On June 30, 2026, the Federal Deposit Insurance Corporation (FDIC) published a notice of proposed rulemaking (FDIC NPR) that would update, clarify, and supplement the FDIC’s regulations regarding disclosure of confidential information by the FDIC and other parties, facilitating disclosure in certain instances that would no longer require prior authorization by the FDIC. The FDIC also seeks to significantly simplify its requirements regarding discretionary disclosure of confidential information and disclosure of confidential information under the Freedom of Information Act (FOIA) and other means.
On August 5, 2026, the Office of the Comptroller of the Currency (OCC) published its notice of proposed rulemaking (OCC NPR) that would clarify the process for obtaining OCC approval to disclose non-public OCC information (“OCC information”), including “confidential supervisory information” (CSI). The OCC NPR would similarly allow for the disclosure of OCC information in certain circumstances without prior authorization by the OCC. The OCC NPR also seeks to update the OCC’s process for requesting nonexempt information under FOIA, including expedited processing requests.
Comments on both proposals are due October 5, 2026, after the FDIC published an extension on August 28, 2026. This client alert summarizes aspects of the agencies’ proposals that address the discretionary disclosure of confidential information.
n The agencies’ proposals are a welcome update to regulations and procedures that have often created significant friction and inefficiencies for the agencies, regulated institutions, fintech partners, outside advisors, and the general public.
For the first time in 30 years, the FDIC proposes significant updates to the FDIC’s information-sharing and disclosure framework for IDIs. The FDIC NPR would amend the agency’s regulations at 12 CFR Part 309 and add a new Part 306 where certain regulations on service of process would be relocated. The FDIC’s current regulations would be reorganized into four subparts: (i) General; (ii) FOIA; (iii) Discretionary Disclosure of Confidential Information; and (iv) Disclosure of Confidential Information in Legal Proceedings in Which the FDIC Is Not a Party.
Disclosure of confidential information by the FDIC and other parties
The FDIC NPR would generally remove restrictions on the disclosure of confidential information that is more than 25 years old. It would also broaden the universe of parties with whom an IDI may share confidential information, where necessary or appropriate for business purposes, without prior FDIC approval, subject to certain conditions. The parties with whom an IDI could share confidential information (subject to a confidentiality agreement, described below) are as follows:
Conditions for disclosure of confidential information by an IDI would require that, prior to or concurrently with any disclosure under categories 3–7 above, the IDI must enter into a qualifying confidentiality agreement with the intended recipient that is written and governed by state or federal law. Among other things, the confidentiality agreement would need to prohibit use of the information by the recipient for non-designated purposes and any onward disclosure. The confidentiality agreement would expressly provide that the FDIC is an intended third-party beneficiary of the agreement and is permitted to enforce its terms through a civil action.
Discretionary disclosure of confidential information that is exempt from disclosure under FOIA would need to meet the FDIC’s “good cause” standard. This standard would apply to decisions by the FDIC to disclose confidential information either on its own initiative or in response to a request. The standard would also apply to decisions by the FDIC to permit an IDI to disclose to a third party confidential information in the IDI’s possession, in those circumstances where such approval would continue to be required.
The good cause standard would be informed by FDIC consideration of eight non-exhaustive factors:
The OCC NPR would revise the agency’s regulations at 12 CFR Part 4 Subparts B and C regarding the availability of OCC information under FOIA and the release of OCC information. Currently, the OCC permits supervised entities to disclose OCC information only with OCC prior approval (subject to certain exceptions). In its proposal, the OCC states that the current categorization of non-public information in a “one-size-fits-all approach” fails to consider the context of the disclosure and limits government accountability.
Disclosure of CSI by the OCC and other parties
The OCC NPR would allow for disclosures to improve the efficiency of the supervisory process, without prior approval, to certain entities, including some that overlap with the FDIC NPR:
One notable difference from the FDIC NPR is that the OCC NPR would also allow for disclosure to not-for-profit entities, such as trade organizations. The OCC indicates that this inclusion might allow for greater advocacy efforts, academic research, and new analyses and insights into the banking sector.
The OCC NPR would establish tailored safeguards around these exceptions, such as the required use of confidentiality agreements and other data-sharing safeguards, including that the recipient be incorporated in the U.S., have a business need for the information (such as assisting the supervised entity with remediating supervisory concerns or fulfilling supervisory expectations), and have a formal agreement with or be under a written contact to provide services to the supervised entity. The confidentiality agreement requirements would largely mirror those of the FDIC NPR, requiring a prohibition on the use of the information by the recipient for non-designated purposes and any onward disclosure and expressly providing that the OCC is an intended third-party beneficiary of the agreement and is permitted to enforce its terms through a civil action. In addition, the OCC NPR would require that the OCC receive notice of any violations of the agreement.
The OCC NPR would also eliminate references indicating that referrals for criminal prosecution may be sought for the unauthorized disclosure of non-public OCC information under 18 U.S.C. § 641. Notably, the FDIC NPR does not include similar language.
The OCC proposes a two-tiered framework for OCC information, establishing a new subcategory of OCC information for CSI and maintaining a category of other non-public OCC information. CSI would be defined to include:
The OCC NPR states that information created or collected by a supervised entity for its own business purposes does not qualify as CSI simply because it is shared with the OCC.
Under the new framework, CSI could be disclosed without prior OCC approval in certain scenarios, while other non-public OCC information would follow the traditional approval process for disclosure. The OCC said it believes this would help to ensure more nuance than a “one-size-fits-all approach” to categorizing OCC information.
In addition, the OCC NPR would make several changes to the agency’s FOIA rules, including:
The agencies’ proposals represent a significant shift in the treatment and disclosure of confidential information. The treatment and sharing of confidential supervisory information have historically been a significant friction point in bank-fintech arrangements, at times impeding effective risk management and compliance coordination between banks and their fintech partners. The proposals would reduce the information asymmetry between banks and their fintech partners, potentially allowing for the sharing of critical supervisory findings, risk assessments, or compliance deficiencies without prior agency approval and encouraging robust, well-coordinated operational compliance and risk management programs.
If the proposals are finalized in their current form, the agencies would play less of an active gatekeeper role, allowing for routine disclosures to be handled without their prior approval. This should allow for smoother day-to-day business operations for regulated entities and meaningfully reduce administrative costs.
Minor differences in the agencies’ proposed approaches would still leave a slightly fractured regulatory landscape. Ideally, the FDIC, the OCC, and the FRB would adopt a uniform, interagency framework for handling and disclosing CSI with conforming definitions of the term “service provider” and interagency adoption of the term “confidential supervisory information.”
In sum, these proposals would represent a major shift toward greater transparency and a freer flow of information, allowing regulated entities to share confidential information under a broader threshold of preauthorized disclosures and reducing the administrative burden by no longer requiring agency approval for routine disclosures of CSI to covered third parties.
[1] The FDIC NPR specifically provides that this definition “would include third party ‘fintech’ companies that provide services used in connection with the provision of financial products or services to customers.” Disclosure of Information, 91 Fed. Reg. 39,726, 39,731 (proposed June 30, 2026).