Digital Identity Federation Competition Issues

 

Digital Identity Federation Competition Issues

Introduction

Digital identity federation refers to arrangements in which multiple online services rely on a common identity provider or interoperable identity infrastructure to authenticate users. Instead of creating separate credentials for every service, a user may authenticate through a dominant identity provider, government identity system, bank, telecom operator, platform, or other trusted intermediary.

Federation can generate substantial efficiencies: reduced authentication costs, improved security, easier portability, fraud reduction, and seamless access across services. However, when a small number of identity providers control authentication infrastructure, federation can also create competition concerns.

The central competition-law question is whether interoperability and trust arrangements that are technically designed to make digital identity easier can instead become mechanisms for foreclosure, exclusion, data concentration, tying, self-preferencing, switching-cost creation, or durable ecosystem dependency.

1. Meaning and Structure of Digital Identity Federation

A simplified federation can be represented as:

User → Identity Provider → Federation Protocol → Relying Party → Digital Service

For example:

  • Identity Provider (IdP): verifies and authenticates the individual.
  • Federation operator: establishes technical and governance rules.
  • Relying parties: banks, websites, marketplaces, public services, apps, etc.
  • Authentication protocol: allows the relying party to accept authentication performed by the IdP.
  • Attribute provider: supplies additional information such as age, address, qualification, or payment status.
  • Trust framework: determines which entities are recognised as legitimate participants.

The economic significance arises because the identity layer can become an infrastructure layer above many downstream markets.

2. Why Identity Federation Can Create Market Power

A federation provider may possess several forms of competitive advantage.

A. Network effects

The value of an identity system increases as more users and relying parties participate.

More users → more relying parties → greater usefulness → more users.

This can produce a positive feedback loop.

B. Data advantages

An identity provider may obtain information concerning:

  • authentication events;
  • account relationships;
  • device identifiers;
  • transaction metadata;
  • behavioural patterns;
  • attributes used by relying parties.

The combination can create a significant informational advantage.

C. Switching costs

A user who has accumulated numerous accounts connected to one identity provider may face significant costs in moving to another provider.

Businesses face similar costs because changing identity infrastructure can require:

  • API modification;
  • security certification;
  • contractual renegotiation;
  • user migration;
  • compliance testing;
  • fraud-model recalibration.

D. Trust effects

Identity systems depend heavily upon reputation and security.

Once a provider becomes widely trusted, new competitors may find it difficult to convince users and businesses to adopt an alternative.

3. Relevant Competition Markets

Competition authorities may need to define several related markets rather than treating "digital identity" as one market.

Possible markets include:

  1. Identity verification services
  2. Authentication services
  3. Federated identity services
  4. Digital credentials
  5. Identity-as-a-service
  6. Attribute verification
  7. Single-sign-on services
  8. Trust-framework certification
  9. Identity APIs
  10. Identity-related data services

There may also be a distinction between:

  • consumer identity federation;
  • enterprise identity federation;
  • government identity federation;
  • financial-sector identity federation;
  • platform identity systems.

4. Competition Issue: Dominant Identity Provider

The most obvious concern occurs where one provider becomes the indispensable gateway to numerous downstream services.

A dominant identity provider could potentially:

  • restrict access to its federation;
  • impose discriminatory technical conditions;
  • charge excessive fees;
  • degrade competing identity providers;
  • require exclusivity;
  • limit interoperability;
  • favour its own downstream services.

This resembles the economic logic of essential infrastructure.

The important distinction is that technical indispensability does not automatically establish an antitrust violation. Authorities must examine dominance, foreclosure, objective justification, efficiencies, and competitive effects.

5. Competition Issue: Refusal to Interoperate

A federation may become effectively closed.

For example, an incumbent could refuse to permit a competing authentication provider to participate in its ecosystem even though interoperability is technically feasible.

Competition-law analysis may examine:

  • whether the incumbent is dominant;
  • whether access is objectively necessary;
  • whether exclusion eliminates effective competition;
  • whether interoperability is commercially reasonable;
  • whether there is a legitimate security justification.

This is particularly relevant to essential-facilities-type theories.

6. Competition Issue: Interoperability Discrimination

Even where access is formally available, a dominant identity provider may provide superior interoperability to its own services.

Examples include:

  • faster authentication APIs for affiliated services;
  • privileged access to identity attributes;
  • better fraud signals;
  • superior documentation;
  • preferential API quotas;
  • lower authentication costs;
  • access to additional identity fields.

Such conduct may constitute self-preferencing or discriminatory access if it produces exclusionary effects.

7. Competition Issue: Tying and Bundling

A powerful identity provider could condition access to authentication services on the purchase or use of another service.

For example:

"Businesses using our identity federation must also use our payment-processing service."

Other possibilities include tying:

  • identity authentication to cloud services;
  • identity verification to advertising services;
  • identity services to payment systems;
  • identity federation to enterprise software;
  • identity authentication to app-store services.

The competition concern is that power in the identity market may be leveraged into an adjacent market.

8. Competition Issue: Self-Preferencing

A vertically integrated identity provider may operate both:

  • the identity infrastructure; and
  • downstream digital services.

It may then design federation rules that favour its own downstream products.

Potential mechanisms include:

  • preferred authentication flows;
  • superior visibility;
  • automatic login;
  • preferential trust status;
  • exclusive identity attributes;
  • lower verification friction.

This creates a vertical foreclosure problem.

9. Competition Issue: Data Concentration

Federated identity systems can generate significant data concentration.

The identity provider may know that a particular user authenticated with:

  • a bank;
  • a healthcare service;
  • an online marketplace;
  • a government service;
  • an educational platform.

Even where the provider does not receive the substantive content of those interactions, authentication metadata can have competitive value.

The resulting advantage may reinforce dominance through a data-network effect:

More users → more identity data → better fraud/security services → more adoption → more users.

10. Competition Issue: Privacy as a Parameter of Competition

Digital identity markets demonstrate why competition cannot always be evaluated solely through price.

A federation may compete on:

  • privacy;
  • anonymity;
  • data minimisation;
  • security;
  • user control;
  • portability;
  • transparency.

If a dominant provider reduces privacy protections in a way that users cannot realistically avoid because alternative identity providers are unavailable, the deterioration may constitute a quality dimension of competition.

This connects competition law with data-protection principles.

11. Competition Issue: Lock-In

Federation can create substantial ecosystem lock-in.

Suppose a business connects its services to Provider A.

Migration to Provider B may require:

  1. new APIs;
  2. new certification;
  3. new security testing;
  4. user re-registration;
  5. account reconciliation;
  6. new contractual arrangements.

Consequently, even if Provider B offers a superior service, customers may remain with A.

Competition authorities may therefore examine migration costs as a barrier to entry.

12. Competition Issue: Default Identity Provider

Defaults are particularly powerful in identity markets.

A device, browser, operating system, marketplace, or enterprise software provider may designate its own identity service as the default.

Because authentication is often repetitive, users may rarely switch from the default.

The competitive mechanism is:

Default → reduced search → reduced switching → greater adoption → stronger network effects → higher entry barriers.

This is analogous to concerns examined in search, browser, mobile-platform, and app-distribution markets.

13. Competition Issue: Exclusive Federation Agreements

A federation operator may enter agreements requiring relying parties to use only its authentication infrastructure.

Exclusive arrangements can:

  • prevent multi-homing;
  • foreclose rival identity providers;
  • increase switching costs;
  • deprive entrants of scale;
  • reinforce network effects.

The analysis should consider both duration and coverage.

A short, easily terminable agreement may present limited concerns, whereas long-term exclusivity covering a large proportion of the market may substantially foreclose rivals.

14. Competition Issue: Multi-Homing

Multi-homing is particularly important in digital identity.

If relying parties can easily accept several identity providers, competition is easier.

For example:

Login with Provider A / Provider B / Provider C

reduces dependency on any single identity provider.

A dominant provider may therefore have incentives to make multi-homing difficult by:

  • imposing technical incompatibilities;
  • requiring exclusivity;
  • increasing API costs;
  • limiting simultaneous authentication options;
  • preventing portability.

15. Competition Issue: Interoperability Standards

Standards can promote competition but can also become instruments of exclusion.

A dominant federation may influence standards concerning:

  • authentication protocols;
  • credential formats;
  • security certification;
  • identity attributes;
  • API specifications.

Competition concerns arise where a technically neutral standard is manipulated to disadvantage competing technologies.

There is therefore a distinction between:

open interoperability standard

and

strategic standard-setting controlled by incumbents.

16. Competition Issue: Standards-Essential Identity Infrastructure

If a particular federation standard becomes unavoidable, access to that standard may become commercially indispensable.

A dominant entity controlling the standard could potentially:

  • discriminate against rivals;
  • impose unreasonable licensing conditions;
  • refuse access;
  • alter technical requirements to disadvantage competitors.

Where intellectual-property rights are involved, competition-law analysis may overlap with FRAND-type principles.

17. Competition Issue: Government-Backed Identity Federations

Government-backed identity systems create a special competition problem.

A government may simultaneously act as:

  • regulator;
  • identity infrastructure operator;
  • certifier;
  • purchaser;
  • rule-maker.

This creates potential risks of regulatory and infrastructural favouritism.

For example, if government services recognise only the government's own identity federation while private competitors are denied equivalent certification without objective justification, competition may be distorted.

However, public-interest, security, national-security, and legal-compliance objectives can justify some restrictions.

18. Competition Issue: Platform Identity and Ecosystem Expansion

Large digital platforms may use identity federation to reinforce dominance in adjacent markets.

An integrated ecosystem might contain:

Operating system → App store → Payment → Identity → Cloud → Advertising → Marketplace

Control over identity can therefore increase the platform's ability to coordinate and reinforce these complementary markets.

The competition concern is not simply the identity service itself but ecosystem leverage.

19. Competition Issue: Artificial Degradation of Rival Authentication

A dominant provider could technically degrade competitors.

Examples:

  • slower authentication;
  • additional verification steps;
  • reduced API functionality;
  • lower reliability;
  • increased latency;
  • unnecessary security prompts.

Such conduct may appear superficially neutral because the competitor remains technically available.

But competition analysis should examine whether the degradation materially changes user behaviour.

20. Competition Issue: Identity Portability

Effective portability can substantially reduce lock-in.

Users should potentially be able to transfer:

  • identity credentials;
  • verified attributes;
  • authentication history where appropriate;
  • account identifiers;
  • consent preferences.

However, portability must balance competition with security and privacy.

The competitive principle is:

A user should not lose access to their digital economic identity merely because they change identity providers.

21. Competition Issue: Authentication Data as an Essential Input

Identity information can become an important input for downstream businesses.

Examples include:

  • fraud prevention;
  • age verification;
  • credit assessment;
  • KYC;
  • financial onboarding;
  • insurance;
  • marketplaces.

If one provider controls access to high-quality verified identity information, it may gain substantial leverage over downstream competitors.

This raises input foreclosure concerns.

22. Competition Issue: Algorithmic Identity Verification

Modern identity systems increasingly use:

  • facial recognition;
  • behavioural biometrics;
  • device intelligence;
  • AI fraud detection;
  • risk scoring.

A dominant identity provider may therefore accumulate technological advantages that reinforce its position.

A competitor may be unable to reproduce the same accuracy without equivalent:

  • training data;
  • authentication events;
  • fraud signals;
  • network scale.

This creates a potentially self-reinforcing algorithmic data advantage.

23. Competition Issue: Pricing

Federated identity providers may charge:

  • per authentication;
  • per user;
  • per API call;
  • subscription fees;
  • verification fees.

Competition authorities may examine whether a dominant provider engages in:

Excessive pricing

Charges substantially above competitive levels.

Predatory pricing

Temporary below-cost pricing designed to eliminate rivals.

Margin squeeze

Wholesale identity-access prices are high while the provider's downstream service prices are sufficiently low to disadvantage competitors.

24. Competition Issue: Cross-Subsidisation

A large platform may subsidise identity services using profits from another market.

For example:

Advertising profits → free identity service → rapid adoption → exclusion of independent identity providers.

Free provision does not automatically mean anti-competitive conduct.

The relevant question is whether the pricing structure forms part of a strategy that produces durable exclusionary effects.

25. Competition Issue: Merger and Acquisition Risks

Competition authorities may scrutinise acquisitions involving:

  • identity verification companies;
  • authentication providers;
  • credential platforms;
  • biometric firms;
  • digital-wallet identity systems;
  • enterprise identity providers.

A dominant platform acquiring an emerging identity provider could eliminate an important future competitor.

Particular attention should be paid to nascent competition and data-related competitive advantages.

26. Case Laws

Because there are relatively few cases dealing directly with "digital identity federation" as a standalone antitrust category, the most useful authorities are cases concerning interoperability, access, tying, platform defaults, data, network effects, standards, and ecosystem leverage.

1. United States v. Microsoft Corp. (D.C. Cir. 2001)

Microsoft's conduct concerning Windows and competing technologies is a foundational authority on platform foreclosure.

The court examined Microsoft's use of its operating-system position to disadvantage competing technologies.

Relevance to identity federation

A dominant platform controlling authentication infrastructure could similarly use control over a platform layer to disadvantage competing identity providers.

The case illustrates the importance of examining:

  • platform control;
  • technical restrictions;
  • interoperability;
  • exclusionary effects;
  • barriers to entry.

2. Bronner v. Mediaprint (CJEU, Case C-7/97)

This case established the strict conditions under which refusal to provide access to infrastructure can amount to abuse of dominance.

The Court emphasised the exceptional nature of compulsory access.

Relevance

Where a dominant identity federation refuses interoperability, Bronner provides an important framework for asking:

  1. Is access indispensable?
  2. Is there a viable alternative?
  3. Would refusal eliminate effective competition?
  4. Is refusal objectively justified?

Thus, identity infrastructure should not automatically be classified as an essential facility merely because it is commercially important.

3. Slovak Telekom v Commission (CJEU, Joined Cases C-165/19 P and C-166/19 P)

The case concerned access to telecommunications infrastructure and the application of Article 102 TFEU.

Relevance

Identity federation may similarly involve a dominant infrastructure operator providing access to downstream competitors.

The case is useful for analysing:

  • access obligations;
  • foreclosure;
  • infrastructure dependence;
  • margin squeeze;
  • the relationship between sector-specific regulation and Article 102.

4. Google Shopping (Commission / General Court)

The Google Shopping litigation concerned the preferential treatment of Google's comparison-shopping service within its general search results.

Relevance

The underlying principle is highly relevant to identity federation:

A vertically integrated platform controlling an important gateway may have the ability and incentive to favour its own downstream service.

An identity provider could potentially favour its own:

  • payment service;
  • marketplace;
  • cloud platform;
  • advertising ecosystem;
  • authentication product.

The case therefore provides an important self-preferencing and leveraging analogy.

5. Google Android (Commission Decision, General Court)

The Android proceedings concerned Google's contractual arrangements involving mobile-device manufacturers, including restrictions relating to Google's services.

Relevance

The case demonstrates how control over one digital layer can reinforce power in adjacent layers.

For identity federation, the analogous structure could be:

Operating system → default identity service → downstream applications.

The case is particularly relevant to:

  • defaults;
  • tying;
  • pre-installation;
  • ecosystem leverage;
  • barriers to rival entry.

6. Google Search (Shopping) and Google Android as Ecosystem Cases

Taken together, the Google cases demonstrate that competition analysis increasingly considers ecosystem architecture rather than isolated products.

For digital identity, the relevant competitive unit may therefore be:

identity + authentication + attributes + platform + data + downstream services

rather than merely the authentication transaction.

7. IMS Health (CJEU, Case C-418/01)

IMS Health concerned access to an industry-standard data structure and the circumstances in which refusal to license intellectual property could constitute abuse.

Relevance

Identity federation may similarly develop a standardised technical structure upon which competing services depend.

IMS Health is relevant where:

  • a proprietary format becomes unavoidable;
  • interoperability depends on access;
  • alternative technical solutions are commercially impractical;
  • refusal threatens elimination of competition.

8. Huawei Technologies v ZTE (CJEU, Case C-170/13)

Huawei v ZTE concerned standard-essential patents and the interaction between intellectual-property rights and competition law.

Relevance

Identity federations may use standardised authentication protocols and proprietary technologies.

The case is useful when analysing:

  • standards;
  • interoperability;
  • licensing;
  • FRAND-type obligations;
  • strategic control over essential technology.

It demonstrates that standardisation and intellectual-property rights can generate competition-law issues when rivals depend upon standardised technology.

27. Comparative Case-Law Principles

Competition issueRelevant authority
Refusal of accessBronner
Infrastructure accessSlovak Telekom
Platform foreclosureMicrosoft
Self-preferencingGoogle Shopping
Defaults and ecosystem leverageGoogle Android
Standardised proprietary infrastructureIMS Health
Standards and interoperabilityHuawei v ZTE

These cases do not establish that digital identity federation itself is unlawful. Rather, they provide analytical tools for assessing specific conduct.

28. Applying Competition Law to a Hypothetical Identity Federation

Assume Federation X controls 70% of federated authentication for major online services.

It then introduces a rule:

All relying parties using Federation X must use X's payment service.

This raises several possible theories.

Step 1 — Relevant market

Possible market:

Federated digital authentication services.

Step 2 — Dominance

The authority would examine:

  • market share;
  • network effects;
  • switching costs;
  • entry barriers;
  • data advantages;
  • interoperability.

Step 3 — Tying

Identity authentication is potentially the tying product.

Payment processing is the tied product.

Step 4 — Foreclosure

The authority asks whether rival payment providers are substantially disadvantaged.

Step 5 — Objective justification

Federation X may argue that integrated payment and identity systems improve:

  • fraud prevention;
  • security;
  • consumer protection.

Step 6 — Proportionality

The authority should consider whether less restrictive methods could achieve the same security objective.

29. Regulatory Remedies

Competition authorities may consider several remedies.

A. Interoperability requirements

Require the dominant federation to permit technically reasonable interoperability.

B. Data portability

Enable users and businesses to move relevant identity information.

C. API access

Require non-discriminatory access to necessary interfaces.

D. Non-discrimination

Prevent preferential treatment of affiliated services.

E. Multi-homing

Prevent contractual or technical restrictions that unnecessarily prevent users from employing multiple identity providers.

F. Structural separation

In extreme circumstances, identity infrastructure could be separated from downstream commercial services.

G. Transparency

Require disclosure of technical access conditions and federation rules.

H. Governance safeguards

Independent governance can reduce the ability of a dominant participant to manipulate federation standards.

30. Key Legal Tests

A competition authority examining digital identity federation should ask:

Market power

  • Who controls authentication?
  • How many users and relying parties participate?
  • Are network effects significant?

Entry

  • Can a new federation attract users?
  • Can it obtain equivalent trust certification?
  • Can it reach sufficient scale?

Interoperability

  • Can rival identity providers connect?
  • Is access technically feasible?
  • Is access commercially reasonable?

Data

  • Does the incumbent possess uniquely valuable identity data?
  • Can rivals obtain comparable data?

Lock-in

  • What does migration cost?
  • Can users and businesses multi-home?

Conduct

  • Is there tying?
  • Bundling?
  • Self-preferencing?
  • Exclusivity?
  • Discrimination?
  • Refusal to deal?
  • Predatory pricing?
  • Margin squeeze?

Justification

  • Is the restriction necessary for security?
  • Is it proportionate?
  • Are less restrictive alternatives available?

31. Key Distinction: Security vs Competition

Identity federation creates an unusual antitrust problem because security can legitimately require centralisation.

For example, a federation might reasonably require:

  • rigorous certification;
  • identity assurance levels;
  • encryption standards;
  • fraud controls;
  • audit requirements.

Competition law should therefore avoid treating every interoperability restriction as exclusionary.

The crucial question is:

Is the restriction genuinely necessary for identity security, or is security being used as a pretext to protect market power?

This distinction will become increasingly important as AI-driven authentication and biometric verification become widespread.

32. Emerging Competition Concerns

Future identity ecosystems may involve:

  • AI-generated identity agents;
  • biometric wallets;
  • decentralised identifiers;
  • verifiable credentials;
  • government digital-ID systems;
  • bank-issued identities;
  • telecom identities;
  • platform identities;
  • cross-border identity federation.

Competition issues may consequently move from traditional authentication toward control over the identity trust layer itself.

A dominant identity provider could potentially become a digital gatekeeper, determining which individuals, businesses, credentials, and services are trusted throughout an ecosystem.

Conclusion

Digital identity federation can be highly pro-competitive because interoperability reduces friction and allows users to authenticate across multiple services. However, the same network effects can transform an identity provider into a powerful digital infrastructure gatekeeper.

The principal competition risks are:

  1. dominance over authentication infrastructure;
  2. refusal to interoperate;
  3. discriminatory access;
  4. self-preferencing;
  5. tying and bundling;
  6. exclusive federation agreements;
  7. identity-data concentration;
  8. user and business lock-in;
  9. default manipulation;
  10. control over technical standards;
  11. leveraging identity power into adjacent markets; and
  12. foreclosure of competing identity providers.

The most appropriate legal approach is therefore effects-based rather than infrastructure-based. Digital identity federation should not be condemned merely because it is concentrated. The central inquiry should be whether control over the identity layer is being used to exclude rivals, exploit dependent users, or extend market power into neighbouring digital markets without adequate objective justification.

LEAVE A COMMENT