Digital Identity Stack Consolidation And Universal Gatekeeping Risks

 

Digital Identity Stack Consolidation and Universal Gatekeeping Risks Under German and EU Competition Law

1. Introduction

Digital identity stack consolidation occurs when multiple layers of digital identification become controlled by one undertaking or a tightly integrated ecosystem. These layers may include:

  1. identity creation and verification;
  2. authentication and login;
  3. digital credentials and wallets;
  4. biometric verification;
  5. identity attributes and reputation data;
  6. device and account identifiers;
  7. access-management APIs;
  8. payment or transaction authentication;
  9. government-service authentication;
  10. interoperability and identity-resolution infrastructure.

The competition concern is not merely that one company becomes large. The deeper risk is universal gatekeeping: the same infrastructure becomes the practical gateway through which individuals, businesses, public authorities and platforms must pass to participate in multiple markets.

Under German and EU competition law, this can engage Articles 101 and 102 TFEU, Sections 18, 19 and 19a GWB, merger control, interoperability principles, essential-facility reasoning, self-preferencing, tying, discriminatory access, data advantages and ecosystem foreclosure.

The central question is:

When does control over a digital identity layer cease to be ordinary technological infrastructure and become a form of market-wide gatekeeping power?

2. What Is the “Digital Identity Stack”?

A digital identity stack can be represented as follows:

                    DIGITAL IDENTITY STACK        ┌───────────────────────────────────┐        │ Applications / Public Services    │        ├───────────────────────────────────┤        │ Payments / Commerce / Platforms   │        ├───────────────────────────────────┤        │ Identity Attributes & Reputation  │        ├───────────────────────────────────┤        │ Credentials / Digital Wallet      │        ├───────────────────────────────────┤        │ Authentication / Login / SSO      │        ├───────────────────────────────────┤        │ Identity Verification / Biometrics│        ├───────────────────────────────────┤        │ Identity Resolution / APIs        │        ├───────────────────────────────────┤        │ Device / Account Identifiers      │        └───────────────────────────────────┘

 

Consolidation occurs when the same undertaking controls several of these layers.

The competition risk increases dramatically when the undertaking also controls:

  • a dominant operating system;
  • an app store;
  • a cloud platform;
  • search or advertising;
  • payments;
  • communications;
  • public-sector authentication infrastructure;
  • AI services;
  • enterprise identity management.

This produces vertical integration across identity-dependent markets.

3. From Dominance to Universal Gatekeeping

Traditional dominance analysis normally asks whether an undertaking possesses substantial market power in a defined relevant market.

Universal gatekeeping raises a broader issue.

A firm may have:

Market A dominance → control of identity → leverage into Markets B, C, D and E.

For example:

Dominant Identity Provider          │          ├── Banking authentication          │          ├── E-commerce login          │          ├── Government services          │          ├── Healthcare access          │          ├── Employment verification          │          ├── Age verification          │          └── AI / platform access

 

The identity layer therefore becomes a strategic bottleneck.

4. Relevant German Legal Framework

A. Section 18 GWB — Market Power

Section 18 GWB provides the foundation for assessing market power.

Digital identity ecosystems create unusual market-definition problems because services may be:

  • zero-price;
  • multi-sided;
  • data-driven;
  • bundled;
  • supplied through infrastructure;
  • simultaneously used by consumers, businesses and governments.

The relevant market may therefore be narrower than the entire digital-services economy.

Possible markets include:

  • digital authentication;
  • identity verification;
  • enterprise identity management;
  • digital wallet services;
  • biometric verification;
  • authentication APIs;
  • identity-as-a-service;
  • public-sector digital identification.

5. Section 19 GWB

Section 19 addresses abusive conduct by undertakings with dominant market positions.

Potential identity-stack abuses include:

1. Refusal of interoperability

A dominant identity provider may prevent competing identity providers from connecting to its authentication infrastructure.

2. Discriminatory access

The dominant undertaking may provide APIs or identity attributes to its own subsidiaries on better terms.

3. Tying

A business may be required to use the dominant firm's identity service to access another product.

4. Self-preferencing

The provider may privilege its own identity credentials, wallet or authentication service.

5. Data exploitation

Identity data accumulated through one service may be used to strengthen another market.

6. Section 19a GWB — Digital Gatekeepers

Section 19a is particularly important.

It enables the Bundeskartellamt to address undertakings of paramount significance across markets and subsequently prohibit specified anti-competitive practices.

This is highly relevant to digital identity consolidation because identity infrastructure can create cross-market leverage.

The problem is not simply:

“Company X dominates digital identity.”

It may instead be:

“Company X possesses a cross-market ecosystem position enabling it to determine who can authenticate, transact, communicate, advertise, access applications or establish commercial relationships.”

That is much closer to the logic of Section 19a.

7. Universal Gatekeeping as a Competition Concept

Universal gatekeeping exists where an undertaking controls an infrastructure that becomes practically indispensable for participation in numerous markets.

Five characteristics are particularly important:

1. Centrality

The identity layer is used by many downstream services.

2. Dependency

Businesses cannot easily substitute the identity infrastructure.

3. Network effects

More users make the identity system more valuable.

4. Data accumulation

The provider obtains information about users across different contexts.

5. Switching costs

Leaving the ecosystem requires changing credentials, accounts, authentication methods and accumulated identity history.

These factors can create a self-reinforcing gatekeeper position.

8. Identity Data as a Competitive Asset

Identity infrastructure generates unusually valuable data.

A consolidated provider may observe:

  • who a user is;
  • which services they access;
  • when authentication occurs;
  • devices used;
  • transaction relationships;
  • professional affiliations;
  • geographic patterns;
  • age or eligibility attributes;
  • behavioural signals.

The competitive concern is therefore not merely privacy.

It is data-enabled market power.

Identity data can improve:

  • advertising;
  • fraud detection;
  • credit assessment;
  • recommendation algorithms;
  • authentication;
  • AI personalization;
  • risk scoring;
  • marketplace ranking.

This can create a feedback loop:

More Identity Users       ↓ More Identity Data       ↓ Better Authentication / Analytics       ↓ More Attractive Identity Infrastructure       ↓ More Downstream Adoption       ↓ More Identity Users

 

9. Network Effects and Tipping

Digital identity markets are particularly susceptible to tipping.

Suppose users prefer the identity system accepted by the largest number of services.

Businesses consequently adopt the most widely accepted identity provider.

This produces:

acceptance → adoption → more acceptance → further adoption.

Once a critical threshold is reached, competing identity systems may struggle to obtain sufficient scale.

This creates a potential identity infrastructure tipping point.

10. Universal Login as a Bottleneck

Single sign-on can generate substantial efficiencies.

However, universal login can also become a competitive bottleneck.

If one provider controls authentication for thousands of services, it may gain the ability to determine:

  • who can access a service;
  • which authentication methods are permitted;
  • what information businesses receive;
  • which identity attributes can be verified;
  • what technical standards competitors must satisfy.

The authentication layer therefore becomes a quasi-regulatory infrastructure despite being privately controlled.

11. Tying and Bundling

A dominant ecosystem might require:

“If you want access to our cloud, advertising or operating-system ecosystem, you must use our identity credentials.”

This could raise concerns under Article 102 TFEU and Section 19 GWB.

The legal assessment would consider:

  • dominance in the tying product;
  • distinctness of the tied product;
  • coercion or practical compulsion;
  • foreclosure;
  • efficiencies;
  • objective justification.

The greater the downstream dependency, the greater the foreclosure risk.

12. Self-Preferencing

Suppose a dominant identity provider operates its own digital wallet.

It could potentially:

  • authenticate its own wallet automatically;
  • make competing wallets harder to configure;
  • provide its own identity attributes more quickly;
  • rank its own credentials more prominently;
  • impose technical disadvantages on competitors.

This resembles broader platform self-preferencing problems.

The identity layer becomes a mechanism for competitive discrimination.

13. Refusal of Access

A particularly serious scenario occurs where competing services cannot reasonably operate without access to the dominant identity infrastructure.

The analysis may draw upon essential-facility principles.

Relevant questions include:

  1. Is the infrastructure genuinely indispensable?
  2. Can a competitor realistically replicate it?
  3. Is duplication economically or technically feasible?
  4. Is access objectively necessary?
  5. Does refusal eliminate effective competition?
  6. Is there a legitimate justification?

Not every popular identity system is an essential facility.

But technical indispensability combined with cross-market dependency can significantly strengthen the case.

14. Interoperability

Interoperability is one of the most important remedies.

Competition authorities could consider requiring:

  • open authentication protocols;
  • API access;
  • credential portability;
  • identity-attribute portability;
  • secure verification interfaces;
  • non-discriminatory access;
  • interoperability between wallets;
  • standardized authentication protocols.

The objective is not necessarily to break up the identity provider.

It may instead be to prevent the identity layer from becoming a closed gate.

15. Data Portability and Article 20 GDPR

Identity consolidation also interacts with data portability.

Article 20 GDPR gives individuals rights concerning portability of certain personal data.

Competition law may ask a different question:

Can users realistically move their identity relationships between competing providers?

A formally available portability right may be insufficient if:

  • credentials cannot be transferred;
  • authentication history is lost;
  • downstream services do not recognize the new credential;
  • reputation cannot be carried across;
  • identity attributes remain technically siloed.

Thus, formal portability ≠ effective portability.

16. Switching Costs

Identity systems can generate unusually high switching costs.

Users may have to change:

  • usernames;
  • authentication credentials;
  • recovery methods;
  • biometric registrations;
  • enterprise permissions;
  • government-service accounts;
  • banking authentication;
  • professional credentials.

Businesses may face even larger costs.

Therefore:

The more services attached to one identity, the more costly identity switching becomes.

This can transform ordinary network effects into ecosystem lock-in.

17. Cross-Market Leverage

The dominant provider can potentially leverage identity power into adjacent markets.

For example:

Identity Dominance       ↓ Authentication       ↓ Payments       ↓ Commerce       ↓ Advertising       ↓ Cloud       ↓ AI Services

 

The legal theory resembles leveraging under Article 102.

The important question is whether the identity infrastructure provides the firm with an advantage that competitors in downstream markets cannot realistically reproduce.

18. Six Important Case Laws

Case 1 — Google Shopping

Google Search (Shopping), European Commission / General Court

The Google Shopping litigation demonstrates how dominance in one digital infrastructure can be used to advantage an affiliated downstream service.

Relevance

For identity ecosystems, the analogy is:

dominant access infrastructure → preferential treatment of own downstream service.

The identity equivalent could be:

  • preferential authentication;
  • preferred credential recognition;
  • privileged access to identity attributes;
  • ranking advantages.

The central lesson is that a platform cannot necessarily use control over an important infrastructure to systematically disadvantage downstream rivals.

19. Case 2 — Google Android

Google Android

The Android case is especially relevant to identity-stack consolidation because it concerned tying and ecosystem leverage involving several interconnected digital services.

The Commission examined Google's contractual arrangements concerning Android, Google Search and the Play Store.

Identity relevance

A comparable identity ecosystem could involve:

operating system + app store + authentication + wallet + identity credentials.

The more tightly these layers are contractually or technically integrated, the stronger the potential concern that competitors are being excluded through ecosystem architecture.

20. Case 3 — Microsoft / Interoperability

Microsoft v Commission

The Microsoft litigation is foundational for understanding interoperability and refusal-to-supply problems in technology markets.

The case concerned Microsoft's control over important software interfaces and interoperability information.

Identity relevance

A dominant identity provider could similarly control technical interfaces necessary for competitors to interact with its ecosystem.

The important principle is that technological interoperability can become a competition issue when control over an interface substantially affects downstream competition.

21. Case 4 — Bronner

Oscar Bronner GmbH & Co. KG v Mediaprint

Bronner remains an important EU authority concerning the conditions under which refusal of access to infrastructure can constitute an abuse.

The Court imposed demanding conditions for essential-facility treatment.

Identity relevance

A dominant digital identity infrastructure should not automatically be classified as an essential facility simply because it is widely used.

A competition authority would need to establish genuine indispensability and the relevant foreclosure effects.

This provides an important safeguard against over-expanding essential-facility doctrine.

22. Case 5 — Slovak Telekom

Slovak Telekom

The case concerned access to telecommunications infrastructure and exclusionary conduct.

Identity relevance

The case is useful because it illustrates how vertically integrated infrastructure operators can potentially use control over an upstream layer to restrict downstream competition.

Digital identity infrastructure can present an analogous structure:

Identity Infrastructure          ↓ Authentication Access          ↓ Downstream Digital Services

 

The more dependent downstream competitors become, the more significant discriminatory access can become.

23. Case 6 — Deutsche Telekom

Deutsche Telekom v Commission

The Deutsche Telekom litigation is important for understanding discriminatory or exclusionary pricing and the competitive significance of infrastructure control.

Identity relevance

A dominant identity provider could potentially impose:

  • excessive access charges;
  • discriminatory API pricing;
  • preferential internal pricing;
  • margin-squeeze effects.

For example, the provider might charge independent downstream platforms heavily for identity verification while providing the same functionality internally at effectively lower cost.

24. Case 7 — Bundeskartellamt / Facebook

Facebook — Abuse of Dominance Proceedings

The German Facebook proceeding is particularly important for digital ecosystems because it connected data practices with competition law.

The case demonstrates that the competitive assessment of a dominant digital platform may involve the interaction between:

  • data collection;
  • user relationships;
  • platform power;
  • contractual conditions;
  • privacy-related restrictions.

Identity relevance

Digital identity systems can make this issue even more significant because identity data is inherently connected to authentication and user relationships.

A consolidated identity provider could potentially use identity information obtained in one context to reinforce market power elsewhere.

25. Case 8 — Booking.com

Booking.com

The German competition-law proceedings concerning Booking.com provide another example of how contractual restrictions imposed by a powerful digital intermediary can affect market dynamics.

Identity relevance

Identity platforms may similarly impose conditions upon participating businesses, such as requiring particular authentication mechanisms or restricting alternative identity systems.

The broader lesson is:

Contractual architecture can itself become a mechanism of platform control.

26. Why Identity Consolidation Is Different From Ordinary Platform Dominance

Identity infrastructure has an unusually deep economic role.

A search engine can potentially be replaced.

A social network can potentially be abandoned.

But an identity credential may become connected to:

  • employment;
  • banking;
  • taxation;
  • healthcare;
  • education;
  • commerce;
  • government;
  • telecommunications;
  • professional licensing.

Consequently, identity consolidation can produce institutional dependency, not merely consumer preference.

27. State-Backed Identity and Competition

The problem becomes even more complex when identity infrastructure is state-backed.

A government may designate one identity infrastructure as the default mechanism for public services.

That can create a powerful network effect:

public-sector acceptance → private-sector adoption → universal recognition.

If a private undertaking subsequently becomes the technological operator of the infrastructure, it may obtain extraordinary market leverage.

Competition analysis may then intersect with:

  • public procurement;
  • state aid;
  • administrative law;
  • neutrality obligations;
  • public-service obligations;
  • data protection;
  • constitutional principles.

28. Risks of “Identity-as-a-Utility”

Once an identity system becomes universally accepted, it may begin to resemble infrastructure.

Potential characteristics include:

FeatureCompetition consequence
Universal authenticationGateway power
Network effectsTipping
Identity portability barriersLock-in
Centralized credentialsDependency
Cross-service dataData advantage
API controlInteroperability bottleneck
Universal acceptanceEntry barriers
State integrationInstitutional entrenchment

This raises the possibility of treating certain identity services functionally like digital utilities, although competition law does not automatically confer utility status.

29. Algorithmic Gatekeeping

AI makes identity gatekeeping more powerful.

An identity provider may use algorithms to decide:

  • fraud risk;
  • account eligibility;
  • authentication confidence;
  • age;
  • identity matching;
  • suspicious behaviour;
  • access privileges.

If the same provider controls identity infrastructure and algorithmic decision-making, it may influence downstream market access.

This creates a new category:

algorithmic gatekeeping through identity infrastructure.

30. Universal Identity and AI Agents

Future AI agents may transact on behalf of users.

The identity layer would then authenticate not only humans but:

  • AI agents;
  • autonomous businesses;
  • software agents;
  • machines;
  • IoT systems.

A dominant identity provider could consequently become the gateway for the machine economy.

This makes interoperability especially important.

If only one provider can reliably authenticate autonomous agents, competing AI ecosystems may become dependent upon it.

31. Competitive Risks of Identity Scoring

Identity systems may gradually incorporate reputation.

For example:

Identity   ↓ Transaction History   ↓ Risk Score   ↓ Trust Rating   ↓ Access Decision

 

The danger is that the identity provider becomes not merely an authenticator but a market-access regulator.

This could affect:

  • lending;
  • insurance;
  • employment;
  • marketplaces;
  • advertising;
  • online commerce.

Competition law could therefore encounter a system in which identity infrastructure determines downstream commercial opportunity.

32. Conglomerate Effects

A large technology group could combine:

  • identity;
  • cloud;
  • search;
  • advertising;
  • payments;
  • AI;
  • operating systems;
  • app stores.

The identity layer would then become a common infrastructure connecting the entire conglomerate.

The resulting competitive advantage may be greater than the sum of individual market shares.

This is a classic ecosystem leverage problem.

33. Merger-Control Risk

Acquisitions of identity providers can therefore have significant competition implications.

A merger should potentially be examined for:

  1. elimination of a future identity competitor;
  2. access to identity data;
  3. foreclosure of rival authentication systems;
  4. increased interoperability control;
  5. cross-market data advantages;
  6. increased switching costs;
  7. vertical integration.

Traditional turnover thresholds may not capture the strategic importance of an emerging identity provider.

German merger-control rules and EU merger-control mechanisms may therefore become particularly relevant for acquisitions of strategically important identity infrastructure.

34. Killer Acquisition Scenario

Consider:

A major platform acquires a small but rapidly growing decentralized identity provider.

Initially the target has little revenue.

But it possesses:

  • highly scalable identity technology;
  • privacy-preserving credentials;
  • interoperability standards;
  • rapidly growing developer adoption.

The acquisition eliminates a potential future challenger.

The competitive harm may therefore be innovation foreclosure, rather than immediate price increases.

35. Data Advantage Versus Identity Advantage

Two distinct forms of power must be separated.

Data advantage

The firm possesses more information.

Identity advantage

The firm controls the mechanism by which participants prove who they are.

The second can be substantially more powerful.

A data-rich platform can compete with other data-rich platforms.

But if one undertaking controls the identity verification layer, competitors may not even be able to establish trusted relationships with users without passing through that infrastructure.

36. Universal Gatekeeping Indicators

Competition authorities should examine the following indicators:

Structural indicators

  • number of connected services;
  • percentage of users;
  • number of authenticating businesses;
  • public-sector integration;
  • credential acceptance.

Technical indicators

  • API openness;
  • interoperability;
  • portability;
  • protocol restrictions;
  • authentication dependencies.

Economic indicators

  • switching costs;
  • multi-homing;
  • entry barriers;
  • network effects;
  • pricing.

Data indicators

  • cross-service data combination;
  • identity-resolution capabilities;
  • profiling;
  • data feedback loops.

Behavioural indicators

  • tying;
  • self-preferencing;
  • discriminatory access;
  • exclusionary contracts;
  • degradation of rival interoperability.

37. A Possible German Enforcement Framework

A Bundeskartellamt investigation could proceed approximately as follows:

Identify Identity Layer        ↓ Define Relevant Market(s)        ↓ Assess Market Power        ↓ Examine Section 18        ↓ Section 19 / Section 19a        ↓ Identify Gatekeeping Conduct        ↓ Test Foreclosure Effects        ↓ Assess Objective Justification        ↓ Consider Interoperability / Portability        ↓ Impose Proportionate Remedy

 

38. Potential Remedies

A. Interoperability

Require standardized access to authentication interfaces.

B. Data portability

Allow effective transfer of relevant identity information.

C. API access

Require fair and non-discriminatory access.

D. Separation

In extreme cases, structural separation between identity infrastructure and downstream commercial services may be considered.

E. Non-discrimination

Prevent preferential treatment of affiliated services.

F. Consent separation

Prevent identity data collected for authentication from automatically becoming available for unrelated commercial purposes where competition concerns arise.

G. Auditability

Require independent auditing of identity infrastructure and access rules.

39. The Proportionality Problem

Authorities should avoid assuming that decentralization is always superior.

Centralized identity can provide:

  • security;
  • fraud prevention;
  • convenience;
  • lower transaction costs;
  • reliable authentication;
  • standardized credentials.

Therefore, the legal question should not be:

“Is identity centralized?”

It should be:

“Does the structure or conduct of the centralized identity provider materially prevent effective competition?”

This distinction is essential.

40. Competition Law and Privacy Law Should Not Be Collapsed

Privacy and competition law overlap but pursue different objectives.

A privacy violation does not automatically constitute an antitrust violation.

Conversely, a competition problem may exist even where privacy compliance is formally satisfied.

For example:

A dominant identity provider could lawfully process data but still use interoperability restrictions to exclude competing identity providers.

Thus:

GDPR compliance ≠ competition-law immunity.

41. The Core Theory of Harm

The strongest theory of harm can be expressed as:

Identity consolidation → network effects → dependency → switching costs → universal acceptance → cross-market leverage → foreclosure → entrenchment.

The danger is a positive feedback loop:

More Services     ↓ More Users     ↓ More Identity Data     ↓ More Trust / Accuracy     ↓ Greater Adoption     ↓ Higher Switching Costs     ↓ Fewer Competitors     ↓ More Services

 

Once this loop becomes sufficiently strong, market power can become self-reinforcing.

42. Conclusion

Digital identity stack consolidation presents a distinctive form of ecosystem competition risk because identity can become the gateway to participation across numerous otherwise separate markets.

Under German and EU competition law, the most relevant analytical tools include:

  • Section 18 GWB for market power;
  • Section 19 GWB for abuse of dominance;
  • Section 19a GWB for cross-market digital gatekeepers;
  • Articles 101 and 102 TFEU;
  • essential-facility and interoperability principles;
  • merger control;
  • data-related competition theories.

The most important distinction is between having a successful identity service and controlling an identity infrastructure upon which competitors and entire markets depend.

Where a single undertaking controls authentication, credentials, identity attributes, APIs and downstream digital services, the risk is no longer ordinary platform dominance. It becomes universal gatekeeping.

The appropriate competition-law response should therefore focus on interoperability, effective portability, non-discriminatory access, prevention of self-preferencing and cross-market leveraging, while preserving legitimate security and efficiency benefits.

LEAVE A COMMENT