Identity Federation Platform Dominance Issues .

 

Identity Federation Platform Dominance Issues

1. Introduction

Identity federation is a system in which a user’s digital identity, authentication credentials, attributes, or authorization information are managed by one identity provider and accepted across multiple independent services or platforms. Examples include single sign-on (SSO), federated enterprise identities, government digital identities, social-login systems, and identity-as-a-service platforms.

Identity federation can generate substantial efficiencies: users avoid maintaining multiple credentials, service providers reduce authentication costs, and identity providers can improve security. However, when one identity provider becomes indispensable across a large ecosystem, identity federation can become a source of market power.

The competition-law concern is not simply that an identity provider is large. The concern is that control over authentication can become a gateway to downstream digital markets. A dominant identity provider may potentially:

  • deny or degrade interoperability;
  • impose discriminatory access conditions;
  • bundle authentication with other services;
  • use identity data to advantage downstream businesses;
  • self-preference its own applications;
  • make switching costly;
  • exploit network effects;
  • impose discriminatory technical standards;
  • foreclose competing identity providers; or
  • leverage identity dominance into adjacent markets.

The legal analysis therefore intersects essential-facility principles, refusal to deal, tying, interoperability, data access, self-preferencing, platform neutrality and digital-market regulation.

2. Meaning of Identity Federation

A simplified federated identity structure is:

User → Identity Provider → Authentication/Identity Assertion → Relying Party → Digital Service

For example, a user may authenticate through an identity provider, which then supplies an authentication assertion to several independent services.

The important actors are:

  1. Identity Provider (IdP) – authenticates the user.
  2. Relying Party (RP) – accepts the identity assertion.
  3. User – controls or uses the identity.
  4. Federation operator/standard setter – may establish technical rules.
  5. Attribute provider – supplies information such as age, professional status or organizational affiliation.

Where a single IdP becomes widely accepted, the system can exhibit strong network effects.

3. Why Identity Federation Can Produce Market Power

A. Network Effects

The value of an identity system increases as more users and service providers accept it.

More users → more relying parties want compatibility → more services become available → more users adopt the identity system.

This creates a positive feedback loop.

Eventually, competing identity providers may find it difficult to attract users because consumers prefer an identity accepted everywhere.

B. Switching Costs

Switching identity providers can involve:

  • re-registering accounts;
  • re-authenticating users;
  • transferring identity attributes;
  • reconfiguring enterprise systems;
  • changing APIs;
  • replacing security infrastructure;
  • obtaining new certificates;
  • migrating authentication logs; and
  • retraining personnel.

Consequently, nominally "open" identity markets may become highly difficult to contest.

C. Identity as a Gateway

Authentication occurs before access to many digital services.

Consequently, an identity provider can occupy a strategic position similar to a gateway.

A dominant provider might theoretically influence:

Who can access the market → how they authenticate → what information they provide → what services they can use.

This makes identity infrastructure particularly important from an abuse-of-dominance perspective.

4. Relevant Competition-Law Theories

A. Refusal to Deal

A dominant identity provider may refuse to provide federation services or interoperability to competing downstream platforms.

The question is whether access to the identity infrastructure is indispensable.

Traditional essential-facility analysis generally asks whether:

  1. the facility is indispensable;
  2. duplication is practically or economically impossible;
  3. refusal is capable of eliminating effective competition; and
  4. there is no objective justification.

In digital identity markets, the analysis may additionally consider whether technical interoperability can reasonably be replicated.

5. Tying and Bundling

A dominant identity provider could require:

"If you want to use our authentication service, you must also use our cloud, advertising, payments, browser or other ecosystem services."

Such conduct can create leverage from an identity market into another digital market.

The competitive concern becomes stronger when:

  • the products are distinct;
  • the provider is dominant in identity;
  • customers are effectively forced to take the second product;
  • competitors are foreclosed; and
  • the conduct lacks objective justification.

6. Self-Preferencing

Suppose an identity provider operates both:

  • the identity infrastructure; and
  • competing downstream applications.

It may have an incentive to provide its own applications with:

  • preferential authentication;
  • faster verification;
  • better APIs;
  • additional identity attributes;
  • privileged access to user information; or
  • lower transaction costs.

This creates a vertical foreclosure problem.

The provider simultaneously acts as:

infrastructure operator + gatekeeper + downstream competitor.

7. Data Advantages

Identity providers may possess exceptionally valuable datasets concerning:

  • authentication history;
  • account relationships;
  • organizational affiliation;
  • device information;
  • verification status;
  • identity attributes;
  • login frequency; and
  • authentication behaviour.

The competitive concern is not merely privacy.

Data concentration can produce a competitive advantage that reinforces dominance.

For example:

Identity dominance → data accumulation → improved services → greater adoption → stronger identity dominance.

This can create a data-driven feedback loop.

8. Interoperability as a Competition Issue

Interoperability is particularly important.

A dominant provider could potentially make competing identity systems technically inferior by:

  • restricting APIs;
  • changing authentication protocols;
  • withholding documentation;
  • imposing discriminatory certification;
  • limiting token portability;
  • restricting attribute portability;
  • imposing excessive integration costs; or
  • creating technical incompatibilities.

Competition authorities may therefore examine whether interoperability conditions are genuinely neutral.

9. Identity Portability

Portability is different from interoperability.

Interoperability means:

another identity system can work with the existing ecosystem.

Portability means:

the user can move identity-related information or relationships from one provider to another.

Without portability, users may technically have multiple choices but still face substantial switching costs.

This can produce lock-in without an explicit contractual exclusivity clause.

10. Essential-Facility Analogy

Identity infrastructure can resemble an essential facility where a provider controls an indispensable authentication gateway.

However, competition authorities should be cautious.

Not every popular identity system is an essential facility.

The relevant questions include:

  • Can another identity system realistically be created?
  • Can users maintain multiple identities?
  • Can relying parties accept several IdPs?
  • Are technical standards open?
  • Is switching economically feasible?
  • Does the incumbent control unique identity attributes?
  • Would access obligations undermine legitimate security protections?

The security characteristics of identity systems make this analysis more complex than ordinary infrastructure cases.

11. At Least 6 Important Case Laws

1. United Brands v Commission

Case: United Brands Company and United Brands Continentaal BV v Commission, Case 27/76.

The Court of Justice established important principles concerning dominance and the ability of an undertaking to behave independently of competitors, customers and consumers.

Relevance to identity federation

A dominant identity provider may possess substantial market power if users and relying parties have become dependent upon it.

The case helps establish the fundamental inquiry:

Is the undertaking sufficiently powerful to behave independently of competitive constraints?

In identity markets, this could involve examining user dependence, technical switching barriers and the availability of alternative authentication systems.

12. 2. Bronner v Mediaprint

Case: Oscar Bronner GmbH & Co. KG v Mediaprint Zeitungs und Zeitschriftenverlag GmbH & Co. KG, Case C-7/97.

This is one of the most important cases for analysing access to infrastructure controlled by a dominant undertaking.

The Court imposed a demanding standard for requiring a dominant firm to provide access to infrastructure.

Relevance

A competition authority should not automatically characterize a dominant identity provider's infrastructure as an essential facility.

It would need to consider:

  • indispensability;
  • lack of realistic alternatives;
  • elimination of competition; and
  • objective justification.

Thus, Bronner provides an important limiting principle for identity-platform regulation.

13. 3. IMS Health v Commission

Cases: IMS Health GmbH & Co. OHG v NDC Health GmbH & Co. KG, Joined Cases C-418/01 P.

The case concerned access to an intellectual-property-protected structure and developed important principles concerning exceptional compulsory access.

Relevance to identity federation

Identity platforms frequently rely upon:

  • proprietary APIs;
  • authentication protocols;
  • technical architectures;
  • identity databases; and
  • interoperability interfaces.

The case is relevant where a dominant identity provider argues that its proprietary technology or architecture should not be made available to competitors.

The key issue becomes whether refusal of access crosses the exceptional threshold for anticompetitive exclusion.

14. 4. Microsoft v Commission

Case: Microsoft Corp. v Commission, Case T-201/04.

The General Court upheld important findings concerning Microsoft's refusal to provide interoperability information and the leveraging of dominance into neighbouring markets.

Relevance to identity federation

This is particularly significant.

Identity systems are fundamentally interoperability-dependent.

A dominant identity provider that restricts information necessary for competing services to interoperate may potentially engage in conduct analogous to Microsoft's interoperability problem.

The case demonstrates that:

technical interoperability can itself be a competition parameter.

This is especially important where an incumbent controls a technological interface necessary for competitors to participate effectively.

15. 5. Google Shopping

Case: Google and Alphabet v Commission, Case T-612/17.

The case concerned Google's preferential treatment of its own comparison-shopping service within general search results.

Relevance

Although Google Shopping was not an identity-federation case, it is highly relevant to the self-preferencing theory.

An identity provider that operates downstream services could theoretically favour its own services by:

  • giving them preferential authentication;
  • giving them privileged identity attributes;
  • providing superior technical interfaces;
  • reducing authentication friction; or
  • restricting competitors' access.

The underlying concern is similar:

control over an upstream platform can be used to favour the platform operator's own downstream service.

16. 6. Slovak Telekom

Case: Slovak Telekom a.s. v Commission, Joined Cases C-165/19 P and C-166/19 P.

The case concerned abusive exclusionary conduct involving access conditions and margin-squeeze issues in telecommunications.

Relevance

Identity federation frequently involves vertically related markets.

For example:

identity infrastructure → authentication → digital services

A dominant provider could theoretically manipulate upstream access conditions in ways that disadvantage downstream competitors.

Slovak Telekom therefore illustrates how competition law can scrutinize discriminatory or exclusionary conduct occurring between vertically related levels of a technology ecosystem.

17. 7. Google Android

Case: Google LLC and Alphabet Inc. v Commission, Case T-604/18.

The case concerned Google's Android ecosystem and contractual arrangements involving search, browser and application distribution.

Relevance

The case demonstrates how a dominant digital ecosystem can use contractual and technological arrangements to reinforce ecosystem-wide advantages.

Identity federation can create a similar ecosystem effect.

For example:

identity → browser → cloud → payments → applications → advertising

If authentication becomes tied to other ecosystem services, identity can function as an entry point for leveraging dominance.

18. 8. Meta Platforms / Facebook Data Combination Issues

European competition enforcement concerning Facebook/Meta has also demonstrated the importance of combining platform power, data and adjacent markets.

The Facebook/Meta data-related competition controversy is relevant because identity platforms can obtain unusually comprehensive information about users.

The competitive question is whether combining identity-related information with data from other services:

  • strengthens entry barriers;
  • advantages the incumbent;
  • reduces contestability; or
  • creates an unfair competitive advantage.

The case law demonstrates that data practices can become relevant to competition analysis where they reinforce market power.

19. 9. MEO v Autoridade da Concorrência

Case: MEO – Serviços de Comunicações e Multimédia SA v Autoridade da Concorrência, Case C-525/16.

The Court examined discriminatory pricing under Article 102 TFEU and emphasized the importance of assessing whether the conduct places trading partners at a competitive disadvantage.

Relevance

A dominant identity platform might offer different authentication terms to different relying parties.

For example:

  • preferred authentication fees for affiliated businesses;
  • higher verification fees for competitors;
  • better API access for selected partners;
  • different authentication speeds; or
  • discriminatory certification conditions.

MEO helps frame the analysis around actual or potential competitive disadvantage, rather than treating every difference in treatment as automatically abusive.

20. Consolidated Case-Law Table

CasePrincipal doctrineIdentity-federation relevance
United BrandsDominanceMarket power of identity gateways
BronnerEssential facilitiesWhether identity infrastructure is indispensable
IMS HealthExceptional access obligationsProprietary identity infrastructure
MicrosoftInteroperability/refusal to supplyAPI and authentication interoperability
Google ShoppingSelf-preferencingPreferential treatment of own identity-linked services
Slovak TelekomVertical exclusionDiscriminatory access conditions
Google AndroidEcosystem leveragingIdentity-to-ecosystem expansion
MEODiscriminatory treatmentDifferent federation terms for competitors

21. Market Definition Problems

Identity federation creates difficult market-definition questions.

A competition authority might investigate:

Market 1

Identity verification services

Market 2

Authentication services

Market 3

Federated identity/SSO services

Market 4

Enterprise identity-management services

Market 5

Consumer digital identity services

Market 6

Identity-as-a-Service infrastructure

These markets may overlap but are not necessarily identical.

22. Two-Sided and Multi-Sided Effects

Federated identity platforms may connect:

Users ↔ Identity providers ↔ Relying parties ↔ Developers

Consequently, traditional price-based market analysis may be inadequate.

The relevant competitive variables include:

  • security;
  • privacy;
  • authentication speed;
  • interoperability;
  • portability;
  • reliability;
  • number of supported services;
  • verification quality;
  • developer access; and
  • data practices.

A platform offering identity services for free can nevertheless possess substantial market power.

23. Privacy and Competition Interaction

Identity federation makes privacy particularly important because identity information can be highly sensitive.

But privacy and competition law should not be conflated.

A privacy violation does not automatically establish an antitrust violation.

Nevertheless, privacy practices may become competitively relevant where they:

  • create switching costs;
  • reduce contestability;
  • strengthen network effects;
  • prevent data portability;
  • disadvantage rival identity providers; or
  • increase the incumbent's informational advantage.

Thus:

Privacy can function as a competitive parameter.

24. Security as an Objective Justification

Identity providers have a legitimate reason to impose security restrictions.

For example, interoperability may be denied or limited because of:

  • authentication vulnerabilities;
  • fraud;
  • identity theft;
  • credential stuffing;
  • compromised APIs;
  • inadequate encryption;
  • malicious applications; or
  • insufficient verification standards.

Therefore, competition law should distinguish between:

legitimate security requirements

and

security requirements used as a pretext for exclusion.

A proportionality assessment becomes particularly important.

25. Dominance Through Standards

A company may become dominant not merely because it owns infrastructure but because its identity protocol becomes the de facto standard.

This can create:

standardization → adoption → network effects → dependency → dominance.

Once the standard becomes embedded across thousands of services, competing protocols may face enormous entry barriers.

The competition issue therefore becomes whether standard-setting is:

  • open;
  • transparent;
  • nondiscriminatory;
  • interoperable; and
  • accessible on reasonable terms.

26. Government Identity Systems

Identity federation can become even more complicated where a government is involved.

For example, a state-controlled identity infrastructure may simultaneously function as:

  • public infrastructure;
  • authentication authority;
  • regulatory gateway;
  • service provider; and
  • commercial platform.

This creates potential competition-neutrality concerns.

The government-linked identity provider could potentially give affiliated services preferential access or impose conditions that private competitors cannot replicate.

Competition law may then intersect with:

  • public procurement;
  • state-aid/state-support principles;
  • administrative law;
  • constitutional rights;
  • privacy law; and
  • sector-specific regulation.

27. Identity Federation and Ecosystem Lock-In

The strongest competition concern may not be traditional monopoly pricing.

Instead, it may be ecosystem dependency.

A simplified cycle is:

Dominant IdP

↓

More relying parties accept it

↓

More users depend upon it

↓

More identity data and authentication history accumulate

↓

Switching becomes harder

↓

Competing IdPs become less attractive

↓

Dominant IdP becomes even stronger

This is a classic self-reinforcing digital-market feedback loop.

28. Possible Abusive Practices

Potential competition concerns include:

1. Exclusive federation

Requiring platforms to use only the dominant IdP.

2. API discrimination

Giving affiliated services superior API functionality.

3. Authentication degradation

Making rival identity providers technically slower or less reliable.

4. Identity-data foreclosure

Preventing competitors from accessing necessary user-authorized information.

5. Tying

Conditioning identity access upon purchasing another service.

6. Self-preferencing

Favouring the provider's own downstream applications.

7. Excessive switching barriers

Making identity migration artificially difficult.

8. Discriminatory certification

Applying more burdensome technical standards to competitors.

9. Protocol manipulation

Changing technical standards in ways that disadvantage competing systems.

10. Data leveraging

Using identity information to obtain an advantage in adjacent markets.

29. Possible Competition Remedies

Authorities could consider:

A. Interoperability obligations

Require standardized interfaces allowing competing identity providers to interact.

B. Non-discrimination

Require equivalent technical and commercial access conditions.

C. Data portability

Allow users to transfer appropriate identity-related information.

D. Multi-homing

Allow relying parties to support multiple identity providers.

E. API access

Require reasonable access to necessary interfaces.

F. Structural separation

In extreme circumstances, separate identity infrastructure from downstream competing services.

G. Transparency

Require publication of technical requirements and certification criteria.

H. Monitoring

A regulator could monitor:

  • authentication failures;
  • API restrictions;
  • access conditions;
  • switching rates;
  • technical degradation; and
  • discriminatory treatment.

30. Key Legal Test

A useful framework for analysing Identity Federation Platform Dominance is:

Step 1 — Define the market

Identify the relevant identity, authentication or federation service.

Step 2 — Establish dominance

Examine:

  • market share;
  • network effects;
  • switching costs;
  • data advantages;
  • interoperability;
  • entry barriers; and
  • dependence of relying parties.

Step 3 — Identify the conduct

Determine whether the provider:

  • refuses access;
  • discriminates;
  • ties services;
  • self-preferences;
  • restricts interoperability; or
  • exploits data advantages.

Step 4 — Assess foreclosure

Ask whether rivals' ability to compete is materially reduced.

Step 5 — Examine indispensability

For refusal-to-deal theories, determine whether alternatives realistically exist.

Step 6 — Examine justification

Consider legitimate:

  • security;
  • privacy;
  • fraud prevention;
  • technical integrity; and
  • regulatory compliance

justifications.

Step 7 — Assess proportionality

Determine whether the restriction goes further than reasonably necessary.

Step 8 — Select remedies

Possible remedies include interoperability, portability, non-discrimination, monitoring or, in exceptional circumstances, structural separation.

31. Conclusion

Identity federation platform dominance represents an emerging form of digital gatekeeper power. Unlike conventional monopolies, the dominant provider may not charge users a monetary price. Its power may instead arise from network effects, authentication dependency, data accumulation, interoperability control, switching costs and ecosystem integration.

The most relevant established competition-law principles come from cases such as Bronner, IMS Health and Microsoft concerning access and interoperability, while Google Shopping and Android demonstrate the importance of ecosystem leveraging and self-preferencing. United Brands, Slovak Telekom and MEO provide broader principles concerning dominance, vertical exclusion and discriminatory treatment.

The central competition-law question is therefore:

When does control over digital identity cease to be merely an efficient authentication service and become a strategic bottleneck through which an undertaking can control access to neighbouring digital markets?

The answer requires a careful combination of dominance analysis, essential-facility principles, interoperability, data-related market power, self-preferencing, tying, switching costs and legitimate security justifications. In digital markets, identity infrastructure can become a particularly powerful form of invisible economic infrastructure, because control over authentication can determine who is able to participate in the wider digital ecosystem.

LEAVE A COMMENT