Your bank doesn’t own your transaction history. It holds it. Those are different things, and the difference is the entire argument Patrick M. Brenner has decided to skip. In There’s No Such Thing as Free Data at National Review, Brenner argues that the Consumer Financial Protection Bureau’s plan to let consumers take their financial data to a budgeting app or a competing bank is really just a price control forcing banks to give away their infrastructure for free.
The price control argument sounds smart until you ask a simple question: whose data is sitting on those servers?
Let me concede what’s true. APIs cost money to build, secure, and run. Fraud monitoring, authentication, server capacity — none of it is free, and Brenner is right that costs don’t disappear when a regulator says the price is zero. They move somewhere else. And the marginal costs of third-party access — new endpoints, additional server load, fraud surfaces for external firms — are real. This is not make-believe overhead.
But that’s not the right question. The right question is who authorized those costs and who should bear them. The consumer authorized the data sharing. The bank’s job at that point is to comply, and the cost of compliance — like the cost of responding to a subpoena or printing a statement or honoring a wire transfer — is part of being a regulated custodian of other people’s money. The bank doesn’t charge you a separate compliance surcharge every time it has to hand over records to a court. The infrastructure to respond is a cost of holding what isn’t yours.
Brenner treats the infrastructure as the bank’s private asset, like a toll road the bank laid down with its own capital. But the cargo moving through those pipes is your data. You authorized the budget app. You told Chase to hand over the information. The bank’s job at that point is compliance with your instruction, not a commercial negotiation with the fintech about what the toll should be.
Here’s the mechanism. JPMorgan proposed a price. The data aggregators objected. They negotiated and reached a deal. Brenner calls this the free market working, and in a narrow sense he’s right: two firms bargained and settled on a number. But look at what they were bargaining over. They were bargaining over the price of letting you control information that belongs to you. The consumer authorized the data request. The bank responded by saying the consumer’s own authorization is not enough — the fintech needs to pay for the privilege of receiving data the consumer already told the bank to give them.
Call that what it is. Your bank just set up a tollbooth on the road between you and your own file cabinet, and it wants the app to pay before it unlocks the drawer.
Brenner raises a statutory point I should not skip. He argues that Section 1033 of Dodd-Frank never authorized the CFPB to set the price of API access at zero, and a federal judge agreed enough to enjoin the Biden-era rule. Fair reading. But the statute does something more fundamental: it gives the consumer a right to their financial information in a usable electronic form upon request. That is Congress saying the data is yours and the bank must hand it over when you ask. If the bank can charge the party you send to pick it up, the right is not really yours. A toll between the consumer and the data the statute says the consumer can access is a toll on the right itself. You don’t need a separate price-setting clause to see that — you need to read the authorization clause as meaning what it says.
Think of it like the electric company. Your utility built the meter, runs the grid, and bears the cost of keeping the lights on. If you authorize a solar-panel installer to read your usage data to pitch you a better deal, the utility doesn’t get to charge the installer for access to the meter reading. The meter is theirs, the data is yours, and your authorization is the whole ballgame.
Brenner’s fallback is the anticompetitive-conduct concern: a bank might charge fees to block competitors. Fix that case, he says. Don’t nationalize the whole price. It sounds reasonable, but giving the bank the right to charge at all is the anticompetitive lever. The bank holds your transaction history as custodian. It competes with the fintech you authorized. Giving it the right to charge the fintech for access is giving the incumbent a veto over your own switching cost. You don’t fix that by policing individual bad acts after the fact. You fix it by stating the premise clearly: the customer’s data belongs to the customer, and the bank’s job when the customer authorizes access is to hand it over.
The model that already works is the one the CFPB’s rule would extend. Consumers authorize secure access. Banks comply. Fintechs receive the data and bear liability if they misuse it. No tollbooth in the middle because the tollbooth is the problem — it turns your own financial history into a revenue stream your bank can rent back to you.
Let banks build secure pipes. Let fintechs compete on what they do with the data. And let the customer — the person whose money and history and choices live on those servers — walk into the bank, authorize access, and have the bank open the drawer, without standing between you and the app asking what the key is worth.