Global Biometric Authentication Infrastructure And Exclusion Power .

Global Biometric Authentication Infrastructure And Exclusion Power

1. Introduction

Biometric authentication infrastructure refers to systems that identify or authenticate individuals through physical or behavioural characteristics such as fingerprints, facial images, iris patterns, voiceprints, palm prints, gait, or other biometric identifiers. These systems increasingly operate as critical gateways to economic and social participation: banking, telecommunications, border control, employment, healthcare, government benefits, digital identity, payments, and access to online platforms.

The competition-law significance goes beyond privacy. Where a biometric infrastructure becomes indispensable, its operator may acquire “exclusion power”—the practical ability to determine who can enter a market, access a service, transact, authenticate, or remain economically active.

This creates a convergence between:

  • competition law;
  • data and privacy law;
  • digital-platform regulation;
  • essential-facilities doctrine;
  • interoperability and standards regulation;
  • public-law due process; and
  • fundamental rights.

The central competition question is therefore:

When does control over biometric authentication cease to be merely a technological advantage and become infrastructure-level market power capable of excluding competitors, consumers, workers, or entire categories of users?

2. What Is Biometric Authentication Infrastructure?

A biometric authentication ecosystem normally contains several layers:

  1. Capture layer – cameras, fingerprint readers, microphones, iris scanners, etc.
  2. Identity layer – databases or identity repositories.
  3. Matching layer – algorithms compare presented biometric information with stored templates.
  4. Credential layer – the system issues an authentication result or credential.
  5. API/interface layer – banks, platforms, employers, governments and applications connect to the system.
  6. Decision layer – authentication determines whether the person receives access.
  7. Monitoring layer – fraud detection, behavioural analytics and continuous authentication.
  8. Governance layer – rules concerning enrollment, verification, suspension, interoperability and appeals.

The most powerful entity may therefore not be the manufacturer of the biometric sensor.

It may instead be the entity controlling the authentication gateway.

3. Meaning of “Exclusion Power”

Exclusion power is the capacity to prevent or materially restrict another person or business from participating in an economic or social ecosystem.

In biometric systems, exclusion can occur through:

A. Authentication denial

A legitimate individual is rejected by the matching system.

B. Enrollment exclusion

An individual cannot initially register a biometric identity.

C. Device exclusion

Only approved biometric hardware is permitted.

D. API exclusion

Third-party applications cannot access authentication functionality.

E. Standards exclusion

The infrastructure operator establishes technical standards that competing providers cannot realistically satisfy.

F. Database exclusion

Competitors cannot access the identity or verification database.

G. Algorithmic exclusion

Changes to matching algorithms systematically disadvantage particular users or competing technologies.

H. Credential revocation

Previously valid authentication credentials are suspended or terminated.

The competition-law concern becomes especially serious where authentication is a prerequisite to reaching customers or markets.

4. Why Biometrics Can Create Structural Market Power

Biometric authentication has unusual characteristics.

4.1 High switching costs

Biometric identifiers are difficult to replace in the way consumers replace passwords.

A person can create a new password.

They cannot practically create an entirely new fingerprint.

This makes biometric infrastructure potentially more identity-specific and persistent than ordinary authentication services.

4.2 Network effects

The value of a biometric identity infrastructure increases as more:

  • banks;
  • governments;
  • merchants;
  • employers;
  • platforms; and
  • consumers

use it.

This can create a reinforcing network effect:

more users → more relying institutions → more utility → more users.

4.3 Data advantages

Large authentication networks generate information concerning:

  • identity;
  • transaction patterns;
  • authentication attempts;
  • fraud;
  • device characteristics;
  • geographic patterns;
  • behavioural signals.

The resulting data advantage can strengthen the incumbent's position.

4.4 High security barriers

Security requirements are legitimate, but they can also become entry barriers.

An incumbent may argue that interoperability would weaken security even where alternative architectures could satisfy equivalent security requirements.

5. Relevant Competition-Law Theories

A. Abuse of Dominance

An operator controlling indispensable biometric infrastructure could potentially abuse a dominant position through:

  • discriminatory access;
  • refusal to supply;
  • excessive access charges;
  • tying;
  • self-preferencing;
  • exclusionary interoperability requirements;
  • discriminatory authentication standards;
  • technical degradation; or
  • selective suspension.

B. Essential Facilities

The infrastructure may resemble an essential facility where:

  1. access is indispensable;
  2. duplication is technically or economically impracticable;
  3. exclusion eliminates effective competition; and
  4. access can be provided without undermining legitimate security requirements.

The doctrine must be applied carefully because forcing access to sensitive biometric infrastructure can create security and privacy risks.

C. Leveraging

A dominant biometric authentication provider might use control over authentication to expand into an adjacent market.

For example:

Biometric identity → authentication → payments → banking → insurance

or:

device authentication → app access → payments → digital services.

The competition concern is that control at one infrastructure layer can be leveraged into another market.

6. Biometric Authentication as a “Gateway”

The most important conceptual development is the transformation of authentication into a gateway function.

Traditional infrastructure:

electricity → business operation

Digital infrastructure:

operating system → application access

Biometric infrastructure:

authentication → economic participation

If authentication becomes mandatory for:

  • opening a bank account;
  • receiving public benefits;
  • accessing telecommunications;
  • entering workplaces;
  • completing digital payments; or
  • accessing major digital platforms,

then the infrastructure operator may acquire power resembling a private regulator.

That raises an important competition-law question:

Can a private authentication intermediary decide who is economically visible?

7. Case Law

Because there is still relatively little case law directly addressing a worldwide biometric-authentication monopoly, the strongest authorities come from essential facilities, digital identity, data, interoperability, platform access, and exclusionary infrastructure disputes.

Case 1 — United States v. Terminal Railroad Association of St. Louis (1912)

This is one of the foundational American essential-facilities cases.

A railroad terminal controlled by an association of competing railroads created a bottleneck through which competing rail traffic had to pass.

The Supreme Court treated the refusal to provide fair access as an antitrust problem.

Relevance to biometrics

A biometric authentication gateway can produce a comparable bottleneck where:

biometric authentication infrastructure → access to downstream markets.

If virtually every provider must use one authentication system, exclusion from that system may effectively mean exclusion from the downstream market.

The case therefore provides the conceptual foundation for treating a biometric gateway as a potential bottleneck facility.

8. United States v. AT&T (1982)

The AT&T litigation concerned control over telecommunications infrastructure and the competitive consequences of vertical integration.

The eventual restructuring separated telecommunications network functions from competitive downstream activities.

Relevance

The analogy is particularly strong where one company controls:

  • authentication infrastructure;
  • biometric identity databases;
  • authentication APIs; and
  • downstream commercial services.

The concern is that the infrastructure owner may discriminate against downstream competitors.

A modern equivalent could be:

Biometric authentication gateway + payment platform + financial services

or:

Device biometric system + app marketplace + payment system.

The structural lesson is that control over a foundational network can create leverage into competitive markets.

9. MCI Communications Corp. v. AT&T (1983)

The Seventh Circuit developed an influential formulation of the essential-facilities doctrine.

The case concerned access to AT&T's telecommunications network.

The court considered factors including:

  1. control of the facility by a monopolist;
  2. inability reasonably to duplicate the facility;
  3. denial of access; and
  4. feasibility of providing access.

Application to biometric authentication

The framework can be translated into biometric infrastructure:

Essential-facility questionBiometric application
Monopoly controlWho controls authentication?
DuplicationCan a rival realistically build an equivalent identity network?
DenialCan users or competitors be excluded?
FeasibilityCan secure interoperability be provided?

However, biometric systems introduce an additional issue absent from ordinary infrastructure:

Would compulsory access compromise biometric security or privacy?

Therefore, interoperability may need to be designed through controlled APIs rather than unrestricted database access.

10. Bronner v. Mediaprint (CJEU, 1998)

In Oscar Bronner GmbH & Co. KG v Mediaprint, the Court of Justice applied a strict approach to refusal-to-supply and essential-facilities principles.

The Court emphasized the need for genuine indispensability and the absence of a realistic alternative.

Importance

This case prevents every commercially useful biometric system from automatically becoming an essential facility.

For example, merely because a biometric API is convenient does not mean competitors must receive access.

The stronger case arises where:

  • biometric authentication is effectively mandatory;
  • alternative authentication systems are unavailable;
  • consumers cannot realistically switch;
  • competitors cannot duplicate the infrastructure; and
  • exclusion materially eliminates competition.

Thus, Bronner supplies an important limiting principle.

11. Microsoft Corp. v Commission (General Court, 2007)

The Microsoft case concerned refusal to provide interoperability information to competing work-group server products.

The European courts recognized that interoperability could be competitively significant where refusal prevented effective competition.

Biometric relevance

Biometric ecosystems can have a similar interoperability problem.

Suppose:

  • Platform A controls biometric authentication;
  • Platform B develops competing identity services;
  • Platform A refuses interoperability;
  • consumers cannot easily use Platform B because applications are designed around Platform A's authentication infrastructure.

The refusal can become an interoperability-based exclusion strategy.

The important lesson is that competition can be harmed not only through price discrimination but through technical incompatibility.

12. Google Shopping (Google Search, CJEU, 2024)

The Google Shopping litigation illustrates the competition significance of a dominant digital gateway favouring its own downstream service.

The case concerned the use of Google's dominant general search service to advantage its comparison-shopping service.

Biometric analogy

Imagine a biometric authentication provider controlling the gateway and ranking or approving downstream identity services.

It could potentially:

  • privilege its own authentication products;
  • reduce the visibility of rival authenticators;
  • make competing credentials harder to use;
  • impose discriminatory technical requirements.

The underlying principle is particularly relevant to biometric infrastructure:

Control of a gateway can become a mechanism for downstream self-preferencing.

13. Meta Platforms v Bundeskartellamt (CJEU, 2023)

The Meta decision addressed the relationship between competition law and extensive data collection in a dominant digital platform.

The Court recognized the importance of data-protection considerations when assessing conduct by a dominant platform.

Biometric relevance

Biometric information is substantially more sensitive than ordinary behavioural data.

A dominant authentication provider could potentially combine:

biometric identity + authentication history + transaction information + behavioural data.

That creates a particularly powerful data ecosystem.

The competition concern is not merely collection of biometric data.

It is the possibility that control over identity data reinforces dominance in adjacent markets.

14. Intel v Commission (CJEU, 2017)

Intel is principally associated with loyalty rebates and the requirement for competition authorities to assess whether conduct is capable of producing exclusionary effects.

Biometric relevance

A biometric infrastructure provider could potentially offer:

  • preferential authentication rates;
  • exclusive access agreements;
  • rebates to banks or platforms;
  • technical incentives for adopting its biometric standard.

Such arrangements could make rival authentication infrastructures commercially non-viable.

The relevant lesson is that apparently attractive commercial arrangements can have anticompetitive effects when imposed by a powerful incumbent.

15. Google Android (CJEU, 2022)

The Google Android litigation addressed restrictions and contractual arrangements concerning the Android ecosystem and competing services.

Biometric significance

Biometric authentication can be embedded deeply into an operating system.

An OS provider could potentially require developers to use:

its biometric API → its authentication mechanism → its identity ecosystem.

If competing biometric providers are technically or commercially disadvantaged, the authentication layer can become a means of extending dominance.

This makes ecosystem foreclosure an important theory in biometric competition cases.

16. Summary of the Six+ Major Authorities

CaseCore principleBiometric relevance
Terminal Railroad (1912)Bottleneck infrastructureAuthentication gateway
United States v. AT&T (1982)Network control and structural foreclosureIdentity infrastructure
MCI v AT&T (1983)Essential-facilities frameworkAccess/interoperability
Bronner (1998)Strict indispensability requirementLimits compulsory biometric access
Microsoft (2007)Interoperability and exclusionBiometric API compatibility
Intel (2017)Exclusionary effects of commercial arrangementsExclusive biometric contracts
Google Android (2022)Ecosystem restrictionsOS/biometric ecosystem
Meta v Bundeskartellamt (2023)Data and dominance interactionBiometric data accumulation
Google Shopping (2024)Gateway/self-preferencing theoryAuthentication gateway discrimination

17. Authentication Exclusion and Fundamental Rights

Biometric exclusion can have consequences beyond conventional competition law.

A rejected biometric match may prevent someone from:

  • accessing money;
  • receiving benefits;
  • boarding transport;
  • entering employment;
  • accessing healthcare;
  • opening an account;
  • using telecommunications.

Consequently, biometric authentication disputes can involve:

Privacy

Is biometric information being collected and processed lawfully?

Equality

Does the system disproportionately reject particular populations?

Due process

Can an individual challenge an authentication failure?

Transparency

Can the person understand why access was denied?

Competition

Are alternative authentication providers available?

Proportionality

Is biometric authentication actually necessary for the objective pursued?

18. False Positives and False Negatives as Competition Issues

Biometric systems create two principal technical errors.

False positive

The system incorrectly authenticates an individual.

False negative

The system incorrectly rejects a legitimate individual.

A false negative can become a competitive exclusion mechanism where authentication is a gateway to economic activity.

For example:

User → biometric verification → rejection → no transaction.

If there is no alternative authentication mechanism, technological error effectively becomes economic exclusion.

19. Algorithmic Discrimination

Biometric systems may produce different accuracy rates across populations.

From a competition perspective, this becomes important when a dominant infrastructure provider:

  • controls the matching algorithm;
  • controls testing standards;
  • controls access to performance data;
  • refuses independent auditing; and
  • prevents competing verification systems from being used.

The problem becomes structural:

algorithmic control → authentication control → access control → market power.

20. Exclusion Through Standards

Technical standards can be legitimate.

Security requirements are especially important in biometric infrastructure.

But standards may become anticompetitive when an incumbent designs requirements that unnecessarily exclude competitors.

Examples include:

  • proprietary biometric templates;
  • closed authentication protocols;
  • proprietary encryption;
  • exclusive hardware certification;
  • restrictive API requirements;
  • mandatory cloud infrastructure;
  • incompatible credential formats.

Competition authorities therefore need to distinguish:

security-based exclusion

from

strategic exclusion disguised as security.

21. Self-Preferencing

Suppose Company A controls biometric authentication and also operates:

  • a bank;
  • payment platform;
  • app marketplace;
  • insurance platform; or
  • employment marketplace.

It could theoretically prioritize its own services.

For example:

Biometric verification → Company A authentication → Company A payment service

while competitors experience additional authentication steps.

This creates a vertical foreclosure risk.

22. Tying

A dominant biometric provider could potentially tie authentication to another service.

For example:

“To use our biometric authentication, you must also use our payment service.”

or:

“Applications using our biometric system must use our cloud infrastructure.”

The traditional tying analysis would examine:

  1. dominance in the tying product;
  2. separate products;
  3. coercion;
  4. foreclosure; and
  5. objective justification.

23. Refusal to Interoperate

This may become one of the most significant future issues.

Imagine:

System A: controls national-scale biometric authentication.

System B: provides competing digital identity services.

If System A refuses technically reasonable interoperability, System B may be unable to compete.

Possible remedies include:

  • API access;
  • credential portability;
  • common technical standards;
  • secure interoperability;
  • certification neutrality;
  • data portability;
  • independent verification.

24. Biometric Portability

Ordinary data portability is relatively straightforward.

Biometric portability is much harder.

A biometric identifier cannot simply be treated like an ordinary photograph or email address because unrestricted copying can create permanent security risks.

Therefore, competition policy should favor privacy-preserving portability, such as:

  • cryptographic proofs;
  • federated authentication;
  • zero-knowledge verification;
  • interoperable credentials;
  • tokenized biometric templates;
  • decentralized identity systems.

The objective should be:

portability of authentication rights without unrestricted portability of raw biometric data.

25. Government-Controlled Biometric Infrastructure

The competition analysis becomes more complicated where the infrastructure is operated by the state.

Government biometric infrastructure may be necessary for:

  • welfare;
  • passports;
  • taxation;
  • immigration;
  • public healthcare;
  • elections;
  • public-sector employment.

In such cases, ordinary private-sector dominance principles may not completely resolve the issue.

The relevant questions may instead concern:

  • procurement neutrality;
  • non-discrimination;
  • access to government infrastructure;
  • public undertakings;
  • state aid;
  • regulatory neutrality;
  • constitutional rights;
  • administrative law.

The state can become both:

infrastructure provider + regulator.

That creates a particularly powerful form of institutional exclusion.

26. Public Procurement and Biometric Lock-In

Governments frequently purchase biometric systems through large contracts.

A poorly designed procurement framework can create long-term dependence upon one vendor.

For example:

Government → Vendor A biometric system → proprietary database → proprietary API → Vendor A maintenance → Vendor A upgrades.

Once deployed, replacement becomes extremely expensive.

This can produce technological lock-in and discourage competing vendors from entering subsequent procurement rounds.

Competition authorities may therefore examine:

  • interoperability requirements;
  • open standards;
  • switching costs;
  • data migration;
  • source-code escrow;
  • vendor-neutral APIs;
  • competitive tendering.

27. Merger Control

Biometric infrastructure mergers can raise particularly serious concerns where an incumbent acquires:

  • a facial-recognition company;
  • identity-verification provider;
  • authentication API;
  • biometric database;
  • fraud-detection provider;
  • digital-wallet company.

The key question is whether the merger combines identity infrastructure with downstream economic services.

Potential theories include:

Horizontal overlap

Two biometric authentication providers merge.

Vertical foreclosure

An authentication provider acquires a bank or payments platform.

Data aggregation

A biometric database combines with transaction or behavioural data.

Ecosystem consolidation

Authentication + cloud + payments + operating system become integrated.

28. The “Identity Bottleneck” Theory

A useful conceptual model is:

Identity → Authentication → Authorization → Transaction → Market Participation

If one undertaking controls the identity and authentication stages, it can potentially influence all downstream stages.

This creates an identity bottleneck.

The economic significance of the bottleneck increases when:

  • users cannot easily opt out;
  • competing authentication systems are unavailable;
  • network effects are strong;
  • switching costs are high;
  • biometric credentials are persistent;
  • the infrastructure is widely accepted.

29. Remedies

Competition authorities could employ several remedies.

Structural remedies

In extreme circumstances:

  • separation of infrastructure and downstream services;
  • divestiture;
  • ownership restrictions.

Behavioural remedies

More commonly:

  • non-discriminatory access;
  • interoperability;
  • API access;
  • fair certification;
  • transparent standards;
  • prohibition of self-preferencing;
  • non-exclusive contracts.

Data remedies

Potential measures include:

  • data minimization;
  • privacy-preserving portability;
  • restrictions on cross-use;
  • separation of biometric and commercial datasets.

Procedural remedies

Because authentication decisions can exclude individuals, systems may require:

  • human review;
  • appeals;
  • independent auditing;
  • error correction;
  • explanation mechanisms.

30. Competition-Law Test for Biometric Exclusion

A future competition authority could ask:

Step 1 — Define the market

Is the relevant market:

  • biometric authentication;
  • digital identity;
  • identity verification;
  • authentication APIs;
  • device authentication;
  • national identity infrastructure?

Step 2 — Establish market power

Consider:

  • network effects;
  • switching costs;
  • data advantages;
  • installed base;
  • regulatory recognition;
  • interoperability.

Step 3 — Identify the bottleneck

Does the undertaking control an indispensable authentication gateway?

Step 4 — Identify exclusion

Has it:

  • denied access;
  • degraded interoperability;
  • discriminated;
  • tied services;
  • self-preferenced;
  • imposed exclusivity?

Step 5 — Test indispensability

Can competitors reasonably reproduce or bypass the infrastructure?

Step 6 — Assess objective justification

Are restrictions genuinely necessary for:

  • cybersecurity;
  • fraud prevention;
  • privacy;
  • national security?

Step 7 — Examine proportionality

Could the same security objective be achieved through a less exclusionary design?

Step 8 — Examine downstream foreclosure

Has the conduct materially reduced competition in related markets?

31. A Particularly Important Future Problem: Authentication as a Private Regulatory Power

The deepest competition concern is not simply that biometric companies may become monopolists.

It is that they may become private rule-makers.

An infrastructure operator could determine:

  • who is recognized;
  • what credentials are valid;
  • what devices are trusted;
  • which applications are permitted;
  • which transactions require additional verification;
  • which users are suspended;
  • which competitors receive API access.

This resembles regulatory authority.

The resulting structure could be represented as:

Biometric infrastructure

↓

Identity recognition

↓

Authentication decision

↓

Access decision

↓

Economic participation

↓

Market power

The competition-law problem therefore intersects with the constitutional question of who should possess the power to determine economic identity.

32. Overall Assessment

Biometric authentication infrastructure can become a powerful source of market power because it combines network effects, high switching costs, persistent identifiers, sensitive data, interoperability dependencies, security barriers and gateway control.

The most important legal distinction is between:

a biometric product

and

a biometric infrastructure.

A biometric product is normally just another technology.

A biometric infrastructure becomes competition-law significant when other businesses or individuals cannot realistically participate without it.

The strongest historical analogies come from Terminal Railroad, AT&T, MCI, Bronner and Microsoft, while modern digital cases such as Google Shopping, Google Android and Meta demonstrate how gateway control, interoperability, data accumulation and vertical leverage can create contemporary exclusionary risks.

Core principle

The greater the extent to which biometric authentication becomes indispensable to economic participation, the greater the justification for treating its operator as infrastructure-level market power subject to interoperability, non-discrimination and competition safeguards.

 

LEAVE A COMMENT