In JPMorgan’s Data Deal With Plaid, the Giants Cement Their Position
Online services have long had to contend with bot traffic, and your banking app is no exception. While most of us log on to our apps an average of two times every three days (at least according to Bank of America Corp. data), electronic intermediaries that pull data on behalf of third-party services are a lot more aggressive. “Aggregators are accessing customer data multiple times daily, even when the customer is not actively using the app,” a JPMorgan Chase & Co. systems employee wrote in a July memo. “These access requests are massively taxing our systems.”
The JPMorgan memo refers to services provided by platforms such as Plaid Inc., MX and Mastercard Inc.’s Finicity. With customers’ pre-approval, they connect bank accounts to apps offering cash-flow monitoring, payment authentication and other services that rely on individuals’ financial data. Yet in many cases, their demand for information goes beyond a user’s immediate needs. JPMorgan reveals that it was hit with 1.89 billion third-party requests in June, of which only 13% were initiated by a customer – the rest were reportedly to help app developers improve their products or prevent fraud.
Last week, JPMorgan said enough. In a deal with Plaid – which accounted for 57% of intermediary activity in June – the bank agreed to a pricing structure in which it will charge for access. It’s the culmination of a battle Chief Executive Officer Jamie Dimon flagged in his 2024 shareholder letter outlining the bank’s position: “Third parties should pay for accessing the banking system and payment rails; third parties should be restricted from using the customers’ data for purposes beyond what the customer authorized, and they should be liable for the risks they create when accessing and using that data.”
The issue has been festering for some time. Section 1033 of the Dodd-Frank Act, signed way back in 2010, guaranteed customers the right to access their banking data but provided few details on how the process should be governed. A 2024 rule from the Consumer Financial Protection Bureau advanced the initiative, requiring financial providers to transfer data to other providers at the consumer’s request for free, though resistance from banks led to it being withdrawn by the Trump administration. Last month, the agency circled back, seeking feedback on a revised rule that hints at tighter restrictions on the types of company allowed to request data and flexibility for providers to charge fees.