Chase announced on September 25, 2026 that it has begun rolling out the Chase Data Security Center inside the Chase Mobile app. The hub shows customers which outside apps are connected to their accounts and what those apps can see. It also lets them cut the connections off. Chase serves 87 million consumers and 7.5 million small businesses. The feature is arriving in phases, and the release does not say who gets it first.
Melissa Feldsher, head of payments, trust and security and open banking at Chase, framed the launch around visibility. “Customers should be in control of their financial data,” she said. Chase is not cutting off third-party access. It is trying to make an existing web of connections readable to the people whose data moves through it.
What the Chase Data Security Center Does
Through the new hub, customers can view every app connected to their accounts and review what data is shared and how often. They can manage individual app permissions and adjust how long an app keeps access. They can choose which eligible accounts an app can see, or unlink a connection entirely. Chase has added plain-language education and FAQs. Many customers may not realize a budgeting or lending app has standing access to their transaction history.
Not all of this is new. Chase already offered some account-linking controls in its app. The Chase Data Security Center puts those controls in one dedicated place, with clearer explanations. Before, they were spread across settings screens most customers never open.
For now, the Chase Data Security Center is a consumer feature. Chase’s 7.5 million small business customers appear only in the release boilerplate, with nothing said about extending the hub to them.
Why This Is Landing Now, With Washington Stalled
Timing matters here. The Consumer Financial Protection Bureau finalized its Section 1033 personal financial data rights rule in October 2024. The rule was meant to make banks provide secure, standardized data access to authorized third parties. Banks sued in the Eastern District of Kentucky, in Forcht Bank v. CFPB, and in 2025 the bureau itself acknowledged the rule was unlawful.
The CFPB opened a reconsideration with an advance notice in August 2025. On October 29, 2025, the court enjoined the bureau from enforcing the rule while it rewrites it. In August 2026, the CFPB sent a new proposed rule to the Office of Information and Regulatory Affairs for review. As of September 28, that proposal had not been published.
That leaves large banks in a gap where the federal standard is neither settled nor fully gone. The Chase Data Security Center builds the customer-facing half of that standard anyway, on the bank’s own schedule and terms. Whatever the CFPB finalizes, a bank that already gives customers visibility and revocation tools should have less to retrofit.
The Screen-Scraping Problem Underneath
The deeper issue is screen scraping. A fintech app asks a customer for their bank login, then simulates a login to pull data. The customer’s real password ends up stored outside the bank. Nor does the customer have a clean way to see or revoke what has been shared.
The alternative is tokenized, permissioned connections that replace stored passwords with access the customer can revoke. On a smaller scale, Lumin Digital and MX announced such a setup for credit unions earlier this month. A hub like the Chase Data Security Center works best when connections run through channels the bank can see and control. The release does not say how many connections still rely on scraped passwords.
Money is also part of this. In July 2025, JPMorgan told aggregators it would begin charging for data access. In September 2025, it reached a data-sharing agreement with Plaid on undisclosed terms. Fintech trade groups objected to the fees. Chase frames the Chase Data Security Center as customer control. It also gives the bank a clearer view of who is drawing on its data.
Adoption Is the Real Test
The risk is adoption, not architecture. Most customers do not review which apps can see their transaction history until something goes wrong. That might be a fraud alert, a denied loan, or a breach at an app they forgot they had linked. A well-built settings page that nobody opens does little for security.
What is different here is that the Chase Data Security Center arrives as a named product with its own education content. That gives Chase a reason to keep steering customers toward it. Whether that leads people to prune old connections is the part a press release cannot show. Chase has not said whether it will report how many customers use the hub or how many connections they revoke. Those two numbers would show whether the Chase Data Security Center changes behavior or simply exists.
What to Watch
As of September 28, Chase had not said the Data Security Center had moved from phased rollout to full availability.
One clear signal is whether other large banks launch their own branded version before a federal rule forces them. Another is whether Chase extends the Chase Data Security Center to its small business customers. Those businesses face the same scattered third-party access problem, with less regulatory attention on it. The fate of the rewritten Section 1033 proposal will shape both, including whether it sets rules on data access fees.
For related coverage, see why financial firms overrate their defenses against account takeover and how Eclipse Bank moved its digital banking to Lumin.
FintechBits covers payments, banking and fintech developments for readers in the US and UK. This article is for information only and is not financial advice. Views expressed are those of the FintechBits editorial team.



