Digital Identity Wallet Competition Internationally .
Digital Identity Verification Monopolization Concerns
Introduction
Digital identity verification monopolization refers to a situation in which one enterprise, platform, infrastructure operator, government-linked entity, or small group of providers obtains substantial control over the systems used to establish that a person or business is digitally identifiable, authenticated, trusted, or eligible to access services.
Digital identity verification may include:
- biometric authentication;
- government-issued digital identity;
- electronic KYC;
- authentication APIs;
- identity wallets;
- device-based identity;
- bank or telecom identity verification;
- digital signatures and certificates;
- age and eligibility verification;
- identity-risk scoring;
- facial recognition;
- fraud and identity databases; and
- interoperability or federation infrastructure.
The competition-law concern is not simply that one company is large. The central concern is that control over identity verification can become a gatekeeping position through which access to downstream markets is controlled.
1. Meaning of Digital Identity Verification Monopolization
A digital identity provider becomes potentially problematic when competitors, consumers, public authorities, or businesses cannot realistically operate without using its verification infrastructure.
A simplified structure is:
Identity data → Verification infrastructure → Authentication decision → Access to downstream market
For example:
Identity provider → verifies individual → bank accepts verification → individual obtains financial service.
If the identity provider becomes indispensable, it may acquire bottleneck or essential-input characteristics.
The monopolization concern becomes stronger where the provider:
- controls a unique identity database;
- controls authentication standards;
- determines who can access verification services;
- controls APIs or interoperability;
- combines identity verification with another dominant platform;
- discriminates between affiliated and competing services;
- imposes excessive or discriminatory fees;
- restricts data portability;
- uses verification data to enter adjacent markets; or
- makes exclusion from its identity ecosystem equivalent to exclusion from important digital markets.
2. Why Identity Verification Can Become a Monopoly Bottleneck
A. Network effects
Digital identity systems benefit from network effects.
The more businesses that accept an identity credential, the more valuable that credential becomes to users.
Likewise:
More users → more relying parties → greater value → more users
A dominant identity system can therefore become progressively harder to challenge.
B. High switching costs
Changing identity infrastructure is difficult because businesses may have to:
- redesign authentication systems;
- reverify millions of customers;
- modify compliance procedures;
- integrate new APIs;
- obtain regulatory approvals;
- retrain personnel;
- change fraud-detection systems; and
- maintain two systems during migration.
Consequently, even where another provider technically exists, effective competition may remain weak.
C. Identity data advantages
A large identity provider may possess:
- historical verification records;
- biometric information;
- fraud indicators;
- device information;
- transaction-linked identity information;
- behavioural signals; and
- authentication histories.
These datasets can produce a substantial competitive advantage.
A particularly important concern is data feedback:
More verification activity → more data → better verification → greater adoption → still more data.
This can create a self-reinforcing competitive advantage.
3. Relevant Competition-Law Theories
A. Abuse of dominance
A dominant identity-verification provider may potentially engage in:
- discriminatory access;
- refusal to supply;
- excessive pricing;
- tying;
- self-preferencing;
- exclusionary interoperability restrictions;
- loyalty-inducing arrangements;
- discriminatory technical standards; or
- exploitation of identity-dependent users.
B. Essential-facilities-type concerns
Where a verification infrastructure is genuinely indispensable, refusal to provide access can raise an essential-facilities-type issue.
However, courts generally do not treat every important infrastructure as an essential facility.
The claimant ordinarily needs to establish something approaching:
- control of an indispensable facility;
- lack of realistic alternatives;
- inability to reasonably duplicate the facility; and
- potential elimination of effective competition.
C. Tying
Suppose a dominant identity provider requires companies using its identity-verification service also to use its:
- payment service;
- cloud platform;
- advertising service;
- cybersecurity product; or
- marketplace.
That may create a tying concern where dominance in identity verification is leveraged into an adjacent market.
D. Self-preferencing
A vertically integrated identity provider might verify users for its own downstream platform while making verification:
- slower;
- more expensive;
- technically inferior; or
- less reliable
for competing services.
This creates a potential identity infrastructure self-preferencing problem.
4. Six Important Case Laws
Although there are relatively few reported decisions dealing specifically with modern digital identity-verification monopolies, established competition-law cases provide the principal legal framework.
1. United Brands v Commission — C-27/76
Principle
The European Court of Justice examined dominance, market power and abusive conduct in the banana market.
The case is important because it demonstrates that dominance is assessed through the undertaking's economic power and ability to behave independently of competitors, customers and consumers.
Application to digital identity
An identity-verification provider could potentially be dominant where:
- users cannot realistically switch;
- relying businesses have no equivalent alternative;
- the provider controls a critical identity ecosystem; and
- customers are effectively dependent upon it.
Market share alone would not be sufficient; the relevant question would be whether the provider possesses substantial market power.
2. Commercial Solvents v Commission — Joined Cases 6/73 and 7/73
Principle
The Court recognized that a dominant undertaking controlling an important upstream input could potentially abuse its position by restricting supplies to downstream competitors.
Relevance
This is highly relevant to identity verification.
Imagine:
Identity database/API → downstream financial platforms
If a dominant identity infrastructure provider supplies verification to its own downstream business but refuses equivalent access to competing businesses, the upstream identity service can function as a bottleneck input.
The case therefore supports the proposition that dominance in an upstream market cannot legitimately be used to eliminate downstream competition.
3. Bronner v Mediaprint — C-7/97
Principle
Bronner is one of the most important cases concerning refusal to deal and essential facilities.
The Court adopted a demanding test for requiring a dominant undertaking to provide access to infrastructure.
The facility generally must be indispensable, and there must be no realistic alternative or reasonable possibility of duplication.
Application
A digital identity infrastructure would not automatically qualify as an essential facility merely because it is popular.
The claimant would need to demonstrate, for example:
- no practical substitute verification mechanism;
- technical impossibility of replication;
- regulatory barriers;
- enormous duplication costs; and
- substantial elimination of competition.
Thus, indispensability is considerably more demanding than mere usefulness.
4. Microsoft Corp. v Commission — Case T-201/04
Principle
The EU General Court upheld findings concerning Microsoft's refusal to provide interoperability information and its leveraging of dominance into adjacent markets.
The case is particularly important for interoperability and technological ecosystems.
Digital identity relevance
Identity systems frequently depend upon interoperability.
A dominant identity provider might control:
- authentication protocols;
- APIs;
- identity credentials;
- verification tokens;
- interoperability specifications; and
- technical certification.
If interoperability restrictions prevent competing verification or authentication services from functioning effectively, Microsoft provides a useful analytical framework.
The competition concern becomes especially strong where technical restrictions effectively convert an open digital market into a closed identity ecosystem.
5. Google Shopping — Case T-612/17
Principle
The EU General Court upheld the Commission's finding that Google had abused its dominant position in general search by favouring its own comparison-shopping service.
The case is highly relevant to self-preferencing.
Application to identity verification
Suppose a company operates:
dominant identity verification → identity wallet → financial marketplace
and systematically gives its own downstream services preferential access to:
- authentication speed;
- verification accuracy;
- identity credentials;
- API functionality; or
- user visibility.
The competition question would then be whether the identity infrastructure is being used to advantage the provider's own downstream operations.
Digital identity can therefore become a new form of vertical gatekeeping.
6. Slovak Telekom v Commission — Joined Cases C-165/19 P and C-166/19 P
Principle
The Court considered abusive exclusionary conduct involving access to telecommunications infrastructure and the relationship between general abuse-of-dominance principles and access obligations.
Relevance
Identity verification increasingly resembles infrastructure.
A provider may occupy several layers:
identity database → authentication → API → credential → downstream service
Control over one layer can affect competition across the entire stack.
The telecommunications analogy is therefore useful: where infrastructure is controlled by a dominant undertaking, access conditions may have substantial competitive consequences for downstream markets.
7. IMS Health v Commission — Case C-418/01
Principle
IMS Health concerned intellectual-property rights and access to an indispensable structure.
The Court developed important criteria concerning when refusal to license or provide access may constitute abuse.
Among the relevant considerations were:
- indispensability;
- prevention of the emergence of a new product or service;
- lack of justification; and
- elimination of competition.
Digital identity application
An identity-verification system could potentially raise analogous issues where:
access to the identity infrastructure is indispensable for developing a competing service.
For example, a dominant identity provider might prevent competing identity-wallet providers from accessing necessary authentication infrastructure.
But the IMS Health/Bronner threshold remains high.
5. Monopoly Through Identity Federation
Identity federation creates another potential concentration problem.
A federation allows multiple services to rely upon a common authentication mechanism.
For example:
Identity Provider A
↓
Government services
Banks
Healthcare platforms
Education platforms
E-commerce
Employment platforms
If one provider becomes the default federation authority, it may acquire considerable gatekeeping power.
The provider may then influence:
- who can participate;
- what authentication standards apply;
- what information is disclosed;
- what verification level is required;
- how quickly authentication occurs; and
- whether competitors can interoperate.
The competition issue therefore moves beyond ordinary authentication into ecosystem governance.
6. Government-Backed Identity Monopolies
A particularly difficult problem arises where the identity provider is:
- government-owned;
- government-designated;
- legally mandatory; or
- operating under a statutory monopoly.
Competition law cannot necessarily be used to create competition where legislation intentionally establishes a monopoly.
However, several separate issues may arise:
1. Equal access
Private businesses may require non-discriminatory access.
2. Downstream neutrality
The identity operator should not favour particular downstream providers.
3. Interoperability
Alternative identity systems may need appropriate technical interoperability.
4. Data governance
Identity data should not automatically become a competitive weapon.
5. Separation of functions
There may be justification for separating:
identity verification infrastructure
from
commercial services competing downstream.
7. Data Portability as a Competition Remedy
Traditional competition remedies may be insufficient where identity itself creates lock-in.
Possible remedies include:
A. Data portability
Users may be allowed to transfer identity credentials or verification information.
B. API access
Qualified competitors could obtain standardized technical access.
C. Interoperability obligations
Different identity systems could communicate using common standards.
D. Non-discrimination
The identity provider could be prohibited from treating affiliated and competing services differently.
E. Functional separation
Infrastructure and downstream commercial activities could be separated.
F. Multi-provider authentication
Users could choose among multiple identity providers.
8. Privacy and Competition Intersect
Digital identity monopolization is unusual because privacy and competition can reinforce one another.
A dominant identity provider may possess enormous quantities of sensitive information.
Competition authorities may therefore confront a combined problem:
Market power + data concentration + identity dependence.
A company could theoretically use identity data to:
- improve targeted advertising;
- develop creditworthiness models;
- identify valuable consumers;
- discriminate between users;
- strengthen fraud systems;
- enter financial markets; or
- reinforce an existing platform ecosystem.
Accordingly, competition analysis may need to examine not only price, but also:
- privacy;
- data control;
- security;
- interoperability;
- consumer choice; and
- technological independence.
9. Exclusionary Conduct in Digital Identity Markets
| Conduct | Potential competition concern |
|---|---|
| Refusal to provide verification | Foreclosure |
| Excessive verification fees | Exploitative abuse |
| Discriminatory API access | Raising rivals' costs |
| Self-preferencing | Vertical foreclosure |
| Mandatory bundling | Tying |
| Exclusive authentication | Market foreclosure |
| Data hoarding | Entry barrier |
| Technical incompatibility | Interoperability foreclosure |
| Restricting portability | Lock-in |
| Preferential treatment of affiliates | Discrimination |
| Exclusive government contracts | Entrenchment |
| Acquisition of competing identity provider | Elimination of potential competition |
10. Market Definition Problems
Defining the relevant market is particularly difficult.
Possible markets include:
Narrow market
Digital identity verification services
Functional market
Electronic identity authentication
Technology-specific market
Biometric identity verification
Customer-specific market
Enterprise identity verification
Infrastructure market
Identity authentication APIs
Broader market
Digital trust and authentication services
A regulator must determine whether alternative methods—such as passwords, bank verification, telecom verification, government credentials, biometrics or decentralized identity—actually constrain the dominant provider.
The critical distinction is between technical substitutability and commercial substitutability.
A theoretically available alternative may not be a genuine competitive constraint if businesses cannot practically migrate to it.
11. Entry Barriers
Digital identity markets can have unusually high entry barriers.
Regulatory barriers
Identity providers may need authorization to operate within regulated sectors.
Security barriers
A new provider must establish extremely high levels of:
- cybersecurity;
- reliability;
- fraud prevention; and
- authentication accuracy.
Trust barriers
Users and businesses may hesitate to adopt unknown identity providers.
Network effects
An identity provider needs both:
- individuals; and
- relying institutions.
This creates a difficult two-sided adoption problem.
Data advantages
Incumbents may have datasets that new entrants cannot reproduce.
12. Consumer Welfare Concerns
Monopolization may harm consumers even where identity verification is nominally free.
Possible harms include:
- reduced privacy;
- excessive data collection;
- mandatory tracking;
- reduced choice;
- exclusion from digital services;
- identity errors;
- discriminatory authentication;
- account lockouts;
- surveillance risks; and
- reduced innovation.
Therefore:
Zero monetary price does not necessarily mean zero competitive harm.
The relevant competitive dimensions can include privacy, quality, security, innovation and autonomy.
13. Error and Exclusion as a Competition Issue
Identity verification is different from ordinary digital platforms because authentication errors can exclude a person from an entire ecosystem.
Suppose one identity provider incorrectly classifies an individual as:
- fraudulent;
- underage;
- high-risk;
- unverified; or
- ineligible.
If thousands of downstream services rely upon that decision, one error can propagate throughout the digital economy.
This creates a potential single point of failure.
From a competition perspective, centralized verification can therefore produce both:
market concentration risk
and
systemic exclusion risk.
14. Structural Competition Concerns
The most serious concern arises where identity verification becomes the foundation of several markets simultaneously.
For example:
Identity
↓
Banking
↓
Payments
↓
E-commerce
↓
Healthcare
↓
Government services
↓
Employment
A single dominant identity infrastructure could consequently exercise influence across multiple adjacent markets.
This is sometimes described as cross-market gatekeeping.
Traditional competition analysis may therefore need to consider ecosystem effects rather than examining every market independently.
15. Possible Legal Remedies
Competition authorities could consider a combination of behavioural and structural remedies.
Behavioural remedies
- mandatory interoperability;
- non-discriminatory access;
- transparent verification criteria;
- API access;
- portability;
- prohibition of tying;
- restrictions on self-preferencing;
- audit requirements; and
- independent dispute mechanisms.
Structural remedies
In extreme cases:
- functional separation;
- data separation;
- divestiture;
- independent infrastructure governance; or
- separation between verification and downstream commercial services.
Structural intervention would generally require particularly strong evidence that behavioural remedies cannot adequately restore competition.
16. Key Legal Lessons From the Case Law
The six principal cases collectively establish several important propositions:
| Case | Core principle | Digital identity application |
|---|---|---|
| United Brands | Dominance | Identity market power |
| Commercial Solvents | Upstream bottleneck abuse | Identity input foreclosure |
| Bronner | Indispensability | Essential identity infrastructure |
| Microsoft | Interoperability | Identity/API interoperability |
| Google Shopping | Self-preferencing | Preferential authentication |
| Slovak Telekom | Infrastructure access | Identity infrastructure |
| IMS Health | Exceptional access obligation | Access to indispensable identity architecture |
Conclusion
Digital identity verification monopolization represents a potentially significant next-generation competition-law problem.
The fundamental risk is not simply that an identity provider becomes large. It is that identity verification becomes a mandatory gateway to participation in other markets.
The strongest competition concerns arise where one provider simultaneously controls:
identity data + authentication infrastructure + interoperability + verification standards + downstream commercial services.
At that point, identity verification can transform from an ordinary digital service into critical competitive infrastructure.
The most relevant established legal principles come from Bronner, IMS Health, Commercial Solvents, Microsoft, Slovak Telekom, Google Shopping and United Brands. These cases suggest that competition authorities should distinguish ordinary market success from genuine bottleneck control, while paying particular attention to indispensability, interoperability, refusal to supply, self-preferencing, data advantages, switching costs and downstream foreclosure.
Ultimately, the central regulatory question is:
Can individuals and businesses meaningfully participate in digital markets without being forced to depend upon one identity-verification gatekeeper?

comments