Digital Identity-Linked Finance Systems And Universal Control Risks .
Digital Identity Wallet Competition Internationally
Introduction
Digital identity wallets are applications or devices that allow individuals and businesses to store, manage, present and sometimes selectively disclose verified identity credentials—such as government identification, driving licences, professional qualifications, payment credentials, health records or age-verification attributes.
From a competition-law perspective, the important issue is not merely whether several wallets exist. The deeper question is whether control over identity credentials, verification infrastructure, operating systems, app stores, authentication interfaces, trust frameworks or government-recognised credentials allows one undertaking or ecosystem to restrict competing wallets.
Internationally, competition concerns can arise through:
operating-system control;
mandatory use of a proprietary wallet;
exclusion from NFC or secure-element functionality;
app-store restrictions;
discriminatory access to APIs;
control over identity-verification standards;
interoperability restrictions;
tying identity wallets to payment or other services;
preferential treatment of affiliated identity providers;
data accumulation and portability barriers;
government procurement and certification advantages;
network effects and switching costs; and
cross-border incompatibility between national identity systems.
1. Meaning and Economic Structure of Digital Identity Wallet Competition
A digital identity wallet ecosystem normally contains several layers:
Government / trusted issuer → Identity credential → Wallet → Operating system/device → Verification service → Relying party
For example, a government may issue a digitally signed identity credential. The citizen stores it in a wallet. A bank, airline, employer or online platform then requests particular attributes from that wallet.
Competition may therefore occur at several different levels:
A. Wallet layer
Different companies may compete to provide the application through which credentials are stored and presented.
B. Credential layer
Competition can concern who is permitted to issue or verify credentials.
C. Infrastructure layer
Secure elements, hardware-backed authentication, identity APIs and cryptographic infrastructure can become bottlenecks.
D. Verification layer
Businesses may compete to provide identity verification and authentication services.
E. Operating-system layer
Mobile operating systems can determine which wallets obtain access to NFC, biometrics, secure elements, background authentication and other technical functions.
F. Government/public-infrastructure layer
Where governments mandate a particular identity architecture, private competitors may face difficulties entering complementary markets.
2. Why Digital Identity Wallets Can Generate Market Power
A. Strong network effects
The value of a wallet increases as more:
citizens use it;
governments issue credentials compatible with it;
banks accept it;
merchants accept it;
websites integrate it; and
service providers rely upon it.
This creates a classic two-sided or multi-sided network.
A dominant wallet can therefore become difficult to challenge even without charging users a monetary price.
B. Data advantages
Identity wallets potentially generate highly valuable information concerning:
authentication;
age;
location;
professional status;
financial relationships;
device usage;
verification history; and
interaction with relying parties.
A dominant provider may therefore obtain a data advantage that reinforces its position in adjacent markets.
C. Switching costs
Users may be reluctant to switch where moving between wallets requires:
re-verification;
reissuance of credentials;
repeated KYC;
loss of stored credentials;
reconfiguration of relying-party relationships; or
incompatible government credentials.
Consequently, credential portability becomes a competition issue.
3. Operating-System Gatekeeping
One of the most significant international competition concerns is the relationship between identity wallets and mobile operating systems.
An operating-system provider may control:
NFC;
secure elements;
biometric authentication;
device attestation;
application permissions;
default applications;
app-store distribution; and
APIs necessary for identity functions.
If the OS provider gives its own wallet privileged technical access while restricting rivals, the conduct can resemble self-preferencing or discriminatory access.
The competition-law question is not simply whether the proprietary wallet is better. It is whether the technical restrictions artificially protect the OS provider's downstream wallet from competition.
4. Tying and Bundling
A powerful technology company could potentially bundle:
operating system + device + authentication + identity wallet + payment service.
Suppose a consumer purchasing a smartphone automatically receives a proprietary identity wallet, while competing wallets cannot access the same security functionality.
This could raise concerns under:
tying;
bundling;
leveraging;
exclusionary discrimination; and
abuse of dominance.
The competitive harm becomes greater where identity authentication is necessary to participate in another digital market.
5. Interoperability as a Competition Principle
Interoperability is particularly important for digital identity.
A competitive ecosystem should ideally permit a person to move or use credentials across compatible wallets without unnecessary re-verification.
Potentially anticompetitive restrictions include:
refusing interoperability;
limiting API access;
restricting credential export;
withholding technical specifications;
imposing discriminatory certification requirements;
preventing competing wallets from communicating with government systems; and
making third-party wallets technically inferior.
Interoperability can therefore operate as a market-opening remedy.
6. International Competition-Law Case Laws
Because digital identity wallets are relatively new, there are comparatively few decisions directly concerning them. The most useful precedents therefore come from adjacent digital-platform, interoperability, tying, essential-facility and discrimination cases.
Case 1 — Google Android, European Commission
Google Android (Case AT.40099, European Commission, 2018)
The European Commission found several forms of Google's conduct concerning Android devices abusive, including tying Google Search and Chrome to the Play Store and restrictions concerning competing Android versions.
Relevance to identity wallets
The case demonstrates how control over a mobile operating system can be leveraged into adjacent digital markets.
For digital identity wallets, the analogous concern would arise if an OS provider:
privileged its own identity wallet;
restricted competing wallets;
tied wallet functionality to another service; or
prevented manufacturers from supporting rival identity architectures.
The central lesson is that ecosystem control can create downstream exclusion even when the underlying operating system itself is not the downstream product being investigated.
Case 2 — Google Shopping, European Commission
Google Search (Shopping) (Case AT.39740, European Commission, 2017; subsequent EU judicial proceedings)
The European Commission found that Google had given systematic prominence to its own comparison-shopping service in general search results while demoting competing services.
Relevance
The precedent is important for self-preferencing.
A dominant digital identity ecosystem could theoretically prefer its own wallet or verification service by:
placing it as the default;
giving it superior authentication interfaces;
displaying it more prominently;
providing faster APIs;
giving it privileged access to device functions; or
making rival wallets harder to select.
The legal question would be whether such preferential treatment departs from competition on the merits and produces exclusionary effects.
Case 3 — Microsoft v Commission
Microsoft Corp. v Commission (Case T-201/04, General Court, 2007)
The Microsoft litigation concerned Microsoft's dominance in PC operating systems and its refusal to provide interoperability information needed by competing work-group server products, as well as tying Windows Media Player to Windows.
Relevance
This is particularly important for digital identity wallets because interoperability information can itself become competitively significant.
If a dominant operating-system or identity infrastructure provider controls technical information necessary for competing wallets to function effectively, a refusal or discriminatory restriction may raise concerns similar to those examined in Microsoft.
The case provides a foundation for analysing:
interoperability;
refusal to supply technical information;
leveraging;
tying; and
foreclosure of adjacent markets.
Case 4 — IMS Health
IMS Health GmbH & Co. OHG v NDC Health GmbH & Co KG (Joined Cases C-418/01 P and C-419/01 P, Court of Justice of the European Union, 2004)
The case concerned access to a commercially significant data structure and the circumstances in which refusal of access to an indispensable resource could constitute an abuse.
The Court developed demanding conditions around compulsory access.
Relevance
Digital identity systems can produce highly standardised identity infrastructures.
Where one undertaking controls an identity infrastructure that competitors genuinely cannot replicate, questions may arise about whether access constitutes an essential facility-type issue.
However, IMS Health cautions against automatically requiring dominant firms to share infrastructure. The resource must satisfy stringent legal conditions before compulsory access is justified.
Case 5 — Slovak Telekom
Slovak Telekom a.s. v European Commission (Joined Cases C-152/19 P and C-165/19 P, CJEU, 2021)
The case involved exclusionary conduct concerning access to telecommunications infrastructure.
Relevance
Digital identity ecosystems may similarly involve infrastructure controlled by a vertically integrated undertaking.
A dominant provider might control:
authentication infrastructure → API → wallet → verification service.
If rivals require access to an upstream infrastructure layer to compete downstream, competition authorities may examine whether access restrictions constitute exclusionary conduct.
The case is therefore useful for analysing vertical foreclosure and infrastructure access.
Case 6 — Apple App Store / Epic Games
Epic Games, Inc. v Apple Inc. (U.S. District Court, Northern District of California, 2021)
The litigation concerned Apple's App Store rules, distribution restrictions and payment-system requirements.
Relevance to identity wallets
The case illustrates the competition implications of controlling an important digital distribution gateway.
For identity wallets, app-store control can become relevant where:
competing wallets depend upon app-store distribution;
the platform imposes discriminatory rules;
identity functionality is subject to special permissions;
competing authentication services are restricted; or
the platform favours its own wallet.
The broader principle is that control over distribution can become a competitive bottleneck even where competing products technically exist.
Case 7 — Epic Games v Google
Epic Games, Inc. v Google LLC (U.S. District Court, Northern District of California, 2023)
The case examined Google's Android ecosystem, Google Play distribution and payment-related restrictions.
Relevance
The decision is useful for analysing ecosystem-based competition where the platform operator simultaneously controls:
operating-system architecture;
application distribution;
payment infrastructure; and
commercial relationships with developers.
An identity-wallet ecosystem can reproduce this structure if a company controls both the mobile platform and identity wallet.
Case 8 — Mastercard v Commission
Mastercard Inc. v Commission (Case C-382/12 P, CJEU, 2014)
The case concerned restrictions in the payment-card ecosystem and the assessment of competition effects.
Relevance
Digital identity wallets increasingly interact with:
payments;
banking;
authentication;
KYC;
age verification; and
financial identity.
Mastercard demonstrates the importance of analysing network effects and restrictions within multi-sided infrastructures, rather than examining a single transaction in isolation.
7. European Union Approach
The EU regulatory environment is particularly important because digital identity sits at the intersection of competition, data protection and digital-platform regulation.
Relevant instruments include:
Article 101 TFEU — restrictive agreements;
Article 102 TFEU — abuse of dominance;
Digital Markets Act (DMA);
GDPR;
eIDAS / European Digital Identity framework; and
national competition laws.
The European Digital Identity framework seeks to establish interoperable digital identity wallets across the EU.
From a competition perspective, interoperability can reduce the ability of a single technical provider to establish an exclusive identity ecosystem.
8. United States Approach
In the United States, digital identity-wallet competition could potentially involve:
Sherman Act §1 — agreements restricting competition;
Sherman Act §2 — monopolisation and attempted monopolisation;
Clayton Act §3 — certain exclusive-dealing arrangements;
FTC Act §5;
state competition laws; and
sector-specific financial and privacy regulation.
The most relevant precedents are likely to come from:
platform distribution;
mobile operating systems;
payment systems;
authentication;
interoperability; and
digital advertising.
The U.S. approach generally requires careful examination of market definition, market power, exclusionary conduct and competitive effects.
9. United Kingdom
Under UK competition law, digital identity wallet conduct could primarily engage:
Competition Act 1998, Chapter II
This prohibits abuse of a dominant position.
Potential theories include:
discriminatory access;
refusal to supply;
tying;
self-preferencing;
exclusionary interoperability restrictions;
predatory or exclusionary conduct; and
leveraging dominance from operating systems into identity services.
The Digital Markets, Competition and Consumers Act 2024 also creates a broader framework for firms designated with strategic market status.
A firm with substantial strategic power over a mobile or digital ecosystem could therefore face obligations affecting interoperability and competitive access.
10. Germany
Germany is particularly significant because §19a GWB gives the Bundeskartellamt enhanced powers concerning undertakings of paramount significance across markets.
Digital identity wallets could become relevant where a large ecosystem operator possesses:
extensive user data;
operating-system power;
app-store power;
cloud infrastructure;
payment services; and
identity/authentication capabilities.
The German approach is therefore capable of addressing ecosystem-wide leveraging, rather than requiring competition authorities to look at each individual market completely in isolation.
11. India
In India, the competition analysis would primarily involve the Competition Act 2002, particularly:
Section 3 — anti-competitive agreements;
Section 4 — abuse of dominant position;
Section 19 — investigation by the CCI; and
Section 26 — investigation procedure.
Digital identity competition can be particularly complex because identity infrastructure may involve substantial government participation.
The analytical distinction should be made between:
government identity infrastructure and competitive private-sector services built around that infrastructure.
A government-backed identity system does not automatically mean that every adjacent identity-wallet market is monopolised. However, preferential government access, mandatory technical standards, exclusionary certification or discriminatory interoperability could affect competition.
12. State-Backed Digital Identity Monopolies
A special concern arises when the state establishes a single official identity wallet.
There can be legitimate reasons for doing so:
security;
fraud prevention;
authentication reliability;
privacy;
national security;
administrative efficiency; and
standardisation.
But competition concerns arise where the government-controlled infrastructure also becomes the gateway to commercial services.
For example:
State identity → mandatory wallet → bank authentication → insurance → healthcare → employment → payments
At that point, the identity wallet can become a universal gatekeeper.
13. Government Procurement and Competitive Neutrality
Government procurement can also affect the market.
A government may award the identity-wallet infrastructure to one technology company.
Competition concerns can arise if:
procurement specifications unnecessarily favour the incumbent;
interoperability requirements are weak;
proprietary technology becomes mandatory;
competitors cannot obtain certification;
switching is technically difficult; or
government contracts create an entrenched installed base.
The appropriate approach is therefore competitive neutrality and technology-neutral procurement.
14. Data Portability
Data portability is particularly important.
A user should ideally be able to move:
identity credentials;
verified attributes;
certificates;
permissions;
authentication history; and
relevant wallet information
between compatible providers.
Without portability, the wallet provider may acquire a form of digital identity lock-in.
This can reinforce network effects because users remain with the incumbent simply because leaving would require rebuilding their digital identity relationships.
15. Privacy and Competition Can Reinforce Each Other
Digital identity competition cannot be analysed solely through price.
Users may compete over:
privacy;
security;
data minimisation;
anonymity;
selective disclosure;
credential portability;
transparency; and
control over personal data.
A wallet that collects excessive data may therefore compete differently from a privacy-preserving wallet.
Consequently, quality competition becomes important.
Competition authorities should examine whether exclusionary conduct reduces:
privacy + security + interoperability + innovation
even where monetary prices remain zero.
16. Cross-Border Competition
International fragmentation creates another problem.
A European wallet may not seamlessly work with:
an Indian identity infrastructure;
a U.S. authentication provider;
an Asian payment ecosystem; or
another national credential system.
This can create identity interoperability barriers.
Large global technology companies may exploit these differences by offering a universal proprietary identity layer connecting otherwise fragmented national systems.
This creates a paradox:
Interoperability can increase competition within each market, but the company controlling the interoperability layer can itself become a new global gatekeeper.
17. Potential Anticompetitive Conduct
| Conduct | Possible competition concern |
|---|---|
| Exclusive government wallet | Foreclosure |
| OS blocking rival wallets | Abuse of dominance |
| Proprietary identity API | Access discrimination |
| Default-wallet preference | Self-preferencing |
| Mandatory wallet bundling | Tying |
| Credential export restrictions | Switching-cost exploitation |
| Exclusive verification agreements | Foreclosure |
| Discriminatory certification | Entry barrier |
| Preferential biometric access | Technical discrimination |
| Proprietary secure-element access | Essential-input concerns |
| Identity-data accumulation | Data-based market power |
| Cross-border interoperability restrictions | Market fragmentation |
18. Competition-Friendly Regulatory Model
A robust international framework should encourage:
1. Open standards
Technical standards should be sufficiently interoperable to permit competing wallets.
2. Credential portability
Users should not be unnecessarily trapped within one wallet.
3. Non-discriminatory API access
Comparable wallets should receive comparable technical access.
4. Device neutrality
Operating systems should not arbitrarily prevent legitimate competing wallets from functioning.
5. Transparent certification
Government certification should be based on objective security and privacy criteria.
6. Data minimisation
Competition should not depend upon collecting excessive identity information.
7. Multi-wallet compatibility
A user should be capable of maintaining multiple identity credentials/wallets where security permits.
8. Competitive procurement
Public authorities should avoid unnecessarily proprietary technical specifications.
19. Central Legal Test
The most important analytical question is:
Does control over digital identity infrastructure constitute legitimate security architecture, or is it being used as a mechanism to exclude competing identity services?
Competition authorities should examine:
relevant market;
market power;
control over essential technical inputs;
network effects;
interoperability;
switching costs;
foreclosure of rivals;
effects on innovation;
privacy and quality effects;
legitimate security justifications;
proportionality; and
whether less restrictive alternatives exist.
Conclusion
Digital identity wallet competition internationally is fundamentally an ecosystem and infrastructure competition issue. The wallet itself may be only the visible layer of a much larger structure involving operating systems, secure hardware, APIs, government credentials, verification services, payment systems and data.
The strongest existing precedents come from adjacent digital-platform and infrastructure cases such as Microsoft, Google Android, Google Shopping, IMS Health, Slovak Telekom, Epic Games v Apple and Epic Games v Google. These cases collectively demonstrate that competition law can scrutinise tying, self-preferencing, interoperability restrictions, infrastructure access, distribution control and ecosystem leverage.
The future competition question will increasingly be whether a digital identity wallet becomes merely a convenient credential-management tool—or evolves into a universal digital gatekeeper controlling access to government, financial, commercial and social services. If the latter occurs, interoperability, portability, non-discrimination and competitive neutrality will become central safeguards against identity-infrastructure monopolisation.

comments