{"data":{"id":"us/12-cfr-1033.321","jurisdiction":"us","citation":"12 CFR 1033.321","heading":"Interface access.","body":"(a) Denials related to risk management. A data provider does not violate the general obligation in § 1033.201(a)(1) by denying a consumer or third party access to all elements of the interface described in § 1033.301(a) if:\n(1) Granting access would be inconsistent with policies and procedures reasonably designed to comply with:\n(i) Safety and soundness standards of a prudential regulator, as defined at 12 U.S.C. 5481(24), of the data provider;\n(ii) Information security standards required by section 501 of the Gramm-Leach-Bliley Act, 15 U.S.C. 6801; or\n(iii) Other applicable laws and regulations regarding risk management; and\n(2) The denial is reasonable pursuant to paragraph (b) of this section.\n(b) Requirements for reasonable denials. A denial is reasonable pursuant to paragraph (a)(2) of this section if it is:\n(1) Directly related to a specific risk of which the data provider is aware, such as a failure of a third party to maintain adequate data security; and\n(2) Applied in a consistent and non-discriminatory manner.\n(c) Indicia bearing on reasonable denials. Indicia bearing on the reasonableness of a denial pursuant to paragraph (b) of this section include:\n(1) Whether the denial adheres to a consensus standard related to risk management;\n(2) Whether the denial proceeds from standardized risk management criteria that are available to the third party upon request; and\n(3) Whether the third party has a certification or other identification of fitness to access covered data that is issued or recognized by a recognized standard setter or the CFPB.\n(d) Conditions sufficient to justify a denial. Each of the following is a sufficient basis for denying access to a third party:\n(1) The third party does not present any evidence that its information security practices are adequate to safeguard the covered data; or\n(2) The third party does not make the following information available in both human-readable and machine-readable formats, and readily identifiable to members of the public, meaning the information must be at least as available as it would be on a public website:\n(i) Its legal name and, if applicable, any assumed name it is using while doing business with the consumer;\n(ii) A link to its website;\n(iii) Its Legal Entity Identifier (LEI) that is issued by:\n(A) A utility endorsed by the LEI Regulatory Oversight Committee, or\n(B) A utility endorsed or otherwise governed by the Global LEI Foundation (or any successor thereof) after the Global LEI Foundation assumes operational governance of the global LEI system; and\n(iv) Contact information a data provider can use to inquire about the third party's information security and compliance practices.","path":["Title 12—Banks and Banking","CHAPTER X—CONSUMER FINANCIAL PROTECTION BUREAU","PART 1033—PERSONAL FINANCIAL DATA RIGHTS","Subpart C—Data Provider Interfaces; Responding to Requests"],"source_url":"https://www.ecfr.gov/api/versioner/v1/full/2026-08-25/title-12.xml","current_through":"2026-08-25","vintage":"","retrieved_at":"2026-08-27T02:24:16Z","sha256":"506661d8663ab343ae62782673e0decd60b1c17999495eb7348e57b0e16aa246","source_id":"us-cfr","stale":true,"prev":"us/12-cfr-1033.311","next":"us/12-cfr-1033.331"},"notice":"GroundRules: Original legal text. Not legal advice."}
