Digital Identity-Linked Finance Systems And Universal Control Risks .

Digital Identity Wallet Competition Internationally

Introduction

Digital identity wallets are applications or devices that allow individuals and businesses to store, manage, present and sometimes selectively disclose verified identity credentials—such as government identification, driving licences, professional qualifications, payment credentials, health records or age-verification attributes.

From a competition-law perspective, the important issue is not merely whether several wallets exist. The deeper question is whether control over identity credentials, verification infrastructure, operating systems, app stores, authentication interfaces, trust frameworks or government-recognised credentials allows one undertaking or ecosystem to restrict competing wallets.

Internationally, competition concerns can arise through:

operating-system control;

mandatory use of a proprietary wallet;

exclusion from NFC or secure-element functionality;

app-store restrictions;

discriminatory access to APIs;

control over identity-verification standards;

interoperability restrictions;

tying identity wallets to payment or other services;

preferential treatment of affiliated identity providers;

data accumulation and portability barriers;

government procurement and certification advantages;

network effects and switching costs; and

cross-border incompatibility between national identity systems.

1. Meaning and Economic Structure of Digital Identity Wallet Competition

A digital identity wallet ecosystem normally contains several layers:

Government / trusted issuer → Identity credential → Wallet → Operating system/device → Verification service → Relying party

For example, a government may issue a digitally signed identity credential. The citizen stores it in a wallet. A bank, airline, employer or online platform then requests particular attributes from that wallet.

Competition may therefore occur at several different levels:

A. Wallet layer

Different companies may compete to provide the application through which credentials are stored and presented.

B. Credential layer

Competition can concern who is permitted to issue or verify credentials.

C. Infrastructure layer

Secure elements, hardware-backed authentication, identity APIs and cryptographic infrastructure can become bottlenecks.

D. Verification layer

Businesses may compete to provide identity verification and authentication services.

E. Operating-system layer

Mobile operating systems can determine which wallets obtain access to NFC, biometrics, secure elements, background authentication and other technical functions.

F. Government/public-infrastructure layer

Where governments mandate a particular identity architecture, private competitors may face difficulties entering complementary markets.

2. Why Digital Identity Wallets Can Generate Market Power

A. Strong network effects

The value of a wallet increases as more:

citizens use it;

governments issue credentials compatible with it;

banks accept it;

merchants accept it;

websites integrate it; and

service providers rely upon it.

This creates a classic two-sided or multi-sided network.

A dominant wallet can therefore become difficult to challenge even without charging users a monetary price.

B. Data advantages

Identity wallets potentially generate highly valuable information concerning:

authentication;

age;

location;

professional status;

financial relationships;

device usage;

verification history; and

interaction with relying parties.

A dominant provider may therefore obtain a data advantage that reinforces its position in adjacent markets.

C. Switching costs

Users may be reluctant to switch where moving between wallets requires:

re-verification;

reissuance of credentials;

repeated KYC;

loss of stored credentials;

reconfiguration of relying-party relationships; or

incompatible government credentials.

Consequently, credential portability becomes a competition issue.

3. Operating-System Gatekeeping

One of the most significant international competition concerns is the relationship between identity wallets and mobile operating systems.

An operating-system provider may control:

NFC;

secure elements;

biometric authentication;

device attestation;

application permissions;

default applications;

app-store distribution; and

APIs necessary for identity functions.

If the OS provider gives its own wallet privileged technical access while restricting rivals, the conduct can resemble self-preferencing or discriminatory access.

The competition-law question is not simply whether the proprietary wallet is better. It is whether the technical restrictions artificially protect the OS provider's downstream wallet from competition.

4. Tying and Bundling

A powerful technology company could potentially bundle:

operating system + device + authentication + identity wallet + payment service.

Suppose a consumer purchasing a smartphone automatically receives a proprietary identity wallet, while competing wallets cannot access the same security functionality.

This could raise concerns under:

tying;

bundling;

leveraging;

exclusionary discrimination; and

abuse of dominance.

The competitive harm becomes greater where identity authentication is necessary to participate in another digital market.

5. Interoperability as a Competition Principle

Interoperability is particularly important for digital identity.

A competitive ecosystem should ideally permit a person to move or use credentials across compatible wallets without unnecessary re-verification.

Potentially anticompetitive restrictions include:

refusing interoperability;

limiting API access;

restricting credential export;

withholding technical specifications;

imposing discriminatory certification requirements;

preventing competing wallets from communicating with government systems; and

making third-party wallets technically inferior.

Interoperability can therefore operate as a market-opening remedy.

6. International Competition-Law Case Laws

Because digital identity wallets are relatively new, there are comparatively few decisions directly concerning them. The most useful precedents therefore come from adjacent digital-platform, interoperability, tying, essential-facility and discrimination cases.

Case 1 — Google Android, European Commission

Google Android (Case AT.40099, European Commission, 2018)

The European Commission found several forms of Google's conduct concerning Android devices abusive, including tying Google Search and Chrome to the Play Store and restrictions concerning competing Android versions.

Relevance to identity wallets

The case demonstrates how control over a mobile operating system can be leveraged into adjacent digital markets.

For digital identity wallets, the analogous concern would arise if an OS provider:

privileged its own identity wallet;

restricted competing wallets;

tied wallet functionality to another service; or

prevented manufacturers from supporting rival identity architectures.

The central lesson is that ecosystem control can create downstream exclusion even when the underlying operating system itself is not the downstream product being investigated.

Case 2 — Google Shopping, European Commission

Google Search (Shopping) (Case AT.39740, European Commission, 2017; subsequent EU judicial proceedings)

The European Commission found that Google had given systematic prominence to its own comparison-shopping service in general search results while demoting competing services.

Relevance

The precedent is important for self-preferencing.

A dominant digital identity ecosystem could theoretically prefer its own wallet or verification service by:

placing it as the default;

giving it superior authentication interfaces;

displaying it more prominently;

providing faster APIs;

giving it privileged access to device functions; or

making rival wallets harder to select.

The legal question would be whether such preferential treatment departs from competition on the merits and produces exclusionary effects.

Case 3 — Microsoft v Commission

Microsoft Corp. v Commission (Case T-201/04, General Court, 2007)

The Microsoft litigation concerned Microsoft's dominance in PC operating systems and its refusal to provide interoperability information needed by competing work-group server products, as well as tying Windows Media Player to Windows.

Relevance

This is particularly important for digital identity wallets because interoperability information can itself become competitively significant.

If a dominant operating-system or identity infrastructure provider controls technical information necessary for competing wallets to function effectively, a refusal or discriminatory restriction may raise concerns similar to those examined in Microsoft.

The case provides a foundation for analysing:

interoperability;

refusal to supply technical information;

leveraging;

tying; and

foreclosure of adjacent markets.

Case 4 — IMS Health

IMS Health GmbH & Co. OHG v NDC Health GmbH & Co KG (Joined Cases C-418/01 P and C-419/01 P, Court of Justice of the European Union, 2004)

The case concerned access to a commercially significant data structure and the circumstances in which refusal of access to an indispensable resource could constitute an abuse.

The Court developed demanding conditions around compulsory access.

Relevance

Digital identity systems can produce highly standardised identity infrastructures.

Where one undertaking controls an identity infrastructure that competitors genuinely cannot replicate, questions may arise about whether access constitutes an essential facility-type issue.

However, IMS Health cautions against automatically requiring dominant firms to share infrastructure. The resource must satisfy stringent legal conditions before compulsory access is justified.

Case 5 — Slovak Telekom

Slovak Telekom a.s. v European Commission (Joined Cases C-152/19 P and C-165/19 P, CJEU, 2021)

The case involved exclusionary conduct concerning access to telecommunications infrastructure.

Relevance

Digital identity ecosystems may similarly involve infrastructure controlled by a vertically integrated undertaking.

A dominant provider might control:

authentication infrastructure → API → wallet → verification service.

If rivals require access to an upstream infrastructure layer to compete downstream, competition authorities may examine whether access restrictions constitute exclusionary conduct.

The case is therefore useful for analysing vertical foreclosure and infrastructure access.

Case 6 — Apple App Store / Epic Games

Epic Games, Inc. v Apple Inc. (U.S. District Court, Northern District of California, 2021)

The litigation concerned Apple's App Store rules, distribution restrictions and payment-system requirements.

Relevance to identity wallets

The case illustrates the competition implications of controlling an important digital distribution gateway.

For identity wallets, app-store control can become relevant where:

competing wallets depend upon app-store distribution;

the platform imposes discriminatory rules;

identity functionality is subject to special permissions;

competing authentication services are restricted; or

the platform favours its own wallet.

The broader principle is that control over distribution can become a competitive bottleneck even where competing products technically exist.

Case 7 — Epic Games v Google

Epic Games, Inc. v Google LLC (U.S. District Court, Northern District of California, 2023)

The case examined Google's Android ecosystem, Google Play distribution and payment-related restrictions.

Relevance

The decision is useful for analysing ecosystem-based competition where the platform operator simultaneously controls:

operating-system architecture;

application distribution;

payment infrastructure; and

commercial relationships with developers.

An identity-wallet ecosystem can reproduce this structure if a company controls both the mobile platform and identity wallet.

Case 8 — Mastercard v Commission

Mastercard Inc. v Commission (Case C-382/12 P, CJEU, 2014)

The case concerned restrictions in the payment-card ecosystem and the assessment of competition effects.

Relevance

Digital identity wallets increasingly interact with:

payments;

banking;

authentication;

KYC;

age verification; and

financial identity.

Mastercard demonstrates the importance of analysing network effects and restrictions within multi-sided infrastructures, rather than examining a single transaction in isolation.

7. European Union Approach

The EU regulatory environment is particularly important because digital identity sits at the intersection of competition, data protection and digital-platform regulation.

Relevant instruments include:

Article 101 TFEU — restrictive agreements;

Article 102 TFEU — abuse of dominance;

Digital Markets Act (DMA);

GDPR;

eIDAS / European Digital Identity framework; and

national competition laws.

The European Digital Identity framework seeks to establish interoperable digital identity wallets across the EU.

From a competition perspective, interoperability can reduce the ability of a single technical provider to establish an exclusive identity ecosystem.

8. United States Approach

In the United States, digital identity-wallet competition could potentially involve:

Sherman Act §1 — agreements restricting competition;

Sherman Act §2 — monopolisation and attempted monopolisation;

Clayton Act §3 — certain exclusive-dealing arrangements;

FTC Act §5;

state competition laws; and

sector-specific financial and privacy regulation.

The most relevant precedents are likely to come from:

platform distribution;

mobile operating systems;

payment systems;

authentication;

interoperability; and

digital advertising.

The U.S. approach generally requires careful examination of market definition, market power, exclusionary conduct and competitive effects.

9. United Kingdom

Under UK competition law, digital identity wallet conduct could primarily engage:

Competition Act 1998, Chapter II

This prohibits abuse of a dominant position.

Potential theories include:

discriminatory access;

refusal to supply;

tying;

self-preferencing;

exclusionary interoperability restrictions;

predatory or exclusionary conduct; and

leveraging dominance from operating systems into identity services.

The Digital Markets, Competition and Consumers Act 2024 also creates a broader framework for firms designated with strategic market status.

A firm with substantial strategic power over a mobile or digital ecosystem could therefore face obligations affecting interoperability and competitive access.

10. Germany

Germany is particularly significant because §19a GWB gives the Bundeskartellamt enhanced powers concerning undertakings of paramount significance across markets.

Digital identity wallets could become relevant where a large ecosystem operator possesses:

extensive user data;

operating-system power;

app-store power;

cloud infrastructure;

payment services; and

identity/authentication capabilities.

The German approach is therefore capable of addressing ecosystem-wide leveraging, rather than requiring competition authorities to look at each individual market completely in isolation.

11. India

In India, the competition analysis would primarily involve the Competition Act 2002, particularly:

Section 3 — anti-competitive agreements;

Section 4 — abuse of dominant position;

Section 19 — investigation by the CCI; and

Section 26 — investigation procedure.

Digital identity competition can be particularly complex because identity infrastructure may involve substantial government participation.

The analytical distinction should be made between:

government identity infrastructure and competitive private-sector services built around that infrastructure.

A government-backed identity system does not automatically mean that every adjacent identity-wallet market is monopolised. However, preferential government access, mandatory technical standards, exclusionary certification or discriminatory interoperability could affect competition.

12. State-Backed Digital Identity Monopolies

A special concern arises when the state establishes a single official identity wallet.

There can be legitimate reasons for doing so:

security;

fraud prevention;

authentication reliability;

privacy;

national security;

administrative efficiency; and

standardisation.

But competition concerns arise where the government-controlled infrastructure also becomes the gateway to commercial services.

For example:

State identity → mandatory wallet → bank authentication → insurance → healthcare → employment → payments

At that point, the identity wallet can become a universal gatekeeper.

13. Government Procurement and Competitive Neutrality

Government procurement can also affect the market.

A government may award the identity-wallet infrastructure to one technology company.

Competition concerns can arise if:

procurement specifications unnecessarily favour the incumbent;

interoperability requirements are weak;

proprietary technology becomes mandatory;

competitors cannot obtain certification;

switching is technically difficult; or

government contracts create an entrenched installed base.

The appropriate approach is therefore competitive neutrality and technology-neutral procurement.

14. Data Portability

Data portability is particularly important.

A user should ideally be able to move:

identity credentials;

verified attributes;

certificates;

permissions;

authentication history; and

relevant wallet information

between compatible providers.

Without portability, the wallet provider may acquire a form of digital identity lock-in.

This can reinforce network effects because users remain with the incumbent simply because leaving would require rebuilding their digital identity relationships.

15. Privacy and Competition Can Reinforce Each Other

Digital identity competition cannot be analysed solely through price.

Users may compete over:

privacy;

security;

data minimisation;

anonymity;

selective disclosure;

credential portability;

transparency; and

control over personal data.

A wallet that collects excessive data may therefore compete differently from a privacy-preserving wallet.

Consequently, quality competition becomes important.

Competition authorities should examine whether exclusionary conduct reduces:

privacy + security + interoperability + innovation

even where monetary prices remain zero.

16. Cross-Border Competition

International fragmentation creates another problem.

A European wallet may not seamlessly work with:

an Indian identity infrastructure;

a U.S. authentication provider;

an Asian payment ecosystem; or

another national credential system.

This can create identity interoperability barriers.

Large global technology companies may exploit these differences by offering a universal proprietary identity layer connecting otherwise fragmented national systems.

This creates a paradox:

Interoperability can increase competition within each market, but the company controlling the interoperability layer can itself become a new global gatekeeper.

17. Potential Anticompetitive Conduct

ConductPossible competition concern
Exclusive government walletForeclosure
OS blocking rival walletsAbuse of dominance
Proprietary identity APIAccess discrimination
Default-wallet preferenceSelf-preferencing
Mandatory wallet bundlingTying
Credential export restrictionsSwitching-cost exploitation
Exclusive verification agreementsForeclosure
Discriminatory certificationEntry barrier
Preferential biometric accessTechnical discrimination
Proprietary secure-element accessEssential-input concerns
Identity-data accumulationData-based market power
Cross-border interoperability restrictionsMarket fragmentation

18. Competition-Friendly Regulatory Model

A robust international framework should encourage:

1. Open standards

Technical standards should be sufficiently interoperable to permit competing wallets.

2. Credential portability

Users should not be unnecessarily trapped within one wallet.

3. Non-discriminatory API access

Comparable wallets should receive comparable technical access.

4. Device neutrality

Operating systems should not arbitrarily prevent legitimate competing wallets from functioning.

5. Transparent certification

Government certification should be based on objective security and privacy criteria.

6. Data minimisation

Competition should not depend upon collecting excessive identity information.

7. Multi-wallet compatibility

A user should be capable of maintaining multiple identity credentials/wallets where security permits.

8. Competitive procurement

Public authorities should avoid unnecessarily proprietary technical specifications.

19. Central Legal Test

The most important analytical question is:

Does control over digital identity infrastructure constitute legitimate security architecture, or is it being used as a mechanism to exclude competing identity services?

Competition authorities should examine:

relevant market;

market power;

control over essential technical inputs;

network effects;

interoperability;

switching costs;

foreclosure of rivals;

effects on innovation;

privacy and quality effects;

legitimate security justifications;

proportionality; and

whether less restrictive alternatives exist.

Conclusion

Digital identity wallet competition internationally is fundamentally an ecosystem and infrastructure competition issue. The wallet itself may be only the visible layer of a much larger structure involving operating systems, secure hardware, APIs, government credentials, verification services, payment systems and data.

The strongest existing precedents come from adjacent digital-platform and infrastructure cases such as Microsoft, Google Android, Google Shopping, IMS Health, Slovak Telekom, Epic Games v Apple and Epic Games v Google. These cases collectively demonstrate that competition law can scrutinise tying, self-preferencing, interoperability restrictions, infrastructure access, distribution control and ecosystem leverage.

The future competition question will increasingly be whether a digital identity wallet becomes merely a convenient credential-management tool—or evolves into a universal digital gatekeeper controlling access to government, financial, commercial and social services. If the latter occurs, interoperability, portability, non-discrimination and competitive neutrality will become central safeguards against identity-infrastructure monopolisation.

LEAVE A COMMENT