Digital Immunity Passports And Access Control Systems

 

Digital Identity-Linked Finance Systems And Universal Control Risks

1. Introduction

Digital identity-linked finance systems are financial arrangements in which access to banking, payments, credit, securities, insurance, public benefits, taxation, or other economic services is linked to a persistent digital identity. The identity may incorporate government identification, biometric authentication, device identifiers, KYC records, transaction histories, credit information, or credentials issued by private identity providers.

The competition-law concern becomes particularly serious when identity infrastructure, financial infrastructure, and access-control mechanisms converge. A system initially designed for secure authentication can become a mechanism through which one institution or coordinated group of institutions determines who may participate in economic life, on what terms, and through which channels.

The principal risk can therefore be expressed as:

Digital identity → authentication → financial access → transaction monitoring → eligibility decisions → economic participation

When these layers become indispensable and difficult to bypass, identity infrastructure may evolve into a form of universal economic gatekeeping.

2. Meaning of Digital Identity-Linked Finance

A digital identity-linked financial system can contain several interconnected layers:

  1. Identity layer – establishes who the person or business is.
  2. Authentication layer – verifies that the person controlling an account is the legitimate identity holder.
  3. KYC/AML layer – determines whether the person satisfies regulatory requirements.
  4. Payment layer – permits or restricts financial transactions.
  5. Credit layer – uses identity-linked information for lending decisions.
  6. Platform layer – connects identity to marketplaces, apps, wallets, or digital services.
  7. Government layer – links financial identity to taxation, benefits, licences, or public services.
  8. Analytics layer – aggregates behavioural and transactional information.

The competition problem does not arise merely because these systems exist. It arises where control over one indispensable layer gives the operator leverage over adjacent markets.

3. The Universal-Control Risk

The concept of universal control describes a situation in which a digital identity infrastructure becomes capable of controlling access across numerous economic and social functions.

For example:

Identity provider

↓

KYC verification

↓

Bank account

↓

Payment wallet

↓

Credit

↓

Insurance

↓

Government benefits

↓

Digital marketplace

↓

Employment platform

The more services depend upon the same identity credential, the greater the possibility that exclusion at the identity layer will produce exclusion throughout the economy.

This produces a competition concern that is broader than conventional price-based monopoly.

4. Relevant Competition-Law Theories

A. Dominance

Under traditional competition law, the first question is whether an identity provider possesses dominant market power.

Relevant factors may include:

  • network effects;
  • switching costs;
  • regulatory recognition;
  • interoperability;
  • access to identity databases;
  • number of enrolled users;
  • control over authentication infrastructure;
  • barriers to entry;
  • data advantages;
  • institutional dependence.

A government-backed or quasi-public identity system can be especially difficult for competitors to challenge because legal recognition itself may create a substantial competitive advantage.

5. Essential-Facility-Type Concerns

An identity-verification system may become economically indispensable.

Suppose banks, payment institutions and fintech companies are legally or commercially expected to use a particular identity infrastructure.

If an operator refuses access to competing financial institutions, competition may be weakened even though the operator is not itself a conventional bank.

The critical questions become:

  • Is the identity infrastructure indispensable?
  • Can another identity system reasonably substitute for it?
  • Is duplication economically or legally feasible?
  • Does the operator control access?
  • Is refusal objectively justified?
  • Are access conditions discriminatory?
  • Are prices or technical conditions excessive?
  • Can competitors authenticate customers independently?

This resembles the logic of essential-facility and refusal-to-deal doctrine.

6. Leveraging Across Markets

The more dangerous scenario is cross-market leveraging.

An identity provider may operate simultaneously in:

  • identity verification;
  • payments;
  • banking;
  • digital wallets;
  • credit scoring;
  • advertising;
  • e-commerce;
  • cloud services.

It could potentially use identity dominance to strengthen its position in another market.

For example:

Identity verification → mandatory wallet → preferential payment processing → privileged financial data → stronger lending platform.

This creates a digital conglomerate advantage.

7. Discriminatory Access

A dominant identity infrastructure may provide different technical or commercial conditions to different financial institutions.

Potentially problematic conduct includes:

  • faster verification for affiliated banks;
  • higher API fees for rivals;
  • preferential access to identity attributes;
  • discriminatory authentication limits;
  • delayed verification of competitors' customers;
  • refusal to support alternative wallets;
  • technical incompatibility;
  • exclusion of independent identity providers.

Such conduct can become an exclusionary abuse if the necessary dominance and competitive effects are established.

8. Tying and Bundling

Digital identity can also be tied to financial services.

For example:

"To use this identity credential, you must use our payment wallet."

or:

"Customers verified through our identity system automatically receive our financial services, while rival services require additional verification."

This may raise tying/bundling concerns, particularly where:

  1. the identity service is dominant;
  2. the financial product is separate;
  3. customers are effectively compelled to take both;
  4. competitors are foreclosed.

9. Data Concentration

One of the strongest sources of market power is identity-linked data.

A financial identity system may aggregate:

  • identity information;
  • transaction history;
  • income;
  • credit history;
  • location;
  • device information;
  • purchasing behaviour;
  • payment relationships;
  • authentication records.

The resulting dataset can create powerful economies of scope.

A rival may be unable to reproduce the dataset even if it possesses superior technology.

Thus:

identity data + financial data + behavioural data = potentially significant competitive advantage.

10. Privacy and Competition Can Intersect

Privacy and competition law traditionally pursue different objectives, but digital identity demonstrates their interaction.

A service can theoretically be:

  • free in monetary terms;
  • convenient;
  • secure;

while nevertheless creating substantial competitive risks through compulsory data concentration.

A reduction in privacy or consumer control may therefore become relevant to competitive assessment where privacy is an important parameter of competition.

11. Exclusion Through Identity Revocation

An especially serious risk occurs where identity credentials can be suspended, downgraded, or revoked.

If the credential is necessary for financial participation, revocation may effectively mean:

loss of economic access.

Potential consequences include inability to:

  • open accounts;
  • receive wages;
  • make payments;
  • obtain credit;
  • receive benefits;
  • operate a business;
  • access digital marketplaces.

This creates a powerful form of non-price exclusion.

Competition authorities may therefore need to examine not merely whether a person has been denied identity verification, but whether the denial indirectly excludes that person from downstream markets.

12. Network Effects

Digital identity systems exhibit strong network effects.

The more:

  • banks,
  • merchants,
  • government agencies,
  • fintech companies,
  • employers,
  • platforms,

that accept one identity standard, the more valuable that standard becomes.

This can create a feedback loop:

more users → more institutions → greater acceptance → greater dependency → fewer viable alternatives → still more users.

Eventually, competing identity systems may face substantial entry barriers even if their technology is superior.

13. Lock-In and Switching Costs

Identity systems create unusually strong switching costs because an individual may have accumulated:

  • KYC history;
  • financial credentials;
  • credit records;
  • authentication history;
  • verified credentials;
  • transaction relationships.

A user cannot easily abandon the system if doing so means repeatedly proving identity to dozens of institutions.

Therefore, portability of identity credentials becomes an important competition-policy issue.

14. Financial Exclusion as a Competition Concern

Universal identity systems can have a paradoxical effect.

They may promote financial inclusion by simplifying verification, but excessive centralisation can also create system-wide exclusion.

A technical error, inaccurate risk classification, sanctions flag, fraud score, or identity mismatch could propagate across multiple services.

The concern is amplified when there is:

  • no independent verification mechanism;
  • no effective appeal;
  • no alternative identity provider;
  • no interoperability;
  • no human review;
  • no portability.

15. State-Backed Monopoly Risk

The most difficult competition question arises where the identity infrastructure is state-created or state-backed.

Ordinary monopoly analysis assumes competitors can potentially enter.

But if legislation requires financial institutions to use one identity system, market power may arise from law rather than superior competitive performance.

The relevant policy question becomes:

Can the state legitimately create a single identity infrastructure without unnecessarily eliminating competitive alternatives in downstream financial markets?

This does not mean every public monopoly violates competition law. Certain identity functions may legitimately require centralisation for security, national identification, AML, or public-administration purposes.

The competition concern arises when monopoly control is extended beyond the legitimate function into adjacent commercial markets.

16. Six Important Case Laws

1. United Brands v Commission

The United Brands judgment established important principles concerning dominance and the ability of an undertaking to behave to an appreciable extent independently of competitors, customers, and consumers.

Relevance

For digital identity-linked finance, the case helps frame whether an identity infrastructure possesses sufficient market power to behave independently.

Indicators may include:

  • dependence of financial institutions;
  • absence of substitutes;
  • entry barriers;
  • network effects;
  • institutional dependency.

The case therefore provides a foundation for analysing whether identity infrastructure can constitute a dominant position.

2. Commercial Solvents v Commission

Commercial Solvents v Commission is a foundational EU authority concerning refusal to supply and the use of dominance in an upstream market to restrict competition in a downstream market.

Digital identity relevance

The analogy is particularly strong where:

identity verification = upstream infrastructure
financial services = downstream market.

If a dominant identity operator refuses necessary access to competing financial providers while favouring its own downstream services, the conduct may raise an exclusionary leveraging concern.

3. Bronner v Mediaprint

In Oscar Bronner GmbH & Co. KG v Mediaprint, the Court of Justice established demanding conditions for imposing a duty on a dominant undertaking to provide access to an infrastructure under the essential-facilities/refusal-to-deal doctrine.

Relevance

The case is important because not every important identity system automatically becomes an essential facility.

A claimant would generally need to demonstrate factors such as:

  • indispensability;
  • lack of realistic alternatives;
  • inability to reproduce the infrastructure;
  • potential elimination of effective competition.

This provides a useful limiting principle against excessive intervention.

4. IMS Health v Commission

IMS Health GmbH & Co. KG v Commission is another major authority concerning access to indispensable infrastructure and intellectual-property-related market power.

Relevance

Identity systems may contain:

  • proprietary authentication technologies;
  • databases;
  • technical standards;
  • APIs;
  • credential structures.

Where a dominant operator controls an indispensable identity architecture, the case provides an important framework for assessing when refusal of interoperability or access may become abusive.

5. Microsoft v Commission

The Microsoft case is particularly significant for digital identity-linked financial infrastructure because it addresses interoperability and leveraging.

Microsoft's conduct concerning interoperability information illustrated how control over an important technological layer can be used to disadvantage competitors in adjacent markets.

Application

The same analytical concern can arise where an identity provider controls:

  • authentication APIs;
  • verification protocols;
  • identity attributes;
  • interoperability standards.

If competitors cannot effectively interoperate without access to those resources, technical design itself can become an exclusionary instrument.

6. Google Shopping

The Google Shopping litigation demonstrates how a powerful digital ecosystem can use an important platform position to favour its own downstream service.

Relevance

Digital identity systems may similarly create opportunities for:

  • self-preferencing;
  • preferential authentication;
  • privileged data access;
  • ranking advantages;
  • automatic integration with affiliated financial services.

The important lesson is that competition harm can arise without conventional price increases.

17. Additional Relevant Case Laws

7. Hoffmann-La Roche v Commission

This is a leading authority on the concept of dominance and the special responsibility of dominant undertakings.

Digital relevance: A dominant identity infrastructure provider may have a heightened obligation not to use its position to exclude competitors.

8. Michelin v Commission

Michelin developed the principle that a dominant undertaking has a special responsibility not to allow its conduct to impair genuine undistorted competition.

Digital relevance: Loyalty mechanisms, preferential access or contractual arrangements surrounding identity-linked financial services may be scrutinised where they reinforce dependency.

9. Slovak Telekom v Commission

The case concerns exclusionary conduct and access to infrastructure in telecommunications.

Digital relevance: It provides useful analytical guidance for situations where control over an upstream network or infrastructure can disadvantage downstream competitors.

10. Deutsche Telekom v Commission

The case is important for infrastructure-based market power and exclusionary pricing.

Digital relevance: Where identity infrastructure charges different access prices to different financial institutions, discriminatory or margin-related theories may become relevant depending on the facts.

18. Universal-Control Architecture

The competition risk can be conceptualised as follows:

             DIGITAL IDENTITY                    │        ┌───────────┼───────────┐        ↓           ↓           ↓      KYC       Authentication  Data        │           │           │        └───────────┼───────────┘                    ↓              FINANCIAL ACCESS                    │       ┌────────────┼────────────┐       ↓            ↓            ↓    Banking       Payments     Credit       │            │            │       └────────────┼────────────┘                    ↓             ECONOMIC ACCESS                    │       ┌────────────┼────────────┐       ↓            ↓            ↓    Benefits     Commerce    Employment

 

The closer the system comes to this architecture, the greater the importance of interoperability, portability, contestability and due process.

19. Competition Risks in Detail

RiskCompetition consequence
Identity monopolyEntry barriers
Mandatory identity providerReduced contestability
Identity-finance bundlingTying/leveraging
Preferential APIsCompetitor foreclosure
Identity data concentrationData advantage
Lack of portabilityUser lock-in
Exclusive contractsMarket foreclosure
Self-preferencingDownstream discrimination
Identity revocationEconomic exclusion
Closed technical standardsInteroperability barriers
Cross-market data combinationEconomies-of-scope advantage
State-backed exclusivityEntrenchment of market power

20. Regulatory Remedies

A competition authority or regulator could consider several remedies.

A. Interoperability

Require dominant identity infrastructure to support reasonable interoperability with competing financial institutions and identity providers.

B. Data portability

Individuals should be able, subject to legitimate security and legal requirements, to transfer relevant credentials or verification information.

C. Non-discriminatory access

Equivalent financial institutions should receive equivalent technical and commercial access.

D. Functional separation

Where appropriate, identity infrastructure could be structurally or operationally separated from competing financial services.

E. Prohibition of self-preferencing

The identity operator should not automatically favour its affiliated financial products.

F. Multi-provider architecture

A system can preserve central security standards while allowing multiple certified identity providers.

G. Independent appeal mechanisms

Identity suspension should not automatically become permanent financial exclusion without review.

H. Data-use restrictions

Identity information collected for authentication should not automatically be repurposed for unrelated commercial advantages.

21. Special Issue: Digital Identity as a Public Utility

A particularly important legal-policy question is whether certain identity infrastructures should be treated similarly to public utilities or essential digital infrastructure.

Traditional infrastructure regulation focuses on:

  • electricity;
  • telecommunications;
  • transport;
  • water;
  • payment systems.

Digital identity increasingly shares several characteristics:

  • high fixed costs;
  • network effects;
  • interoperability requirements;
  • significant switching costs;
  • public dependence;
  • security externalities.

Consequently, competition policy may need to move from simply asking:

"Is the provider dominant?"

toward asking:

"What governance architecture preserves contestability when the infrastructure itself must be widely shared?"

22. Balancing Security and Competition

Centralised identity systems can produce legitimate benefits:

  • fraud reduction;
  • AML compliance;
  • faster onboarding;
  • reduced identity theft;
  • financial inclusion;
  • secure authentication;
  • lower transaction costs.

Competition law should therefore avoid treating centralisation itself as unlawful.

The proper distinction is between:

necessary centralisation of a security function

and

unnecessary commercial expansion of monopoly control.

A state may reasonably require common security standards while still permitting competitive provision of:

  • wallets;
  • financial services;
  • authentication interfaces;
  • credential management;
  • payment services;
  • identity-verification technology.

23. Core Legal Test

A useful competition-law framework is:

Step 1 — Define the relevant market

Is the relevant market:

  • digital identity verification?
  • financial KYC?
  • authentication?
  • digital wallets?
  • payment infrastructure?
  • identity-linked financial data?

Step 2 — Determine dominance

Examine:

  • market shares;
  • legal exclusivity;
  • network effects;
  • switching costs;
  • interoperability;
  • entry barriers.

Step 3 — Identify the conduct

Examples:

  • refusal of access;
  • discriminatory access;
  • tying;
  • bundling;
  • self-preferencing;
  • excessive access pricing;
  • exclusive dealing;
  • data leveraging.

Step 4 — Assess foreclosure

Would the conduct materially disadvantage:

  • rival banks?
  • fintech providers?
  • payment institutions?
  • independent identity providers?

Step 5 — Examine justification

Possible legitimate objectives include:

  • cybersecurity;
  • AML;
  • fraud prevention;
  • privacy;
  • national-security requirements.

Step 6 — Apply proportionality

Could the legitimate objective be achieved through a less exclusionary architecture?

24. Conclusion

Digital identity-linked finance systems represent a new form of infrastructure-based competition risk. The central danger is not merely that one company might dominate identity verification. The deeper concern is that identity can become the control layer through which access to multiple financial and economic markets is determined.

The most important risks are:

  1. identity infrastructure monopolisation;
  2. financial-service tying and bundling;
  3. refusal of interoperability;
  4. cross-market data leveraging;
  5. self-preferencing;
  6. user lock-in;
  7. discriminatory access;
  8. state-backed exclusion;
  9. identity revocation producing financial exclusion; and
  10. concentration of identity, financial and behavioural information.

The case law from United Brands, Commercial Solvents, Bronner, IMS Health, Microsoft, Google Shopping, Hoffmann-La Roche, Michelin, Slovak Telekom and Deutsche Telekom provides a substantial doctrinal foundation for analysing these risks.

LEAVE A COMMENT