></li>\n<li><a href=\"https://plaid.com/products/enrich/\">Enrich</a></li>\n<li>\n<a href=\"https://plaid.com/docs/payment-initiation/\">Payment Initiation</a> (Europe only)</li>\n<li>\n<a href=\"https://plaid.com/docs/payment-initiation/variable-recurring-payments/\">Variable Recurring Payments</a> (UK only)</li>\n</ul>\n<p><strong>Am I able to manage Data Transparency Messaging myself after it has been enabled by Plaid?</strong></p>\n<p>Once Data Transparency Messaging is enabled for your business to assist with the regulatory requirements, you will not be able to disable it from the Plaid Dashboard. However, you can update your <a href=\"https://dashboard.plaid.com/link/data-transparency-v5\">use cases</a> at any time.</p>\n<p><strong>Is it required to use update mode for capturing reauthorization every 12 months?</strong></p>\n<p>Using <a href=\"https://plaid.com/docs/link/update-mode/#requesting-additional-consented-products\">update mode</a> is not required, but we recommend integrating with it to provide a seamless experience for reauthorization. Update mode can be used to add permissions to Items, or to resolve <code style=\"border:none;background:#f1f3f5;padding:1px 4px;border-radius:3px;font-size:0.9em;\">ITEM_LOGIN_REQUIRED</code> status. For reauthorization, Plaid will consolidate all of the elements of authorization into one screen for the consumer to review and reauthorize. Some institutions will require consumers to reconnect their accounts using OAuth for reauthorization.</p>\n<p>Note that 12-month reauthorization is not a blanket Plaid behavior today. Specific US institutions (American Express, Bank of America, Capital One, Citibank, and others) enforce 12-month consent windows on their own data-sharing requirements; the 1033 rule, once enforced, would extend this as a regulatory baseline.</p>\n<p>To track Items approaching disconnection, integrate the <a href=\"https://plaid.com/docs/api/items/#pending_disconnect\"><code style=\"border:none;background:#f1f3f5;padding:1px 4px;border-radius:3px;font-size:0.9em;\">PENDING_DISCONNECT</code></a> webhook, which fires when an Item is expected to be disconnected (roughly 7 days before disconnection for US Items). For European institutions on PSD2 consent windows, listen for <a href=\"https://plaid.com/docs/api/items/#pending_expiration\"><code style=\"border:none;background:#f1f3f5;padding:1px 4px;border-radius:3px;font-size:0.9em;\">PENDING_EXPIRATION</code></a> instead.</p>\n<p><strong>Will there be a way to track when consent is scheduled to expire for an Item?</strong></p>\n<p>The <a href=\"https://plaid.com/docs/api/items/#item-get-response-item-consent-expiration-time\"><code style=\"border:none;background:#f1f3f5;padding:1px 4px;border-radius:3px;font-size:0.9em;\">consent_expiration_time</code></a> field will track when consent is scheduled to expire. Currently, this field is only populated for institutions in Europe and a small number of US institutions; for all others, it returns <code style=\"border:none;background:#f1f3f5;padding:1px 4px;border-radius:3px;font-size:0.9em;\">null</code>.</p>\n<p><strong>If a consumer revokes access to their data or their consent expires after 12 months, do I have to delete their data from my systems?</strong></p>\n<p>There is a general obligation to not retain the data, but there are some exceptions. We recommend consulting with your legal team to determine when you are required to delete data and when any of the exceptions apply to you.</p>\n<p><strong>If I have a consumer’s account and routing number to use for facilitating payments, will reauthorization apply to my business and my use case?</strong></p>\n<p>1033 says that after consent expiration, unless reauthorization is obtained, authorized parties may no longer use or retain covered data that was previously collected pursuant to the most recent authorization, unless use or retention of that covered data remains reasonably necessary to provide the consumer's requested product or service.</p>\n<h2>Record Retention</h2>\n<p><strong>How can I obtain a record of my customers’ authorizations?</strong></p>\n<p>With Plaid’s consent logs, you can retrieve a history of the authorizations for your customers which can be used for audit purposes. See our <a href=\"https://plaid.com/docs/api/consent/\">API docs</a> to learn more.</p>\n<h2>Onboarding</h2>\n<p><strong>How do I review if I have any missing business information that is required under Section 1033?</strong></p>\n<p>Plaid’s <a href=\"https://dashboard.plaid.com/settings/company/compliance?tab=companyProfile\">Compliance Center</a> in the Dashboard allows you to review and fill in any missing business information that is required under 1033, such as legal entity name, contact information (email), website URL, and your Legal Entity Identifier (LEI). Once the information is complete, Plaid will share it on the behalf of our customers with data providers as needed to enable data access.</p>\n<p><strong>What is a Legal Entity Identifier (LEI) and do all businesses need to obtain one?</strong></p>\n<p>Legal Entity Identifier (LEI) is a 20-digit alphanumeric code that is used across markets and jurisdictions to uniquely identify a legally distinct entity. The 1033 rule, once enforced, would require third parties to register for and provide an LEI, with data providers able to deny access to those that don't. <strong>As of today, given the uncertain status of 1033 enforcement (see top of this article), there is no active LEI requirement.</strong> Businesses that want to register proactively can follow the steps below.</p>\n<p><strong>How do I register for a Legal Entity Identifier (LEI)?</strong></p>\n<p>Follow these steps to obtain your LEI:</p>\n<ul>\n<li>Visit <a href=\"https://www.gleif.org/organizational-identity/get-an-lei-find-lei-issuing-organizations/\">www.gleif.org</a> and scroll to the bottom of the page.</li>\n<li>Look up country (USA) and select a LOUs/Registration Agent. For example, choose Bloomberg Finance L.P.</li>\n<li>Sign up for a Bloomberg account by completing all required fields.</li>\n<li>Sign into Bloomberg account with credentials.</li>\n<li>Complete 2FA via email.</li>\n<li>Once logged in, choose to complete via web form or Excel workbook.</li>\n<li>If web form, complete required fields to submit application.</li>\n<li>Pay $60 for registration ($40 annual renewal).</li>\n</ul>\n<p>Once you have your LEI, please provide it to Plaid in the <a href=\"https://dashboard.plaid.com/settings/company/compliance?tab=companyProfile\">Compliance Center</a> of the Dashboard (under the Company Profile tab).</p>","user_segment_ids":[]}}