Digital Identity Infrastructure As State-Backed Monopoly Risk .
Digital Identity Infrastructure as State-Backed Monopoly Risk
Introduction
Digital identity infrastructure refers to the technological and institutional systems through which individuals and organisations are authenticated and identified for access to public and private services. Examples include national digital-ID systems, government authentication credentials, identity registries, biometric databases, digital signatures, federated identity systems and state-backed authentication gateways.
A state-backed digital identity monopoly arises when the State either directly operates, or gives one infrastructure provider privileged control over, an identity layer that becomes indispensable for participation in downstream markets. The competition concern is not simply that the State has a monopoly. Public authorities may legitimately operate certain identification functions. The problem arises where exclusive control over identity infrastructure is leveraged into adjacent commercial or digital markets, or where competitors cannot realistically enter without access to the state-controlled identity layer.
The issue therefore sits at the intersection of:
- competition law;
- administrative and constitutional law;
- essential-facilities principles;
- non-discrimination;
- interoperability;
- data access and portability;
- public procurement;
- privacy and data protection;
- digital-platform regulation; and
- state-aid/subsidy principles.
1. Meaning of Digital Identity Infrastructure
Digital identity infrastructure can include:
- Identity registries — authoritative databases containing identity attributes.
- Authentication systems — mechanisms establishing that a person is who they claim to be.
- Biometric infrastructure — fingerprints, facial recognition, iris recognition and similar identifiers.
- Digital credentials — electronic certificates, identity tokens and verifiable credentials.
- Digital signatures — mechanisms allowing legally recognised electronic authentication.
- Federation systems — systems allowing one identity credential to authenticate a person across numerous services.
- Identity APIs — interfaces allowing banks, platforms, healthcare providers and other businesses to verify identity.
- Trust frameworks — accreditation and certification systems determining which identity providers are accepted.
- Identity wallets — applications storing government-issued or government-recognised credentials.
The competitive significance increases where one identity layer becomes the gateway through which other markets must operate.
2. How State Backing Can Produce Monopoly Power
State backing can create competitive advantages that would be difficult for an ordinary private firm to obtain.
A. Legal exclusivity
Legislation may designate one identity system as the authoritative mechanism for authentication.
Competitors may therefore be unable to reproduce the same legal status.
B. Mandatory use
If banks, telecommunications companies, healthcare providers or public-service platforms are required to use a particular identity infrastructure, demand is effectively guaranteed.
C. Network effects
The more organisations that accept a digital identity, the more valuable that identity becomes.
This can generate:
Users → service providers → authentication acceptance → more users → more service providers.
D. Data advantage
A state identity infrastructure can accumulate extraordinarily valuable identity information.
Competitors may lack comparable datasets because:
- identity information is legally restricted;
- biometric information cannot easily be replicated;
- public records may be inaccessible;
- individuals cannot practically create equivalent authoritative credentials.
E. Regulatory endorsement
Government certification itself can become a competitive advantage.
A provider designated as an official or trusted identity provider may be perceived as inherently safer or legally superior.
3. The Relevant Competition-Law Problem
The central question is not:
"Does the government have a monopoly?"
Instead, the competition-law question is:
Has control over an indispensable identity infrastructure been used to distort competition in markets that depend upon that infrastructure?
Potential theories include:
- abuse of dominance;
- refusal to supply;
- discriminatory access;
- tying;
- leveraging;
- exclusionary interoperability restrictions;
- discriminatory technical standards;
- self-preferencing;
- excessive access charges;
- foreclosure of competing identity providers;
- exclusionary certification;
- predatory subsidisation of downstream services;
- discriminatory procurement;
- interoperability denial.
4. Defining the Relevant Market
Several markets may need to be distinguished.
Upstream market
Digital identity infrastructure
This could include:
- identity verification;
- authentication;
- digital credentials;
- biometric verification;
- identity federation.
Intermediate market
Identity-as-a-service
Private companies may provide:
- KYC services;
- authentication APIs;
- credential verification;
- digital signatures.
Downstream markets
Identity infrastructure may provide access to:
- banking;
- fintech;
- telecommunications;
- e-commerce;
- healthcare;
- government services;
- employment platforms;
- insurance;
- digital payments.
A crucial competition-law question is whether the government-backed system is an essential gateway between upstream identity infrastructure and downstream commercial markets.
5. Essential-Facility Theory
The closest competition-law analogy is the essential-facilities doctrine.
The classic requirements generally involve:
- control of infrastructure by a dominant undertaking;
- inability or substantial difficulty for competitors to duplicate it;
- indispensability for competing in a downstream market;
- refusal of access;
- absence of objective justification; and
- potential elimination or substantial restriction of effective competition.
However, applying the doctrine to state identity infrastructure requires caution.
An identity system may be:
- legally unique;
- technically difficult to duplicate;
- based on sovereign records;
- impossible for private competitors to recreate.
This can make the indispensability element particularly powerful.
6. State Monopoly Does Not Automatically Equal Antitrust Abuse
A critical distinction must be maintained.
A government may legitimately reserve certain sovereign functions to itself.
For example, it may legitimately determine:
- who possesses a legal identity;
- which identity documents are authoritative;
- citizenship status;
- official population records;
- issuance of passports;
- national-security authentication.
Competition law becomes more significant when those sovereign functions are combined with commercial activities.
For example:
State identity authority → mandatory authentication → government-controlled commercial authentication service → exclusion of independent authentication providers.
The final stages create a much stronger competition concern than the mere existence of a national identity register.
7. Leveraging into Adjacent Markets
Suppose a state-controlled identity system becomes mandatory for accessing banking services.
The authority then also operates a digital-payment platform.
If competing payment providers cannot access the identity system on equivalent terms, the identity monopoly can potentially be leveraged into payments.
The structure becomes:
Identity monopoly → mandatory authentication → restricted access → downstream foreclosure → strengthened payment-market position.
This is a classic leveraging concern.
8. Discriminatory Access
One of the most significant risks is discriminatory access.
The state-backed infrastructure might provide:
- faster APIs to affiliated entities;
- cheaper verification to government-linked companies;
- superior technical documentation to preferred firms;
- greater authentication limits to incumbents;
- preferential access to new identity attributes.
Even apparently neutral technical rules may have exclusionary effects.
For example, an API limit that is manageable for large banks but impossible for small fintech firms may indirectly protect incumbents.
9. Interoperability as a Competition Remedy
Interoperability is particularly important.
A competition authority may consider requiring:
- open APIs;
- common technical standards;
- non-discriminatory authentication;
- portability of credentials;
- interoperable identity wallets;
- transparent certification;
- equivalent access terms.
The objective is not necessarily to eliminate the government system.
Instead, it is to prevent infrastructure ownership from becoming downstream market foreclosure.
10. Data as a Source of Market Power
Digital identity systems create another important competition issue: identity data.
The infrastructure may contain:
- verified name;
- age;
- address;
- nationality;
- biometric identifiers;
- authentication history;
- organisational affiliation.
Competitors cannot necessarily reproduce these datasets.
Consequently, the combination of:
legal authority + identity data + authentication infrastructure
can create a particularly durable form of market power.
Data protection law can simultaneously restrict indiscriminate disclosure, meaning that competition remedies must be designed carefully.
11. Network Effects and Tipping
Identity infrastructure exhibits strong network effects.
A provider becomes more valuable when more:
- citizens use it;
- banks accept it;
- websites integrate it;
- government agencies recognise it;
- merchants depend upon it.
Once a system reaches sufficient scale, migration becomes expensive.
Users may have to:
- re-register;
- verify their identity again;
- replace credentials;
- reconnect financial accounts;
- update government records.
This creates identity-layer lock-in.
12. Switching Costs
Identity switching can be more difficult than switching ordinary digital platforms.
For example:
Customer changes social-media platform → relatively easy.
But:
Customer changes identity provider → government verification, bank authentication, professional credentials and other services may need to be re-established.
Therefore identity infrastructure can generate unusually high switching costs.
13. Competition Between State and Private Providers
A particularly sensitive problem arises where the State is simultaneously:
- regulator;
- infrastructure owner;
- identity certifier;
- purchaser of identity services; and
- competitor in downstream markets.
This creates a potential institutional conflict of interest.
A state authority could establish technical requirements that favour its own identity infrastructure.
Competition safeguards therefore may require:
- institutional separation;
- transparent technical standards;
- independent supervision;
- non-discriminatory licensing;
- objective certification criteria.
14. Case Laws
The following cases provide useful doctrinal foundations for analysing state-backed digital identity monopolies.
1. United Brands v Commission — C-27/76
The European Court of Justice established important principles concerning dominance and the possibility that a dominant undertaking may possess substantial economic power enabling it to behave independently of competitors and customers.
Relevance
A state-backed identity infrastructure could possess dominance where organisations cannot realistically avoid using it.
The case is particularly useful for understanding:
- market power;
- dominance;
- dependence;
- exclusionary conduct.
2. Commercial Solvents v Commission — Joined Cases 6/73 and 7/73
Commercial Solvents concerned the use of dominance in an upstream market to exclude competitors in a downstream market.
Relevance
It provides a strong conceptual foundation for analysing:
identity infrastructure → downstream digital services.
If a dominant identity provider restricts access to an essential upstream input in order to strengthen its own downstream position, the conduct may raise leveraging concerns.
3. Bronner v Mediaprint — C-7/97
Bronner is one of the leading EU cases concerning refusal of access to infrastructure under Article 102 TFEU.
The Court applied a demanding test for treating an infrastructure as indispensable.
Relevance
Digital identity infrastructure could potentially satisfy the indispensability requirement where:
- the infrastructure is uniquely authoritative;
- duplication is legally or practically impossible;
- competitors cannot operate effectively without it.
Bronner therefore provides the framework for assessing whether identity infrastructure should be treated as an essential facility.
4. IMS Health v Commission — C-418/01 P
IMS Health concerned access to a commercially controlled information structure that competitors needed to compete effectively.
The case developed the circumstances in which refusal to license or provide access to an indispensable resource could constitute abuse.
Relevance
The analogy is particularly strong for identity infrastructure containing unique datasets.
Where competitors cannot realistically recreate:
- verified identity records;
- authoritative identity attributes;
- legally recognised authentication;
the IMS Health framework becomes highly relevant.
5. Microsoft v Commission — Case T-201/04
Microsoft concerned, among other things, refusal to provide interoperability information and the resulting effects on competing products.
Relevance
This case is highly relevant to digital identity systems because interoperability can determine whether competitors can effectively participate.
A state-backed identity provider could potentially foreclose competitors by controlling:
- APIs;
- authentication protocols;
- interoperability specifications;
- technical certification.
The Microsoft reasoning demonstrates why interoperability restrictions can have competition consequences.
6. Slovak Telekom v Commission — Joined Cases C-165/19 P and C-166/19 P
The case concerned access to telecommunications infrastructure and the relationship between dominance and exclusionary conduct.
Relevance
Its broader importance lies in analysing infrastructure access where the dominant operator controls an input necessary for competitors' downstream activities.
Digital identity systems can exhibit the same structural relationship:
identity infrastructure → downstream digital services.
7. MEO — Case C-525/16
MEO concerned discriminatory pricing by a dominant undertaking.
The Court emphasised that not every difference in treatment automatically constitutes an abuse; competitive effects remain important.
Relevance
This is useful where a state-backed identity infrastructure charges different:
- verification fees;
- API fees;
- authentication costs;
- certification charges
to different categories of identity providers.
The analysis should therefore distinguish legitimate differentiated pricing from discrimination capable of disadvantaging competition.
8. Google Shopping — Case T-612/17
The General Court examined Google's treatment of competing comparison-shopping services within its broader platform ecosystem.
Relevance
The case illustrates how control over a powerful gateway can be used to favour an affiliated downstream service.
The analogy for identity infrastructure is:
Identity gateway → preferential treatment of state-affiliated downstream service.
The important principle is that infrastructure control can have competitive consequences beyond the infrastructure market itself.
15. Public-Law Dimension
Digital identity monopolies are not purely competition-law problems.
They may also raise:
Administrative-law issues
- procedural fairness;
- transparency;
- reasoned decision-making;
- judicial review;
- proportionality.
Constitutional issues
Depending upon the jurisdiction:
- equality;
- privacy;
- informational autonomy;
- freedom of economic activity;
- due process.
Data-protection issues
Identity systems involve extremely sensitive information, making competition remedies subject to:
- purpose limitation;
- data minimisation;
- security requirements;
- lawful processing;
- access controls.
16. State-Aid and Subsidisation Concerns
A government may heavily subsidise its identity infrastructure.
Subsidisation is not automatically unlawful.
However, competition concerns become stronger where:
- the infrastructure receives preferential public financing;
- it competes with private providers;
- the subsidy is unavailable to competing infrastructure providers;
- costs are allocated selectively;
- the state-backed entity uses subsidised infrastructure to underprice downstream competitors.
The relevant question is whether public support creates an artificial competitive advantage rather than merely financing a legitimate public function.
17. Procurement Risks
Government procurement can reinforce monopoly structures.
For example:
Government selects one identity provider → all government departments adopt it → banks integrate with it → private businesses follow → competing identity providers lose scale → switching becomes increasingly costly.
A procurement decision can therefore create a de facto market standard even without formally declaring a monopoly.
Competition authorities should examine:
- exclusivity;
- contract duration;
- interoperability requirements;
- data ownership;
- switching obligations;
- API access;
- subcontracting restrictions.
18. Self-Preferencing Risk
Suppose a state-backed identity provider also operates:
- payments;
- healthcare platforms;
- tax services;
- financial authentication;
- e-commerce verification.
It could potentially favour its own downstream products through:
- superior API access;
- preferential authentication;
- lower verification costs;
- faster processing;
- exclusive identity attributes.
This creates a self-preferencing problem similar to other vertically integrated digital ecosystems.
19. Denial of Identity Portability
Portability is especially important because identity credentials may become deeply embedded in the user's digital life.
A competition-friendly system should ideally allow users to migrate without losing:
- authentication capability;
- verified credentials;
- legitimate attributes;
- professional identity;
- access to connected services.
However, portability must be reconciled with security and privacy requirements.
20. When State Monopoly May Be Justified
Not every identity monopoly should be dismantled.
A government may have legitimate reasons for maintaining exclusive control over:
- citizenship registers;
- national population registers;
- passports;
- sovereign credentials;
- national-security authentication;
- foundational identity records.
The appropriate competition response may therefore be regulated access rather than structural separation.
21. Possible Competition Remedies
A regulator could consider:
Structural remedies
- separation of identity infrastructure from downstream commercial services;
- independent governance;
- functional separation.
Behavioural remedies
- non-discriminatory access;
- transparent pricing;
- interoperability;
- API access;
- prohibition of self-preferencing.
Data remedies
- controlled access to verification attributes;
- portability;
- standardised credential formats.
Governance remedies
- independent technical oversight;
- transparent standards;
- auditability;
- regulatory neutrality.
Switching remedies
- interoperable credentials;
- migration mechanisms;
- prohibition of unreasonable exclusivity.
22. Competition-Law Test for Digital Identity Infrastructure
A useful analytical framework is:
Step 1 — Identify the infrastructure
What identity system is controlled by the State or state-backed provider?
Step 2 — Define the market
Is the relevant market:
- authentication;
- identity verification;
- digital credentials;
- identity federation;
- or a broader digital-services market?
Step 3 — Establish market power
Assess:
- legal exclusivity;
- network effects;
- user base;
- switching costs;
- data advantages;
- regulatory barriers.
Step 4 — Determine indispensability
Can competitors realistically duplicate or bypass the infrastructure?
Step 5 — Examine conduct
Look for:
- refusal to supply;
- discriminatory access;
- tying;
- interoperability restrictions;
- self-preferencing;
- excessive fees;
- exclusivity.
Step 6 — Examine downstream effects
Does the conduct:
- foreclose competitors;
- increase entry barriers;
- raise switching costs;
- reduce innovation;
- protect an affiliated provider?
Step 7 — Assess objective justification
Consider:
- national security;
- fraud prevention;
- privacy;
- cybersecurity;
- reliability;
- sovereign functions.
Step 8 — Select proportionate remedies
Prefer interoperability and non-discriminatory access where the sovereign identity function itself legitimately needs to remain under state control.
23. Central Legal Principle
The most important distinction is between:
State monopoly over sovereign identity
and
State-backed monopoly over identity infrastructure used as a commercial gateway.
The first can be a legitimate exercise of sovereign authority.
The second can become a competition-law problem when exclusive infrastructure control is leveraged to exclude competitors in adjacent markets.
Conclusion
Digital identity infrastructure can become an unusually powerful form of state-backed economic infrastructure because identity is upstream of numerous digital transactions. Unlike an ordinary platform, a state-backed identity system can possess advantages arising from legislation, compulsory usage, authoritative public records, network effects and legal recognition.
The principal competition concern is therefore not monopoly ownership in isolation. It is the possibility that:
State authority → exclusive identity infrastructure → mandatory adoption → interoperability control → data advantage → downstream leverage → competitor foreclosure.
The most appropriate legal response will often be regulated neutrality rather than forced privatisation. Sovereign identity functions may legitimately remain under public control, while competition can be protected through interoperability, non-discriminatory access, transparent standards, portability, independent governance and separation from downstream commercial activities.

comments