Global Identity Infrastructure Consolidation And Dependency Risks
Global Identity Infrastructure Consolidation And Dependency Risks
1. Introduction
Global identity infrastructure consolidation refers to the increasing concentration of digital identity functions—authentication, single sign-on (SSO), identity verification, digital credentials, biometric identification, account recovery, access management, and identity-related data—within a relatively small number of technology platforms, cloud providers, governments, and specialist identity providers.
Identity infrastructure has become a foundational layer of the digital economy. A single identity provider may determine whether a person can access email, cloud applications, banking services, government portals, employment systems, healthcare platforms, e-commerce accounts, or enterprise networks.
This creates an important competition-law problem: when identity infrastructure becomes concentrated, dependence on the infrastructure itself may become a source of market power even where the infrastructure provider does not directly sell the downstream service.
The principal risks include:
- concentration of authentication infrastructure;
- foreclosure of competing identity providers;
- interoperability restrictions;
- switching costs and technical lock-in;
- control over authentication APIs;
- aggregation of identity and behavioural data;
- discriminatory access;
- self-preferencing;
- tying identity services to cloud or operating-system ecosystems;
- exclusionary security requirements;
- degradation of rival authentication services;
- acquisition of emerging identity competitors;
- systemic outage and single-point-of-failure risks; and
- excessive dependence by governments and essential services.
The legal analysis therefore sits at the intersection of competition law, digital regulation, privacy, cybersecurity, essential-facility principles, interoperability, and public infrastructure governance.
2. What Is Identity Infrastructure?
Identity infrastructure can be divided into several layers.
A. Identity creation
This includes:
- government-issued digital identities;
- passports and national identity systems;
- corporate identity accounts;
- customer identity verification;
- KYC systems;
- biometric enrollment.
B. Authentication
Examples include:
- passwords;
- multi-factor authentication;
- hardware security keys;
- biometric authentication;
- authentication apps;
- passkeys;
- certificates.
C. Identity federation
A user can authenticate through one identity provider and access multiple independent services.
Examples include:
- SSO;
- OAuth;
- OpenID-based authentication;
- enterprise identity federation;
- government identity federation.
D. Identity management
Enterprise identity platforms may control:
- employee accounts;
- permissions;
- privileged access;
- authentication policies;
- device identity;
- application access.
E. Identity data
Providers may possess information concerning:
- names;
- email addresses;
- devices;
- login histories;
- authentication events;
- organizational relationships;
- behavioural patterns;
- biometric identifiers.
The combination of these functions can create highly strategic infrastructure power.
3. Why Consolidation Creates Competition Risks
A. Network effects
Identity systems become more valuable as more organisations accept them.
For example:
More websites accept Identity Provider A → more consumers maintain accounts with A → businesses have greater incentives to integrate A → A becomes even more important.
This produces a positive feedback loop.
Eventually, competitors may find it difficult to enter because they cannot reproduce the same network.
4. Switching Costs
Identity infrastructure can be unusually difficult to replace.
An enterprise changing identity providers may have to migrate:
- millions of accounts;
- authentication credentials;
- access permissions;
- employee directories;
- security policies;
- application integrations;
- audit histories.
Consequently, even a technically available alternative may not constitute an effective competitive constraint.
This produces dependency-based market power.
5. Interoperability as a Competition Issue
Interoperability is particularly important.
Suppose Identity Provider A becomes dominant and refuses to provide adequate interoperability with Identity Provider B.
The result may be:
A → exclusive authentication ecosystem → B loses users → B's network shrinks → A becomes stronger.
The conduct can potentially constitute exclusionary abuse where the relevant legal requirements are satisfied.
Interoperability therefore becomes analogous to access to other digital infrastructure.
6. Identity Infrastructure as an Essential-Facility Problem
Traditional essential-facility doctrine asks whether a dominant undertaking controls an input that competitors cannot reasonably reproduce and whether denial of access prevents effective competition.
In digital identity markets, the question can become:
Can a dominant identity platform deny or restrict access to authentication, identity verification, or interoperability without unlawfully excluding competitors?
Not every important identity service is an essential facility. Courts generally require demanding conditions before imposing compulsory access.
However, the doctrine becomes increasingly relevant where identity infrastructure has become unavoidable for downstream participation.
7. Data Advantages
Identity providers may possess exceptionally valuable data.
For example:
identity → authentication → device → account → transaction → behavioural information
If a provider can combine these datasets across multiple markets, it may obtain advantages unavailable to competitors.
This can reinforce market power through:
- improved fraud detection;
- better authentication;
- superior risk scoring;
- lower customer-acquisition costs;
- stronger security;
- personalization;
- ecosystem integration.
The competition concern is not merely the possession of data but whether exclusive control over identity data prevents rivals from competing effectively.
8. Tying and Bundling
A dominant technology ecosystem may combine identity infrastructure with:
- cloud computing;
- operating systems;
- productivity software;
- enterprise applications;
- advertising;
- app stores;
- cybersecurity services.
For example, an enterprise may effectively be encouraged or required to purchase an identity service together with cloud infrastructure.
This can extend market power from one market into another.
The relevant theory resembles traditional tying:
dominance in Market A + conditional access to Market B + exclusionary effects in Market B.
9. Self-Preferencing
A vertically integrated identity provider can potentially favour its own downstream products.
For example, it could:
- give its own applications preferential authentication;
- restrict API functionality available to rivals;
- provide competitors with inferior technical access;
- impose higher authentication burdens on rival services;
- prioritize its own identity credentials.
Such conduct can create a closed identity ecosystem.
10. Security Requirements and Competition
Security creates a particularly difficult issue.
Identity providers can legitimately impose strict security requirements.
However, a dominant provider could theoretically use security as a justification for discriminatory restrictions.
Competition authorities therefore face a difficult distinction:
Legitimate security measure
The restriction is:
- objectively justified;
- proportionate;
- technically necessary;
- applied consistently.
Potential exclusionary restriction
The restriction:
- disproportionately affects competitors;
- lacks objective justification;
- is selectively applied;
- makes interoperability unnecessarily difficult.
Thus, security cannot automatically immunize exclusionary conduct from competition scrutiny.
11. Acquisition of Identity Start-Ups
Consolidation may also occur through mergers and acquisitions.
Large platforms may acquire emerging firms specializing in:
- passwordless authentication;
- biometric identity;
- digital credentials;
- decentralized identity;
- fraud prevention;
- identity verification;
- enterprise access management.
The competitive concern is the nascent-competitor theory.
A small identity company may have limited current revenue but significant future competitive potential.
Acquisition can eliminate that future constraint.
12. Government Dependency
Identity infrastructure is not merely a commercial market.
Governments increasingly rely on digital identity for:
- taxation;
- welfare;
- immigration;
- voting-related services;
- licensing;
- healthcare;
- education;
- public procurement.
If a private provider becomes deeply embedded in these systems, government dependence can create significant bargaining asymmetry.
A provider may become too important to replace.
This produces a structural distinction between ordinary market concentration and infrastructure dependency.
13. Systemic Outage Risk
Consolidation also creates a non-price competition problem.
Suppose a single identity provider authenticates access to:
- banks;
- hospitals;
- airlines;
- cloud platforms;
- government systems;
- corporate networks.
A major outage could simultaneously disrupt multiple markets.
Thus:
market concentration → infrastructure concentration → systemic dependency → correlated failure.
Competition policy may therefore increasingly need to consider resilience as part of competitive structure.
14. Six Major Case Laws
The following cases do not all concern identity infrastructure directly. They are important because they establish legal principles that can be applied to identity-platform consolidation, interoperability, tying, data advantages, ecosystem foreclosure, and infrastructure dependency.
Case 1: Microsoft Corp. v. Commission
Court: General Court of the European Union
Year: 2007
Facts
Microsoft was found to have abused its dominant position through several practices, including restricting interoperability information needed by competing work-group server products and tying Windows Media Player to Windows.
Principle
The case is particularly significant for digital infrastructure because interoperability information can become competitively essential.
The Court accepted that restricting interoperability could contribute to foreclosure of competitors under stringent conditions.
Relevance to identity infrastructure
A dominant identity platform might control:
- authentication protocols;
- APIs;
- identity-management interfaces;
- federation mechanisms.
If competitors cannot effectively interoperate because the dominant provider deliberately restricts necessary technical information or interfaces, the Microsoft reasoning becomes highly relevant.
Key lesson
Control over interoperability can become a source of exclusionary power.
Case 2: Bronner v. Mediaprint
Case: Oscar Bronner GmbH & Co. KG v Mediaprint Zeitungs und Zeitschriftenverlag GmbH
Court: Court of Justice of the European Union
Year: 1998
Facts
Bronner sought access to Mediaprint's newspaper home-delivery system.
Principle
The CJEU established a restrictive test for compulsory access under the essential-facilities doctrine.
A facility generally must be indispensable, duplication must be impossible or economically unreasonable, and refusal must risk eliminating effective competition.
Relevance
Identity infrastructure providers may argue that their systems are merely useful rather than indispensable.
Bronner demonstrates that importance alone does not automatically create a legal duty to provide access.
Key lesson
Competition authorities must distinguish:
“very important infrastructure”
from
“legally indispensable infrastructure.”
Case 3: IMS Health GmbH & Co. KG v NDC Health
Court: Court of Justice of the European Union
Year: 2004
Facts
IMS Health controlled a data structure used by pharmaceutical companies and competitors sought access to it.
Principle
The Court developed the exceptional circumstances applicable to compulsory licensing/access involving intellectual property and dominant infrastructure.
The refusal must satisfy demanding conditions, including the prospect of eliminating competition and preventing the emergence of a new product or service for which consumer demand exists.
Relevance
Identity platforms may control proprietary:
- identity datasets;
- authentication technologies;
- technical interfaces;
- identity verification systems.
IMS Health demonstrates that competition law may intervene in exceptional circumstances where control over a proprietary system threatens competitive development.
Key lesson
Control of an indispensable data or technological architecture can have competition-law consequences, but compulsory access remains exceptional.
Case 4: Google Android
Case: Google and Alphabet v Commission / Google Android
Court: General Court of the European Union
Year: 2022
Facts
The European Commission found that Google imposed contractual restrictions involving Android devices, including requirements connected with Google Search, Chrome, and the Google Play Store.
Principle
The case demonstrates how a dominant platform can use contractual arrangements and ecosystem dependencies to reinforce market power across adjacent digital markets.
The General Court substantially upheld the Commission's findings while modifying the fine.
Relevance
Identity services are increasingly embedded in operating systems and cloud ecosystems.
An identity provider could potentially use:
- operating-system integration;
- default authentication;
- cloud contracts;
- app-store relationships;
- enterprise licensing
to strengthen its identity position.
Key lesson
Digital ecosystem power can extend dominance from a core platform into adjacent markets.
Case 5: Google Shopping
Case: Google and Alphabet v Commission / Google Shopping
Court: General Court of the European Union
Year: 2021
Facts
The Commission found that Google systematically favoured its own comparison-shopping service in search results.
Principle
The case is important for the concept of self-preferencing within a dominant platform.
The issue was not merely ownership of infrastructure but the use of infrastructure control to favour a downstream service.
Relevance to identity
Imagine a dominant identity provider operating both:
- identity infrastructure; and
- downstream applications.
If it gives its own services preferential authentication, discoverability, technical access, or security treatment, Google Shopping provides an important analytical analogy.
Key lesson
Infrastructure neutrality can become a competition issue when a dominant platform competes downstream.
Case 6: United States v. Microsoft Corp.
Court: U.S. Court of Appeals for the District of Columbia Circuit
Year: 2001
Facts
Microsoft's conduct concerning Internet Explorer and relationships with computer manufacturers and software developers was examined under U.S. antitrust law.
Principle
The case established an important framework for analysing exclusionary conduct by a dominant digital platform.
The court recognised that contractual restrictions and platform design can protect monopoly power when they make competitive entry substantially more difficult.
Relevance
Identity infrastructure can similarly become an access layer between users and downstream services.
Potentially problematic conduct could include:
- exclusive identity contracts;
- restrictive authentication APIs;
- technical degradation of competing identity providers;
- contractual restrictions preventing multi-homing;
- tying identity to another dominant platform.
Key lesson
Digital-platform design and contractual restrictions can be anticompetitive when they preserve or extend monopoly power.
15. Additional Relevant Authorities
Several other decisions provide useful supporting principles.
Aspen Skiing Co. v. Aspen Highlands Skiing Corp.
U.S. Supreme Court, 1985
Relevant to refusal-to-deal analysis and the circumstances in which termination of a previously profitable relationship may constitute exclusionary conduct.
Verizon Communications Inc. v. Law Offices of Curtis V. Trinko
U.S. Supreme Court, 2004
Important for the limits of compulsory dealing under U.S. antitrust law.
The decision cautions against converting antitrust law into general sectoral regulation of infrastructure access.
Slovak Telekom v Commission
CJEU, 2021
Important for refusal-of-access and margin-squeeze principles in telecommunications infrastructure.
It demonstrates the relevance of access conditions where a dominant network operator controls an upstream infrastructure layer and competes downstream.
MEO v Autoridade da Concorrência
CJEU, 2018
Important for discriminatory pricing and the requirement to examine actual competitive disadvantage rather than assuming that every difference in treatment is unlawful.
This has relevance where identity providers offer different authentication conditions to different downstream platforms.
16. Competition Theories Applicable to Identity Infrastructure
| Theory | Identity-infrastructure application |
|---|---|
| Monopoly | One identity provider controls authentication |
| Essential facilities | Competitors require access to identity infrastructure |
| Refusal to deal | Dominant provider denies interoperability |
| Tying | Identity bundled with cloud/OS services |
| Self-preferencing | Own applications receive preferential identity access |
| Foreclosure | Rival identity providers cannot obtain sufficient scale |
| Data advantage | Identity data improves competing services |
| Network effects | More users and relying parties reinforce dominance |
| Switching costs | Migration between identity providers is expensive |
| Killer acquisitions | Large platforms acquire emerging identity competitors |
| Discrimination | Rival services receive inferior technical access |
| Margin squeeze | Upstream identity access is priced to disadvantage downstream rivals |
| Exclusive dealing | Enterprises are prevented from using multiple identity providers |
| Ecosystem leveraging | Identity dominance extends into cloud, advertising or software |
17. The Special Problem of Multi-Homing
Competition is stronger when businesses can use multiple identity providers.
For example:
Provider A + Provider B + Provider C
creates competitive discipline.
But if technical integration or contractual restrictions force organisations to select one provider, the market can move toward:
Provider A → universal authentication layer.
Multi-homing therefore acts as an important competitive safeguard.
Competition authorities should examine:
- API compatibility;
- credential portability;
- authentication standards;
- contract duration;
- migration costs;
- data portability;
- interoperability;
- technical certification requirements.
18. Identity Portability
A major structural remedy is identity portability.
Users or organisations should, where legally and technically appropriate, be able to move:
- identity attributes;
- authentication credentials;
- organizational permissions;
- verification records;
- account information
between providers.
Without portability:
incumbent advantage → switching costs → customer captivity → reduced entry.
Portability therefore functions as a contestability mechanism.
19. Decentralized Identity and Competition
Decentralized identity systems potentially reduce dependence on centralized identity providers.
Instead of:
User → Central Identity Provider → Every Service
the architecture can become:
User → Digital Credential → Multiple Independent Verifiers
This can reduce concentration.
However, decentralization itself can create new competition problems involving:
- dominant credential issuers;
- blockchain infrastructure;
- wallet platforms;
- certificate authorities;
- verification networks;
- standards governance.
Thus decentralization does not automatically eliminate market power.
20. Government Digital Identity Systems
Government-operated identity infrastructure presents a different legal problem.
Where identity is provided by the state, ordinary competition law may not always apply in the same manner as it would to private undertakings.
Nevertheless, competition principles remain relevant where government identity infrastructure interacts with private markets.
Examples include:
- banks required to use a government identity system;
- private authentication providers excluded from public services;
- government identity APIs available only to selected firms;
- private companies dependent upon public identity verification;
- state-owned identity providers competing with private providers.
The crucial question becomes whether state infrastructure is being used to distort downstream competition.
21. Privacy–Competition Interaction
Identity consolidation creates an unusual relationship between privacy and competition.
A dominant provider may argue:
“We restrict data sharing because privacy requires it.”
That justification can be legitimate.
However, privacy protection must not automatically become a pretext for discriminatory exclusion.
Conversely, forced data portability may create privacy and security risks.
Therefore regulators must balance:
competition + privacy + cybersecurity + user autonomy.
This is one of the most difficult aspects of identity regulation.
22. Cybersecurity and Market Concentration
Identity systems are attractive targets because compromising one provider may expose access to thousands of organisations.
Concentration can therefore create:
Security economies of scale
A large provider can invest heavily in security.
But also:
Systemic concentration risk
A single compromise can have widespread effects.
Thus the policy question is not simply:
“Is the largest provider the safest?”
It is also:
“Does excessive dependence on one provider create systemic risk?”
23. Merger-Control Implications
Competition authorities examining identity-sector mergers should consider more than current revenue.
Relevant factors include:
- number of active identities;
- number of relying parties;
- API integration;
- switching costs;
- network effects;
- data advantages;
- security certifications;
- government contracts;
- enterprise dependence;
- future innovation potential.
Traditional turnover thresholds may fail to capture the significance of an identity platform with relatively low present revenue but rapidly increasing strategic importance.
24. Remedies
Possible competition remedies include:
Structural remedies
- divestiture;
- separation of identity and downstream services;
- restrictions on acquisitions.
Behavioural remedies
- interoperability obligations;
- API access;
- non-discrimination;
- transparent technical standards;
- prohibition of exclusive dealing.
Portability remedies
- credential portability;
- identity-data portability;
- account migration tools.
Governance remedies
- independent technical oversight;
- auditing;
- transparent certification;
- security-neutral interoperability standards.
Resilience remedies
- multi-provider architecture;
- redundancy;
- disaster recovery;
- mandatory exit plans for critical public systems.
25. A Useful Regulatory Framework
A regulator examining identity infrastructure consolidation can use the following sequence:
Market definition
↓
Identify identity infrastructure layer
↓
Measure concentration and network effects
↓
Assess switching and multi-homing
↓
Determine dependency/indispensability
↓
Examine interoperability
↓
Investigate tying/self-preferencing/exclusivity
↓
Assess data advantages
↓
Evaluate foreclosure and innovation effects
↓
Consider privacy/security justifications
↓
Assess systemic-resilience risks
↓
Design proportionate remedies
26. Key Legal Distinction: Concentration ≠ Illegality
A highly concentrated identity market is not automatically unlawful.
Large identity providers may achieve scale because they offer:
- better security;
- lower costs;
- greater reliability;
- global interoperability;
- stronger fraud prevention;
- better technology.
Competition law normally intervenes when market power is acquired or maintained through prohibited conduct, rather than simply because a firm is successful.
The central inquiry is therefore:
Has identity infrastructure become concentrated because of superior competition, or because control over an unavoidable digital access layer is being used to exclude competitors?
27. Emerging Global Risk
The most important long-term issue is the transformation of identity from an ordinary software function into digital economic infrastructure.
If one provider controls:
identity → authentication → access → data → payments → cloud → government services
then identity becomes an entry point to multiple markets.
The resulting power can be substantially greater than the provider's market share in any single conventional market suggests.
This produces a new form of infrastructure-based digital market power.
28. Conclusion
Global identity infrastructure consolidation presents a distinctive competition-law challenge because identity is increasingly an upstream access layer for the entire digital economy.
The central risks are:
- network-effect-driven concentration;
- high switching costs;
- interoperability foreclosure;
- identity-data advantages;
- tying and ecosystem leverage;
- self-preferencing;
- exclusive contracts;
- acquisition of nascent competitors;
- government and critical-service dependency;
- systemic cybersecurity and outage risks.
The principles from Microsoft, Bronner, IMS Health, Google Android, Google Shopping, and U.S. Microsoft, together with Aspen Skiing, Trinko and Slovak Telekom, provide a useful legal framework for analysing these problems.
The emerging regulatory objective should not necessarily be to prevent scale. Rather, it should be to ensure that identity infrastructure remains contestable, interoperable, portable, non-discriminatory, and resilient, while preserving legitimate privacy and cybersecurity protections.

comments