What is Section 1071? It is the Dodd-Frank Act provision, codified at 12 U.S.C. § 5552, requiring financial institutions to compile, maintain and report to the Consumer Financial Protection Bureau data on credit applications from small businesses — including women-owned, minority-owned and LGBTQ+-owned status, as the statute defines its reach — so the public data can illuminate lending patterns the way Home Mortgage Disclosure Act data does for mortgages. The CFPB finalized the implementing rule in 2023, setting data collection to begin in phases during 2024 for the largest lenders, before the rule's compliance dates were stayed and reset by litigation and subsequent administrative review.
Political Digest publishes information, not legal or compliance advice.
What does the rule actually require?
- Coverage: financial institutions that originated at least 100 small-business credit applications in each of the two preceding years, with a small business defined by revenue thresholds aligned with the Small Business Act.
- Data points: application outcomes, credit amount and type, pricing, revenue of the applicant, and demographic self-identifications of principal owners, when voluntarily provided.
- Firewall: underwriting personnel are generally walled off from demographic data applicants submit — a statutory privacy feature the rule implements.
- Reporting: annual submissions to the CFPB, which publishes aggregated data like HMDA's public loan registers.
Why the dates keep moving
The rule was challenged immediately after finalization by banking and trade groups, and a Texas federal court's ruling — narrowed on appeal — plus the CFPB's own reconsideration under new leadership froze the original 2024 start. In 2025 the bureau moved to revisit the rule's coverage thresholds and data points, keeping institutions in a compliance posture where the operative dates are whatever the current Federal Register notices say, not the 2023 final rule's original table. Lenders building systems now write them to the statute's requirements with modular compliance dates.
What should covered lenders be doing meanwhile?
Three things survive every version of the rule: the statute itself is not going away, so data capture on small-business applications is the safe architecture; the firewall between underwriting and demographic data is statutory, not regulatory; and vendor contracts for loan-origination systems should price compliance-date flexibility. Institutions that built to the 2023 rule generally kept their build; the alternative — waiting for finality — risks a compressed runway if dates land on short notice, as mortgage lenders learned under HMDA expansions.
What the data will enable
Once flowing, the dataset gives regulators, journalists and researchers county-level views of small-business credit access by applicant demographics — the provision's original purpose, articulated in Dodd-Frank's section-by-section findings. Community reinvestment advocates and banks themselves will for the first time share a common factual baseline in debates over credit gaps, replacing competing anecdotes with reported figures.
FAQ
Who is covered by Section 1071?
Institutions meeting the application-volume threshold in the rule's current form — thresholds under reconsideration — for credit to businesses within the revenue definition.
Must applicants answer demographic questions?
No; demographic data is self-reported voluntarily, and the firewall bars underwriters from seeing it.
When does reporting start?
On the compliance dates in the current controlling Federal Register actions — check the CFPB's 1071 resource page, as dates have shifted with litigation and review.
For more context, read Federal Contracting 101: Set-Asides, Size Standards and SAM.gov.
For more context, read ieepa tariff ruling.
For more context, read FTC and DOJ Extend Antitrust Comment Window to May 21.
