Digital Identity Wallet Competition Internationally .

 

Digital Identity Verification Monopolization Concerns

Introduction

Digital identity verification monopolization refers to a situation in which one enterprise, platform, infrastructure operator, government-linked entity, or small group of providers obtains substantial control over the systems used to establish that a person or business is digitally identifiable, authenticated, trusted, or eligible to access services.

Digital identity verification may include:

  • biometric authentication;
  • government-issued digital identity;
  • electronic KYC;
  • authentication APIs;
  • identity wallets;
  • device-based identity;
  • bank or telecom identity verification;
  • digital signatures and certificates;
  • age and eligibility verification;
  • identity-risk scoring;
  • facial recognition;
  • fraud and identity databases; and
  • interoperability or federation infrastructure.

The competition-law concern is not simply that one company is large. The central concern is that control over identity verification can become a gatekeeping position through which access to downstream markets is controlled.

1. Meaning of Digital Identity Verification Monopolization

A digital identity provider becomes potentially problematic when competitors, consumers, public authorities, or businesses cannot realistically operate without using its verification infrastructure.

A simplified structure is:

Identity data → Verification infrastructure → Authentication decision → Access to downstream market

For example:

Identity provider → verifies individual → bank accepts verification → individual obtains financial service.

If the identity provider becomes indispensable, it may acquire bottleneck or essential-input characteristics.

The monopolization concern becomes stronger where the provider:

  1. controls a unique identity database;
  2. controls authentication standards;
  3. determines who can access verification services;
  4. controls APIs or interoperability;
  5. combines identity verification with another dominant platform;
  6. discriminates between affiliated and competing services;
  7. imposes excessive or discriminatory fees;
  8. restricts data portability;
  9. uses verification data to enter adjacent markets; or
  10. makes exclusion from its identity ecosystem equivalent to exclusion from important digital markets.

2. Why Identity Verification Can Become a Monopoly Bottleneck

A. Network effects

Digital identity systems benefit from network effects.

The more businesses that accept an identity credential, the more valuable that credential becomes to users.

Likewise:

More users → more relying parties → greater value → more users

A dominant identity system can therefore become progressively harder to challenge.

B. High switching costs

Changing identity infrastructure is difficult because businesses may have to:

  • redesign authentication systems;
  • reverify millions of customers;
  • modify compliance procedures;
  • integrate new APIs;
  • obtain regulatory approvals;
  • retrain personnel;
  • change fraud-detection systems; and
  • maintain two systems during migration.

Consequently, even where another provider technically exists, effective competition may remain weak.

C. Identity data advantages

A large identity provider may possess:

  • historical verification records;
  • biometric information;
  • fraud indicators;
  • device information;
  • transaction-linked identity information;
  • behavioural signals; and
  • authentication histories.

These datasets can produce a substantial competitive advantage.

A particularly important concern is data feedback:

More verification activity → more data → better verification → greater adoption → still more data.

This can create a self-reinforcing competitive advantage.

3. Relevant Competition-Law Theories

A. Abuse of dominance

A dominant identity-verification provider may potentially engage in:

  • discriminatory access;
  • refusal to supply;
  • excessive pricing;
  • tying;
  • self-preferencing;
  • exclusionary interoperability restrictions;
  • loyalty-inducing arrangements;
  • discriminatory technical standards; or
  • exploitation of identity-dependent users.

B. Essential-facilities-type concerns

Where a verification infrastructure is genuinely indispensable, refusal to provide access can raise an essential-facilities-type issue.

However, courts generally do not treat every important infrastructure as an essential facility.

The claimant ordinarily needs to establish something approaching:

  1. control of an indispensable facility;
  2. lack of realistic alternatives;
  3. inability to reasonably duplicate the facility; and
  4. potential elimination of effective competition.

C. Tying

Suppose a dominant identity provider requires companies using its identity-verification service also to use its:

  • payment service;
  • cloud platform;
  • advertising service;
  • cybersecurity product; or
  • marketplace.

That may create a tying concern where dominance in identity verification is leveraged into an adjacent market.

D. Self-preferencing

A vertically integrated identity provider might verify users for its own downstream platform while making verification:

  • slower;
  • more expensive;
  • technically inferior; or
  • less reliable

for competing services.

This creates a potential identity infrastructure self-preferencing problem.

4. Six Important Case Laws

Although there are relatively few reported decisions dealing specifically with modern digital identity-verification monopolies, established competition-law cases provide the principal legal framework.

1. United Brands v Commission — C-27/76

Principle

The European Court of Justice examined dominance, market power and abusive conduct in the banana market.

The case is important because it demonstrates that dominance is assessed through the undertaking's economic power and ability to behave independently of competitors, customers and consumers.

Application to digital identity

An identity-verification provider could potentially be dominant where:

  • users cannot realistically switch;
  • relying businesses have no equivalent alternative;
  • the provider controls a critical identity ecosystem; and
  • customers are effectively dependent upon it.

Market share alone would not be sufficient; the relevant question would be whether the provider possesses substantial market power.

2. Commercial Solvents v Commission — Joined Cases 6/73 and 7/73

Principle

The Court recognized that a dominant undertaking controlling an important upstream input could potentially abuse its position by restricting supplies to downstream competitors.

Relevance

This is highly relevant to identity verification.

Imagine:

Identity database/API → downstream financial platforms

If a dominant identity infrastructure provider supplies verification to its own downstream business but refuses equivalent access to competing businesses, the upstream identity service can function as a bottleneck input.

The case therefore supports the proposition that dominance in an upstream market cannot legitimately be used to eliminate downstream competition.

3. Bronner v Mediaprint — C-7/97

Principle

Bronner is one of the most important cases concerning refusal to deal and essential facilities.

The Court adopted a demanding test for requiring a dominant undertaking to provide access to infrastructure.

The facility generally must be indispensable, and there must be no realistic alternative or reasonable possibility of duplication.

Application

A digital identity infrastructure would not automatically qualify as an essential facility merely because it is popular.

The claimant would need to demonstrate, for example:

  • no practical substitute verification mechanism;
  • technical impossibility of replication;
  • regulatory barriers;
  • enormous duplication costs; and
  • substantial elimination of competition.

Thus, indispensability is considerably more demanding than mere usefulness.

4. Microsoft Corp. v Commission — Case T-201/04

Principle

The EU General Court upheld findings concerning Microsoft's refusal to provide interoperability information and its leveraging of dominance into adjacent markets.

The case is particularly important for interoperability and technological ecosystems.

Digital identity relevance

Identity systems frequently depend upon interoperability.

A dominant identity provider might control:

  • authentication protocols;
  • APIs;
  • identity credentials;
  • verification tokens;
  • interoperability specifications; and
  • technical certification.

If interoperability restrictions prevent competing verification or authentication services from functioning effectively, Microsoft provides a useful analytical framework.

The competition concern becomes especially strong where technical restrictions effectively convert an open digital market into a closed identity ecosystem.

5. Google Shopping — Case T-612/17

Principle

The EU General Court upheld the Commission's finding that Google had abused its dominant position in general search by favouring its own comparison-shopping service.

The case is highly relevant to self-preferencing.

Application to identity verification

Suppose a company operates:

dominant identity verification → identity wallet → financial marketplace

and systematically gives its own downstream services preferential access to:

  • authentication speed;
  • verification accuracy;
  • identity credentials;
  • API functionality; or
  • user visibility.

The competition question would then be whether the identity infrastructure is being used to advantage the provider's own downstream operations.

Digital identity can therefore become a new form of vertical gatekeeping.

6. Slovak Telekom v Commission — Joined Cases C-165/19 P and C-166/19 P

Principle

The Court considered abusive exclusionary conduct involving access to telecommunications infrastructure and the relationship between general abuse-of-dominance principles and access obligations.

Relevance

Identity verification increasingly resembles infrastructure.

A provider may occupy several layers:

identity database → authentication → API → credential → downstream service

Control over one layer can affect competition across the entire stack.

The telecommunications analogy is therefore useful: where infrastructure is controlled by a dominant undertaking, access conditions may have substantial competitive consequences for downstream markets.

7. IMS Health v Commission — Case C-418/01

Principle

IMS Health concerned intellectual-property rights and access to an indispensable structure.

The Court developed important criteria concerning when refusal to license or provide access may constitute abuse.

Among the relevant considerations were:

  • indispensability;
  • prevention of the emergence of a new product or service;
  • lack of justification; and
  • elimination of competition.

Digital identity application

An identity-verification system could potentially raise analogous issues where:

access to the identity infrastructure is indispensable for developing a competing service.

For example, a dominant identity provider might prevent competing identity-wallet providers from accessing necessary authentication infrastructure.

But the IMS Health/Bronner threshold remains high.

5. Monopoly Through Identity Federation

Identity federation creates another potential concentration problem.

A federation allows multiple services to rely upon a common authentication mechanism.

For example:

Identity Provider A

↓

Government services
Banks
Healthcare platforms
Education platforms
E-commerce
Employment platforms

If one provider becomes the default federation authority, it may acquire considerable gatekeeping power.

The provider may then influence:

  • who can participate;
  • what authentication standards apply;
  • what information is disclosed;
  • what verification level is required;
  • how quickly authentication occurs; and
  • whether competitors can interoperate.

The competition issue therefore moves beyond ordinary authentication into ecosystem governance.

6. Government-Backed Identity Monopolies

A particularly difficult problem arises where the identity provider is:

  • government-owned;
  • government-designated;
  • legally mandatory; or
  • operating under a statutory monopoly.

Competition law cannot necessarily be used to create competition where legislation intentionally establishes a monopoly.

However, several separate issues may arise:

1. Equal access

Private businesses may require non-discriminatory access.

2. Downstream neutrality

The identity operator should not favour particular downstream providers.

3. Interoperability

Alternative identity systems may need appropriate technical interoperability.

4. Data governance

Identity data should not automatically become a competitive weapon.

5. Separation of functions

There may be justification for separating:

identity verification infrastructure

from

commercial services competing downstream.

7. Data Portability as a Competition Remedy

Traditional competition remedies may be insufficient where identity itself creates lock-in.

Possible remedies include:

A. Data portability

Users may be allowed to transfer identity credentials or verification information.

B. API access

Qualified competitors could obtain standardized technical access.

C. Interoperability obligations

Different identity systems could communicate using common standards.

D. Non-discrimination

The identity provider could be prohibited from treating affiliated and competing services differently.

E. Functional separation

Infrastructure and downstream commercial activities could be separated.

F. Multi-provider authentication

Users could choose among multiple identity providers.

8. Privacy and Competition Intersect

Digital identity monopolization is unusual because privacy and competition can reinforce one another.

A dominant identity provider may possess enormous quantities of sensitive information.

Competition authorities may therefore confront a combined problem:

Market power + data concentration + identity dependence.

A company could theoretically use identity data to:

  • improve targeted advertising;
  • develop creditworthiness models;
  • identify valuable consumers;
  • discriminate between users;
  • strengthen fraud systems;
  • enter financial markets; or
  • reinforce an existing platform ecosystem.

Accordingly, competition analysis may need to examine not only price, but also:

  • privacy;
  • data control;
  • security;
  • interoperability;
  • consumer choice; and
  • technological independence.

9. Exclusionary Conduct in Digital Identity Markets

ConductPotential competition concern
Refusal to provide verificationForeclosure
Excessive verification feesExploitative abuse
Discriminatory API accessRaising rivals' costs
Self-preferencingVertical foreclosure
Mandatory bundlingTying
Exclusive authenticationMarket foreclosure
Data hoardingEntry barrier
Technical incompatibilityInteroperability foreclosure
Restricting portabilityLock-in
Preferential treatment of affiliatesDiscrimination
Exclusive government contractsEntrenchment
Acquisition of competing identity providerElimination of potential competition

10. Market Definition Problems

Defining the relevant market is particularly difficult.

Possible markets include:

Narrow market

Digital identity verification services

Functional market

Electronic identity authentication

Technology-specific market

Biometric identity verification

Customer-specific market

Enterprise identity verification

Infrastructure market

Identity authentication APIs

Broader market

Digital trust and authentication services

A regulator must determine whether alternative methods—such as passwords, bank verification, telecom verification, government credentials, biometrics or decentralized identity—actually constrain the dominant provider.

The critical distinction is between technical substitutability and commercial substitutability.

A theoretically available alternative may not be a genuine competitive constraint if businesses cannot practically migrate to it.

11. Entry Barriers

Digital identity markets can have unusually high entry barriers.

Regulatory barriers

Identity providers may need authorization to operate within regulated sectors.

Security barriers

A new provider must establish extremely high levels of:

  • cybersecurity;
  • reliability;
  • fraud prevention; and
  • authentication accuracy.

Trust barriers

Users and businesses may hesitate to adopt unknown identity providers.

Network effects

An identity provider needs both:

  • individuals; and
  • relying institutions.

This creates a difficult two-sided adoption problem.

Data advantages

Incumbents may have datasets that new entrants cannot reproduce.

12. Consumer Welfare Concerns

Monopolization may harm consumers even where identity verification is nominally free.

Possible harms include:

  • reduced privacy;
  • excessive data collection;
  • mandatory tracking;
  • reduced choice;
  • exclusion from digital services;
  • identity errors;
  • discriminatory authentication;
  • account lockouts;
  • surveillance risks; and
  • reduced innovation.

Therefore:

Zero monetary price does not necessarily mean zero competitive harm.

The relevant competitive dimensions can include privacy, quality, security, innovation and autonomy.

13. Error and Exclusion as a Competition Issue

Identity verification is different from ordinary digital platforms because authentication errors can exclude a person from an entire ecosystem.

Suppose one identity provider incorrectly classifies an individual as:

  • fraudulent;
  • underage;
  • high-risk;
  • unverified; or
  • ineligible.

If thousands of downstream services rely upon that decision, one error can propagate throughout the digital economy.

This creates a potential single point of failure.

From a competition perspective, centralized verification can therefore produce both:

market concentration risk

and

systemic exclusion risk.

14. Structural Competition Concerns

The most serious concern arises where identity verification becomes the foundation of several markets simultaneously.

For example:

Identity

↓

Banking

↓

Payments

↓

E-commerce

↓

Healthcare

↓

Government services

↓

Employment

A single dominant identity infrastructure could consequently exercise influence across multiple adjacent markets.

This is sometimes described as cross-market gatekeeping.

Traditional competition analysis may therefore need to consider ecosystem effects rather than examining every market independently.

15. Possible Legal Remedies

Competition authorities could consider a combination of behavioural and structural remedies.

Behavioural remedies

  • mandatory interoperability;
  • non-discriminatory access;
  • transparent verification criteria;
  • API access;
  • portability;
  • prohibition of tying;
  • restrictions on self-preferencing;
  • audit requirements; and
  • independent dispute mechanisms.

Structural remedies

In extreme cases:

  • functional separation;
  • data separation;
  • divestiture;
  • independent infrastructure governance; or
  • separation between verification and downstream commercial services.

Structural intervention would generally require particularly strong evidence that behavioural remedies cannot adequately restore competition.

16. Key Legal Lessons From the Case Law

The six principal cases collectively establish several important propositions:

CaseCore principleDigital identity application
United BrandsDominanceIdentity market power
Commercial SolventsUpstream bottleneck abuseIdentity input foreclosure
BronnerIndispensabilityEssential identity infrastructure
MicrosoftInteroperabilityIdentity/API interoperability
Google ShoppingSelf-preferencingPreferential authentication
Slovak TelekomInfrastructure accessIdentity infrastructure
IMS HealthExceptional access obligationAccess to indispensable identity architecture

Conclusion

Digital identity verification monopolization represents a potentially significant next-generation competition-law problem.

The fundamental risk is not simply that an identity provider becomes large. It is that identity verification becomes a mandatory gateway to participation in other markets.

The strongest competition concerns arise where one provider simultaneously controls:

identity data + authentication infrastructure + interoperability + verification standards + downstream commercial services.

At that point, identity verification can transform from an ordinary digital service into critical competitive infrastructure.

The most relevant established legal principles come from Bronner, IMS Health, Commercial Solvents, Microsoft, Slovak Telekom, Google Shopping and United Brands. These cases suggest that competition authorities should distinguish ordinary market success from genuine bottleneck control, while paying particular attention to indispensability, interoperability, refusal to supply, self-preferencing, data advantages, switching costs and downstream foreclosure.

Ultimately, the central regulatory question is:

Can individuals and businesses meaningfully participate in digital markets without being forced to depend upon one identity-verification gatekeeper?

 

LEAVE A COMMENT