Framework for the Future: Reviewing Data Privacy in Today's Financial System

Digital Assets and Bank RegulationHouse Financial Services Subcommittee on Financial Institutions · 2025-06-05 · 119th Congress
The House Financial Services Subcommittee on Financial Institutions held this hearing to examine whether the Gramm-Leach-Bliley Act (GLBA), enacted more than 25 years ago, still adequately protects consumer financial data amid open banking, fintech partnerships, artificial intelligence, and a growing patchwork of state privacy laws. Begins at 0:13:31
Transcript
Highlights

Title

Modernizing Financial Data Privacy Law and the Future of Open Banking

Purpose

The House Financial Services Subcommittee on Financial Institutions held this hearing to examine whether the Gramm-Leach-Bliley Act (GLBA), enacted more than 25 years ago, still adequately protects consumer financial data amid open banking, fintech partnerships, artificial intelligence, and a growing patchwork of state privacy laws. Witnesses from industry, a credit union trade group, a former FTC official, and privacy researchers testified on GLBA modernization, federal preemption, private rights of action, and the CFPB's contested Section 1033 open banking rule. Much of the debate centered on the Trump administration CFPB's move to rescind that rule and on Elon Musk/DOGE access to federal data. Begins at0:13:31

Who spoke

Chairman Andy Barr (R-KY)0:13:31: Opened the hearing, framed GLBA as needing review given open banking and AI0:15:14, and argued for a uniform national privacy standard with GLBA preemption and no private right of action0:16:590:17:47.

Rep. Bill Foster (D-IL), Ranking Member0:18:13: Praised the CFPB's October Section 1033 open banking rule as a bipartisan, multi-administration achievement0:19:07; announced a letter with 12 colleagues urging Acting Director Vought not to rescind the rule0:20:00; criticized DOGE's access to Social Security, Treasury, HHS, and CFPB data0:20:53; later pressed on the administration's court argument that Section 1033 excludes third-party agents0:59:14.

Chairman French Hill (R-AR), Full Committee0:21:19: Said GLBA has "kept pace" reasonably well but called for modernized, tailored legislation from committee Republicans0:21:41.

Rep. Maxine Waters (D-CA), Ranking Member, Full Committee0:22:33: Accused Republicans of ignoring DOGE's access to Americans' data and criticized the administration for vacating the CFPB's open banking rule0:23:00.

Scott Talbott, Electronic Transactions Association0:24:47: Said the industry processed over $11 trillion in payments last year0:25:17; urged a uniform national standard, permissible data use for fraud prevention0:28:04, and cited California's data-level (not entity-level) GLBA exemption as a compliance conflict0:26:401:31:07.

Andrew Morris, America's Credit Unions0:29:53: Called for an entity-level GLBA exemption for credit unions0:31:43, preservation of the opt-out framework0:33:02, and limits on private rights of action0:33:28; later flagged API development costs and lack of third-party liability allocation under the 1033 rule1:18:572:00:05.

Rebecca Kuehn, Hudson Cook LLP (former FTC assistant director)0:34:23: Explained GLBA's opt-out and notice-exception structure0:35:140:36:33; criticized the CFPB's proposed data broker rule for conflating regulated GLBA data sharing with bad-actor misuse0:37:210:37:45.

Jennifer Huddleston, Cato Institute0:38:51: Said financial data is already regulated by GLBA and FCRA0:40:15; warned that a state patchwork (19+ states) and private rights of action deter innovation, citing Illinois's Biometric Information Privacy Act litigation against Meta and Six Flags0:42:120:42:22.

Zoë Strickland, Future of Privacy Forum0:44:12: Described benefits and challenges of an omnibus federal privacy law0:44:530:45:14; supported open banking but flagged the 1033 rule's misses on secondary data use, deidentified data, and fraud liability0:48:031:28:53.

Rep. Bill Huizenga (R-MI)0:59:59: Asked how to balance consumer protection against excessive compliance burdens on small providers1:00:40 and whether GLBA's "financial institution" definition is broad enough1:02:05.

Rep. David Scott (D-GA)1:05:17: Warned that rescinding Section 1033 would harm consumers and cited the rule's provisions barring data broker monetization without consent1:06:121:06:37.

Rep. Roger Williams (R-TX)1:10:17: Asked how to preserve bank-fintech data sharing partnerships for smaller institutions and rural access1:11:071:13:21.

Rep. Brad Sherman (D-CA)1:14:45: Argued hacking liability should fall on whichever party could have prevented the breach1:15:37; asked about banning screen scraping and allowing smaller institutions to charge fintechs API fees1:18:04.

Rep. Barry Loudermilk (R-GA)1:20:12: Argued the federal government, not Elon Musk personally, is the biggest data security risk given its own weak protections1:20:331:21:00.

Rep. Juan Vargas (D-CA)1:24:45: Said the government holds too much data and protects it poorly, including airport biometric collection1:25:17; asked why the 2024 Section 1033 rule had bipartisan support1:27:33.

Rep. John Rose (R-TN)1:29:59: Asked Talbott to detail conflicting state privacy laws, citing California's B2B carve-out gap1:30:231:31:07; asked about credit unions' and ETA members' data-security investment levels, cited in the "billions"1:33:521:34:12.

Rep. Sean Casten (D-IL)1:35:18: Asked how the 1033 rule would boost competition1:35:48 and raised concerns that AI liability shields in recent House-passed legislation could let companies evade accountability for misused data1:39:30.

Rep. William Timmons (R-SC)1:40:29: Highlighted California's opt-in standard versus states like Alabama aligning with the federal floor, asking about compliance burdens for smaller institutions1:41:031:42:32.

Rep. Mike Flood (R-NE)2:15:04: Walked through the many parties involved in a mortgage application to illustrate data-sharing complexity2:15:32; argued this is one of the few areas warranting a national standard over states' rights2:19:11.

Rep. Emilia Sykes / "Miss Batty" (Ohio)1:45:43: Asked about consumer harm if third-party data sharing tools are restricted1:46:14 and about her mentor-protégé bill for small financial institutions1:47:52.

Rep. Young Kim (R-CA)1:51:03: Asked about dual state-federal compliance burdens under California's privacy laws and outdated GLBA annual privacy notices, last revised roughly 15 years ago1:56:10.

Rep. Cleo Fields (D-LA)1:56:37: Asked how blocked data portability harms lower-income families using free financial tools and how Section 1033 addresses equity1:57:09.

Rep. Scott Fitzgerald (R-WI)2:01:03: Asked how a federal private right of action for data privacy would affect credit unions, warning of Illinois- and California-style litigation waves2:02:16.

Rep. Al Green (D-TX)2:04:57: Discussed his bill HR 3716, the Systemic Risk Authority Transparency Act, requiring GAO and bank regulator reports after invocation of the systemic risk exception, following the 2023 failures of Silicon Valley Bank and Signature Bank2:06:322:06:53.

Rep. Warren Davidson (R-OH)2:10:08: Argued privacy should be settled before AI regulation2:10:55; cited Google's Android "do not track" geolocation tracking fine and Wells Fargo's $4 billion fine for fake accounts as examples of inadequate accountability2:14:042:14:34.

Key moments

Foster revealed he led 12 committee Democrats in a letter to Acting CFPB Director Russell Vought opposing full rescission of the Section 1033 rule, urging targeted amendments instead0:20:00.

Waters and Foster tied the hearing to DOGE's access to Social Security, Treasury, HHS, and CFPB data under Elon Musk, calling it a bigger privacy threat than anything GLBA addresses0:20:530:23:00.

Talbott said 8 of nearly two dozen state privacy laws took effect in 2025 alone, and detailed how California treats bank-to-business (B2B) data as covered while federal law exempts it0:26:402:17:20.

Kuehn said enforcement history shows few actual cases brought under GLBA despite active regulatory oversight, arguing this undercuts the case for adding a private right of action0:52:130:53:06.

Talbott disclosed the CFPB's 1033 open banking rule left fraud/breach liability unaddressed and barred financial institutions from charging fees for API access — two "misses" cited repeatedly by witnesses0:50:380:50:58.

Foster confronted witnesses with the Trump CFPB's court brief argument (filed the preceding Friday) that Section 1033 covers only consumers themselves, not third-party agents — despite statutory language including "an agent, trustee or representative acting on behalf of the individual"0:59:140:59:45.

Huddleston cited Illinois's Biometric Information Privacy Act as generating major litigation against companies including Meta and Six Flags Amusement Park, largely over technical violations rather than proven harm0:42:222:18:43.

Strickland detailed unresolved 1033 rule gaps: no allowance for consumer-authorized secondary data use, no clear deidentified-data standard, and insufficient fraud/liability monitoring1:28:531:29:29.

Rose established through questioning that no witness could identify a case where complying with one state's privacy law would actually violate another state's law — conflicts arise mainly on implementation and cost, not direct legal contradiction1:31:361:32:22.

Casten highlighted that AI liability-shield language in legislation the House passed the prior week could let companies claiming an "algorithm" caused a privacy violation escape accountability, a concern Strickland was asked but ran out of time to fully address1:39:301:39:59.

Metadata

CommitteeHouse Financial Services Subcommittee on Financial Institutions
Chamber / CongressHouse · 119th Congress
Date2025-06-05
TypeHearing
Witnesses
Ms. Rebecca Kuehn — Partner, Hudson Cook, LLP
Ms. Zoë Strickland — Senior Fellow, Future of Privacy Forum (FPF)
Ms. Jennifer Huddleston — Fellow in Technology Policy, Cato Institute
Mr. Scott Talbott — Executive Vice President, Electronic Transactions Association
Mr. Andrew Morris — Director of Innovation and Technology, America's Credit Unions (ACU)
Videoyoutube
Transcript293 caption blocks · 20,942 words · 2:20:34 runtime
EventCongress.gov 118324