Digital Identity Verification Monopolies In Legal Systems .
Digital Identity Verification Monopolies in Legal Systems
Introduction
Digital identity verification monopolies arise when a government, court system, regulated intermediary, dominant technology provider, or state-authorised identity infrastructure becomes the effectively indispensable provider through which individuals must establish who they are in order to exercise legal rights.
Examples include mandatory digital-ID systems used for:
- access to courts and tribunals;
- electronic filing;
- notarisation and digital signatures;
- legal-aid applications;
- company and beneficial-ownership registration;
- immigration and citizenship procedures;
- public benefits;
- banking and regulated transactions;
- professional licensing; and
- authentication of lawyers, litigants, witnesses and public officials.
The competition-law problem is not simply that one entity has a large market share. Identity verification can become a foundational access layer. If access to that layer is indispensable and alternatives are practically unavailable, control over identity verification can translate into control over participation in legally protected markets and institutions.
The legal analysis therefore combines competition law, administrative law, constitutional rights, data protection, due process, proportionality, interoperability and essential-facilities principles.
1. Meaning of a Digital Identity Verification Monopoly
A digital identity verification monopoly exists where one infrastructure or provider has substantial and durable control over the verification function necessary for participation in a legal or economic system.
The monopoly can take several forms.
A. State monopoly
The government itself operates the exclusive identity infrastructure.
Example:
A court requires every litigant to authenticate through a government digital-ID system and provides no meaningful alternative.
B. Delegated monopoly
The state legally authorises one private provider to perform verification.
The provider may therefore have:
- exclusive verification rights;
- privileged access to government databases;
- exclusive certification authority;
- mandatory integration with public systems.
C. Platform monopoly
A private digital platform becomes the de facto identity provider because courts, banks, marketplaces or regulators rely upon its authentication infrastructure.
D. Federated identity monopoly
Multiple institutions nominally operate independently but depend upon one identity federation or authentication layer.
The apparent multiplicity of services therefore conceals a single infrastructural bottleneck.
2. Why Identity Verification Is Different From Ordinary Digital Services
Identity verification has unusually strong network effects.
A normal software provider can often be replaced.
A legal identity infrastructure may be difficult to replace because the verification system contains or connects to:
- authoritative identity records;
- biometric information;
- government databases;
- digital certificates;
- professional credentials;
- authentication histories;
- trust lists;
- court credentials;
- electronic signatures.
Consequently, the infrastructure can become a trust bottleneck.
The critical competition question becomes:
Can a person meaningfully participate in the legal system without using the dominant identity-verification infrastructure?
If the answer is no, ordinary market-share analysis may be inadequate.
3. Relevant Market
A competition authority or court would first need to define the relevant market.
Possible markets include:
Product market
- digital identity verification;
- biometric verification;
- electronic authentication;
- qualified electronic signatures;
- legal-professional authentication;
- identity-as-a-service;
- government identity federation services.
In some circumstances, however, the narrower market could be:
Identity verification services for access to legally regulated digital services.
That market may have significant barriers to entry because competitors cannot easily reproduce government recognition or authoritative databases.
Geographic market
The market may be:
- national;
- regional;
- EU-wide;
- sector-specific; or
- platform-specific.
Where identity credentials are legally recognised only within one jurisdiction, geographic competition can be especially limited.
4. Sources of Market Power
A. Legal exclusivity
Legislation may expressly designate one identity provider.
This creates a de jure monopoly.
B. Network effects
More institutions accepting an identity system increase its value.
More users then adopt the same system.
This creates a reinforcing cycle:
More institutions → more users → more authentication data → greater trust → more institutions.
C. Switching costs
Users may have to:
- re-register;
- revalidate biometrics;
- obtain new credentials;
- reconnect legal accounts;
- transfer professional certificates.
These costs discourage entry.
D. Data advantages
The incumbent may possess:
- historical authentication data;
- identity graphs;
- fraud-detection information;
- behavioural signals;
- device information.
Competitors may therefore face a structural information disadvantage.
5. Identity Infrastructure as an Essential Facility
An identity system may potentially resemble an essential facility where:
- the infrastructure is indispensable;
- duplication is technically or economically impracticable;
- access is necessary to compete or exercise legal rights; and
- refusal or discriminatory access can eliminate effective competition.
However, courts traditionally apply essential-facilities doctrine cautiously.
The mere fact that an infrastructure is useful does not automatically create a legal obligation to provide access.
The strongest case arises where identity verification is effectively the gateway to a legally protected activity.
6. Monopoly Power Can Become Legal-System Gatekeeping
This is particularly important.
Suppose a person cannot file a claim electronically without a particular identity credential.
The identity provider can therefore indirectly influence:
- whether proceedings can be initiated;
- who can appear before a court;
- whether evidence can be submitted;
- whether lawyers can access case files;
- whether appeals can be filed;
- whether legal documents can be executed.
The identity provider consequently becomes a private or quasi-public gatekeeper of procedural rights.
This creates a constitutional and administrative-law dimension beyond ordinary competition law.
7. Abuse of Dominance
Where competition law applies, potentially abusive conduct includes:
1. Refusal to provide access
A dominant identity provider refuses authentication to legitimate users or competing services.
2. Discriminatory authentication
Different competitors receive materially different verification conditions.
3. Excessive charges
The provider imposes disproportionate verification fees where users have no practical alternative.
4. Tying
Identity verification is tied to unrelated services.
5. Self-preferencing
The identity provider favours its own downstream services.
6. Data exploitation
Identity data collected for authentication is reused to compete in adjacent markets.
7. Interoperability restrictions
The dominant system prevents competitors from interoperating with its identity credentials.
8. Data Protection and Competition Intersection
Identity monopolies frequently involve extremely sensitive information.
A dominant provider may control:
- biometric identifiers;
- government identification numbers;
- addresses;
- professional credentials;
- authentication records;
- device identifiers.
This creates a potential conflict between:
identity security + privacy + competition + access to justice.
A provider cannot necessarily justify every exclusionary practice by invoking cybersecurity.
Security requirements must be genuine and proportionate.
9. Due Process Problems
A particularly serious issue arises when identity verification determines whether an individual can access a legal institution.
Suppose an algorithm incorrectly classifies a person as:
- fraudulent;
- duplicated;
- suspicious;
- unverified;
- impersonating another person.
If the person cannot access a court or administrative procedure until verification succeeds, the error may become a procedural barrier to justice.
Important safeguards therefore include:
- notice;
- explanation;
- human review;
- correction mechanisms;
- appeal;
- alternative authentication;
- temporary access pending review.
10. Relevant Case Laws
The following cases provide useful doctrinal foundations even though several arose in adjacent areas rather than involving modern digital identity monopolies directly.
1. United Brands v Commission
United Brands Company v Commission, Case 27/76
The European Court of Justice established important principles concerning dominance and abusive conduct.
Relevance
The case demonstrates that possessing substantial market power creates heightened responsibilities regarding conduct capable of restricting effective competition.
For identity infrastructure, the principle is important because an operator controlling a critical authentication gateway may have special obligations not to exploit that position to exclude competitors.
2. Commercial Solvents v Commission
Commercial Solvents Corp v Commission, Joined Cases 6/73 and 7/73
The Court recognised that a dominant undertaking's control over an upstream input can create competition concerns where access is withheld from downstream competitors.
Digital identity relevance
An identity-verification service can constitute an upstream input into downstream legal or commercial services.
For example:
Identity verification → court platform → legal service
If the identity provider selectively denies access to competing downstream services, the conduct can resemble an exclusionary refusal to supply.
3. Bronner v Mediaprint
Oscar Bronner GmbH & Co KG v Mediaprint, Case C-7/97
This is one of the most important European cases concerning refusal to supply and essential facilities.
The Court imposed a demanding test for requiring a dominant undertaking to provide access to infrastructure.
Digital identity relevance
A claimant challenging an identity monopoly cannot merely establish that the infrastructure is advantageous.
It would need to demonstrate something approaching indispensability and the absence of realistic alternatives.
This makes Bronner particularly important for analysing identity verification infrastructure.
4. IMS Health v Commission
IMS Health GmbH & Co OHG v NDC Health, Case C-418/01
The Court examined circumstances in which refusal to license an intellectual-property-related infrastructure could amount to abuse.
The judgment is particularly significant because it addresses circumstances in which an upstream infrastructure becomes indispensable to downstream competition.
Digital identity relevance
Where a proprietary identity architecture becomes indispensable for access to a legally regulated market, the case provides an important analytical framework.
The more difficult duplication or substitution becomes, the stronger the argument for regulated access.
5. Microsoft v Commission
Microsoft Corp v Commission, Case T-201/04
The EU courts upheld findings concerning Microsoft's refusal to provide interoperability information to competing products.
Digital identity relevance
Interoperability is central to digital identity systems.
A dominant identity provider could potentially use technical restrictions to prevent competing:
- authentication services;
- legal platforms;
- credential providers;
- verification applications
from interoperating with its infrastructure.
The Microsoft litigation therefore provides an important conceptual foundation for interoperability remedies.
6. Google Shopping
Google Search (Shopping), Case AT.39740
The European Commission found that Google had abused its dominant position by favouring its own comparison-shopping service in search results.
The General Court subsequently examined the Commission's findings.
Digital identity relevance
The case illustrates how a dominant digital infrastructure can use control over a gateway to favour its own downstream services.
The same structural concern could arise where an identity provider operates competing downstream:
- legal services;
- financial services;
- authentication products;
- compliance services.
The critical issue becomes neutrality of the identity gateway.
7. Meta Platforms / Bundeskartellamt
Meta Platforms Inc. v Bundeskartellamt, Case C-252/21
The Court of Justice considered the relationship between competition law and data-protection rules in the context of Meta's collection and combination of personal data.
Digital identity relevance
This case is especially important because identity infrastructures inevitably process personal data.
It demonstrates that competition authorities may need to consider data-protection requirements when assessing conduct by a dominant digital platform.
For identity monopolies, this supports an integrated analysis of:
dominance + data collection + consent + data combination + market power.
8. MEO v Autoridade da Concorrência
MEO – Serviços de Comunicações e Multimédia SA v Autoridade da Concorrência, Case C-525/16
The Court examined discriminatory pricing and the requirement to establish competitive disadvantage under Article 102 TFEU.
Digital identity relevance
An identity provider might offer different authentication terms to different institutions.
Different prices or access conditions do not automatically establish unlawful discrimination.
The analysis must examine whether the conduct creates a competitive disadvantage capable of affecting competition.
11. Consolidated Case-Law Principle
| Case | Principal doctrine | Identity-monopoly relevance |
|---|---|---|
| United Brands | Abuse of dominance | Duties of dominant infrastructure providers |
| Commercial Solvents | Refusal to supply | Identity verification as upstream input |
| Bronner | Essential facilities | Indispensability and alternatives |
| IMS Health | Indispensable infrastructure | Access/licensing of critical systems |
| Microsoft | Interoperability | Technical access to identity infrastructure |
| Google Shopping | Gateway/self-preferencing | Neutral identity gateway |
| Meta Platforms | Data + competition | Identity-data exploitation |
| MEO | Discriminatory conditions | Differential authentication access |
12. State Monopoly Versus Private Monopoly
A crucial distinction must be made.
Private monopoly
The principal legal questions are:
- dominance;
- exclusionary conduct;
- refusal to deal;
- discrimination;
- interoperability;
- data exploitation.
State monopoly
Additional questions arise:
- legality;
- constitutional proportionality;
- administrative fairness;
- equality;
- due process;
- right of access to courts;
- privacy;
- availability of alternatives.
The state cannot necessarily avoid constitutional scrutiny merely because the identity infrastructure is operated through a statutory authority.
13. Identity Verification and Access to Justice
The most serious scenario is:
Digital identity becomes a condition for exercising a legal right.
For example:
No digital identity → no court login → no electronic filing → no effective access to justice.
This can create a form of digital procedural exclusion.
A legally sustainable system should therefore consider alternative mechanisms such as:
- in-person verification;
- lawyer-assisted verification;
- judicial verification;
- certified documents;
- temporary credentials;
- emergency access;
- human review.
14. Competition Remedies
Authorities could employ several remedies.
A. Interoperability
Require the dominant identity provider to permit technically reasonable interoperability.
B. Multi-provider authentication
Allow users to authenticate through multiple accredited providers.
C. Data portability
Permit users to transfer relevant identity credentials where legally permissible.
D. Non-discrimination
Require equivalent access conditions for competing service providers.
E. Functional separation
Separate:
identity verification
from:
downstream commercial services.
F. Independent certification
Permit competing identity providers to become certified under objective criteria.
G. Alternative authentication
Maintain non-digital or secondary authentication channels.
H. Auditability
Require independent auditing of automated identity-verification decisions.
15. Regulatory Model
A robust legal framework could adopt the following structure:
Authoritative identity database
↓
Multiple accredited identity providers
↓
Interoperable authentication layer
↓
Courts / regulators / banks / legal platforms
This is preferable to:
State database
↓
Single mandatory identity provider
↓
Every legal institution
because the latter creates a single point of failure and a potential universal gatekeeper.
16. Algorithmic Identity Verification
Modern identity monopolies increasingly depend upon AI.
Algorithms may determine:
- facial similarity;
- document authenticity;
- behavioural anomalies;
- fraud probability;
- device trust;
- identity linkage.
This introduces another competition concern.
If one provider possesses the dominant algorithm and authentication dataset, competitors may be unable to replicate its performance.
The resulting data–algorithm–network-effect loop can make the monopoly increasingly durable.
17. Security Cannot Automatically Justify Monopoly
A common justification is:
"Only one identity provider can guarantee security."
That proposition should not automatically be accepted.
Security may justify:
- accreditation;
- certification;
- encryption requirements;
- auditing;
- minimum technical standards.
It does not necessarily justify:
- permanent exclusivity;
- discriminatory access;
- self-preferencing;
- unreasonable switching costs;
- prohibition of interoperable alternatives.
The regulatory objective should therefore be secure plurality rather than insecure fragmentation or unnecessary monopoly.
18. Structural Risk: Universal Identity Gatekeeper
The most serious long-term concern is the emergence of a universal legal identity gatekeeper.
If one infrastructure controls authentication for:
- courts;
- banks;
- taxation;
- healthcare;
- employment;
- company registration;
- immigration;
- government benefits,
then its power extends far beyond a conventional market.
It can become a cross-market infrastructural monopoly.
The resulting risk is not merely economic.
It involves:
- privacy;
- civil liberties;
- administrative accountability;
- access to justice;
- equality;
- democratic oversight;
- systemic resilience.
19. Key Legal Tests
A competition authority or court examining a digital identity monopoly should ask:
Market-power test
- Who controls identity verification?
- What alternatives exist?
- Can users realistically switch?
Essentiality test
- Is the infrastructure indispensable?
- Can competitors duplicate it?
Conduct test
- Is access being refused?
- Are competitors discriminated against?
- Is the provider self-preferencing?
Data test
- What personal data is collected?
- Is authentication data reused commercially?
Legal-system test
- Does verification determine access to courts or legal rights?
- Is there an alternative authentication route?
Due-process test
- Can an erroneous identity decision be challenged?
- Is there human review?
- Can access be restored rapidly?
Conclusion
Digital identity verification monopolies in legal systems represent a distinctive form of infrastructural market power. Their importance derives not merely from market share but from their ability to control the gateway through which individuals, lawyers, businesses and institutions establish legal identity.
The strongest competition-law concerns arise where an identity provider is simultaneously:
indispensable + exclusive + non-interoperable + data-rich + vertically integrated.
The principles developed in Commercial Solvents, Bronner, IMS Health, Microsoft, Google Shopping, Meta Platforms, United Brands and MEO provide a useful doctrinal foundation for analysing these situations.
The appropriate legal response is generally not to prohibit centralised identity infrastructure altogether. Rather, the objective should be to ensure interoperability, non-discrimination, independent oversight, alternative authentication, data protection, contestability and due process.

comments