Competition Law And Digital Trust Infrastructures And Competition Law
Competition Law and Digital Trust Infrastructures
Introduction
Digital trust infrastructures are technological and institutional systems that enable users, businesses, governments, and platforms to determine whether a digital transaction, identity, communication, payment, credential, dataset, or software interaction can be trusted. They include digital identity systems, authentication services, electronic signatures, certificate authorities, trust registries, reputation systems, payment authentication networks, cybersecurity certification infrastructures, verification APIs, content-authentication systems, and interoperability frameworks.
Competition law becomes relevant when control over such infrastructure gives an undertaking the ability to exclude competitors, raise rivals’ costs, restrict interoperability, discriminate in access, tie complementary services, exploit data advantages, or entrench an existing ecosystem.
The central competition-law problem is therefore not simply whether an infrastructure is technologically important. It is whether control over a critical trust layer can be converted into durable market power in adjacent or downstream markets.
I. Meaning of Digital Trust Infrastructure
Digital trust infrastructure may include:
- Digital identity infrastructure
- digital identity verification;
- authentication services;
- KYC infrastructure;
- biometric verification;
- digital credentials.
- Authentication and security infrastructure
- authentication APIs;
- two-factor authentication;
- security certificates;
- public-key infrastructure;
- cybersecurity verification.
- Electronic-signature infrastructure
- certificate authorities;
- electronic-signature platforms;
- digital document verification.
- Reputation and rating infrastructure
- seller ratings;
- user reviews;
- professional verification;
- trust scores.
- Payment-trust infrastructure
- tokenisation;
- payment authentication;
- fraud detection;
- payment-security networks.
- Data and verification infrastructure
- identity databases;
- business registries;
- product authenticity systems;
- provenance databases.
- Platform trust infrastructure
- account verification;
- seller authentication;
- content verification;
- marketplace integrity systems.
- AI and algorithmic trust systems
- AI model authentication;
- model provenance;
- automated fraud detection;
- algorithmic certification.
II. Why Digital Trust Infrastructure Raises Competition Concerns
Digital trust systems frequently have network effects.
The more users that rely on a particular identity, authentication, reputation, or verification system, the more valuable that system becomes.
This can create a reinforcing cycle:
More users → more data → better verification → greater trust → more users → greater market power
Competition problems arise when the operator of the infrastructure can use that position to restrict alternative providers.
Principal concerns
- refusal to provide access;
- discriminatory access;
- interoperability restrictions;
- excessive access charges;
- tying;
- bundling;
- self-preferencing;
- exclusive arrangements;
- data accumulation;
- interoperability degradation;
- switching barriers;
- ecosystem foreclosure;
- leveraging infrastructure dominance into adjacent markets.
III. Digital Trust Infrastructure as an Essential-Facility-Type Problem
A digital trust infrastructure can sometimes resemble an essential facility where:
- the infrastructure is controlled by a dominant undertaking;
- competitors cannot reasonably reproduce it;
- access is indispensable or highly important for effective competition;
- denial or discriminatory access can eliminate or substantially weaken competition;
- providing access is technically and economically feasible.
However, mere importance is not sufficient to establish an essential-facility obligation.
Competition authorities generally have to balance:
access to infrastructure
against
investment incentives, security, privacy, intellectual-property rights and legitimate technical requirements.
IV. Market Definition
Competition authorities may define several relevant markets.
A. Infrastructure market
For example:
market for digital identity verification services.
B. Authentication market
market for authentication and identity-management services.
C. Downstream market
online financial services, e-commerce, advertising, cloud services or digital payments.
D. Two-sided platform market
A trust infrastructure may serve:
- users;
- merchants;
- advertisers;
- financial institutions;
- developers;
- governments.
Market definition therefore has to account for multi-sidedness and indirect network effects.
V. Market Power and Network Effects
Traditional market shares may underestimate power in digital trust infrastructure.
Important indicators include:
- number of verified users;
- number of merchants;
- number of dependent platforms;
- transaction volume;
- data accumulation;
- switching costs;
- interoperability;
- technical standards;
- API dependency;
- ecosystem reach;
- reputation effects;
- authentication coverage.
A provider may possess significant competitive leverage even where the direct price of the trust service is zero.
VI. Data as a Source of Competitive Advantage
Digital trust infrastructures can collect unusually valuable data.
For example, an authentication provider may obtain information concerning:
- user identity;
- transaction history;
- device characteristics;
- location;
- behavioural patterns;
- fraud signals;
- merchant activity.
The infrastructure operator may then use this information in another market.
This creates a potential data-leveraging theory of harm.
Example
Suppose a dominant digital identity provider supplies identity verification to competing fintech companies.
If it uses information generated from those competitors' customers to improve its own competing fintech service, the infrastructure may become a mechanism for vertical competitive advantage.
VII. Interoperability and Competition
Interoperability is particularly important.
A dominant trust infrastructure may impose:
- proprietary authentication protocols;
- restrictive APIs;
- incompatible credentials;
- technical barriers;
- excessive certification requirements.
The result may be:
Trust infrastructure → interoperability restriction → higher switching costs → reduced contestability
Interoperability obligations can therefore become an important competition remedy.
VIII. Refusal to Deal
A dominant operator may refuse access to:
- identity-verification APIs;
- authentication systems;
- reputation databases;
- certification systems;
- trust registries.
A competition-law assessment normally asks whether the refusal has the characteristics necessary for intervention rather than treating every refusal as unlawful.
Relevant considerations include:
- indispensability;
- availability of alternatives;
- technical feasibility;
- economic feasibility;
- discriminatory treatment;
- elimination of effective competition;
- legitimate business justification.
IX. Discriminatory Access
A particularly important issue is non-price discrimination.
A dominant trust infrastructure may technically provide access but give:
- its own affiliate faster verification;
- competitors slower API access;
- preferential technical standards;
- better data fields to its own service;
- superior fraud signals to its affiliate.
Such conduct can produce foreclosure without an explicit refusal to deal.
X. Self-Preferencing
Suppose a platform operates a trusted-seller verification system.
It could potentially:
- certify sellers;
- operate a marketplace;
- rank sellers;
- own competing merchants.
If its verification system systematically privileges its own marketplace sellers, competition concerns can arise.
The key issue is whether the infrastructure is being used to distort competition in an adjacent market.
XI. Tying and Bundling
A dominant authentication provider might require businesses purchasing authentication services also to purchase:
- cloud hosting;
- payment processing;
- cybersecurity;
- advertising;
- identity analytics.
This can create a tying theory of harm where the trust infrastructure is used as a gateway into adjacent markets.
XII. Exclusive Dealing
A trust infrastructure provider may enter agreements requiring:
merchants → use only its authentication system.
Where the provider possesses substantial market power, widespread exclusivity can prevent competing authentication systems from achieving sufficient scale.
This is especially significant in markets characterized by network effects.
XIII. Reputation Systems
Digital reputation systems are themselves trust infrastructures.
Examples include:
- seller ratings;
- driver ratings;
- accommodation reviews;
- professional ratings;
- creditworthiness indicators.
A dominant platform controlling the reputation database may possess an important competitive asset.
Potential concerns include:
- preventing users from transferring reputation;
- deleting or suppressing competitor ratings;
- giving preferential visibility to affiliated businesses;
- preventing multi-homing;
- restricting access to historical reputation data.
XIV. Portability of Digital Trust
Data portability can have a special role.
Consider:
Platform A → user develops 10 years of reputation → user wants to move to Platform B.
If Platform A prevents transfer of meaningful reputation information, the user's accumulated trust capital may become a switching barrier.
Competition policy may therefore consider:
- portability;
- interoperability;
- standardized credentials;
- API access;
- machine-readable reputation data.
However, portability must also respect:
- privacy;
- cybersecurity;
- confidentiality;
- data-protection rules.
XV. Cybersecurity and Competition
A dominant infrastructure provider may justify interoperability restrictions on security grounds.
Some restrictions may therefore be legitimate.
Competition authorities must distinguish between:
Genuine security restriction
A restriction objectively necessary to prevent fraud or cyberattacks.
Strategic restriction
A security justification used primarily to prevent competing services from accessing the infrastructure.
This distinction is particularly important in digital markets.
XVI. Important Case Laws
1. United Brands Co. v Commission
The United Brands case is an important foundation for understanding abuse of dominance and discriminatory conduct.
The Court of Justice recognised that a dominant undertaking has special responsibilities concerning its conduct in the market.
Relevance to digital trust infrastructure
A dominant authentication or identity infrastructure may have to avoid discriminatory treatment of competing users where its infrastructure constitutes an important competitive input.
The case is therefore relevant to:
- dominance;
- discrimination;
- access conditions;
- exclusionary conduct.
2. Commercial Solvents Corp. v Commission
In Commercial Solvents, the dominant undertaking's conduct concerning supply to downstream competitors was examined under Article 86 of the Treaty, now Article 102 TFEU.
Principle
A dominant firm controlling an important upstream input cannot necessarily use that control to eliminate downstream competition.
Digital relevance
The principle can be applied conceptually to:
dominant trust infrastructure → downstream digital service → competing downstream providers.
For example, if an identity infrastructure is indispensable to competing financial services, discriminatory withdrawal of access may raise analogous concerns.
3. Bronner v Mediaprint
Oscar Bronner GmbH & Co. KG v Mediaprint is one of the leading European cases concerning refusal to supply and essential facilities.
The Court established a demanding framework for treating access to infrastructure as mandatory.
Importance
The case demonstrates that:
indispensability is not established merely because access to an infrastructure would make competition easier or more efficient.
Digital application
A competition authority considering mandatory access to:
- digital identity infrastructure;
- authentication networks;
- trust registries;
- verification APIs
would need to consider whether effective competition is genuinely impossible without access.
4. IMS Health GmbH & Co. OHG v NDC Health
IMS Health is especially significant for the interaction between intellectual property and access to commercially important infrastructure.
The case concerned access to a system used by pharmaceutical companies and raised the question of when refusal to license an intellectual-property-protected system may constitute abuse.
Digital significance
Modern digital trust infrastructures may involve:
- proprietary databases;
- authentication protocols;
- APIs;
- technical standards;
- intellectual property.
IMS Health demonstrates that mandatory access requires careful consideration of:
- indispensability;
- elimination of competition;
- new products or services;
- exceptional circumstances.
5. Microsoft Corp. v Commission
The Microsoft decision is highly relevant to digital interoperability.
The European Commission found concerns regarding Microsoft's withholding of interoperability information from competing work-group server operating systems and its tying of Windows with Windows Media Player.
Digital trust relevance
The case illustrates how control over a technical interface can become a source of competitive leverage.
The broader lesson is:
Technical interoperability can be a competition-law issue where a dominant platform controls an interface necessary for competing products.
This is directly relevant to:
- authentication APIs;
- identity protocols;
- trust credentials;
- security interfaces;
- platform interoperability.
6. Google Shopping
The Google Shopping litigation concerns the use of dominance in general search to favour Google's comparison-shopping service.
The case is important for understanding self-preferencing and leveraging in digital ecosystems.
Digital trust relevance
Trust infrastructures can similarly become gateways through which an operator determines:
- which service receives verification;
- which seller receives trusted status;
- which provider receives visibility;
- which competing service obtains access.
The case therefore illustrates the broader competition problem of using control over an important digital gateway to influence adjacent markets.
7. Slovak Telekom
Slovak Telekom concerned access to telecommunications infrastructure and exclusionary conduct.
The case is important because it demonstrates that access-related conduct must be assessed in the context of dominance and competitive foreclosure.
Digital relevance
Telecommunications networks increasingly carry digital identity, authentication, payment and verification services.
The case therefore provides useful analytical principles for infrastructure-dependent digital markets.
8. Deutsche Telekom
Deutsche Telekom addressed exclusionary pricing in the telecommunications sector.
Its importance for digital trust infrastructures lies in demonstrating how control over an important infrastructure layer can affect competition in downstream markets.
Application
A dominant infrastructure provider could theoretically use:
- excessive access pricing;
- margin squeeze;
- discriminatory wholesale terms
to disadvantage downstream competitors.
9. MEO – Serviços de Comunicações e Multimédia
The MEO case concerns discriminatory pricing under Article 102(c) TFEU.
The Court emphasised the importance of assessing whether discriminatory treatment places trading partners at a competitive disadvantage.
Digital application
The principle is relevant where a digital trust provider gives different:
- API prices;
- verification speeds;
- authentication limits;
- technical functionality
to competing businesses.
10. Meta Platforms Inc. v Bundeskartellamt
The Meta Platforms litigation before the Court of Justice concerned the interaction between competition law and personal-data practices.
Importance
The case demonstrates that data practices can become relevant to competition-law analysis where a dominant digital platform combines data obtained from different services.
Digital trust relevance
Trust infrastructures frequently depend upon extensive identity and behavioural data.
The case therefore illustrates the need to examine the relationship between:
data collection → market power → ecosystem expansion → competitive effects.
XVII. Competition Theories of Harm
| Conduct | Potential competition concern |
|---|---|
| Refusal of access | Foreclosure |
| Discriminatory access | Competitive disadvantage |
| Excessive access pricing | Raising rivals' costs |
| Margin squeeze | Downstream exclusion |
| API restriction | Interoperability foreclosure |
| Self-preferencing | Leveraging |
| Exclusive contracts | Entrenchment |
| Tying | Expansion into adjacent markets |
| Data combination | Data-based competitive advantage |
| Reputation lock-in | Switching barriers |
| Technical degradation | Non-price foreclosure |
| Certification discrimination | Entry barriers |
XVIII. Merger Control
Digital trust infrastructures can also raise concentration concerns.
Consider a merger between:
identity provider + payment platform
or:
authentication provider + cloud provider.
The transaction could combine:
- identity data;
- authentication;
- payments;
- cloud infrastructure;
- cybersecurity;
- customer relationships.
Authorities may therefore examine:
Horizontal effects
Whether the merger removes a competing trust provider.
Vertical effects
Whether the merged entity can restrict competitors' access.
Conglomerate effects
Whether trust infrastructure can be used to strengthen an ecosystem across several markets.
Data effects
Whether the transaction creates a uniquely valuable combined dataset.
XIX. Digital Trust Infrastructure and Algorithmic Competition
Trust systems increasingly use algorithms to determine:
- fraud risk;
- seller authenticity;
- account legitimacy;
- creditworthiness;
- transaction risk.
If the dominant infrastructure controls the algorithm, competitors may become dependent on its decisions.
Potential concerns include:
- opaque access criteria;
- discriminatory scoring;
- algorithmic exclusion;
- preferential treatment of affiliated services;
- manipulation of trust scores.
This creates an important intersection between competition law, algorithmic governance and digital regulation.
XX. Standard-Setting and Trust Infrastructure
Technical standards can facilitate competition by allowing interoperability.
However, standard-setting can also create competition concerns where participants:
- exclude rivals;
- manipulate technical standards;
- impose discriminatory certification;
- use standards to disadvantage alternative technologies.
A dominant standard can effectively become a gatekeeping mechanism.
XXI. Competition Remedies
Possible remedies include:
1. Access obligations
Require non-discriminatory access to critical APIs or verification infrastructure.
2. Interoperability
Require technically effective interoperability.
3. Data portability
Allow users to transfer relevant trust credentials.
4. Non-discrimination
Require equivalent treatment of affiliated and unaffiliated businesses.
5. Transparency
Require publication of objective access criteria.
6. Structural separation
In exceptional cases, separate infrastructure functions from downstream commercial operations.
7. Behavioural commitments
Prevent:
- tying;
- exclusive dealing;
- self-preferencing;
- discriminatory pricing.
8. Data-use restrictions
Prevent the infrastructure operator from using competitors' commercially sensitive data to compete against them.
XXII. Tension Between Competition and Security
Digital trust infrastructure creates an unusual regulatory balance.
Opening an infrastructure can promote:
competition + interoperability + innovation
but excessive openness can create:
fraud + identity theft + cyberattacks + security vulnerabilities.
Consequently, competition law should not automatically require unrestricted access.
A more appropriate framework is:
Open access where competitively necessary + objective security standards + non-discriminatory implementation + proportionality.
XXIII. Emerging Issues
Future competition cases may involve:
A. Digital identity monopolies
One provider becomes the principal authentication layer for multiple digital services.
B. AI trust infrastructure
One company controls AI-model verification and certification.
C. Blockchain identity systems
A dominant wallet or credential provider becomes an interoperability bottleneck.
D. Reputation portability
Platforms prevent users from transferring accumulated trust scores.
E. Cybersecurity certification
A dominant cybersecurity certification system excludes rival certification providers.
F. Biometric authentication
Control over biometric verification becomes a gateway to financial or governmental services.
G. Digital credential ecosystems
One provider controls educational, professional and commercial credentials.
H. Trust-data accumulation
A provider combines authentication, transaction and behavioural data to create competitive advantages in adjacent markets.
XXIV. Key Legal Principles
The competition-law analysis of digital trust infrastructure can be reduced to eight principles:
- Infrastructure importance does not automatically establish dominance.
- Dominance does not automatically create an unlimited access obligation.
- Indispensability is important for refusal-to-deal theories.
- Interoperability can be competitively significant.
- Discriminatory access may constitute exclusionary conduct.
- Data accumulated through infrastructure can create leverage into adjacent markets.
- Network effects and switching costs can reinforce market power.
- Security and privacy justifications must be distinguished from strategic exclusion.
Conclusion
Digital trust infrastructures are becoming an important new layer of competition policy. Identity verification, authentication, reputation, certification, payment security and digital credentials can function as gateways through which competitors reach customers and transact in digital markets.
The principal competition-law concern arises where an undertaking controls such infrastructure and uses that position to foreclose rivals, discriminate in access, restrict interoperability, exploit data, impose exclusivity, self-preference affiliated services or extend dominance into neighbouring markets.
The traditional doctrines concerning refusal to deal, essential facilities, tying, discrimination, interoperability, leveraging and abuse of dominance remain relevant, but they must be adapted to digital characteristics such as network effects, data accumulation, APIs, multi-sided platforms, switching costs and algorithmic decision-making.
The major cases—United Brands, Commercial Solvents, Bronner, IMS Health, Microsoft, Google Shopping, Slovak Telekom, Deutsche Telekom, MEO and Meta Platforms—provide a useful doctrinal foundation for analysing these emerging problems. The future challenge for competition law will be to ensure that digital trust infrastructures remain sufficiently secure and reliable while also remaining contestable, interoperable and non-discriminatory.

comments