Complexity-Based Barriers To Entry In Regulated Digital Markets .
Complexity-Based Barriers to Entry in Regulated Digital Markets
1. Introduction
Complexity-based barriers to entry arise where a new undertaking is technically, legally, economically, or institutionally capable of entering a digital market in principle, but faces substantial difficulty because the market requires compliance with a complicated combination of regulatory obligations, technical standards, interoperability requirements, certification procedures, data-access rules, security controls, audit requirements, licensing conditions, and institutional approvals.
In regulated digital markets, complexity can therefore become a form of entry barrier even without an explicit prohibition on entry. The important competition-law question is whether the complexity reflects legitimate regulatory objectives—such as privacy, cybersecurity, consumer protection and financial stability—or whether incumbent firms can exploit or reinforce complexity to foreclose competitors.
The issue is particularly important in:
- digital payments and fintech;
- telecommunications and 5G;
- cloud computing;
- digital identity;
- health-data platforms;
- app stores and digital ecosystems;
- online advertising;
- AI and algorithmic services;
- regulated marketplaces; and
- public-sector digital infrastructure.
2. Meaning of Complexity-Based Entry Barriers
A conventional entry barrier might be:
A legal rule preventing a new undertaking from entering a market.
A complexity-based barrier is subtler:
The cumulative difficulty of satisfying multiple technical, regulatory, contractual and interoperability requirements can make effective entry disproportionately costly, slow or uncertain.
For example, suppose a new fintech company must simultaneously obtain:
- a regulatory licence;
- cybersecurity certification;
- data-protection approval;
- access to a payment network;
- interoperability certification;
- API credentials;
- audit certification;
- consumer-protection compliance;
- fraud-monitoring capability; and
- access to trusted digital identity infrastructure.
None of these requirements may individually exclude the entrant. Their cumulative interaction may nevertheless make entry commercially impracticable.
3. Complexity as a Competition-Law Concept
Complexity becomes relevant to competition law when it affects one or more of the following:
A. Cost of entry
The entrant must spend significantly more resources before generating revenue.
B. Time to market
Regulatory and technical approval may take substantially longer than the incumbent's established compliance process.
C. Uncertainty
An entrant may not know whether its technology will satisfy a regulator, platform, certification body or interoperability standard.
D. Access to essential inputs
Complex requirements may be controlled by an incumbent that supplies:
- APIs;
- authentication;
- cloud infrastructure;
- payment rails;
- data;
- app distribution;
- identity verification;
- interoperability interfaces.
E. Economies of scale
An incumbent may spread compliance costs over millions of users, while a new entrant must bear essentially fixed costs with a much smaller customer base.
4. Regulatory Complexity vs Anticompetitive Complexity
This distinction is fundamental.
Legitimate regulatory complexity
Regulation may legitimately impose substantial requirements because the market involves:
- systemic financial risk;
- sensitive personal data;
- cybersecurity;
- national infrastructure;
- health information;
- children's safety;
- consumer protection;
- AI safety;
- telecommunications security.
Competition law should not treat every costly regulation as anticompetitive.
Potentially problematic complexity
Competition concerns arise where complexity is:
- unnecessary;
- discriminatory;
- selectively enforced;
- manipulated by incumbents;
- unnecessarily incompatible with rival technologies;
- accompanied by denial of interoperability;
- combined with refusal to provide necessary technical information; or
- designed or applied in a manner that disproportionately disadvantages entrants.
5. Principal Forms of Complexity-Based Barriers
5.1 Licensing Complexity
A regulated digital market may require multiple licences.
For example, a digital financial platform could need separate authorisation for:
- payment services;
- lending;
- electronic money;
- data processing;
- cybersecurity;
- digital identity;
- cross-border services.
Where an incumbent already possesses the necessary regulatory infrastructure, the entrant faces a significantly greater fixed cost.
Competition concern
The question is not simply whether licensing is lawful. The question is whether licensing architecture creates unnecessary competitive exclusion.
6. Technical Complexity
Digital markets frequently require compliance with complicated technical standards.
Examples include:
- API specifications;
- encryption standards;
- authentication protocols;
- data formats;
- interoperability requirements;
- cloud-security certification;
- identity protocols;
- network standards.
A technically neutral rule can nevertheless become exclusionary if access to the underlying technical standard is controlled by an incumbent.
7. Interoperability Complexity
Interoperability is particularly important in digital ecosystems.
An entrant may theoretically offer a competing service but remain unable to compete effectively because it cannot interact with:
- the dominant platform;
- payment systems;
- operating systems;
- identity systems;
- cloud infrastructure;
- communications networks.
Thus:
formal entry ≠ effective entry.
A market may have dozens of nominal competitors while interoperability restrictions make meaningful competition extremely difficult.
8. Data-Access Complexity
Data can itself become an entry barrier.
A new undertaking may require:
- historical transaction data;
- consumer-consent information;
- behavioural data;
- technical logs;
- identity information;
- interoperability data;
- performance information.
Where an incumbent possesses accumulated datasets and the entrant cannot reproduce them at reasonable cost, the incumbent may possess a structural advantage.
The competition-law analysis becomes particularly important where access to data is combined with:
- network effects;
- economies of scope;
- switching costs; and
- regulatory obligations.
9. Certification and Audit Complexity
Regulated digital markets increasingly require:
- algorithmic audits;
- cybersecurity audits;
- financial audits;
- privacy impact assessments;
- model validation;
- penetration testing;
- conformity assessments.
These may be justified by legitimate regulatory concerns.
However, if certification requirements are excessively fragmented, unpredictable or controlled by bodies closely connected with incumbent firms, they may increase entry costs.
10. Algorithmic Complexity
AI-driven markets create a new category of entry barrier.
An entrant may need to demonstrate:
- model explainability;
- safety;
- accuracy;
- robustness;
- bias testing;
- cybersecurity;
- auditability;
- provenance;
- data governance.
An incumbent with an established compliance team can satisfy these obligations relatively cheaply.
A smaller entrant may face a much higher compliance cost per unit of output.
Consequently:
Regulatory compliance can generate economies of scale that reinforce incumbent market power.
11. Network Effects and Complexity
Complexity becomes particularly powerful when combined with network effects.
Consider:
Regulatory complexity → higher entry cost → fewer entrants → fewer users → weaker network effects → still fewer entrants
This can create a self-reinforcing cycle.
The incumbent may therefore benefit from:
- larger customer base;
- greater data;
- more compliance resources;
- established certifications;
- stronger regulatory relationships;
- greater interoperability.
12. Six Important Case Laws
The following cases do not all concern "complexity-based barriers" as a formally named doctrine. Rather, they establish principles that can be applied to analysing complexity, interoperability, regulatory exclusion and entry barriers in digital markets.
Case 1: United Brands Co v Commission
Case: United Brands Company and United Brands Continentaal BV v Commission, Case 27/76.
Principle
The European Court of Justice examined market power and barriers to effective competitive entry.
The case is important because it demonstrates that dominance analysis cannot be confined to the existence of theoretical alternatives. The practical structure of the market and the ability of competitors to enter and compete effectively matter.
Relevance to digital regulation
A digital incumbent may argue:
"Nothing legally prevents competitors from entering."
The United Brands approach encourages examination of actual competitive conditions, including structural and economic barriers.
In digital markets, those barriers may include:
- compliance costs;
- technical complexity;
- data advantages;
- switching costs;
- interoperability restrictions.
13. Case 2: Hoffmann-La Roche v Commission
Case: Hoffmann-La Roche & Co AG v Commission, Case 85/76.
Principle
The Court provided the classic formulation of dominance as a position of economic strength enabling an undertaking to behave to an appreciable extent independently of competitors, customers and consumers.
Relevance
Complexity can strengthen such economic independence.
An incumbent may possess:
- regulatory expertise;
- technical infrastructure;
- compliance systems;
- proprietary standards;
- accumulated data.
A competitor may technically be able to enter but lack the infrastructure necessary to compete effectively.
Thus complexity can contribute to the economic strength supporting dominance.
14. Case 3: Commercial Solvents
Case: Istituto Chemioterapico Italiano S.p.A. and Commercial Solvents Corporation v Commission, Joined Cases 6/73 and 7/73.
Principle
The Court recognised that a dominant undertaking controlling an important input could not necessarily exploit that position to eliminate downstream competition.
Digital relevance
This is particularly relevant to digital infrastructure.
Suppose a dominant undertaking controls:
- an authentication service;
- cloud infrastructure;
- a payment interface;
- a critical API;
- a data-access mechanism.
If competing downstream firms depend upon that input, deliberately increasing technical or compliance complexity may make downstream entry difficult.
The legal issue becomes whether the dominant firm is using control over an upstream input to restrict downstream competition.
15. Case 4: Bronner
Case: Oscar Bronner GmbH & Co KG v Mediaprint, Case C-7/97.
Principle
The Court established stringent conditions for treating refusal of access to infrastructure as an abuse of dominance.
Among other things, the infrastructure must be indispensable in the relevant sense and duplication must not be realistically feasible.
Importance for digital markets
This case is highly relevant to digital infrastructure complexity.
A competitor might argue that access to:
- an API;
- a platform;
- an authentication system;
- cloud infrastructure;
- a digital network
is indispensable.
But Bronner shows that competition law does not automatically require dominant firms to provide competitors with access to every infrastructure or system.
The entrant must establish the necessary conditions for an access obligation.
16. Case 5: IMS Health
Case: IMS Health GmbH & Co OHG v NDC Health GmbH & Co KG, Case C-418/01.
Principle
The Court considered whether refusal to license intellectual property could constitute an abuse where access to the protected material was indispensable for competition.
The case developed the exceptional circumstances doctrine associated with refusal to license intellectual property.
Digital relevance
Digital regulation often operates through:
- technical standards;
- proprietary interfaces;
- data structures;
- interoperability specifications;
- software architectures.
If an incumbent controls a technically necessary interface or standard, complexity may become a mechanism through which market access is restricted.
The IMS Health framework reminds courts that access obligations must remain exceptional and legally justified.
17. Case 6: Microsoft v Commission
Case: Microsoft Corp. v Commission, Case T-201/04.
Principle
The General Court upheld major elements of the Commission's finding that Microsoft had abused its dominant position, particularly concerning interoperability information and tying.
The interoperability issue is particularly important.
Relevance to complexity-based barriers
Microsoft illustrates how control over a dominant technological ecosystem can affect competitors' ability to develop interoperable products.
A rival might formally be free to develop a competing product, but without necessary interoperability information its product may not compete effectively.
This is closely analogous to modern digital ecosystems where:
- API access;
- interoperability;
- technical documentation;
- authentication;
- compatibility requirements
can determine effective market entry.
18. Case 7: Slovak Telekom
Case: Slovak Telekom a.s. v Commission, Joined Cases C-165/19 P and C-165/19 P? [and related proceedings].
Principle
The case concerned exclusionary conduct involving access to telecommunications infrastructure and conditions imposed on competitors.
The Court's analysis is significant for understanding how access conditions and technical arrangements can affect downstream competition.
Digital-market significance
Telecommunications markets demonstrate the interaction between:
- regulation;
- infrastructure;
- network effects;
- access obligations;
- technical compatibility.
An incumbent can potentially create barriers not by formally refusing access but through conditions attached to access.
19. Case 8: Google Shopping
Case: Google and Alphabet v Commission, Case T-612/17.
Principle
The General Court upheld the Commission's finding concerning Google's treatment of comparison-shopping services in its general search results.
Relevance to complexity
The case demonstrates how control over a major digital gateway can affect competitors' ability to reach users.
Digital entry may therefore depend not merely upon creating a competing service but upon obtaining effective access to:
- user attention;
- ranking systems;
- distribution channels;
- traffic;
- interoperability.
The broader lesson is that gateway control can transform technical or operational complexity into an effective competitive barrier.
20. Synthesis of the Case Law
The cases collectively support several propositions:
| Competition issue | Relevant case-law principle |
|---|---|
| Practical rather than merely theoretical competition | United Brands |
| Economic strength and barriers | Hoffmann-La Roche |
| Control over important inputs | Commercial Solvents |
| Indispensable infrastructure | Bronner |
| Access to protected technical/intellectual assets | IMS Health |
| Interoperability | Microsoft |
| Infrastructure access conditions | Slovak Telekom |
| Digital gateway control | Google Shopping |
21. Regulatory Complexity as an Entry-Cost Multiplier
One of the most important analytical concepts is the entry-cost multiplier.
Suppose an entrant incurs:
- ₹10 million licensing cost;
- ₹5 million cybersecurity compliance;
- ₹8 million interoperability certification;
- ₹12 million technical integration;
- ₹15 million data-governance infrastructure.
The individual requirements may each be defensible.
But the aggregate cost is:
₹50 million before effective market entry.
An incumbent that already possesses those systems does not face the same incremental cost.
Consequently, regulation may unintentionally create asymmetric fixed costs.
22. Regulatory Asymmetry
A particularly important issue is whether the regulatory burden is symmetrical.
Consider:
Incumbent
Existing:
- licence;
- compliance department;
- audit system;
- security certification;
- infrastructure;
- data architecture.
Entrant
Must build everything from zero.
Even if the law formally treats both firms identically, the economic effect can be asymmetric.
Competition authorities should therefore examine:
- absolute compliance cost;
- cost relative to turnover;
- time required;
- access to certification;
- availability of technical information;
- interoperability;
- incumbent economies of scale.
23. Complexity and Switching Costs
Complex regulatory architecture can also increase switching costs.
Suppose customers want to move from Platform A to Platform B.
Migration may require:
- data conversion;
- regulatory re-verification;
- security certification;
- API changes;
- identity verification;
- contractual amendments;
- compliance revalidation.
The customer may therefore remain with the incumbent even if a rival offers a better service.
This can produce:
complexity → switching cost → customer lock-in → weaker entry → greater incumbent power.
24. Complexity and Essential-Facility Analysis
The essential-facilities doctrine may become relevant where complexity effectively prevents duplication.
For example, a digital infrastructure may be extremely difficult to replicate because it requires:
- nationwide network coverage;
- huge datasets;
- regulatory certification;
- interoperability with thousands of institutions;
- substantial security infrastructure.
However, the Bronner and IMS Health cases demonstrate that competition law must be cautious before imposing mandatory access.
The crucial question is whether the infrastructure is genuinely indispensable and whether refusal or restriction satisfies the applicable abuse-of-dominance test.
25. Complexity Through Private Standards
Not all barriers originate with governments.
Private platforms can create complexity through:
- technical certification;
- developer requirements;
- API documentation;
- security reviews;
- platform policies;
- data-format restrictions;
- proprietary authentication.
This is particularly important where a dominant platform effectively establishes the technical rules governing an ecosystem.
Private standard-setting can therefore function as a form of quasi-regulation.
26. Complexity and Algorithmic Markets
AI markets create additional complexity because entry may require compliance with overlapping regimes.
An AI provider may need to address:
- data protection;
- cybersecurity;
- copyright;
- consumer protection;
- AI governance;
- sector-specific regulation;
- model safety;
- transparency;
- auditability.
A large incumbent may possess the personnel and infrastructure to satisfy these obligations.
A small entrant may not.
This creates a possible regulatory economies-of-scale effect.
27. Complexity-Based Barriers and Article 102 TFEU
Under Article 102 TFEU, complexity becomes relevant particularly where a dominant undertaking:
- refuses necessary access;
- imposes discriminatory access conditions;
- degrades interoperability;
- uses technical restrictions to exclude rivals;
- ties access to unrelated products;
- imposes unfair or discriminatory conditions;
- manipulates technical standards.
The presence of complexity alone does not establish an infringement.
The competition analysis must establish:
- relevant market;
- dominance;
- conduct;
- foreclosure or other competitive harm;
- causal relationship;
- objective justification where applicable.
28. Complexity-Based Barriers and Merger Control
Complexity can also matter in merger review.
A merger between two digital infrastructure providers may combine:
- datasets;
- APIs;
- cloud infrastructure;
- authentication;
- certification;
- distribution.
The resulting firm could potentially increase complexity for rivals.
Authorities may therefore examine whether the transaction would create:
- increased interoperability barriers;
- higher switching costs;
- increased dependency;
- reduced access;
- technical foreclosure.
29. Possible Competition Remedies
Where complexity contributes to competitive foreclosure, possible remedies could include:
1. Interoperability obligations
Require technical compatibility with competing services.
2. API access
Provide rivals with reasonable technical access.
3. Data portability
Allow users to transfer relevant data.
4. Standardisation
Replace unnecessarily fragmented technical requirements with common standards.
5. Transparent certification
Publish objective and non-discriminatory certification criteria.
6. Time limits
Prevent indefinite regulatory or technical approval processes.
7. Non-discrimination
Require equivalent treatment of comparable competitors.
8. Separation
In exceptional circumstances, structural separation may be considered.
30. Safeguards Against Over-Enforcement
Competition authorities should not automatically treat regulatory complexity as unlawful.
A useful framework is:
Complexity
↓
Legitimate regulatory objective?
↓
Necessary and proportionate?
↓
Applied equally?
↓
Incumbent-controlled component?
↓
Can entrants reasonably replicate or satisfy it?
↓
Does complexity materially restrict effective competition?
↓
Is there objective justification?
This avoids converting ordinary regulation into a competition-law violation.
31. Hypothetical Example: Digital Payments
Imagine a dominant digital-payment platform controls a widely used payment ecosystem.
A new competitor must obtain:
- regulatory authorisation;
- security certification;
- API approval;
- network access;
- fraud-monitoring certification;
- identity integration.
The incumbent already has all these capabilities.
If the incumbent merely complies with neutral regulation, there may be no competition-law problem.
But suppose the incumbent additionally:
- delays API certification for rivals;
- changes technical specifications without notice;
- refuses necessary interoperability information;
- imposes discriminatory authentication requirements.
The regulatory complexity then becomes potentially relevant to exclusionary conduct.
32. Hypothetical Example: AI Compliance Platforms
Assume a regulated industry requires AI systems to satisfy:
- explainability;
- auditability;
- cybersecurity;
- data governance;
- model-risk requirements.
A dominant AI provider already has a large compliance infrastructure.
A small competitor must spend a disproportionate amount of capital developing equivalent systems.
This alone does not establish anticompetitive conduct.
But if the dominant firm also controls the certification ecosystem and makes rival certification unnecessarily difficult, the combination of regulatory complexity + control over certification could raise competition concerns.
33. Complexity and Dynamic Competition
Entry barriers should not be measured only at a single point in time.
Digital markets evolve rapidly.
A barrier that appears modest today may become significant because:
- standards become more sophisticated;
- compliance obligations accumulate;
- incumbent datasets grow;
- network effects strengthen;
- interoperability becomes more difficult;
- customers become more locked in.
Therefore competition authorities may need to assess dynamic entry conditions.
34. Key Legal Tests
When analysing complexity-based entry barriers, the following questions are useful:
Market structure
- Who controls the relevant infrastructure?
- Are network effects significant?
- Is the market concentrated?
Regulatory structure
- How many approvals are required?
- Are they objectively necessary?
- Are they duplicative?
Technical structure
- Are APIs open?
- Are standards interoperable?
- Can rivals obtain technical information?
Economic structure
- What are fixed entry costs?
- Can entrants achieve economies of scale?
- How long before entry becomes commercially viable?
Conduct
- Is the incumbent deliberately increasing complexity?
- Are rivals treated differently?
- Is access delayed or degraded?
Justification
- Is the restriction necessary for security?
- Is it required for privacy?
- Is there a less restrictive alternative?
35. Conclusion
Complexity-based barriers to entry represent an increasingly important competition-law issue in regulated digital markets. They differ from traditional legal barriers because exclusion may arise not from an express prohibition but from the cumulative interaction of regulation, technology, infrastructure, data, interoperability and compliance requirements.
The central distinction is between:
legitimate complexity necessary to protect public interests
and
unnecessary or strategically imposed complexity that materially restricts effective competition.
The jurisprudence of United Brands, Hoffmann-La Roche, Commercial Solvents, Bronner, IMS Health, Microsoft, Slovak Telekom and Google Shopping provides useful foundations for analysing these problems.
The emerging competition-law challenge is therefore not simply whether entry is legally permitted, but whether a technically and legally permissible entrant can actually achieve effective competitive access to the digital ecosystem.

comments