Skip to main content

New York's Financial Data Rights Act: What State-Level Open Banking Means for Small Businesses

8 min readMike ThriftMike Thrift
New York's Financial Data Rights Act: What State-Level Open Banking Means for Small Businesses

If you've ever spent an afternoon exporting CSV files from your bank because your accounting software's "auto-sync" quietly broke again, you already understand the problem New York lawmakers are trying to solve. Two companion bills moving through the state legislature — Assembly Bill A10640 and Senate Bill S9483, together called the New York Financial Data Rights Act — would be the first state law in the country to give small businesses, not just individual consumers, a legal right to their own bank data in a usable, machine-readable format, for free.

That might sound like a niche regulatory footnote. It isn't. If you run a small business and rely on any accounting software that connects to your bank account — QuickBooks, Xero, Wave, FreshBooks, or a plain-text ledger fed by exported statements — this bill touches the plumbing underneath almost every financial tool you use.

Why This Bill Exists Right Now

For the past few years, the federal Consumer Financial Protection Bureau has been the primary body trying to guarantee "open banking" rights under Section 1033 of the Dodd-Frank Act — the rule requiring banks to share customer financial data with authorized third parties on request. That federal rule is currently stuck. A Kentucky federal court injunction has left it codified on paper but effectively unenforceable, and the CFPB is simultaneously fighting litigation while working on a revised version of the rule.

New York's legislature decided not to wait. Introduced in March 2026 by Assemblyman Clyde Vanel (chair of the Assembly Banks Committee) and Senator Rachel May (chair of the Senate Consumer Protection Committee), A10640 and S9483 would create a state-level backstop while the federal rule sits in limbo. Industry groups on the fintech side, including the Financial Data and Technology Association and the Financial Technology Association, have already publicly praised the bills.

The bigger story here isn't really about New York. It's about what happens if New York succeeds: other states copying the model, creating a patchwork of different data-access rules that banks and fintech vendors have to comply with state by state — the same pattern that played out with data privacy laws after California's CCPA.

What the Bill Would Actually Require

Strip away the legislative language and the New York Financial Data Rights Act boils down to four concrete obligations for banks and credit unions operating in the state:

1. A Free, Machine-Readable Data Interface

Financial institutions would have to give small businesses (and consumers) access to "covered data" — transaction history, account balances, payment information, account terms, billing data, and identity verification details — in an electronic, machine-readable format. Critically, the bill prohibits charging any fee, directly or indirectly, for accessing or transferring that data.

2. A Standing "Developer Interface"

Banks would need to maintain an actual API — what the bill calls a "developer interface" — built to receive and respond to data requests, secured to the same authentication standard as their consumer online banking systems. This is the mechanism that would let accounting software pull your transactions automatically instead of you exporting and re-uploading a statement every month.

3. No Unreasonable Denials

The bill bars banks from unreasonably denying a data-access request without a documented, risk-based justification. This matters because banks have occasionally throttled or blocked data-aggregator connections (the tools that power your accounting software's "bank feed") citing vague security concerns, sometimes right when a business needs reconciliation data the most.

4. Real Penalties

Violations carry civil penalties of up to $10,000 each — a meaningful deterrent for an institution processing millions of data requests, and a signal that this isn't just a toothless disclosure requirement.

The Small Business Detail Everyone's Missing

Here's the part that separates this from the federal rule: Section 1033 was written with individual consumers in mind. New York's bill explicitly extends the same rights to small businesses. That's a deliberate, and fairly unusual, choice.

Small business owners have long been treated as an afterthought in financial data-rights conversations, even though they depend on clean, timely bank data at least as much as individual consumers — arguably more, since a broken bank feed doesn't just mean a missed budget alert, it means a bookkeeper reconciling blind, a loan application missing current statements, or a tax filing built on stale numbers.

If New York's bill becomes law, a business banking at a covered institution would have an enforceable right to pull 24+ months of transaction history into whatever software it chooses, without paying the bank a fee for the privilege, and without the bank being able to quietly kill that connection.

Why Your Bank Feed Keeps Breaking (And What This Would Fix)

Most small business accounting tools don't connect directly to your bank. They go through data aggregators — companies like Plaid or Yodlee that sit between your bank and your software, using either a licensed API connection or, in older and messier setups, screen-scraping (logging into your bank's website as if they were you, on a schedule, to grab your transaction data).

Screen scraping is fragile by design: any redesign of your bank's login page, any added security step, any rate-limiting change can silently break the connection. You often don't notice until your books are three weeks out of date. Interestingly, the New York bill doesn't ban screen-scraping outright — it focuses on requiring the API alternative to exist and to be free — but a mandated, standardized developer interface would give aggregators (and by extension your accounting software) a far more reliable path than scraping ever was.

What Happens Next

As of this writing, both bills remain in committee — the Assembly version in the Banks Committee, the Senate version also in Banks Committee — with no floor vote scheduled. Bills introduced in New York's legislature can sit in committee for a full two-year session before either advancing or dying, so there's no guarantee this becomes law in 2026, or even in this legislative session.

But regardless of the bill's fate, the direction is worth watching for three reasons:

  1. It fills a real gap. Federal open banking rules for businesses are stalled, and states have historically been the ones to move first on financial data and privacy issues when Washington stalls (data breach notification laws are the clearest precedent).
  2. New York carries outsized weight. As a major financial center, a New York banking-law change tends to get noticed — and sometimes copied — well beyond its borders.
  3. The fee ban is the sharpest part. Prohibiting banks from charging for data access or transfer, even indirectly, would remove a friction point that has occasionally shown up as a line item in accounting-software or aggregator pricing.

What Small Business Owners Should Do Now

You don't need to wait for New York — or any state — to pass a law to protect yourself against unreliable bank connectivity. A few practical habits apply whether or not this bill ever reaches a floor vote:

  • Don't rely on a single connection method. If your accounting software's bank feed breaks, know how to export a CSV or OFX file directly from your bank's website as a fallback, and do a quick reconciliation check monthly rather than discovering a three-month gap at tax time.
  • Ask your bank directly about API access. Many banks, especially larger ones, already offer developer/API access for business accounts even without a legal mandate — some just don't advertise it well.
  • Keep a locally-owned record, not just a live feed. A bank feed is a convenience, not a source of truth. Whatever system you use to categorize and reconcile transactions should be able to survive a broken connection without losing historical data.
  • Watch for state-level guidance, not just headlines. If you operate in New York or a state that follows its lead, keep an eye on your bank's own compliance notices — that's usually where practical changes (new download formats, new authentication flows for data-sharing) show up before they hit the news.

Clean Records Matter More Than Which App Feeds Them

Whether your bank data arrives through a free API mandated by state law, a paid aggregator, or a CSV you download by hand, the actual value is in what happens after the data lands: accurate categorization, timely reconciliation, and records you can actually audit when a lender, investor, or the IRS asks for them. Bank connectivity fights are ultimately a plumbing question — the bookkeeping discipline on top of it is what protects you either way.

That's part of why plain-text accounting has found a following among small business owners who've been burned by black-box software changes they didn't choose. When your ledger is a version-controlled text file instead of a proprietary database locked behind one vendor's bank-feed reliability, a broken connection or a fee dispute with an aggregator is an inconvenience, not a crisis — your historical records stay exactly where you put them.

Simplify Your Financial Management

As open banking rules continue to shift between federal limbo and state-level experiments like New York's, the businesses that come out ahead will be the ones with clean, portable financial records regardless of which pipe the data flows through. Beancount.io offers plain-text accounting that's transparent, version-controlled, and AI-ready — your ledger stays yours no matter what any bank, aggregator, or legislature decides next. Get started for free and see the documentation for how it handles bank imports and reconciliation.

Share this article