Digital Identity Verification Monopolization Concerns .

 

Digital Identity Verification Monopolization Concerns

Introduction

Digital identity verification has become an important infrastructure layer for banking, telecommunications, e-commerce, government services, employment platforms, healthcare, travel, and digital payments. Identity verification may involve government identity databases, biometric authentication, mobile-number verification, digital signatures, facial recognition, know-your-customer (KYC) systems, credit or fraud databases, identity brokers, and private authentication platforms.

A digital identity verification monopoly arises where one undertaking, infrastructure provider, public authority, or tightly integrated ecosystem obtains substantial control over the ability of individuals or businesses to establish identity and consequently controls access to downstream markets.

The competition concern is not simply that one provider has a large market share. The deeper problem is that identity verification can become a gatekeeping input: competitors may technically exist but cannot effectively compete unless they obtain access to the dominant identity infrastructure.

1. Meaning of Digital Identity Verification Monopolization

Digital identity verification monopolization occurs when a firm or institution acquires or exercises substantial market power over the infrastructure used to verify identity and uses that position to:

  • exclude competing verification providers;
  • make its own downstream services compulsory;
  • impose discriminatory access conditions;
  • deny interoperability;
  • restrict portability of identity information;
  • bundle identity verification with other services;
  • exploit sensitive identity data;
  • discriminate against rival platforms;
  • impose excessive or discriminatory fees;
  • prevent multi-homing;
  • use authentication data to strengthen an adjacent monopoly; or
  • make public or essential services dependent upon a proprietary identity stack.

The competitive structure can therefore look like:

Identity database → Authentication layer → Verification service → Access credential → Downstream market

Control at an upstream layer can produce market power downstream.

2. Why Digital Identity Is Particularly Susceptible to Monopoly

Digital identity markets possess several characteristics associated with durable market power.

A. Network effects

The value of an identity system can increase as more:

  • banks;
  • merchants;
  • employers;
  • government departments;
  • platforms; and
  • consumers

adopt it.

This may create a positive feedback loop:

More users → more relying parties → more verification opportunities → greater attractiveness → more users.

B. Switching costs

Changing identity providers may require:

  • re-verification;
  • new credentials;
  • migration of authentication records;
  • regulatory approvals;
  • technical integration;
  • security certification; and
  • renegotiation of contracts.

These costs can discourage customers from moving to competitors.

C. Data advantages

A dominant verification provider may accumulate:

  • identity attributes;
  • transaction metadata;
  • device information;
  • authentication histories;
  • fraud signals;
  • biometric templates;
  • behavioural information; and
  • verification outcomes.

The resulting dataset can create a substantial competitive advantage.

D. Trust and regulatory barriers

Identity verification is unusually dependent on trust.

Financial institutions and public bodies may prefer an established provider because it has already satisfied:

  • security requirements;
  • AML/KYC requirements;
  • data-protection obligations;
  • technical certification;
  • audit requirements; and
  • government accreditation.

These requirements can legitimately protect consumers, but they may also become barriers to entry if applied disproportionately.

3. Relevant Competition-Law Theories

A. Abuse of dominance

A dominant identity-verification provider may violate competition law by engaging in exclusionary or exploitative conduct.

Potential conduct includes:

  • refusal to supply;
  • discriminatory access;
  • excessive pricing;
  • tying;
  • bundling;
  • self-preferencing;
  • exclusive dealing;
  • technical foreclosure;
  • interoperability restrictions; and
  • discriminatory API access.

B. Essential-facility theory

Identity infrastructure can potentially become an essential facility where:

  1. the infrastructure is indispensable;
  2. duplication is practically or economically impossible;
  3. access is necessary for effective competition; and
  4. refusal is capable of eliminating competition.

The doctrine is applied cautiously because competition law should not normally require successful firms to share every proprietary asset.

C. Leveraging

A dominant identity provider may use its position in verification to obtain power in another market.

For example:

Identity verification dominance → preferential access to payment services → payment-platform dominance.

Or:

Government identity infrastructure → exclusive authentication provider → dominant banking or telecommunications position.

4. Tying and Bundling

Suppose a company controls a highly important identity-verification system and requires users to purchase its:

  • payment service;
  • cloud service;
  • advertising service;
  • banking product; or
  • authentication software

as a condition of obtaining identity verification.

This may constitute an anticompetitive tying strategy where the provider uses power in the identity market to foreclose competitors in another market.

The key question is whether customers have a genuine ability to obtain identity verification independently.

5. Self-Preferencing

A particularly important concern arises when the identity provider also operates a downstream platform.

For example:

Platform A verifies identities for competing financial institutions while simultaneously operating its own financial marketplace.

Platform A could theoretically use its control over verification to:

  • rank its own services more favourably;
  • provide its own business with faster verification;
  • provide competitors with inferior authentication;
  • obtain verification data earlier; or
  • impose additional verification requirements on rivals.

This creates a structural conflict between neutral infrastructure provider and downstream competitor.

6. Interoperability and API Restrictions

Identity systems frequently operate through APIs.

A dominant provider may technically provide access but make interoperability difficult through:

  • restrictive API terms;
  • excessive technical requirements;
  • delayed approvals;
  • rate limits;
  • incompatible standards;
  • discriminatory authentication requirements;
  • excessive certification fees; or
  • refusal to support competing protocols.

Consequently, the formal existence of access does not necessarily mean that effective competition exists.

7. Data Portability

Data portability can reduce identity monopolization.

A user should potentially be able to move relevant identity information between competing services without being forced to undergo unnecessary repeated verification.

Portability can reduce:

identity lock-in → switching costs → entry barriers.

However, portability must be balanced against:

  • privacy;
  • cybersecurity;
  • identity theft;
  • consent;
  • data minimization; and
  • authentication integrity.

8. Refusal to Deal

A dominant identity infrastructure provider could refuse access to a competing business.

The competition-law question is whether the refusal constitutes legitimate protection of:

  • security;
  • privacy;
  • intellectual property;
  • infrastructure integrity;

or whether it is primarily designed to eliminate competition.

A refusal becomes more problematic where the infrastructure is indispensable and the provider itself competes against the undertaking requesting access.

9. Discriminatory Access

A dominant identity provider could offer:

  • favourable verification rates to its own subsidiaries;
  • preferential API access;
  • better verification speed;
  • superior fraud-detection information;
  • lower rejection rates; or
  • more favourable technical standards

to affiliated businesses.

Such discrimination can distort downstream competition even when the identity market itself appears competitive.

10. Excessive Pricing

Identity verification can also raise exploitative-abuse concerns.

If a provider controls an indispensable verification infrastructure and charges excessive prices, businesses may have no realistic alternative.

A competition authority would normally examine:

  • cost structure;
  • margins;
  • comparable prices;
  • regulatory constraints;
  • innovation investment;
  • infrastructure costs; and
  • availability of alternatives.

High prices alone are not automatically unlawful.

11. Privacy as a Competition Parameter

Privacy can itself constitute a competitive parameter.

A dominant identity provider may reduce privacy protections because consumers have nowhere else to go.

Competition may therefore involve:

Price + privacy + security + transparency + user control.

A privacy degradation can be particularly significant where users cannot realistically refuse the dominant identity provider.

12. Digital Identity and Public-Sector Monopolies

Public identity systems create a distinctive issue.

A government may legitimately establish a national identity system for:

  • taxation;
  • social welfare;
  • immigration;
  • public benefits;
  • elections;
  • healthcare;
  • public administration.

Such infrastructure is not automatically anticompetitive.

The competition concern arises when the state-backed system is combined with commercial activities or when private competitors are unnecessarily excluded from downstream markets.

13. Government Accreditation and Entry Barriers

Accreditation can be legitimate because identity verification involves security risks.

However, accreditation requirements can become exclusionary if:

  • only one provider is approved;
  • approval criteria are opaque;
  • certification is excessively expensive;
  • incumbent providers participate in setting technical standards;
  • approval processes are unnecessarily slow; or
  • alternative technologies are systematically excluded.

This creates a distinction between:

legitimate regulatory gatekeeping and anticompetitive gatekeeping.

14. Six Important Case Laws

The following cases are not all digital-identity cases specifically. They provide important competition-law principles applicable to digital identity verification monopolization.

1. United Brands v Commission

United Brands Company v Commission, Case 27/76 (1978)

The European Court of Justice examined abuse of dominance and excessive pricing.

Relevance

Digital identity providers may acquire substantial market power where customers cannot realistically substitute away from the verification infrastructure.

The case is particularly relevant to:

  • excessive pricing;
  • market definition;
  • dominance; and
  • exploitation of dependent customers.

It demonstrates that competition law can address exploitation where a dominant undertaking uses its market position to impose unfair conditions.

2. Commercial Solvents v Commission

Commercial Solvents Corp. v Commission, Joined Cases 6/73 and 7/73 (1974)

The Court addressed the refusal by a dominant undertaking to supply an input to a downstream competitor.

Relevance to identity verification

This principle is highly relevant where a dominant identity provider controls an indispensable authentication input while competing in a downstream market.

The concern can be represented as:

Dominant upstream identity input + downstream competition + refusal to supply = potential foreclosure.

3. Bronner v Mediaprint

Oscar Bronner GmbH & Co. KG v Mediaprint, Case C-7/97 (1998)

The Court established a restrictive framework for compulsory access to infrastructure.

Relevance

An identity-verification platform should not automatically be classified as an essential facility simply because competitors would benefit from access.

The Bronner criteria are particularly important for determining:

  • indispensability;
  • absence of realistic alternatives;
  • duplication feasibility; and
  • elimination of effective competition.

Thus, identity infrastructure must be genuinely indispensable before compulsory access is justified under the strict essential-facility framework.

4. Microsoft Corp. v Commission

Microsoft Corp. v Commission, Case T-201/04 (2007)

The General Court upheld important findings concerning Microsoft's refusal to provide interoperability information and its leveraging of market power.

Relevance

This is highly significant for digital identity systems.

Identity providers increasingly depend upon:

  • APIs;
  • interoperability protocols;
  • authentication standards;
  • identity tokens;
  • credential formats; and
  • technical documentation.

Withholding interoperability information can make rival systems technically incapable of competing effectively.

The case therefore provides an important conceptual foundation for interoperability-based identity competition.

5. Google Shopping

Google and Alphabet v Commission, Case T-612/17 (2021)

The General Court upheld the Commission's finding concerning Google's treatment of comparison-shopping services.

Relevance

The case illustrates the importance of self-preferencing and leveraging in digital ecosystems.

A dominant identity provider operating a downstream marketplace could potentially favour its own services through:

  • authentication priority;
  • verification speed;
  • ranking;
  • access to identity signals;
  • fraud-risk information; or
  • technical integration.

The broader principle is that control over an important digital infrastructure layer can influence competition in adjacent markets.

6. Slovak Telekom

Slovak Telekom a.s. v Commission, Joined Cases C-152/19 P and C-165/19 P (2021)

The case concerned exclusionary conduct involving telecommunications infrastructure.

Relevance

Digital identity systems share several characteristics with network infrastructure:

  • high sunk costs;
  • technical interoperability;
  • network effects;
  • switching barriers; and
  • downstream dependency.

The case helps demonstrate how infrastructure-level dominance can be used to foreclose downstream competitors.

15. Additional Important Case Laws

7. IMS Health

IMS Health GmbH & Co. OHG v NDC Health GmbH & Co. KG, Case C-418/01 (2004)

Important for the relationship between intellectual property, indispensability and refusal to license.

Identity relevance

A proprietary identity architecture should not automatically have to be licensed merely because it is commercially useful. The strict conditions governing compulsory access remain important.

8. Magill

RTE and ITP v Commission, Joined Cases C-241/91 P and C-242/91 P (1995)

The case developed the exceptional circumstances in which refusal to license intellectual property may constitute abuse.

Identity relevance

Useful for analysing proprietary identity databases, credential systems, authentication technology and interoperability information.

9. Google Android

Google LLC and Alphabet Inc. v Commission, Case T-604/18 (2022)

The case concerned Google's contractual and ecosystem practices involving Android.

Identity relevance

It illustrates how a dominant platform can use contractual arrangements and ecosystem integration to strengthen its position across interconnected markets.

A similar strategy could theoretically arise where identity verification is integrated with:

  • mobile operating systems;
  • app stores;
  • payments;
  • advertising; and
  • cloud services.

10. Intel

Intel Corp. v Commission, Case C-413/14 P (2017)

The Court clarified the analysis applicable to exclusivity-related rebates.

Identity relevance

A dominant identity provider could potentially offer rebates or preferential commercial terms conditional on customers obtaining identity verification exclusively from it.

The competition authority would need to analyse whether the arrangement is capable of foreclosing equally efficient competitors.

16. Market Definition Problems

Defining the relevant market is particularly difficult.

Possible markets include:

Narrow market

Digital identity verification services

Functional market

Remote identity verification

Technology-specific market

Biometric identity verification

Customer-specific market

Enterprise KYC verification

Infrastructure market

Identity authentication infrastructure

Ecosystem market

Digital identity and credential-management services

A provider might have only moderate market share in the broad identity market but very high market power in a specialised segment such as government-certified biometric authentication.

17. Two-Sided and Multi-Sided Markets

Digital identity verification often connects several groups:

Individuals ↔ Identity provider ↔ Banks/platforms/government agencies

The provider therefore may operate a multi-sided platform.

Competition authorities should consider:

  • indirect network effects;
  • cross-side subsidies;
  • zero-price consumer services;
  • data monetisation;
  • multi-homing;
  • interoperability;
  • switching costs; and
  • platform governance.

Traditional market-share analysis may therefore underestimate actual gatekeeping power.

18. Identity Verification as an Essential Digital Input

The most serious scenario occurs when identity verification becomes indispensable for participating in another market.

For example:

A financial marketplace requires identity verification before any lender can transact with consumers.

If one company controls the only practically usable verification mechanism, it can potentially control entry into the lending market.

The competitive structure becomes:

Identity monopoly → access monopoly → downstream market power.

This is more serious than an ordinary dominant supplier because the identity layer determines who is allowed to participate.

19. Monopolization Through Technical Standards

Identity providers may influence standards concerning:

  • biometric formats;
  • digital credentials;
  • authentication protocols;
  • APIs;
  • encryption;
  • device binding;
  • digital signatures; and
  • identity assurance levels.

A dominant undertaking could potentially use standards strategically to make competing technologies incompatible.

This creates a form of standards-based foreclosure.

20. Algorithmic Discrimination

Modern identity verification increasingly uses AI.

A dominant provider may determine:

  • who is verified;
  • who is rejected;
  • who receives enhanced verification;
  • who is classified as suspicious;
  • which documents are accepted; and
  • which biometric signals are treated as reliable.

If competing businesses receive systematically worse verification outcomes, algorithmic design may become a competitive weapon.

The relevant evidence may include:

  • rejection rates;
  • false-positive rates;
  • API response times;
  • model thresholds;
  • training data;
  • error distributions; and
  • audit logs.

21. Identity Fraud Databases and Competitive Advantage

A provider controlling a large fraud database may have a significant advantage because its system can identify suspicious activity more effectively.

This can create a reinforcing cycle:

More users → more fraud data → better detection → better reputation → more users.

Competitors may struggle to replicate this advantage because they cannot acquire equivalent historical data.

This is a classic data-driven entry barrier.

22. Merger Concerns

Competition authorities should scrutinise mergers involving:

  • identity providers;
  • biometric companies;
  • banks;
  • telecommunications companies;
  • cloud providers;
  • payment platforms;
  • government contractors; and
  • large digital platforms.

A vertical merger could create:

Identity verification + payments

or:

Identity verification + telecommunications

or:

Identity verification + digital marketplace.

The merged entity may then have incentives to foreclose competitors.

23. Remedies

Competition authorities may consider several remedies.

Structural remedies

  • divestiture;
  • separation of identity and downstream commercial operations;
  • independent governance.

Behavioural remedies

  • non-discriminatory access;
  • fair pricing;
  • interoperability obligations;
  • API access;
  • prohibition of self-preferencing;
  • transparent accreditation.

Data remedies

  • portability;
  • interoperability;
  • controlled data sharing;
  • restrictions on combining identity data with unrelated commercial datasets.

Governance remedies

  • independent auditing;
  • technical oversight;
  • transparency requirements;
  • algorithmic accountability.

24. Competition-Law Risk Matrix

ConductPotential competition concern
Refusal to provide identity verificationForeclosure
Excessive verification feesExploitative abuse
Exclusive contractsCompetitor exclusion
Bundling verification with paymentsLeveraging
Self-preferencingDownstream foreclosure
API restrictionsInteroperability foreclosure
Data hoardingEntry barrier
Discriminatory verificationRival disadvantage
Exclusive government accreditationRegulatory foreclosure
Proprietary standardsTechnical lock-in
Identity-data combinationEcosystem dominance
Algorithmic discriminationHidden foreclosure

25. Key Legal Test

A useful competition-law framework is:

Step 1 — Define the market

What exactly is being supplied?

Step 2 — Establish dominance

Does the provider possess substantial market power?

Step 3 — Identify the gatekeeping function

Is identity verification indispensable or merely convenient?

Step 4 — Identify exclusionary conduct

Is the provider:

  • refusing access;
  • discriminating;
  • tying;
  • self-preferencing;
  • restricting interoperability; or
  • imposing exclusivity?

Step 5 — Establish foreclosure

Are competitors actually or potentially excluded?

Step 6 — Examine objective justification

Is the conduct genuinely necessary for:

  • cybersecurity;
  • privacy;
  • fraud prevention;
  • regulatory compliance?

Step 7 — Proportionality

Could the legitimate objective be achieved through a less restrictive method?

Step 8 — Remedy

Would interoperability, portability, non-discrimination, functional separation or another remedy restore competition?

Conclusion

Digital identity verification can evolve from an ordinary digital service into critical economic infrastructure. The most significant competition-law risk arises when a provider simultaneously controls identity verification and competes in markets for which that verification is required.

The central concern is therefore not simply:

“Who verifies identity?”

but:

“Who controls the gateway through which businesses and individuals are permitted to participate in digital markets?”

The principles from United Brands, Commercial Solvents, Bronner, Microsoft, Google Shopping, Slovak Telekom, IMS Health, Magill, Google Android and Intel provide a strong legal framework for analysing these problems.

The most important safeguards are interoperability, non-discriminatory access, data portability, transparent accreditation, limits on self-preferencing, separation of infrastructure from downstream competition, and carefully proportionate regulation. At the same time, competition law must avoid forcing open every proprietary identity system merely because competitors would benefit from access; indispensability and genuine foreclosure remain critical thresholds.

LEAVE A COMMENT