1---2name: cfpb-open-banking-rule-impact3description: Regulatory impact memorandum assessing each existing data sharing agreement against the applicable consumer financial data access and sharing rule, identifying disclosure, authorization, data-use, revocation, deletion, interface, and implementation-gaps across the agreement portfolio.4---56# Skill: CFPB Section 1033 Open Banking Rule Impact on Data Sharing Agreements78## 1. Subject-matter triage910- Treat the assignment as a portfolio review of agreements plus surrounding governance materials, not a single-contract summary.11- Start by sorting the source set into: data sharing agreements, assignment or strategy memo, meeting minutes, and compliance checklist.12- Identify whether each agreement is individually negotiated, renewed automatically, or tied to a broader program so the memorandum can distinguish contract-level fixes from program-level fixes.13- If the source set contains multiple agreements, analyze each agreement separately before drafting any portfolio-level synthesis.1415## 2. Failure modes the skill is correcting1617- Treating the portfolio as broadly compliant or noncompliant without checking each agreement against the governing checklist item by item.18- Missing downstream data-use restrictions by focusing only on initial authorization language and ignoring later internal analytics, onward sharing, marketing, or vendor use.19- Overlooking revocation, deletion, and cessation mechanics after consumer withdrawal of consent.20- Missing periodic reauthorization requirements or allowing indefinite access language to pass unflagged.21- Ignoring disclosure timing defects where authorization terms are buried in general terms rather than presented at or before consent.22- Failing to connect compliance gaps to renewal, amendment, or renegotiation timing that creates practical leverage for remediation.23- Underweighting implementation issues such as developer-interface buildout, engineering planning, budget cycles, and standards alignment.24- Drawing conclusions without tying each legal proposition to the controlling rule or authority that supports it.2526## 3. Legal frameworks / domain conventions that apply2728- Consumer financial data access and sharing rule under Section 1033: use the governing rule to assess access, authorization, disclosure, data-use, revocation, deletion, interface, and implementation requirements.29- Authorization disclosure: verify that the consumer-facing disclosure identifies the data categories, the receiving parties, and the purpose of use with enough specificity to make the consent meaningful.30- Disclosure timing: confirm the disclosure is delivered at or before authorization, not merely incorporated into general account terms or layered into unrelated notices.31- Periodic reauthorization: flag arrangements that permit ongoing or open-ended access without a recurring consumer refresh mechanism when the rule requires one.32- Data-use limitation: test whether internal use, analytics, onward transfers, or other secondary uses exceed the disclosed scope.33- Revocation and deletion: assess whether consumers can revoke authorization and whether the agreement requires prompt cessation, deletion, or equivalent downstream termination steps.34- Developer interface obligations: for covered institutions above the applicable threshold, assess whether a standardized interface must be maintained and whether the implementation timeline is being addressed.35- Standards coordination: where useful, consider engagement with recognized standards bodies or interface frameworks as an implementation aid.36- Contract lifecycle convention: renewal dates, amendment windows, and termination rights are practical leverage points for achieving compliance updates without waiting for a dispute.3738## 4. Analytical scaffolds3940- Build a document inventory first, then map each issue back to the specific agreement, exhibit, checklist item, or meeting-note reference that surfaces it.41- Use a per-agreement review template and apply the same checklist to each item in the portfolio.42- For each agreement, determine:43 - whether the authorization disclosure is specific enough;44 - whether the receiving parties are identified clearly;45 - whether the use purpose is limited to what was disclosed;46 - whether reauthorization is required and built in;47 - whether revocation and deletion rights are operationalized;48 - whether secondary sharing or internal use broadens the permission;49 - whether implementation timing affects compliance;50 - whether renewal or amendment timing creates a practical fix window.51- If one issue implicates more than one source document, explain how the documents interact rather than analyzing them in isolation.52- Where the agreement set contains only one relevant agreement, say so explicitly before proceeding; otherwise enumerate each agreement and analyze each in turn.53- For every issue, state the applicable rule or authority by name and section or part, then identify the deficient term or omission, then state the consequence for compliance or operations.54- For every issue, include an ordinal severity label using one consistent scale across the memorandum; define the scale once at the outset and apply it uniformly.55- For every issue, close the analysis by tying the problem to the source-document facts, the related provision or document, and the practical consequence for the client.56- Distinguish immediate remediation from strategic implementation: some gaps require contract edits now, while others require engineering, policy, or governance work on a longer path.57- If the source materials provide a deadline, milestone, or renewal date, anchor the recommendation to that timing rather than using a generic prompt.5859## 5. Vertical / structural / temporal relationships6061- Disclosure defects often cascade into secondary-use problems: if the authorization is vague about recipients or purposes, later sharing or analytics may sit outside the disclosed scope.62- Revocation, deletion, and cessation obligations should be read together; a paper revocation right without an operational deletion workflow is incomplete.63- Interface compliance depends on internal sequencing: legal interpretation, product specification, engineering resourcing, testing, and launch timing must align.64- Renewal or amendment windows can be more effective than unilateral demands where the counterparty controls the next contract cycle.65- Portfolio-wide remediation should prioritize agreements with the broadest permissions, earliest rollover dates, or the largest implementation gap.66- If multiple documents describe the same arrangement, treat the minutes, memo, and checklist as interpretive context that may narrow or broaden the reading of the operative agreement.6768## 6. Output structure conventions6970- Open with a short executive summary that states the portfolio-level conclusion, the main risk themes, and the recommended remediation posture.71- Include a defined severity scale near the front of the memorandum and use it consistently for each issue.72- Present the body as a per-agreement issue analysis, with one issue entry per discrete compliance gap.73- For each issue entry, include:74 - the agreement or source document;75 - the severity label;76 - the governing rule or authority;77 - the deficient term or omission;78 - the interaction with any related document or clause;79 - the downstream consequence;80 - the recommended fix.81- Include a compact matrix or table that shows, for each agreement, whether the core compliance dimensions are satisfied, uncertain, or deficient.82- Separate immediate compliance actions from strategic implementation considerations.83- End with a Recommended Actions section that assigns each action to a responsible role and ties it to a concrete timing anchor from the source materials or, if none exists, to the next practical regulatory or transactional milestone.84- Keep the memorandum self-contained and written as a regulatory impact analysis, not as a contract summary or a generic policy memo.