Complexity-Based Barriers To Entry In Regulated Digital Markets .

Complexity-Based Barriers to Entry in Regulated Digital Markets

1. Introduction

Complexity-based barriers to entry arise where a new undertaking is technically, legally, economically, or institutionally capable of entering a digital market in principle, but faces substantial difficulty because the market requires compliance with a complicated combination of regulatory obligations, technical standards, interoperability requirements, certification procedures, data-access rules, security controls, audit requirements, licensing conditions, and institutional approvals.

In regulated digital markets, complexity can therefore become a form of entry barrier even without an explicit prohibition on entry. The important competition-law question is whether the complexity reflects legitimate regulatory objectives—such as privacy, cybersecurity, consumer protection and financial stability—or whether incumbent firms can exploit or reinforce complexity to foreclose competitors.

The issue is particularly important in:

  • digital payments and fintech;
  • telecommunications and 5G;
  • cloud computing;
  • digital identity;
  • health-data platforms;
  • app stores and digital ecosystems;
  • online advertising;
  • AI and algorithmic services;
  • regulated marketplaces; and
  • public-sector digital infrastructure.

2. Meaning of Complexity-Based Entry Barriers

A conventional entry barrier might be:

A legal rule preventing a new undertaking from entering a market.

A complexity-based barrier is subtler:

The cumulative difficulty of satisfying multiple technical, regulatory, contractual and interoperability requirements can make effective entry disproportionately costly, slow or uncertain.

For example, suppose a new fintech company must simultaneously obtain:

  1. a regulatory licence;
  2. cybersecurity certification;
  3. data-protection approval;
  4. access to a payment network;
  5. interoperability certification;
  6. API credentials;
  7. audit certification;
  8. consumer-protection compliance;
  9. fraud-monitoring capability; and
  10. access to trusted digital identity infrastructure.

None of these requirements may individually exclude the entrant. Their cumulative interaction may nevertheless make entry commercially impracticable.

3. Complexity as a Competition-Law Concept

Complexity becomes relevant to competition law when it affects one or more of the following:

A. Cost of entry

The entrant must spend significantly more resources before generating revenue.

B. Time to market

Regulatory and technical approval may take substantially longer than the incumbent's established compliance process.

C. Uncertainty

An entrant may not know whether its technology will satisfy a regulator, platform, certification body or interoperability standard.

D. Access to essential inputs

Complex requirements may be controlled by an incumbent that supplies:

  • APIs;
  • authentication;
  • cloud infrastructure;
  • payment rails;
  • data;
  • app distribution;
  • identity verification;
  • interoperability interfaces.

E. Economies of scale

An incumbent may spread compliance costs over millions of users, while a new entrant must bear essentially fixed costs with a much smaller customer base.

4. Regulatory Complexity vs Anticompetitive Complexity

This distinction is fundamental.

Legitimate regulatory complexity

Regulation may legitimately impose substantial requirements because the market involves:

  • systemic financial risk;
  • sensitive personal data;
  • cybersecurity;
  • national infrastructure;
  • health information;
  • children's safety;
  • consumer protection;
  • AI safety;
  • telecommunications security.

Competition law should not treat every costly regulation as anticompetitive.

Potentially problematic complexity

Competition concerns arise where complexity is:

  • unnecessary;
  • discriminatory;
  • selectively enforced;
  • manipulated by incumbents;
  • unnecessarily incompatible with rival technologies;
  • accompanied by denial of interoperability;
  • combined with refusal to provide necessary technical information; or
  • designed or applied in a manner that disproportionately disadvantages entrants.

5. Principal Forms of Complexity-Based Barriers

5.1 Licensing Complexity

A regulated digital market may require multiple licences.

For example, a digital financial platform could need separate authorisation for:

  • payment services;
  • lending;
  • electronic money;
  • data processing;
  • cybersecurity;
  • digital identity;
  • cross-border services.

Where an incumbent already possesses the necessary regulatory infrastructure, the entrant faces a significantly greater fixed cost.

Competition concern

The question is not simply whether licensing is lawful. The question is whether licensing architecture creates unnecessary competitive exclusion.

6. Technical Complexity

Digital markets frequently require compliance with complicated technical standards.

Examples include:

  • API specifications;
  • encryption standards;
  • authentication protocols;
  • data formats;
  • interoperability requirements;
  • cloud-security certification;
  • identity protocols;
  • network standards.

A technically neutral rule can nevertheless become exclusionary if access to the underlying technical standard is controlled by an incumbent.

7. Interoperability Complexity

Interoperability is particularly important in digital ecosystems.

An entrant may theoretically offer a competing service but remain unable to compete effectively because it cannot interact with:

  • the dominant platform;
  • payment systems;
  • operating systems;
  • identity systems;
  • cloud infrastructure;
  • communications networks.

Thus:

formal entry ≠ effective entry.

A market may have dozens of nominal competitors while interoperability restrictions make meaningful competition extremely difficult.

8. Data-Access Complexity

Data can itself become an entry barrier.

A new undertaking may require:

  • historical transaction data;
  • consumer-consent information;
  • behavioural data;
  • technical logs;
  • identity information;
  • interoperability data;
  • performance information.

Where an incumbent possesses accumulated datasets and the entrant cannot reproduce them at reasonable cost, the incumbent may possess a structural advantage.

The competition-law analysis becomes particularly important where access to data is combined with:

  • network effects;
  • economies of scope;
  • switching costs; and
  • regulatory obligations.

9. Certification and Audit Complexity

Regulated digital markets increasingly require:

  • algorithmic audits;
  • cybersecurity audits;
  • financial audits;
  • privacy impact assessments;
  • model validation;
  • penetration testing;
  • conformity assessments.

These may be justified by legitimate regulatory concerns.

However, if certification requirements are excessively fragmented, unpredictable or controlled by bodies closely connected with incumbent firms, they may increase entry costs.

10. Algorithmic Complexity

AI-driven markets create a new category of entry barrier.

An entrant may need to demonstrate:

  • model explainability;
  • safety;
  • accuracy;
  • robustness;
  • bias testing;
  • cybersecurity;
  • auditability;
  • provenance;
  • data governance.

An incumbent with an established compliance team can satisfy these obligations relatively cheaply.

A smaller entrant may face a much higher compliance cost per unit of output.

Consequently:

Regulatory compliance can generate economies of scale that reinforce incumbent market power.

11. Network Effects and Complexity

Complexity becomes particularly powerful when combined with network effects.

Consider:

Regulatory complexity → higher entry cost → fewer entrants → fewer users → weaker network effects → still fewer entrants

This can create a self-reinforcing cycle.

The incumbent may therefore benefit from:

  • larger customer base;
  • greater data;
  • more compliance resources;
  • established certifications;
  • stronger regulatory relationships;
  • greater interoperability.

12. Six Important Case Laws

The following cases do not all concern "complexity-based barriers" as a formally named doctrine. Rather, they establish principles that can be applied to analysing complexity, interoperability, regulatory exclusion and entry barriers in digital markets.

Case 1: United Brands Co v Commission

Case: United Brands Company and United Brands Continentaal BV v Commission, Case 27/76.

Principle

The European Court of Justice examined market power and barriers to effective competitive entry.

The case is important because it demonstrates that dominance analysis cannot be confined to the existence of theoretical alternatives. The practical structure of the market and the ability of competitors to enter and compete effectively matter.

Relevance to digital regulation

A digital incumbent may argue:

"Nothing legally prevents competitors from entering."

The United Brands approach encourages examination of actual competitive conditions, including structural and economic barriers.

In digital markets, those barriers may include:

  • compliance costs;
  • technical complexity;
  • data advantages;
  • switching costs;
  • interoperability restrictions.

13. Case 2: Hoffmann-La Roche v Commission

Case: Hoffmann-La Roche & Co AG v Commission, Case 85/76.

Principle

The Court provided the classic formulation of dominance as a position of economic strength enabling an undertaking to behave to an appreciable extent independently of competitors, customers and consumers.

Relevance

Complexity can strengthen such economic independence.

An incumbent may possess:

  • regulatory expertise;
  • technical infrastructure;
  • compliance systems;
  • proprietary standards;
  • accumulated data.

A competitor may technically be able to enter but lack the infrastructure necessary to compete effectively.

Thus complexity can contribute to the economic strength supporting dominance.

14. Case 3: Commercial Solvents

Case: Istituto Chemioterapico Italiano S.p.A. and Commercial Solvents Corporation v Commission, Joined Cases 6/73 and 7/73.

Principle

The Court recognised that a dominant undertaking controlling an important input could not necessarily exploit that position to eliminate downstream competition.

Digital relevance

This is particularly relevant to digital infrastructure.

Suppose a dominant undertaking controls:

  • an authentication service;
  • cloud infrastructure;
  • a payment interface;
  • a critical API;
  • a data-access mechanism.

If competing downstream firms depend upon that input, deliberately increasing technical or compliance complexity may make downstream entry difficult.

The legal issue becomes whether the dominant firm is using control over an upstream input to restrict downstream competition.

15. Case 4: Bronner

Case: Oscar Bronner GmbH & Co KG v Mediaprint, Case C-7/97.

Principle

The Court established stringent conditions for treating refusal of access to infrastructure as an abuse of dominance.

Among other things, the infrastructure must be indispensable in the relevant sense and duplication must not be realistically feasible.

Importance for digital markets

This case is highly relevant to digital infrastructure complexity.

A competitor might argue that access to:

  • an API;
  • a platform;
  • an authentication system;
  • cloud infrastructure;
  • a digital network

is indispensable.

But Bronner shows that competition law does not automatically require dominant firms to provide competitors with access to every infrastructure or system.

The entrant must establish the necessary conditions for an access obligation.

16. Case 5: IMS Health

Case: IMS Health GmbH & Co OHG v NDC Health GmbH & Co KG, Case C-418/01.

Principle

The Court considered whether refusal to license intellectual property could constitute an abuse where access to the protected material was indispensable for competition.

The case developed the exceptional circumstances doctrine associated with refusal to license intellectual property.

Digital relevance

Digital regulation often operates through:

  • technical standards;
  • proprietary interfaces;
  • data structures;
  • interoperability specifications;
  • software architectures.

If an incumbent controls a technically necessary interface or standard, complexity may become a mechanism through which market access is restricted.

The IMS Health framework reminds courts that access obligations must remain exceptional and legally justified.

17. Case 6: Microsoft v Commission

Case: Microsoft Corp. v Commission, Case T-201/04.

Principle

The General Court upheld major elements of the Commission's finding that Microsoft had abused its dominant position, particularly concerning interoperability information and tying.

The interoperability issue is particularly important.

Relevance to complexity-based barriers

Microsoft illustrates how control over a dominant technological ecosystem can affect competitors' ability to develop interoperable products.

A rival might formally be free to develop a competing product, but without necessary interoperability information its product may not compete effectively.

This is closely analogous to modern digital ecosystems where:

  • API access;
  • interoperability;
  • technical documentation;
  • authentication;
  • compatibility requirements

can determine effective market entry.

18. Case 7: Slovak Telekom

Case: Slovak Telekom a.s. v Commission, Joined Cases C-165/19 P and C-165/19 P? [and related proceedings].

Principle

The case concerned exclusionary conduct involving access to telecommunications infrastructure and conditions imposed on competitors.

The Court's analysis is significant for understanding how access conditions and technical arrangements can affect downstream competition.

Digital-market significance

Telecommunications markets demonstrate the interaction between:

  • regulation;
  • infrastructure;
  • network effects;
  • access obligations;
  • technical compatibility.

An incumbent can potentially create barriers not by formally refusing access but through conditions attached to access.

19. Case 8: Google Shopping

Case: Google and Alphabet v Commission, Case T-612/17.

Principle

The General Court upheld the Commission's finding concerning Google's treatment of comparison-shopping services in its general search results.

Relevance to complexity

The case demonstrates how control over a major digital gateway can affect competitors' ability to reach users.

Digital entry may therefore depend not merely upon creating a competing service but upon obtaining effective access to:

  • user attention;
  • ranking systems;
  • distribution channels;
  • traffic;
  • interoperability.

The broader lesson is that gateway control can transform technical or operational complexity into an effective competitive barrier.

20. Synthesis of the Case Law

The cases collectively support several propositions:

Competition issueRelevant case-law principle
Practical rather than merely theoretical competitionUnited Brands
Economic strength and barriersHoffmann-La Roche
Control over important inputsCommercial Solvents
Indispensable infrastructureBronner
Access to protected technical/intellectual assetsIMS Health
InteroperabilityMicrosoft
Infrastructure access conditionsSlovak Telekom
Digital gateway controlGoogle Shopping

21. Regulatory Complexity as an Entry-Cost Multiplier

One of the most important analytical concepts is the entry-cost multiplier.

Suppose an entrant incurs:

  • ₹10 million licensing cost;
  • ₹5 million cybersecurity compliance;
  • ₹8 million interoperability certification;
  • ₹12 million technical integration;
  • ₹15 million data-governance infrastructure.

The individual requirements may each be defensible.

But the aggregate cost is:

₹50 million before effective market entry.

An incumbent that already possesses those systems does not face the same incremental cost.

Consequently, regulation may unintentionally create asymmetric fixed costs.

22. Regulatory Asymmetry

A particularly important issue is whether the regulatory burden is symmetrical.

Consider:

Incumbent

Existing:

  • licence;
  • compliance department;
  • audit system;
  • security certification;
  • infrastructure;
  • data architecture.

Entrant

Must build everything from zero.

Even if the law formally treats both firms identically, the economic effect can be asymmetric.

Competition authorities should therefore examine:

  1. absolute compliance cost;
  2. cost relative to turnover;
  3. time required;
  4. access to certification;
  5. availability of technical information;
  6. interoperability;
  7. incumbent economies of scale.

23. Complexity and Switching Costs

Complex regulatory architecture can also increase switching costs.

Suppose customers want to move from Platform A to Platform B.

Migration may require:

  • data conversion;
  • regulatory re-verification;
  • security certification;
  • API changes;
  • identity verification;
  • contractual amendments;
  • compliance revalidation.

The customer may therefore remain with the incumbent even if a rival offers a better service.

This can produce:

complexity → switching cost → customer lock-in → weaker entry → greater incumbent power.

24. Complexity and Essential-Facility Analysis

The essential-facilities doctrine may become relevant where complexity effectively prevents duplication.

For example, a digital infrastructure may be extremely difficult to replicate because it requires:

  • nationwide network coverage;
  • huge datasets;
  • regulatory certification;
  • interoperability with thousands of institutions;
  • substantial security infrastructure.

However, the Bronner and IMS Health cases demonstrate that competition law must be cautious before imposing mandatory access.

The crucial question is whether the infrastructure is genuinely indispensable and whether refusal or restriction satisfies the applicable abuse-of-dominance test.

25. Complexity Through Private Standards

Not all barriers originate with governments.

Private platforms can create complexity through:

  • technical certification;
  • developer requirements;
  • API documentation;
  • security reviews;
  • platform policies;
  • data-format restrictions;
  • proprietary authentication.

This is particularly important where a dominant platform effectively establishes the technical rules governing an ecosystem.

Private standard-setting can therefore function as a form of quasi-regulation.

26. Complexity and Algorithmic Markets

AI markets create additional complexity because entry may require compliance with overlapping regimes.

An AI provider may need to address:

  • data protection;
  • cybersecurity;
  • copyright;
  • consumer protection;
  • AI governance;
  • sector-specific regulation;
  • model safety;
  • transparency;
  • auditability.

A large incumbent may possess the personnel and infrastructure to satisfy these obligations.

A small entrant may not.

This creates a possible regulatory economies-of-scale effect.

27. Complexity-Based Barriers and Article 102 TFEU

Under Article 102 TFEU, complexity becomes relevant particularly where a dominant undertaking:

  • refuses necessary access;
  • imposes discriminatory access conditions;
  • degrades interoperability;
  • uses technical restrictions to exclude rivals;
  • ties access to unrelated products;
  • imposes unfair or discriminatory conditions;
  • manipulates technical standards.

The presence of complexity alone does not establish an infringement.

The competition analysis must establish:

  1. relevant market;
  2. dominance;
  3. conduct;
  4. foreclosure or other competitive harm;
  5. causal relationship;
  6. objective justification where applicable.

28. Complexity-Based Barriers and Merger Control

Complexity can also matter in merger review.

A merger between two digital infrastructure providers may combine:

  • datasets;
  • APIs;
  • cloud infrastructure;
  • authentication;
  • certification;
  • distribution.

The resulting firm could potentially increase complexity for rivals.

Authorities may therefore examine whether the transaction would create:

  • increased interoperability barriers;
  • higher switching costs;
  • increased dependency;
  • reduced access;
  • technical foreclosure.

29. Possible Competition Remedies

Where complexity contributes to competitive foreclosure, possible remedies could include:

1. Interoperability obligations

Require technical compatibility with competing services.

2. API access

Provide rivals with reasonable technical access.

3. Data portability

Allow users to transfer relevant data.

4. Standardisation

Replace unnecessarily fragmented technical requirements with common standards.

5. Transparent certification

Publish objective and non-discriminatory certification criteria.

6. Time limits

Prevent indefinite regulatory or technical approval processes.

7. Non-discrimination

Require equivalent treatment of comparable competitors.

8. Separation

In exceptional circumstances, structural separation may be considered.

30. Safeguards Against Over-Enforcement

Competition authorities should not automatically treat regulatory complexity as unlawful.

A useful framework is:

Complexity

↓

Legitimate regulatory objective?

↓

Necessary and proportionate?

↓

Applied equally?

↓

Incumbent-controlled component?

↓

Can entrants reasonably replicate or satisfy it?

↓

Does complexity materially restrict effective competition?

↓

Is there objective justification?

This avoids converting ordinary regulation into a competition-law violation.

31. Hypothetical Example: Digital Payments

Imagine a dominant digital-payment platform controls a widely used payment ecosystem.

A new competitor must obtain:

  • regulatory authorisation;
  • security certification;
  • API approval;
  • network access;
  • fraud-monitoring certification;
  • identity integration.

The incumbent already has all these capabilities.

If the incumbent merely complies with neutral regulation, there may be no competition-law problem.

But suppose the incumbent additionally:

  • delays API certification for rivals;
  • changes technical specifications without notice;
  • refuses necessary interoperability information;
  • imposes discriminatory authentication requirements.

The regulatory complexity then becomes potentially relevant to exclusionary conduct.

32. Hypothetical Example: AI Compliance Platforms

Assume a regulated industry requires AI systems to satisfy:

  • explainability;
  • auditability;
  • cybersecurity;
  • data governance;
  • model-risk requirements.

A dominant AI provider already has a large compliance infrastructure.

A small competitor must spend a disproportionate amount of capital developing equivalent systems.

This alone does not establish anticompetitive conduct.

But if the dominant firm also controls the certification ecosystem and makes rival certification unnecessarily difficult, the combination of regulatory complexity + control over certification could raise competition concerns.

33. Complexity and Dynamic Competition

Entry barriers should not be measured only at a single point in time.

Digital markets evolve rapidly.

A barrier that appears modest today may become significant because:

  • standards become more sophisticated;
  • compliance obligations accumulate;
  • incumbent datasets grow;
  • network effects strengthen;
  • interoperability becomes more difficult;
  • customers become more locked in.

Therefore competition authorities may need to assess dynamic entry conditions.

34. Key Legal Tests

When analysing complexity-based entry barriers, the following questions are useful:

Market structure

  • Who controls the relevant infrastructure?
  • Are network effects significant?
  • Is the market concentrated?

Regulatory structure

  • How many approvals are required?
  • Are they objectively necessary?
  • Are they duplicative?

Technical structure

  • Are APIs open?
  • Are standards interoperable?
  • Can rivals obtain technical information?

Economic structure

  • What are fixed entry costs?
  • Can entrants achieve economies of scale?
  • How long before entry becomes commercially viable?

Conduct

  • Is the incumbent deliberately increasing complexity?
  • Are rivals treated differently?
  • Is access delayed or degraded?

Justification

  • Is the restriction necessary for security?
  • Is it required for privacy?
  • Is there a less restrictive alternative?

35. Conclusion

Complexity-based barriers to entry represent an increasingly important competition-law issue in regulated digital markets. They differ from traditional legal barriers because exclusion may arise not from an express prohibition but from the cumulative interaction of regulation, technology, infrastructure, data, interoperability and compliance requirements.

The central distinction is between:

legitimate complexity necessary to protect public interests

and

unnecessary or strategically imposed complexity that materially restricts effective competition.

The jurisprudence of United Brands, Hoffmann-La Roche, Commercial Solvents, Bronner, IMS Health, Microsoft, Slovak Telekom and Google Shopping provides useful foundations for analysing these problems.

The emerging competition-law challenge is therefore not simply whether entry is legally permitted, but whether a technically and legally permissible entrant can actually achieve effective competitive access to the digital ecosystem.

 

 

LEAVE A COMMENT