Identity Graph Monopoly In Advertising Markets .

Identity Interoperability Standards And Control Over Access Systems

1. Introduction

Identity interoperability standards are technical, contractual, and governance rules that allow a person's or organization's digital identity to be recognized and used across different platforms, services, applications, or institutions. Examples include federated login systems, single sign-on, authentication protocols, identity APIs, digital credentials, and standardized identity attributes.

Competition concerns arise when a dominant undertaking controls the standards, interfaces, authentication infrastructure, or identity credentials necessary for rivals to obtain or retain access to users. The problem becomes particularly serious where the identity layer operates as a gateway between users and multiple downstream markets.

The central competition-law question is:

Can a dominant identity provider use control over interoperability standards or access credentials to exclude competing platforms, raise rivals' costs, or make its own ecosystem indispensable?

This can engage abuse of dominance, refusal to supply, discriminatory access, tying, interoperability obligations, essential-facility reasoning, self-preferencing, exclusionary technical design, and exploitative control over ecosystem participation.

2. Meaning of Identity Interoperability

Identity interoperability exists when different systems can exchange and recognize identity-related information according to common technical or institutional rules.

It may involve:

  • authentication;
  • authorization;
  • identity verification;
  • credential portability;
  • account identifiers;
  • user authentication tokens;
  • identity APIs;
  • single sign-on;
  • federated identity;
  • digital certificates;
  • biometric identifiers;
  • organizational identity;
  • access-control databases; and
  • standardized identity attributes.

For example:

User → Identity Provider → Authentication → Multiple Services

If one undertaking becomes the indispensable identity provider for a large ecosystem, control over interoperability can become a source of market power.

3. Identity Standards As Competitive Infrastructure

An identity standard can perform an infrastructure-like function.

Suppose a dominant platform establishes the technical rules governing:

  1. who can authenticate;
  2. what information must be supplied;
  3. which APIs competitors may access;
  4. which authentication protocols are accepted;
  5. how credentials are transferred;
  6. how frequently credentials must be renewed;
  7. whether third-party identity providers are permitted; and
  8. what technical conditions competing services must satisfy.

The platform may then exercise power over access to downstream markets.

This produces a potential chain:

Identity Standard → Authentication → Access → User Relationship → Data → Network Effects → Market Power

The important point is that the identity system need not itself be the final product market. Its strategic importance may derive from its position as a gateway to another market.

4. How Control Over Identity Standards Creates Market Power

A. Standard-setting power

A dominant firm may control the technical specification used by other market participants.

If competitors cannot realistically depart from the standard, the standard-setter may possess substantial structural influence.

Competition concerns increase where the undertaking:

  • designs the standard;
  • controls certification;
  • controls implementation;
  • controls updates;
  • determines compatibility;
  • controls access to documentation; or
  • controls approval of competing implementations.

B. Network effects

Identity interoperability often becomes more valuable as more participants use it.

A simplified network effect is:

More users → More services → More reliance on identity standard → Higher switching costs → More users

A rival identity system may therefore face a severe chicken-and-egg problem.

It cannot attract users because services do not support it, while services will not support it because users do not possess compatible credentials.

5. Access-Control Bottlenecks

A particularly important issue is the identity access bottleneck.

Consider:

Identity Provider A → controls authentication → Service B, C, D and E

If A can decide whether B, C, D and E may authenticate users, A effectively controls an important gateway.

This can resemble other forms of infrastructure bottleneck.

The dominant firm might:

  • deny authentication;
  • delay approval;
  • impose discriminatory technical conditions;
  • charge excessive interoperability fees;
  • restrict API access;
  • revoke credentials;
  • degrade authentication performance;
  • require exclusive authentication;
  • prevent competing identity providers from interoperating; or
  • condition access on purchasing another product.

6. Refusal To Interoperate

A refusal to interoperate can raise an Article 102 TFEU / domestic abuse-of-dominance issue where the relevant legal requirements are satisfied.

The classic questions include:

  1. Is the undertaking dominant?
  2. Is the requested interoperability genuinely necessary?
  3. Is the refusal capable of eliminating effective competition?
  4. Does the refusal prevent the emergence of a new product or service where relevant?
  5. Is there an objective justification?
  6. Would interoperability impose disproportionate technical or security risks?

The identity context is particularly sensitive because the dominant provider may invoke:

  • cybersecurity;
  • fraud prevention;
  • privacy;
  • authentication integrity;
  • technical reliability; and
  • consumer protection.

Those considerations may be legitimate, but they cannot automatically justify exclusionary conduct.

7. Discriminatory Interoperability

A dominant identity provider may formally permit interoperability while making rival access materially worse.

Examples include:

  • higher API latency for competitors;
  • lower authentication limits;
  • slower certification;
  • inferior technical documentation;
  • restrictive rate limits;
  • unequal access to identity attributes;
  • higher fees;
  • more burdensome compliance requirements.

This can be more difficult to detect than an outright refusal.

The relevant comparison may be:

Dominant firm's affiliated service: full interoperability

versus

Independent competitor: restricted interoperability.

Such conduct may constitute discriminatory treatment or a broader exclusionary strategy depending on the circumstances.

8. Identity Portability And Switching Costs

Interoperability is closely related to identity portability.

Suppose a consumer has spent years accumulating:

  • authentication history;
  • verified credentials;
  • reputation;
  • professional identity;
  • transaction history;
  • security credentials; and
  • linked accounts.

If these cannot easily be transferred to another identity provider, switching becomes costly.

This can produce:

Identity lock-in

The consumer may technically be free to change providers but practically unable to do so.

Competition law may therefore need to consider non-price switching costs, not merely monetary prices.

9. Tying And Bundling

Identity services can also be used as a tying mechanism.

For example:

Dominant Identity Service → access conditional upon using Dominant Cloud / Browser / Payment / Advertising Service

The identity service becomes the gateway through which the dominant undertaking extends its power into another market.

Potential theories include:

  • tying;
  • bundling;
  • leveraging;
  • foreclosure;
  • self-preferencing; and
  • ecosystem exclusion.

The stronger the identity provider's position as an unavoidable access point, the greater the potential competitive significance.

10. Self-Preferencing Through Identity Architecture

A dominant platform might design its interoperability architecture so that its own services receive superior technical treatment.

For example:

FunctionDominant serviceRival service
Authentication speedImmediateDelayed
API accessFullRestricted
Identity attributesComprehensiveLimited
Credential refreshAutomaticManual
Security certificationInternalCostly external process
User promptsMinimalMultiple warnings

Even without an express refusal to deal, the architecture itself can become an exclusionary mechanism.

11. Standards As A Form Of Private Regulation

Large digital platforms increasingly perform functions resembling regulators.

A dominant identity provider may establish:

  • technical standards;
  • certification requirements;
  • security rules;
  • authentication policies;
  • developer conditions;
  • access criteria; and
  • identity-verification rules.

The competitive concern is that a private undertaking can effectively determine who may participate in a market.

This creates a transition from:

Market competition

to:

Competition subject to private access regulation.

12. Relevant Case Laws

The following cases are particularly useful for analysing identity interoperability and control over access systems.

1. Microsoft Corp. v Commission — General Court, 2007

This is one of the most important interoperability cases.

The European Commission found that Microsoft abused its dominant position by refusing to provide interoperability information necessary for competing work-group server operating systems to achieve interoperability with Microsoft's dominant PC operating-system environment.

The General Court substantially upheld the Commission's approach.

Relevance to identity interoperability

The case demonstrates that interoperability information can possess competitive significance where rivals require it to compete effectively.

The identity equivalent would arise where a dominant authentication system controls technical information or interfaces necessary for rival identity-dependent services.

Principle

Control over interoperability information can become an exclusionary advantage when it prevents competitors from operating effectively.

2. Commercial Solvents Corp. v Commission — ECJ, 1974

Commercial Solvents concerned refusal to supply an essential input to a downstream competitor.

The Court recognized that a dominant undertaking occupying an upstream position could abuse its dominance by restricting supply to a downstream market where competition was thereby threatened.

Relevance

Identity infrastructure can similarly operate as an upstream input.

For example:

Identity authentication → downstream financial/social/cloud/service platform

If a dominant authentication provider restricts access to downstream competitors, Commercial Solvents provides an important conceptual foundation for examining the conduct.

Principle

Dominance in an upstream market cannot necessarily be used to eliminate competition downstream.

3. United Brands v Commission — ECJ, 1978

United Brands is foundational for understanding abuse of dominance and the concept of an undertaking possessing economic strength that enables it to behave independently of competitors and customers.

Relevance to identity systems

An identity provider with:

  • massive user coverage;
  • extensive authentication infrastructure;
  • strong network effects;
  • high switching costs; and
  • control over access credentials

may possess substantial economic strength.

The case therefore assists in analysing dominance before the interoperability question is reached.

Principle

Dominance concerns economic power capable of substantially weakening competitive constraints.

4. Bronner v Mediaprint — ECJ, 1998

Bronner is particularly important for refusal-to-supply analysis.

The Court established a demanding framework for treating refusal of access to infrastructure as abusive, including the significance of whether access is indispensable and whether duplication is realistically possible.

Relevance

Suppose an identity provider argues:

"Competitors can simply create their own identity system."

Bronner-type reasoning requires consideration of whether creating an alternative identity infrastructure is realistically possible.

Relevant factors may include:

  • technical feasibility;
  • cost;
  • time;
  • network effects;
  • installed user base;
  • security certification;
  • regulatory requirements; and
  • access to identity credentials.

Principle

Not every refusal to interoperate constitutes abuse; indispensability and competitive effects are crucial.

5. IMS Health v NDC Health — ECJ, 2004

IMS Health involved access to a copyrighted structure that competitors needed to operate effectively in the relevant market.

The Court articulated stringent conditions concerning refusal to license intellectual property, including circumstances involving elimination of competition and prevention of a new product.

Relevance

Identity interoperability standards may be protected by:

  • intellectual property;
  • contractual rights;
  • technical specifications; or
  • proprietary APIs.

IMS Health demonstrates that proprietary control does not automatically create an unrestricted obligation to provide access, but exceptional circumstances can justify intervention.

Principle

Intellectual-property or proprietary control may coexist with competition-law obligations in exceptional exclusionary circumstances.

6. Google Shopping — Google and Alphabet v Commission / Commission decision

The Google Shopping litigation concerns Google's use of its dominant position in general search to favour its own comparison-shopping service.

The case is highly relevant to self-preferencing and platform architecture.

Relevance to identity interoperability

An identity platform could similarly use its gateway position to give preferential treatment to its own services.

For example:

"Authenticated through our identity system" → preferential placement, functionality, speed, or data access for affiliated services.

The competitive issue is not merely ownership of identity infrastructure but how that infrastructure is used to advantage affiliated services.

Principle

The design and operation of a dominant platform can produce exclusionary effects when it systematically disadvantages competing services.

13. Additional Useful Case: Slovak Telekom v Commission

Slovak Telekom v Commission is important for analysing access restrictions involving infrastructure and downstream foreclosure.

The case concerned discriminatory or restrictive access conditions in telecommunications infrastructure.

Relevance

Identity infrastructure increasingly resembles telecommunications infrastructure in one important respect:

competitors may technically exist, but their ability to reach customers depends upon access to a strategically important gateway.

Identity providers can therefore raise similar issues concerning:

  • access;
  • pricing;
  • discrimination;
  • technical conditions; and
  • downstream foreclosure.

14. Comparative Case-Law Matrix

CaseCore doctrineIdentity interoperability relevance
MicrosoftInteroperability refusalTechnical identity interfaces/API access
Commercial SolventsRefusal to supplyAuthentication as upstream input
United BrandsDominanceIdentity-network market power
BronnerEssential-facility/refusal frameworkWhether identity infrastructure is indispensable
IMS HealthExceptional interoperability/IP accessProprietary identity standards
Google ShoppingSelf-preferencingPreferential treatment of affiliated identity services
Slovak TelekomInfrastructure access/foreclosureDiscriminatory identity access

15. Essential-Facility Analysis

Identity systems may sometimes invite an essential-facility-type analysis, but courts generally apply this doctrine cautiously.

A claimant would need to establish factors such as:

A. Control

The defendant controls the identity infrastructure.

B. Indispensability

There is no realistic alternative.

C. Replication difficulty

Competitors cannot reasonably reproduce the system.

D. Competitive foreclosure

Access denial substantially weakens competition.

E. Absence of adequate justification

The restriction lacks legitimate technical, security, or other justification.

Identity infrastructure is particularly interesting because network effects can make an otherwise technically reproducible system commercially difficult to replicate.

16. Cybersecurity And Privacy As Objective Justifications

Identity interoperability creates an important tension.

A dominant firm may legitimately argue that unrestricted interoperability creates:

  • identity theft;
  • account takeover;
  • fraud;
  • credential leakage;
  • spoofing;
  • cybersecurity vulnerabilities;
  • privacy violations; or
  • authentication degradation.

Competition authorities therefore should not automatically require unrestricted access.

The proper question is often:

Is the restriction genuinely necessary and proportionate to the legitimate security objective?

A blanket exclusion may be problematic if less restrictive alternatives exist.

Examples include:

  • certification;
  • encryption requirements;
  • audit procedures;
  • access tokens;
  • authentication standards;
  • security testing;
  • rate limits applied neutrally; and
  • controlled API access.

17. Governance Capture

A particularly advanced concern is identity-standard governance capture.

A dominant identity company might influence the standards body responsible for determining interoperability rules.

This can occur through:

  • voting power;
  • technical committees;
  • proprietary implementations;
  • certification control;
  • funding;
  • control over reference software;
  • intellectual-property claims; or
  • participation asymmetries.

The result could be:

Private technical standard → market-wide dependency → competitive exclusion

Competition law may therefore need to examine not only the final access restriction but also the governance process through which the standard was created.

18. Identity Interoperability And Data Portability

Interoperability and portability are related but distinct.

Interoperability

Allows different systems to communicate.

Portability

Allows users or entities to move relevant information from one system to another.

A competitive identity ecosystem may require both.

For example:

Authentication interoperability without credential portability

may still leave users locked into the incumbent.

Conversely:

Credential portability without interoperable authentication

may make transferred identity information practically unusable.

19. Multi-Homing And Competitive Pressure

Identity interoperability can facilitate multi-homing.

A user could authenticate through:

  • Provider A;
  • Provider B; and
  • Provider C.

This reduces dependence on a single identity provider.

Therefore, restrictions that prevent multi-provider authentication can strengthen market power.

A dominant identity platform may intentionally discourage multi-homing by:

  • making external authentication inconvenient;
  • requiring proprietary credentials;
  • restricting simultaneous identity providers;
  • disabling third-party login;
  • imposing technical incompatibility; or
  • warning users against competing authentication services.

20. Interoperability As A Remedy

Competition authorities may consider interoperability as a behavioural or structural remedy.

Potential remedies include:

Technical interoperability

Require the dominant platform to provide standardized interfaces.

API access

Require reasonable access to authentication APIs.

Credential portability

Allow users to transfer identity credentials.

Non-discrimination

Require equivalent technical access for rivals.

Transparency

Require publication of technical interoperability specifications.

Governance separation

Separate standard-setting from commercial decision-making.

Auditing

Allow independent monitoring of API performance and discriminatory treatment.

Functional separation

In extreme circumstances, separate identity infrastructure from downstream commercial services.

21. Economic Effects Of Interoperability Restrictions

Restrictions may produce several forms of harm:

1. Foreclosure

Competitors cannot effectively access users.

2. Higher entry barriers

New identity providers cannot build sufficient scale.

3. Increased switching costs

Users remain tied to incumbent platforms.

4. Reduced innovation

Alternative authentication technologies cannot obtain sufficient adoption.

5. Higher prices

Reduced competition can eventually permit higher charges.

6. Reduced privacy choice

Consumers may have fewer identity providers to choose from.

7. Reduced security competition

Competition between authentication architectures may diminish.

22. Identity Interoperability And Digital Ecosystems

Identity systems are especially powerful because they connect multiple markets.

A simplified ecosystem can be represented as:

Identity

↓

Authentication

↓

Access

↓

Platform

↓

Data

↓

Advertising / Payments / Cloud / Commerce

Thus, control at the identity layer may permit leverage into several adjacent markets.

This creates the possibility of ecosystem-wide foreclosure, rather than merely foreclosure in a single product market.

23. Key Legal Questions For Competition Authorities

When investigating identity interoperability, authorities should ask:

  1. What is the relevant identity or authentication market?
  2. Is the undertaking dominant?
  3. Is the identity infrastructure commercially indispensable?
  4. Are there effective alternative identity providers?
  5. Can competitors realistically reproduce the infrastructure?
  6. Are users able to multi-home?
  7. Can credentials be ported?
  8. Are APIs available on equal terms?
  9. Are affiliated services receiving preferential treatment?
  10. Are access restrictions objectively justified?
  11. Are security requirements applied consistently?
  12. Does the conduct foreclose equally efficient competitors?
  13. Does it raise rivals' costs?
  14. Does it increase switching costs?
  15. Does it extend dominance into adjacent markets?
  16. Would interoperability increase innovation and consumer choice?

24. Emerging Competition-Law Problem: Identity As A Gatekeeper

The most significant future issue is the transformation of identity providers into digital gatekeepers.

An identity provider may no longer merely authenticate a person.

It may determine:

  • which services recognize that person;
  • what attributes accompany the identity;
  • which transactions can be completed;
  • which devices can authenticate;
  • which applications obtain authorization;
  • which businesses receive verified-user status; and
  • which competing identity providers can interoperate.

At that point, identity infrastructure begins to resemble a general-purpose access-control layer for the digital economy.

The competition concern therefore shifts from:

"Who controls authentication?"

to:

"Who controls participation in digital markets through authentication?"

25. Conclusion

Identity interoperability standards can become a major source of competition-law power when control over authentication, credentials, APIs, or technical standards determines access to downstream markets.

The central legal principles can be synthesized as follows:

Dominance + indispensable identity infrastructure + restrictive interoperability + discriminatory access + downstream foreclosure = potential abuse of dominance.

The leading interoperability and access cases—particularly Microsoft, Commercial Solvents, Bronner, IMS Health, Google Shopping, United Brands, and Slovak Telekom—provide the doctrinal building blocks for analysing these problems.

The most important distinction is that standardization itself is not anti-competitive. Common identity standards can reduce fragmentation, improve security, facilitate entry, and promote consumer choice. The competition concern arises when a dominant undertaking transforms an ostensibly open interoperability standard into a private gatekeeping mechanism, using control over identity and authentication to exclude rivals or extend its market power across a digital ecosystem.

LEAVE A COMMENT