Identity-As-A-Service Monopolies And Participation Control .

Identity-As-A-Service Monopolies And Participation Control

1. Introduction

Identity-as-a-Service (IDaaS) refers to the provision of digital identity functions—authentication, identity verification, single sign-on, credential issuance, access management, fraud detection, account recovery and related identity infrastructure—as a service to businesses, governments, platforms and users.

IDaaS becomes a competition-law concern when a small number of providers acquire control over the identity infrastructure necessary for participation in digital markets. A dominant IDaaS provider may become a gatekeeper between users and competing platforms, applications, financial services, marketplaces, cloud services or public digital services.

The central competition question is therefore not merely:

Who supplies identity verification?

It is:

Can an IDaaS provider control who is able to participate in digital markets, on what terms, and through which competing platforms?

This creates a distinctive form of participation control. Unlike conventional monopoly power over a commodity, identity infrastructure can determine whether an individual, business, developer, merchant or platform is recognized as an eligible participant at all.

2. Meaning of Identity-as-a-Service Monopoly

An IDaaS monopoly exists where one undertaking, or a tightly controlled ecosystem, possesses substantial and durable market power over identity-related infrastructure and competitors cannot reasonably substitute away from it.

Potential IDaaS services include:

  • identity verification;
  • Know Your Customer (KYC);
  • authentication;
  • single sign-on;
  • biometric verification;
  • digital credentials;
  • identity APIs;
  • account recovery;
  • fraud and risk scoring;
  • device identity;
  • enterprise access management;
  • government-service authentication;
  • reputation-linked identity;
  • identity federation;
  • age verification;
  • credential portability.

A monopoly can arise through several mechanisms.

A. Network effects

The more users and businesses that rely on an identity system, the more valuable it becomes.

B. Data accumulation

The provider may accumulate:

  • authentication histories;
  • device information;
  • transaction information;
  • behavioral data;
  • fraud signals;
  • account relationships;
  • reputation information.

This can make entry increasingly difficult.

C. Switching costs

Businesses may become dependent on:

  • proprietary APIs;
  • authentication protocols;
  • stored credentials;
  • fraud models;
  • customer databases;
  • integration infrastructure.

D. Ecosystem integration

An identity provider may combine identity services with:

  • cloud computing;
  • advertising;
  • payments;
  • app stores;
  • social networks;
  • marketplaces;
  • operating systems.

E. Institutional dependence

Governments, banks or large enterprises may adopt one identity infrastructure as a de facto standard, making participation through alternative systems difficult.

3. What Is Participation Control?

Participation control occurs when an infrastructure provider can determine whether another undertaking or user can enter, remain in or effectively compete within a market.

In an IDaaS environment, participation control may operate through:

Identity verification → authentication → eligibility → access → participation

For example:

User → identity provider → verification → credential → platform access → transaction

If the identity provider controls the critical verification stage, it may effectively control the downstream market.

This produces a form of infrastructural gatekeeping.

4. Why IDaaS Is Different From Ordinary Digital Services

Identity is often an upstream input into numerous downstream markets.

An identity provider can therefore occupy a strategic position between:

individuals/businesses

and

digital platforms and services.

The same identity infrastructure may be used for:

  • banking;
  • e-commerce;
  • employment;
  • healthcare platforms;
  • government services;
  • education;
  • cloud computing;
  • social networks;
  • online marketplaces.

Consequently, exclusion from the identity layer can produce cross-market exclusion.

5. Relevant Competition-Law Theories

A. Abuse of dominance

A dominant IDaaS provider may abuse its position through:

  • refusal to supply;
  • discriminatory access;
  • excessive pricing;
  • tying;
  • bundling;
  • self-preferencing;
  • interoperability restrictions;
  • exclusionary technical standards;
  • discriminatory verification;
  • data-based foreclosure.

B. Essential-facility theory

Where an identity service is indispensable for effective participation and duplication is technically or economically impracticable, competitors may argue that access should be provided on fair terms.

However, courts generally apply essential-facility doctrines cautiously.

C. Leveraging

An IDaaS provider may use dominance in identity services to strengthen a position in:

  • cloud services;
  • advertising;
  • payments;
  • marketplaces;
  • enterprise software.

D. Tying

The provider could require customers purchasing identity verification to also use:

  • its cloud infrastructure;
  • authentication service;
  • fraud platform;
  • advertising ecosystem.

E. Discrimination

The provider might provide faster, cheaper or more accurate identity verification to affiliated businesses while imposing inferior conditions on competitors.

6. Participation Control Through Authentication

Authentication can become a competitive bottleneck.

Suppose an identity provider controls a widely adopted authentication protocol.

A competing platform may technically exist but become commercially ineffective if users cannot conveniently authenticate through it.

The competitive harm can therefore occur without an outright refusal to supply.

It can arise through:

  • degraded interoperability;
  • delayed authentication;
  • API restrictions;
  • discriminatory technical standards;
  • excessive authentication charges;
  • mandatory use of proprietary credentials.

Thus, technical compatibility can become a condition of market participation.

7. Identity Verification as a Gatekeeping Mechanism

Verification systems may determine whether:

  • a merchant can open an account;
  • a driver can access a platform;
  • a consumer can use a service;
  • a developer can access an API;
  • a business can advertise;
  • a financial institution can onboard a customer.

A dominant provider could therefore exercise verification-based exclusion.

This becomes particularly problematic where verification decisions are:

  • opaque;
  • automated;
  • difficult to appeal;
  • based on proprietary datasets;
  • impossible to reproduce independently.

8. Data-Based Identity Monopoly

Identity services generate exceptionally valuable datasets.

A dominant provider may obtain:

identity + device + location + behavior + transaction + reputation

This creates a powerful informational advantage.

Competitors may therefore face a data-entry barrier.

Even if another company can technically build an identity platform, it may lack the historical data necessary to achieve comparable:

  • fraud detection;
  • authentication accuracy;
  • risk scoring;
  • identity resolution.

The monopoly can consequently become self-reinforcing.

9. Identity Portability and Switching Costs

Competition is weakened when users cannot easily transfer identity credentials.

For example:

Provider A

→ credential
→ verification history
→ reputation
→ account relationships

may not be portable to

Provider B.

The user must therefore repeat:

  • KYC;
  • verification;
  • authentication setup;
  • reputation building;
  • credential issuance.

This creates identity switching costs.

Identity portability can consequently function as a competition remedy.

10. Self-Preferencing

An IDaaS provider that also operates downstream platforms may have incentives to favor its own services.

For example:

Identity Provider

↓
Own marketplace
Own payment service
Own cloud platform

while competing platforms receive:

  • slower verification;
  • higher fees;
  • restricted APIs;
  • reduced functionality.

This resembles traditional vertical foreclosure, but the bottleneck is identity infrastructure rather than physical distribution.

11. Relevant Case Laws

The following cases are particularly useful for analysing IDaaS monopolies and participation control, even where the underlying technology was not literally an IDaaS platform.

1. United Brands v Commission (1978)

United Brands Company v Commission, Case 27/76

The Court of Justice examined dominance and the ability of a powerful undertaking to impose conditions on trading partners.

Relevance to IDaaS

The case supports the broader principle that dominance involves the ability to behave to an appreciable extent independently of competitors, customers and consumers.

An IDaaS provider possessing substantial control over authentication or verification could potentially exercise similar independence.

Principle: Market power is not limited to traditional monopoly pricing; it concerns the ability to operate without effective competitive constraint.

2. Commercial Solvents v Commission (1974)

Commercial Solvents Corp v Commission, Joined Cases 6/73 and 7/73

The Court considered refusal to supply an important input where the dominant undertaking operated upstream and downstream.

Relevance to IDaaS

An IDaaS provider could occupy an analogous upstream position where identity verification is an important input into a downstream digital market.

If it controls access to a critical identity input and simultaneously competes downstream, refusal or restriction of access can create foreclosure concerns.

Principle: A dominant undertaking controlling an indispensable upstream input cannot necessarily use that position to eliminate downstream competition.

3. Bronner v Mediaprint (1998)

Oscar Bronner GmbH & Co KG v Mediaprint, Case C-7/97

The Court established stringent conditions for requiring a dominant undertaking to provide access to infrastructure under the essential-facilities doctrine.

The facility must, among other things, be indispensable and duplication must be impossible or excessively difficult.

Relevance to IDaaS

This is one of the most important cases for analysing identity infrastructure.

A claimant seeking access to a dominant IDaaS system would need to demonstrate more than convenience.

The identity infrastructure would need to be genuinely indispensable to effective competition.

Principle: Not every valuable infrastructure qualifies as an essential facility.

4. IMS Health v Commission (2004)

IMS Health GmbH & Co OHG v NDC Health GmbH & Co KG, Case C-418/01

The Court considered access to a protected information structure and the circumstances in which refusal to license could constitute abuse.

Relevance to IDaaS

The case is highly relevant to proprietary identity architectures, databases and identity standards.

An identity provider controlling a proprietary identity structure could potentially acquire significant leverage if competing services cannot operate effectively without access.

Principle: Exceptional circumstances can justify intervention where refusal to provide access eliminates effective competition and prevents development of products for which there is consumer demand.

12. Microsoft v Commission

5. Microsoft Corp v Commission (2007)

Microsoft Corp v Commission, Case T-201/04

The General Court upheld findings concerning Microsoft's refusal to provide interoperability information and the resulting effects on competing work-group server products.

Relevance to IDaaS

This is particularly important because identity infrastructure depends heavily on interoperability.

A dominant identity provider could theoretically restrict competitors through:

  • proprietary authentication protocols;
  • API restrictions;
  • interoperability barriers;
  • credential incompatibility;
  • federation restrictions.

The Microsoft reasoning demonstrates that control over interoperability information can become a major source of competitive power.

Principle: Interoperability restrictions may constitute exclusionary conduct where they substantially impair effective competition.

13. Google Android

6. Google Android (2022)

Google and Alphabet v Commission, Case T-604/18

The General Court examined Google's conduct concerning Android and the relationship between operating systems, app stores and search services.

Relevance to IDaaS

The case is highly relevant to ecosystem-based identity control.

A major digital ecosystem may use one layer of infrastructure to reinforce another.

For example:

Operating system

→ authentication
→ identity credential
→ app access
→ payment
→ advertising.

An IDaaS provider could similarly leverage identity infrastructure into adjacent digital markets.

Principle: Ecosystem power and contractual restrictions can reinforce dominance across interconnected digital services.

14. Google Shopping

7. Google and Alphabet v Commission — Google Shopping (2024)

The Google Shopping litigation concerns Google's treatment of competing comparison-shopping services and the use of its dominant search infrastructure.

Relevance to IDaaS

The broader significance lies in leveraging infrastructure power into adjacent markets.

Identity infrastructure may similarly become an upstream gateway through which competing services must reach users.

If the dominant identity provider systematically favors its own downstream services, the conduct could resemble infrastructure-based self-preferencing.

Principle: Dominance in an upstream digital gateway can materially affect competition in downstream markets.

15. Facebook/Meta Data and Platform Power

8. Bundeskartellamt — Facebook (2019)

The German competition authority's Facebook decision examined Facebook's combination of user data from different sources and the relationship between data collection and market power.

Relevance to IDaaS

The decision is particularly important for identity monopolies because identity systems are fundamentally data-intensive infrastructures.

Combining:

  • authentication data;
  • platform activity;
  • third-party data;
  • behavioral information;

can strengthen an identity provider's market position.

The case illustrates how data accumulation can interact with dominance and competitive conditions.

Principle: Data practices can become relevant to competition law where they reinforce market power and reduce competitive constraints.

16. Google/DoubleClick and Data-Driven Gatekeeping

Digital competition cases involving Google also demonstrate that control over multiple layers of digital infrastructure can create reinforcing advantages.

For IDaaS, the equivalent structure might be:

identity → authentication → data → advertising → platform access.

The competitive concern is therefore not necessarily one identity service in isolation, but the vertical accumulation of control over identity, data and downstream participation.

17. Theoretical Model of IDaaS Monopoly

The structure can be represented as:

Identity Infrastructure

↓

Verification

↓

Authentication

↓

Credential

↓

Platform Access

↓

Market Participation

↓

Economic Activity

If one undertaking controls several layers, it may possess a participation bottleneck.

18. Forms of Participation Control

1. Access control

Determining who can enter a digital platform.

2. Authentication control

Determining whose credentials are recognized.

3. Verification control

Determining who is considered trustworthy.

4. Reputation control

Determining whether previous conduct affects future access.

5. Credential control

Determining which identity credentials are technically accepted.

6. Data control

Determining who can obtain identity-related information.

7. Interoperability control

Determining whether competing identity systems can communicate.

8. Pricing control

Determining the cost of identity-based access.

19. Competition Risks

A. Exclusion of competitors

Competitors dependent upon the identity infrastructure may be denied effective access.

B. Raising rivals' costs

A dominant provider can impose:

  • higher API charges;
  • additional verification requirements;
  • technical integration costs.

C. Discriminatory access

Affiliates may receive superior treatment.

D. Lock-in

Users may remain with one ecosystem because changing identity providers is costly.

E. Data foreclosure

Competitors may lack equivalent identity datasets.

F. Innovation foreclosure

Start-ups may be unable to experiment with alternative identity architectures.

G. Market-wide dependency

Multiple downstream markets may become dependent on a single identity provider.

20. Identity-as-Infrastructure Theory

Traditional competition analysis often asks:

Who controls the product?

Digital identity raises a different question:

Who controls the ability to participate?

This is significant because identity may function as an infrastructure layer rather than merely a commercial product.

A dominant identity provider can therefore exercise power through:

recognition → authentication → authorization → participation.

This gives identity infrastructure a quasi-gatekeeping character.

21. Essential Facility Analysis

An IDaaS system is more likely to raise essential-facility concerns where:

  1. it is indispensable;
  2. effective duplication is impracticable;
  3. access is technically feasible;
  4. refusal eliminates effective competition;
  5. there is no objective justification for refusal.

The Bronner and IMS Health principles remain particularly important.

However, courts should distinguish between:

genuine indispensability

and

mere commercial convenience.

A competitor should not automatically receive access merely because integration with the dominant IDaaS system is cheaper or easier.

22. Interoperability as a Competition Remedy

Possible remedies include:

  • open authentication standards;
  • API access;
  • credential portability;
  • data portability;
  • interoperability obligations;
  • non-discriminatory access;
  • transparent verification criteria;
  • independent appeals;
  • separation of identity and downstream services.

Interoperability can be especially important because it allows:

Provider A identity → Provider B service

without forcing users to abandon their existing identity infrastructure.

23. Structural Separation

Where behavioral remedies are inadequate, regulators might consider structural separation.

For example:

Identity Infrastructure Company

separated from

Advertising Platform

or

Identity Verification Company

separated from

Marketplace Platform.

The objective would be to prevent identity infrastructure from becoming a tool for downstream foreclosure.

24. The Role of Data Portability

Data portability can reduce identity lock-in.

A meaningful portability regime might allow users or businesses to transfer:

  • verified identity information;
  • credentials;
  • authentication history;
  • reputation;
  • permissions;
  • relevant verification records.

Without portability, switching identity providers may require complete re-verification.

That can make the dominant provider's position self-reinforcing.

25. Consumer and Business Effects

Consumers

Potential harms include:

  • exclusion from services;
  • discriminatory verification;
  • repeated KYC;
  • excessive switching costs;
  • loss of privacy;
  • inability to challenge automated decisions.

Businesses

Potential harms include:

  • higher authentication costs;
  • dependence on one provider;
  • reduced bargaining power;
  • inability to migrate identity infrastructure;
  • discriminatory API access.

Competitors

Potential harms include:

  • foreclosure;
  • increased entry costs;
  • data disadvantages;
  • interoperability barriers;
  • reduced innovation.

26. A Hypothetical Example

Assume IdentityCorp controls 80% of enterprise identity verification.

It also owns a major cloud marketplace.

IdentityCorp requires businesses using its verification API to use its cloud-hosted authentication system.

It then:

  1. gives its own marketplace preferential verification;
  2. charges competing marketplaces higher API fees;
  3. prevents credentials from being transferred;
  4. refuses interoperability with rival identity providers;
  5. uses identity data to improve its own fraud-detection system.

The competitive theory would involve:

dominance → identity bottleneck → interoperability restriction → higher rival costs → downstream foreclosure → reinforced dominance.

Possible theories include:

  • refusal to deal;
  • tying;
  • discriminatory access;
  • self-preferencing;
  • leveraging;
  • interoperability foreclosure.

27. Relationship With Digital Gatekeeper Regulation

Modern digital competition regulation increasingly recognizes that certain platforms function as gatekeepers.

Identity infrastructure could become a particularly powerful form of gatekeeping because it sits at the point where:

person/entity → authentication → authorization → participation

intersects.

The competition-law significance therefore extends beyond price.

Relevant competitive parameters include:

  • access;
  • interoperability;
  • portability;
  • privacy;
  • quality;
  • innovation;
  • neutrality;
  • transparency.

28. Six Core Case-Law Principles for Examination

CaseCore PrincipleIDaaS Relevance
United Brands v CommissionDominance and independent market conductIdentity-provider market power
Commercial SolventsUpstream control and downstream foreclosureIdentity as critical input
BronnerStrict essential-facility testIdentity infrastructure access
IMS HealthExceptional refusal-to-license circumstancesProprietary identity architectures/data
MicrosoftInteroperability and exclusionAuthentication/API interoperability
Google AndroidEcosystem leverage and contractual restrictionsIdentity ecosystem gatekeeping
Google ShoppingUpstream digital infrastructure and downstream foreclosureIdentity gateway/self-preferencing
Facebook/BundeskartellamtData accumulation and market powerIdentity-data concentration

29. Conclusion

Identity-as-a-Service monopolies represent a potentially new form of infrastructural market power. Their importance lies not simply in controlling identity verification but in controlling the conditions under which individuals and businesses can participate in digital markets.

The strongest competition concerns arise where an IDaaS provider simultaneously controls:

identity + authentication + data + interoperability + downstream services.

At that point, identity ceases to be merely a technical service and can become a market-access infrastructure.

The central legal distinction is therefore between ordinary identity-service dominance and participation control. The latter exists where control over identity infrastructure allows an undertaking to determine, directly or indirectly, who can enter a market, whose credentials will be recognized, what conditions competitors must accept, and whether users can move to alternative ecosystems.

The most useful authorities for developing this doctrine are Commercial Solvents, Bronner, IMS Health, Microsoft, Google Android, Google Shopping, United Brands, and the Bundeskartellamt's Facebook decision. Together they provide the conceptual foundations for analysing refusal of access, interoperability, leveraging, ecosystem dominance, data accumulation and infrastructure-based foreclosure in emerging IDaaS markets.

This might also interest you.

TOPRANKERS EDTECH SOLUTIONS PRIVATE LIMITED

CLAT PG 2028 Preparation Starts Here

Get expert guidance, mock tests and study material for CLAT PG & AILET PG preparation.

Ad

More options

 

LEAVE A COMMENT