Global Identity Infrastructure Consolidation And Dependency Risks

 

Global Identity Infrastructure Consolidation And Dependency Risks

1. Introduction

Global identity infrastructure consolidation refers to the increasing concentration of digital identity functions—authentication, single sign-on (SSO), identity verification, digital credentials, biometric identification, account recovery, access management, and identity-related data—within a relatively small number of technology platforms, cloud providers, governments, and specialist identity providers.

Identity infrastructure has become a foundational layer of the digital economy. A single identity provider may determine whether a person can access email, cloud applications, banking services, government portals, employment systems, healthcare platforms, e-commerce accounts, or enterprise networks.

This creates an important competition-law problem: when identity infrastructure becomes concentrated, dependence on the infrastructure itself may become a source of market power even where the infrastructure provider does not directly sell the downstream service.

The principal risks include:

  • concentration of authentication infrastructure;
  • foreclosure of competing identity providers;
  • interoperability restrictions;
  • switching costs and technical lock-in;
  • control over authentication APIs;
  • aggregation of identity and behavioural data;
  • discriminatory access;
  • self-preferencing;
  • tying identity services to cloud or operating-system ecosystems;
  • exclusionary security requirements;
  • degradation of rival authentication services;
  • acquisition of emerging identity competitors;
  • systemic outage and single-point-of-failure risks; and
  • excessive dependence by governments and essential services.

The legal analysis therefore sits at the intersection of competition law, digital regulation, privacy, cybersecurity, essential-facility principles, interoperability, and public infrastructure governance.

2. What Is Identity Infrastructure?

Identity infrastructure can be divided into several layers.

A. Identity creation

This includes:

  • government-issued digital identities;
  • passports and national identity systems;
  • corporate identity accounts;
  • customer identity verification;
  • KYC systems;
  • biometric enrollment.

B. Authentication

Examples include:

  • passwords;
  • multi-factor authentication;
  • hardware security keys;
  • biometric authentication;
  • authentication apps;
  • passkeys;
  • certificates.

C. Identity federation

A user can authenticate through one identity provider and access multiple independent services.

Examples include:

  • SSO;
  • OAuth;
  • OpenID-based authentication;
  • enterprise identity federation;
  • government identity federation.

D. Identity management

Enterprise identity platforms may control:

  • employee accounts;
  • permissions;
  • privileged access;
  • authentication policies;
  • device identity;
  • application access.

E. Identity data

Providers may possess information concerning:

  • names;
  • email addresses;
  • devices;
  • login histories;
  • authentication events;
  • organizational relationships;
  • behavioural patterns;
  • biometric identifiers.

The combination of these functions can create highly strategic infrastructure power.

3. Why Consolidation Creates Competition Risks

A. Network effects

Identity systems become more valuable as more organisations accept them.

For example:

More websites accept Identity Provider A → more consumers maintain accounts with A → businesses have greater incentives to integrate A → A becomes even more important.

This produces a positive feedback loop.

Eventually, competitors may find it difficult to enter because they cannot reproduce the same network.

4. Switching Costs

Identity infrastructure can be unusually difficult to replace.

An enterprise changing identity providers may have to migrate:

  • millions of accounts;
  • authentication credentials;
  • access permissions;
  • employee directories;
  • security policies;
  • application integrations;
  • audit histories.

Consequently, even a technically available alternative may not constitute an effective competitive constraint.

This produces dependency-based market power.

5. Interoperability as a Competition Issue

Interoperability is particularly important.

Suppose Identity Provider A becomes dominant and refuses to provide adequate interoperability with Identity Provider B.

The result may be:

A → exclusive authentication ecosystem → B loses users → B's network shrinks → A becomes stronger.

The conduct can potentially constitute exclusionary abuse where the relevant legal requirements are satisfied.

Interoperability therefore becomes analogous to access to other digital infrastructure.

6. Identity Infrastructure as an Essential-Facility Problem

Traditional essential-facility doctrine asks whether a dominant undertaking controls an input that competitors cannot reasonably reproduce and whether denial of access prevents effective competition.

In digital identity markets, the question can become:

Can a dominant identity platform deny or restrict access to authentication, identity verification, or interoperability without unlawfully excluding competitors?

Not every important identity service is an essential facility. Courts generally require demanding conditions before imposing compulsory access.

However, the doctrine becomes increasingly relevant where identity infrastructure has become unavoidable for downstream participation.

7. Data Advantages

Identity providers may possess exceptionally valuable data.

For example:

identity → authentication → device → account → transaction → behavioural information

If a provider can combine these datasets across multiple markets, it may obtain advantages unavailable to competitors.

This can reinforce market power through:

  • improved fraud detection;
  • better authentication;
  • superior risk scoring;
  • lower customer-acquisition costs;
  • stronger security;
  • personalization;
  • ecosystem integration.

The competition concern is not merely the possession of data but whether exclusive control over identity data prevents rivals from competing effectively.

8. Tying and Bundling

A dominant technology ecosystem may combine identity infrastructure with:

  • cloud computing;
  • operating systems;
  • productivity software;
  • enterprise applications;
  • advertising;
  • app stores;
  • cybersecurity services.

For example, an enterprise may effectively be encouraged or required to purchase an identity service together with cloud infrastructure.

This can extend market power from one market into another.

The relevant theory resembles traditional tying:

dominance in Market A + conditional access to Market B + exclusionary effects in Market B.

9. Self-Preferencing

A vertically integrated identity provider can potentially favour its own downstream products.

For example, it could:

  • give its own applications preferential authentication;
  • restrict API functionality available to rivals;
  • provide competitors with inferior technical access;
  • impose higher authentication burdens on rival services;
  • prioritize its own identity credentials.

Such conduct can create a closed identity ecosystem.

10. Security Requirements and Competition

Security creates a particularly difficult issue.

Identity providers can legitimately impose strict security requirements.

However, a dominant provider could theoretically use security as a justification for discriminatory restrictions.

Competition authorities therefore face a difficult distinction:

Legitimate security measure

The restriction is:

  • objectively justified;
  • proportionate;
  • technically necessary;
  • applied consistently.

Potential exclusionary restriction

The restriction:

  • disproportionately affects competitors;
  • lacks objective justification;
  • is selectively applied;
  • makes interoperability unnecessarily difficult.

Thus, security cannot automatically immunize exclusionary conduct from competition scrutiny.

11. Acquisition of Identity Start-Ups

Consolidation may also occur through mergers and acquisitions.

Large platforms may acquire emerging firms specializing in:

  • passwordless authentication;
  • biometric identity;
  • digital credentials;
  • decentralized identity;
  • fraud prevention;
  • identity verification;
  • enterprise access management.

The competitive concern is the nascent-competitor theory.

A small identity company may have limited current revenue but significant future competitive potential.

Acquisition can eliminate that future constraint.

12. Government Dependency

Identity infrastructure is not merely a commercial market.

Governments increasingly rely on digital identity for:

  • taxation;
  • welfare;
  • immigration;
  • voting-related services;
  • licensing;
  • healthcare;
  • education;
  • public procurement.

If a private provider becomes deeply embedded in these systems, government dependence can create significant bargaining asymmetry.

A provider may become too important to replace.

This produces a structural distinction between ordinary market concentration and infrastructure dependency.

13. Systemic Outage Risk

Consolidation also creates a non-price competition problem.

Suppose a single identity provider authenticates access to:

  • banks;
  • hospitals;
  • airlines;
  • cloud platforms;
  • government systems;
  • corporate networks.

A major outage could simultaneously disrupt multiple markets.

Thus:

market concentration → infrastructure concentration → systemic dependency → correlated failure.

Competition policy may therefore increasingly need to consider resilience as part of competitive structure.

14. Six Major Case Laws

The following cases do not all concern identity infrastructure directly. They are important because they establish legal principles that can be applied to identity-platform consolidation, interoperability, tying, data advantages, ecosystem foreclosure, and infrastructure dependency.

Case 1: Microsoft Corp. v. Commission

Court: General Court of the European Union
Year: 2007

Facts

Microsoft was found to have abused its dominant position through several practices, including restricting interoperability information needed by competing work-group server products and tying Windows Media Player to Windows.

Principle

The case is particularly significant for digital infrastructure because interoperability information can become competitively essential.

The Court accepted that restricting interoperability could contribute to foreclosure of competitors under stringent conditions.

Relevance to identity infrastructure

A dominant identity platform might control:

  • authentication protocols;
  • APIs;
  • identity-management interfaces;
  • federation mechanisms.

If competitors cannot effectively interoperate because the dominant provider deliberately restricts necessary technical information or interfaces, the Microsoft reasoning becomes highly relevant.

Key lesson

Control over interoperability can become a source of exclusionary power.

Case 2: Bronner v. Mediaprint

Case: Oscar Bronner GmbH & Co. KG v Mediaprint Zeitungs und Zeitschriftenverlag GmbH

Court: Court of Justice of the European Union
Year: 1998

Facts

Bronner sought access to Mediaprint's newspaper home-delivery system.

Principle

The CJEU established a restrictive test for compulsory access under the essential-facilities doctrine.

A facility generally must be indispensable, duplication must be impossible or economically unreasonable, and refusal must risk eliminating effective competition.

Relevance

Identity infrastructure providers may argue that their systems are merely useful rather than indispensable.

Bronner demonstrates that importance alone does not automatically create a legal duty to provide access.

Key lesson

Competition authorities must distinguish:

“very important infrastructure”

from

“legally indispensable infrastructure.”

Case 3: IMS Health GmbH & Co. KG v NDC Health

Court: Court of Justice of the European Union
Year: 2004

Facts

IMS Health controlled a data structure used by pharmaceutical companies and competitors sought access to it.

Principle

The Court developed the exceptional circumstances applicable to compulsory licensing/access involving intellectual property and dominant infrastructure.

The refusal must satisfy demanding conditions, including the prospect of eliminating competition and preventing the emergence of a new product or service for which consumer demand exists.

Relevance

Identity platforms may control proprietary:

  • identity datasets;
  • authentication technologies;
  • technical interfaces;
  • identity verification systems.

IMS Health demonstrates that competition law may intervene in exceptional circumstances where control over a proprietary system threatens competitive development.

Key lesson

Control of an indispensable data or technological architecture can have competition-law consequences, but compulsory access remains exceptional.

Case 4: Google Android

Case: Google and Alphabet v Commission / Google Android

Court: General Court of the European Union
Year: 2022

Facts

The European Commission found that Google imposed contractual restrictions involving Android devices, including requirements connected with Google Search, Chrome, and the Google Play Store.

Principle

The case demonstrates how a dominant platform can use contractual arrangements and ecosystem dependencies to reinforce market power across adjacent digital markets.

The General Court substantially upheld the Commission's findings while modifying the fine.

Relevance

Identity services are increasingly embedded in operating systems and cloud ecosystems.

An identity provider could potentially use:

  • operating-system integration;
  • default authentication;
  • cloud contracts;
  • app-store relationships;
  • enterprise licensing

to strengthen its identity position.

Key lesson

Digital ecosystem power can extend dominance from a core platform into adjacent markets.

Case 5: Google Shopping

Case: Google and Alphabet v Commission / Google Shopping

Court: General Court of the European Union
Year: 2021

Facts

The Commission found that Google systematically favoured its own comparison-shopping service in search results.

Principle

The case is important for the concept of self-preferencing within a dominant platform.

The issue was not merely ownership of infrastructure but the use of infrastructure control to favour a downstream service.

Relevance to identity

Imagine a dominant identity provider operating both:

  1. identity infrastructure; and
  2. downstream applications.

If it gives its own services preferential authentication, discoverability, technical access, or security treatment, Google Shopping provides an important analytical analogy.

Key lesson

Infrastructure neutrality can become a competition issue when a dominant platform competes downstream.

Case 6: United States v. Microsoft Corp.

Court: U.S. Court of Appeals for the District of Columbia Circuit
Year: 2001

Facts

Microsoft's conduct concerning Internet Explorer and relationships with computer manufacturers and software developers was examined under U.S. antitrust law.

Principle

The case established an important framework for analysing exclusionary conduct by a dominant digital platform.

The court recognised that contractual restrictions and platform design can protect monopoly power when they make competitive entry substantially more difficult.

Relevance

Identity infrastructure can similarly become an access layer between users and downstream services.

Potentially problematic conduct could include:

  • exclusive identity contracts;
  • restrictive authentication APIs;
  • technical degradation of competing identity providers;
  • contractual restrictions preventing multi-homing;
  • tying identity to another dominant platform.

Key lesson

Digital-platform design and contractual restrictions can be anticompetitive when they preserve or extend monopoly power.

15. Additional Relevant Authorities

Several other decisions provide useful supporting principles.

Aspen Skiing Co. v. Aspen Highlands Skiing Corp.

U.S. Supreme Court, 1985

Relevant to refusal-to-deal analysis and the circumstances in which termination of a previously profitable relationship may constitute exclusionary conduct.

Verizon Communications Inc. v. Law Offices of Curtis V. Trinko

U.S. Supreme Court, 2004

Important for the limits of compulsory dealing under U.S. antitrust law.

The decision cautions against converting antitrust law into general sectoral regulation of infrastructure access.

Slovak Telekom v Commission

CJEU, 2021

Important for refusal-of-access and margin-squeeze principles in telecommunications infrastructure.

It demonstrates the relevance of access conditions where a dominant network operator controls an upstream infrastructure layer and competes downstream.

MEO v Autoridade da Concorrência

CJEU, 2018

Important for discriminatory pricing and the requirement to examine actual competitive disadvantage rather than assuming that every difference in treatment is unlawful.

This has relevance where identity providers offer different authentication conditions to different downstream platforms.

16. Competition Theories Applicable to Identity Infrastructure

TheoryIdentity-infrastructure application
MonopolyOne identity provider controls authentication
Essential facilitiesCompetitors require access to identity infrastructure
Refusal to dealDominant provider denies interoperability
TyingIdentity bundled with cloud/OS services
Self-preferencingOwn applications receive preferential identity access
ForeclosureRival identity providers cannot obtain sufficient scale
Data advantageIdentity data improves competing services
Network effectsMore users and relying parties reinforce dominance
Switching costsMigration between identity providers is expensive
Killer acquisitionsLarge platforms acquire emerging identity competitors
DiscriminationRival services receive inferior technical access
Margin squeezeUpstream identity access is priced to disadvantage downstream rivals
Exclusive dealingEnterprises are prevented from using multiple identity providers
Ecosystem leveragingIdentity dominance extends into cloud, advertising or software

17. The Special Problem of Multi-Homing

Competition is stronger when businesses can use multiple identity providers.

For example:

Provider A + Provider B + Provider C

creates competitive discipline.

But if technical integration or contractual restrictions force organisations to select one provider, the market can move toward:

Provider A → universal authentication layer.

Multi-homing therefore acts as an important competitive safeguard.

Competition authorities should examine:

  • API compatibility;
  • credential portability;
  • authentication standards;
  • contract duration;
  • migration costs;
  • data portability;
  • interoperability;
  • technical certification requirements.

18. Identity Portability

A major structural remedy is identity portability.

Users or organisations should, where legally and technically appropriate, be able to move:

  • identity attributes;
  • authentication credentials;
  • organizational permissions;
  • verification records;
  • account information

between providers.

Without portability:

incumbent advantage → switching costs → customer captivity → reduced entry.

Portability therefore functions as a contestability mechanism.

19. Decentralized Identity and Competition

Decentralized identity systems potentially reduce dependence on centralized identity providers.

Instead of:

User → Central Identity Provider → Every Service

the architecture can become:

User → Digital Credential → Multiple Independent Verifiers

This can reduce concentration.

However, decentralization itself can create new competition problems involving:

  • dominant credential issuers;
  • blockchain infrastructure;
  • wallet platforms;
  • certificate authorities;
  • verification networks;
  • standards governance.

Thus decentralization does not automatically eliminate market power.

20. Government Digital Identity Systems

Government-operated identity infrastructure presents a different legal problem.

Where identity is provided by the state, ordinary competition law may not always apply in the same manner as it would to private undertakings.

Nevertheless, competition principles remain relevant where government identity infrastructure interacts with private markets.

Examples include:

  • banks required to use a government identity system;
  • private authentication providers excluded from public services;
  • government identity APIs available only to selected firms;
  • private companies dependent upon public identity verification;
  • state-owned identity providers competing with private providers.

The crucial question becomes whether state infrastructure is being used to distort downstream competition.

21. Privacy–Competition Interaction

Identity consolidation creates an unusual relationship between privacy and competition.

A dominant provider may argue:

“We restrict data sharing because privacy requires it.”

That justification can be legitimate.

However, privacy protection must not automatically become a pretext for discriminatory exclusion.

Conversely, forced data portability may create privacy and security risks.

Therefore regulators must balance:

competition + privacy + cybersecurity + user autonomy.

This is one of the most difficult aspects of identity regulation.

22. Cybersecurity and Market Concentration

Identity systems are attractive targets because compromising one provider may expose access to thousands of organisations.

Concentration can therefore create:

Security economies of scale

A large provider can invest heavily in security.

But also:

Systemic concentration risk

A single compromise can have widespread effects.

Thus the policy question is not simply:

“Is the largest provider the safest?”

It is also:

“Does excessive dependence on one provider create systemic risk?”

23. Merger-Control Implications

Competition authorities examining identity-sector mergers should consider more than current revenue.

Relevant factors include:

  1. number of active identities;
  2. number of relying parties;
  3. API integration;
  4. switching costs;
  5. network effects;
  6. data advantages;
  7. security certifications;
  8. government contracts;
  9. enterprise dependence;
  10. future innovation potential.

Traditional turnover thresholds may fail to capture the significance of an identity platform with relatively low present revenue but rapidly increasing strategic importance.

24. Remedies

Possible competition remedies include:

Structural remedies

  • divestiture;
  • separation of identity and downstream services;
  • restrictions on acquisitions.

Behavioural remedies

  • interoperability obligations;
  • API access;
  • non-discrimination;
  • transparent technical standards;
  • prohibition of exclusive dealing.

Portability remedies

  • credential portability;
  • identity-data portability;
  • account migration tools.

Governance remedies

  • independent technical oversight;
  • auditing;
  • transparent certification;
  • security-neutral interoperability standards.

Resilience remedies

  • multi-provider architecture;
  • redundancy;
  • disaster recovery;
  • mandatory exit plans for critical public systems.

25. A Useful Regulatory Framework

A regulator examining identity infrastructure consolidation can use the following sequence:

Market definition
↓
Identify identity infrastructure layer
↓
Measure concentration and network effects
↓
Assess switching and multi-homing
↓
Determine dependency/indispensability
↓
Examine interoperability
↓
Investigate tying/self-preferencing/exclusivity
↓
Assess data advantages
↓
Evaluate foreclosure and innovation effects
↓
Consider privacy/security justifications
↓
Assess systemic-resilience risks
↓
Design proportionate remedies

26. Key Legal Distinction: Concentration ≠ Illegality

A highly concentrated identity market is not automatically unlawful.

Large identity providers may achieve scale because they offer:

  • better security;
  • lower costs;
  • greater reliability;
  • global interoperability;
  • stronger fraud prevention;
  • better technology.

Competition law normally intervenes when market power is acquired or maintained through prohibited conduct, rather than simply because a firm is successful.

The central inquiry is therefore:

Has identity infrastructure become concentrated because of superior competition, or because control over an unavoidable digital access layer is being used to exclude competitors?

27. Emerging Global Risk

The most important long-term issue is the transformation of identity from an ordinary software function into digital economic infrastructure.

If one provider controls:

identity → authentication → access → data → payments → cloud → government services

then identity becomes an entry point to multiple markets.

The resulting power can be substantially greater than the provider's market share in any single conventional market suggests.

This produces a new form of infrastructure-based digital market power.

28. Conclusion

Global identity infrastructure consolidation presents a distinctive competition-law challenge because identity is increasingly an upstream access layer for the entire digital economy.

The central risks are:

  1. network-effect-driven concentration;
  2. high switching costs;
  3. interoperability foreclosure;
  4. identity-data advantages;
  5. tying and ecosystem leverage;
  6. self-preferencing;
  7. exclusive contracts;
  8. acquisition of nascent competitors;
  9. government and critical-service dependency;
  10. systemic cybersecurity and outage risks.

The principles from Microsoft, Bronner, IMS Health, Google Android, Google Shopping, and U.S. Microsoft, together with Aspen Skiing, Trinko and Slovak Telekom, provide a useful legal framework for analysing these problems.

The emerging regulatory objective should not necessarily be to prevent scale. Rather, it should be to ensure that identity infrastructure remains contestable, interoperable, portable, non-discriminatory, and resilient, while preserving legitimate privacy and cybersecurity protections.

LEAVE A COMMENT