Digital Identity Systems And Competition Access .
Digital Identity Systems and Competition Access
Introduction
Digital identity systems are technological and institutional arrangements through which individuals, businesses, devices, or organisations are authenticated and identified for accessing digital services. They may include government-backed digital IDs, private authentication systems, single-sign-on platforms, biometric identifiers, digital wallets, identity brokers, federated identity systems, and platform-based authentication.
From a competition-law perspective, the central issue is not merely whether digital identity is secure or efficient. It is whether control over identity infrastructure can become a gateway to markets. If a dominant undertaking controls the identity layer through which users, merchants, developers, financial institutions, or public services must authenticate, it can potentially determine who gets access to downstream markets and on what terms.
The competition problem can therefore be expressed as:
Control over identity → control over authentication → control over access → control over downstream competition.
Digital identity may consequently operate as a bottleneck infrastructure, particularly where switching is difficult, interoperability is limited, alternative identity providers are unavailable, or public and private services increasingly depend upon one identity standard.
1. Meaning of Competition Access in Digital Identity Systems
Competition access refers to the ability of competing undertakings to obtain access to the identity infrastructure, authentication mechanisms, interoperability interfaces, data, and user base necessary to compete effectively.
It can involve:
- access by competing identity providers;
- access by banks and fintech companies;
- access by online marketplaces;
- access by developers;
- access by competing platforms;
- access by public-service providers;
- access to authentication APIs;
- access to verification databases;
- access to digital-wallet infrastructure;
- access to interoperability standards; and
- access to users without discriminatory authentication conditions.
The problem becomes particularly serious when identity infrastructure is both:
- technically indispensable, and
- controlled by a dominant undertaking or institution.
2. Why Digital Identity Can Become a Competition Bottleneck
Traditional competition analysis generally focuses on markets for goods or services. Digital identity introduces another layer: the infrastructure through which market participation itself occurs.
For example:
Identity provider
↓
Authentication
↓
Account creation
↓
Platform access
↓
Transaction
↓
Data generation
↓
Personalisation
↓
Network effects
This creates the possibility of a recursive competitive advantage.
A dominant identity provider can acquire more users because its identity system is widely accepted. Its greater user base then makes the system more attractive to merchants and platforms. Greater merchant adoption increases its attractiveness to users.
This can produce:
identity network effects + data advantages + switching costs + ecosystem dependency.
3. Forms of Digital Identity Infrastructure
A. Government Digital Identity
Examples include national identity authentication systems used for:
- banking;
- taxation;
- welfare;
- telecommunications;
- healthcare;
- public procurement;
- business registration; and
- digital signatures.
The competition concern arises where private firms are effectively required to depend upon the state-controlled authentication infrastructure.
A state-backed identity system may therefore function as an essential gateway into multiple downstream markets.
B. Private Platform Identity
Large platforms may provide:
- single sign-on;
- account authentication;
- business verification;
- developer identity;
- merchant identity;
- advertising identity;
- payment identity.
If third parties cannot effectively reach users without using the dominant platform's identity mechanism, the identity layer may reinforce platform dominance.
C. Federated Identity
Federated identity permits one identity provider to authenticate users across multiple services.
It creates efficiency but also creates a competition risk:
The more services that depend upon one identity provider, the greater the consequences of exclusion from that provider.
A dominant identity federation can therefore become an interoperability bottleneck.
D. Biometric Identity
Biometric systems can create particularly strong barriers because biometric identifiers are difficult or impossible for users to replace.
Unlike a password, a fingerprint or facial characteristic cannot simply be changed after compromise.
Consequently, biometric identity systems can generate substantial:
- lock-in;
- privacy risks;
- switching costs;
- data advantages; and
- exclusion risks.
4. Competition Risks
4.1 Refusal of Access
A dominant identity provider may refuse authentication access to a competitor.
Suppose Platform A controls the identity infrastructure used by 80% of consumers.
If Platform A refuses to authenticate users of Platform B, Platform B may be unable to compete effectively.
This resembles traditional refusal-to-deal and essential-facilities problems.
5. Discriminatory Access
Access can also be formally available but practically discriminatory.
For example:
| Conduct | Competition effect |
|---|---|
| Higher authentication fees for rivals | Raises rivals' costs |
| Slower API access | Degrades competitor service |
| Reduced verification functionality | Weakens competitor |
| Selective technical standards | Forecloses rivals |
| Preferential access for affiliated services | Ecosystem self-preferencing |
| Differential fraud thresholds | Raises competitor rejection rates |
| Data restrictions | Prevents effective competition |
Thus, non-discrimination becomes a major competition principle.
6. Self-Preferencing Through Identity
A vertically integrated company may operate:
- the identity layer;
- marketplace;
- payment service;
- advertising platform; and
- cloud infrastructure.
It could potentially use identity information to favour its own downstream services.
For example:
Identity provider → authentication data → preferred ranking → affiliated marketplace.
The competition concern is not simply data collection. It is the possibility that identity infrastructure gives the integrated undertaking an artificial advantage in adjacent markets.
7. Identity Data as a Competitive Asset
Identity systems can generate highly valuable information:
- user identity;
- transaction history;
- authentication frequency;
- device information;
- behavioural patterns;
- location-related information;
- fraud history;
- account relationships;
- business credentials.
If a dominant identity provider accumulates this information while competing downstream, it may create a data-based competitive advantage.
This raises the question:
Should competitors receive some form of access to identity-related data necessary to compete?
The answer depends upon the legal framework, privacy law, proportionality, security considerations, and whether the information is genuinely indispensable.
8. Network Effects
Digital identity systems are particularly susceptible to network effects.
More users → more accepting merchants → more services → greater usefulness → more users.
This creates a self-reinforcing cycle.
A competing identity system may therefore face the classic problem:
How can a new identity provider obtain users when businesses will not accept it, and how can businesses accept it when few users possess it?
This is a form of chicken-and-egg market entry barrier.
9. Interoperability as a Competition Remedy
Interoperability can reduce identity-related foreclosure.
Possible remedies include:
- open authentication standards;
- API interoperability;
- common technical protocols;
- data portability;
- multi-provider authentication;
- interoperable credentials;
- switching mechanisms;
- transparent certification;
- non-discriminatory access;
- independent identity verification.
Interoperability prevents one identity provider from becoming the exclusive gateway to digital participation.
10. Essential-Facilities Analysis
Digital identity may potentially satisfy elements associated with an essential-facilities analysis where:
- the facility is controlled by a dominant undertaking;
- access is objectively necessary to compete;
- duplication is technically or economically impracticable;
- refusal eliminates or seriously restricts competition;
- there is no legitimate justification for refusal.
However, courts generally apply essential-facilities principles cautiously.
Not every useful digital identity system becomes an essential facility.
The distinction between commercially important and legally indispensable is crucial.
11. Relevant Case Laws
1. Bronner v Mediaprint — CJEU
Case: Oscar Bronner GmbH & Co. KG v Mediaprint Zeitungs und Zeitschriftenverlag GmbH & Co. KG (C-7/97)
Principle
The Court imposed a demanding standard for compulsory access to infrastructure.
A refusal to provide access becomes abusive only under stringent circumstances, including where access is indispensable for competition and duplication is not realistically possible.
Relevance to Digital Identity
A dominant digital identity provider should not automatically be required to open its infrastructure merely because competitors would benefit.
The claimant would need to demonstrate something closer to indispensability.
This makes Bronner a foundational authority for analysing digital identity systems as potential bottleneck infrastructure.
12. IMS Health — Data and Interoperability
Case: IMS Health GmbH & Co. OHG v NDC Health GmbH & Co. KG (C-418/01)
Principle
The CJEU developed important criteria concerning refusal to license intellectual property where access is indispensable to competing in a downstream market.
Relevance
Digital identity systems can contain proprietary:
- authentication technologies;
- identity databases;
- interoperability interfaces;
- credential formats.
Where competitors cannot realistically operate without access to such infrastructure, IMS Health provides a framework for analysing whether refusal crosses the line into abusive exclusion.
13. Microsoft — Interoperability
Case: Microsoft Corp. v Commission, Case T-201/04
Principle
The European courts upheld important aspects of the Commission's intervention concerning Microsoft's refusal to provide interoperability information to competing work-group server products.
Relevance to Digital Identity
Identity systems often depend on interoperability.
If a dominant platform controls:
- authentication protocols;
- APIs;
- identity credentials;
- interoperability documentation,
it may potentially use technical restrictions to exclude competing services.
Microsoft therefore illustrates how technical interoperability can become a competition-law issue.
14. Google Shopping
Case: Google and Alphabet v Commission, Case T-612/17
Principle
The General Court upheld the finding that Google had abused its dominant position through practices favouring its comparison-shopping service in its general search results.
Relevance
The case demonstrates the competition significance of leveraging dominance from an upstream digital infrastructure into a downstream market.
Applied to identity:
dominant identity layer → preferential treatment for affiliated downstream services.
Identity systems could therefore become mechanisms of ecosystem foreclosure when the infrastructure operator also competes downstream.
15. Google Android
Case: Google and Alphabet v Commission, Case T-604/18
Principle
The case concerned Google's practices involving Android, including contractual restrictions affecting competing search services and browsers.
Relevance
Android illustrates how control over an important digital ecosystem can be leveraged through contractual and technical arrangements.
A dominant identity provider could similarly impose:
- exclusive authentication;
- default identity settings;
- restrictions on competing identity providers;
- technical integration requirements.
The competition concern is therefore broader than simple refusal of access.
16. Slovak Telekom
Case: Slovak Telekom a.s. and Deutsche Telekom AG v Commission, Joined Cases C-152/19 P and C-165/19 P
Principle
The CJEU addressed exclusionary conduct involving access to telecommunications infrastructure and the relationship between general abuse-of-dominance principles and sector-specific access obligations.
Relevance
Digital identity infrastructure increasingly resembles telecommunications infrastructure in one important respect: downstream providers may depend upon access to an upstream network.
The case supports careful analysis of:
- access obligations;
- discriminatory conditions;
- infrastructure bottlenecks;
- foreclosure effects.
17. Apple App Store / Epic Games
Case: Epic Games, Inc. v Apple Inc. (U.S. District Court for the Northern District of California, 2021)
Principle
The litigation examined Apple's control over distribution, payment and platform rules in the iOS ecosystem.
Although the dispute was not principally about digital identity, it illustrates a broader digital-platform competition problem:
control over an access layer can determine the competitive conditions of downstream businesses.
Relevance
A dominant identity provider may occupy a similar strategic position where downstream businesses cannot effectively reach customers without complying with its identity rules.
18. Competition-Law Framework
Digital identity competition cases can be analysed through several doctrines.
Article 102 TFEU / Abuse of Dominance
Potential theories include:
- refusal to supply;
- discriminatory access;
- tying;
- leveraging;
- self-preferencing;
- exclusionary interoperability restrictions;
- exploitative conditions.
German Competition Law
Under German law, GWB §§19 and 19a are particularly significant for powerful digital undertakings.
Section 19a is especially relevant where an undertaking has paramount significance for competition across markets.
Identity infrastructure could become important in this context where a digital ecosystem operator uses control over authentication to affect multiple adjacent markets.
19. Data Portability and Competition
Data portability can reduce identity lock-in.
If consumers can move relevant identity information between providers, the competitive advantage created by incumbency can decrease.
However, portability must be reconciled with:
- GDPR requirements;
- cybersecurity;
- authentication integrity;
- fraud prevention;
- consent;
- data minimisation.
Therefore:
Competition access cannot simply mean unlimited access to identity data.
The legally appropriate model is more likely to be secure, purpose-limited, proportionate interoperability.
20. Public and Private Identity Systems
A particularly difficult issue arises when a government-backed identity system becomes the default infrastructure for private markets.
The state may have legitimate objectives:
- preventing fraud;
- ensuring secure identification;
- delivering welfare;
- complying with AML rules;
- preventing identity theft.
Nevertheless, mandatory dependence on one identity system may have competitive consequences.
For example:
State identity infrastructure
↓
Banks
Fintech
Telecom
E-commerce
Insurance
Healthcare
Government services
If every downstream sector must use the same identity infrastructure, the identity system can become a cross-market gateway.
Competition authorities must therefore distinguish between:
legitimate standardisation and unnecessary competitive foreclosure.
21. Digital Identity and Market Entry
New entrants often face three simultaneous barriers:
First — User acquisition
Consumers already possess established identities.
Second — Merchant acceptance
Businesses may support only the dominant identity provider.
Third — Trust
Users may not trust a new identity provider with sensitive credentials.
Consequently, the incumbent may enjoy an identity credibility advantage that is difficult to replicate.
This can make digital identity an important structural entry barrier.
22. Identity Bundling
A dominant platform might bundle:
identity + cloud + payments + advertising + marketplace + analytics.
A business that wants access to one service may therefore become dependent upon the entire ecosystem.
Competition concerns can arise where identity is used to make other services effectively unavoidable.
Potential theories include:
- tying;
- bundling;
- ecosystem foreclosure;
- leveraging;
- exclusionary contractual restrictions.
23. Authentication Quality as a Competitive Weapon
Competition authorities should also examine apparently neutral technical parameters.
For example:
- authentication speed;
- API uptime;
- fraud-screening thresholds;
- verification requirements;
- account suspension procedures;
- biometric accuracy;
- rate limits;
- API pricing.
A dominant provider could technically comply with a formal access obligation while making access commercially unattractive.
Therefore, effective access matters more than merely nominal access.
24. Digital Identity and Multi-Homing
Competition improves when users can maintain multiple identities or authentication methods.
Multi-homing allows users to switch between:
- government ID;
- bank identity;
- platform identity;
- independent identity provider;
- biometric credential;
- hardware credential.
A system that prevents multi-homing can substantially increase lock-in.
Thus:
single identity dependency = higher foreclosure risk.
25. Possible Competition Remedies
Competition authorities could consider:
Structural remedies
- separation of identity and downstream commercial services;
- divestiture of identity infrastructure.
Behavioural remedies
- non-discriminatory access;
- transparent pricing;
- interoperability obligations;
- API access;
- prohibition of self-preferencing.
Portability remedies
- credential portability;
- secure identity migration;
- interoperable verification.
Governance remedies
- independent technical standards;
- independent certification;
- auditability;
- transparent access criteria.
Data remedies
- controlled data portability;
- purpose limitation;
- secure access mechanisms.
26. Key Legal Test
A useful analytical framework is:
Step 1 — Identify the identity market
Who supplies identity/authentication services?
↓
Step 2 — Identify the bottleneck
Is the identity infrastructure necessary for downstream competition?
↓
Step 3 — Assess dominance
Does the operator possess substantial market power?
↓
Step 4 — Examine access
Can competitors obtain access?
↓
Step 5 — Examine conditions
Are access conditions discriminatory, excessive or technically restrictive?
↓
Step 6 — Assess foreclosure
Does the conduct eliminate or materially weaken competition?
↓
Step 7 — Consider justification
Are security, privacy, fraud prevention or regulatory objectives legitimate and proportionate?
↓
Step 8 — Select remedy
Interoperability / access / portability / non-discrimination / structural separation.
27. Core Competition Principle
The most important conceptual distinction is between identity as a service and identity as infrastructure.
Where identity is merely another competitive service, ordinary market forces may be sufficient.
But where identity becomes the mandatory gateway through which competitors must authenticate users, transact, or access digital markets, it may acquire the characteristics of strategic infrastructure.
The competition concern therefore becomes:
Who controls the digital identity layer controls the conditions under which other firms can participate in digital markets.
Conclusion
Digital identity systems can substantially improve security, trust and transaction efficiency. At the same time, their increasing integration into banking, telecommunications, e-commerce, government services, healthcare and digital platforms creates a significant competition-access problem.
The principal risks are:
- refusal of access;
- discriminatory authentication;
- interoperability restrictions;
- identity-based tying and bundling;
- self-preferencing;
- cross-market leveraging;
- data-based advantages;
- network-effect-driven concentration;
- switching barriers; and
- state-backed or private identity gatekeeping.
The cases of Bronner, IMS Health, Microsoft, Google Shopping, Google Android and Slovak Telekom, together with platform-access litigation such as Epic Games v Apple, demonstrate that competition law already contains several doctrinal tools capable of addressing these problems.

comments