Identity Management System Dominance Risks

 

Identity Management System Dominance Risks

Introduction

Identity Management Systems (IdMS) are technological systems used to create, authenticate, verify, manage, and authorize digital identities. They include single sign-on systems, identity providers, federated identity platforms, authentication services, biometric identity systems, enterprise identity directories, digital wallets, and platforms that connect identity information across multiple services.

From a competition-law perspective, dominance risks arise when one undertaking controls a critical identity layer through which users, businesses, applications, advertisers, public authorities, or other platforms must authenticate or obtain access. The concern is not simply that an identity provider is large. The central issue is whether its control over identity infrastructure can be converted into market power in adjacent markets.

Typical risks include:

  • exclusion of competing identity providers;
  • tying identity services to other products;
  • self-preferencing;
  • discriminatory authentication or interoperability;
  • excessive switching costs;
  • foreclosure through proprietary identity standards;
  • exploitation of identity and authentication data;
  • leveraging dominance from operating systems, cloud services, browsers or platforms;
  • discriminatory access to APIs;
  • degradation of interoperability;
  • refusal to provide technically necessary access;
  • privacy deterioration as a non-price dimension of competition; and
  • acquisition of emerging identity competitors.

1. What Constitutes an Identity Management System?

An identity management system can perform several functions:

A. Identity creation

The system establishes a digital identity for an individual, business, device, or organisation.

B. Authentication

It determines whether the person or entity attempting access corresponds to the claimed identity.

Examples include:

  • passwords;
  • multi-factor authentication;
  • biometric authentication;
  • cryptographic credentials;
  • passkeys;
  • hardware security keys.

C. Authorisation

Authentication answers “Who are you?” while authorisation answers “What are you permitted to access?”

A dominant identity provider controlling both functions can therefore become a particularly important gateway.

D. Federation

Identity federation allows one identity provider to authenticate users for multiple independent services.

This can create significant network effects.

E. Identity data management

Identity systems can aggregate:

  • login information;
  • device identifiers;
  • behavioural information;
  • authentication history;
  • organisational affiliations;
  • account relationships;
  • location-related information; and
  • security signals.

The more services connected to the system, the greater its strategic value.

2. Why Identity Systems Can Become Bottlenecks

Identity is increasingly an infrastructure layer rather than merely a software feature.

A user may depend on one identity provider to access:

operating system → cloud → workplace application → payment service → social platform → government service.

If competitors must obtain access to that identity layer to reach customers, the identity provider can function as a bottleneck facility.

This produces a competition-law question:

Can control over authentication infrastructure be used to control competition in downstream markets?

The answer may be yes where the identity system has substantial network effects, switching costs, interoperability advantages and control over essential technical interfaces.

3. Market Definition

Several relevant markets may need to be distinguished.

3.1 Consumer identity-management market

Services allowing consumers to authenticate across multiple applications.

3.2 Enterprise identity-management market

Services such as workforce identity, access management and single sign-on.

3.3 Authentication market

A narrower market concerning authentication and verification services.

3.4 Federated identity market

Services allowing one identity provider to authenticate users across multiple third-party services.

3.5 Identity-verification market

Services verifying that a person or organisation is genuine.

3.6 Adjacent digital markets

The identity provider may also operate in:

  • cloud computing;
  • operating systems;
  • browsers;
  • advertising;
  • app distribution;
  • cybersecurity;
  • productivity software;
  • payments; or
  • digital marketplaces.

The competition problem becomes particularly serious where dominance in one of these markets gives the undertaking control over identity infrastructure.

4. Sources of Identity-Management Dominance

A. Network effects

An identity system becomes more valuable as more users and service providers participate.

A simplified network-effect structure is:

More users → more relying parties → greater utility → more users.

This can produce market tipping.

B. Switching costs

Users may have to migrate:

  • credentials;
  • authentication policies;
  • permissions;
  • security keys;
  • identity records;
  • enterprise directories;
  • API integrations; and
  • historical authentication information.

Consequently, even technically available alternatives may not constitute effective competitive constraints.

C. Data advantages

A large identity provider may have access to extensive information concerning authentication and user relationships.

That information can improve:

  • fraud detection;
  • security;
  • personalisation;
  • advertising;
  • risk scoring;
  • account recovery; and
  • identity verification.

This creates a potential data feedback loop.

D. Ecosystem integration

An identity system integrated into an operating system, browser, cloud platform or mobile ecosystem may receive preferential technical advantages.

For example:

OS → identity provider → browser → applications → cloud → advertising

can produce ecosystem-wide leverage.

5. Major Dominance Risks

5.1 Self-Preferencing

A dominant identity provider could give its own downstream applications preferential access to:

  • authentication APIs;
  • verification signals;
  • security credentials;
  • identity attributes; or
  • interoperability functions.

Competitors may receive inferior access.

This resembles the broader self-preferencing problem identified in digital-platform competition cases.

6. Tying and Bundling

A dominant firm could condition access to one product upon adoption of its identity service.

For example:

“To obtain access to the dominant cloud ecosystem, customers must use the provider's identity-management service.”

If competing identity providers are excluded, this may constitute leveraging of dominance.

The legal analysis would consider:

  1. dominance in the tying market;
  2. separate products;
  3. coercion or practical compulsion;
  4. foreclosure;
  5. objective justification; and
  6. effects on consumers and competitors.

7. Refusal to Interoperate

An identity provider may refuse to provide:

  • authentication APIs;
  • federation protocols;
  • interoperability interfaces;
  • credential portability;
  • verification services; or
  • technical documentation.

Where the identity infrastructure has become indispensable, such conduct may raise essential-facilities/refusal-to-deal concerns.

However, competition law generally does not require dominant companies to assist competitors merely because assistance would be commercially useful.

The threshold for intervention is therefore high.

8. Identity Portability and Lock-In

A particularly important competition issue is whether users can move their identity from one provider to another.

Suppose:

Provider A → identity + credentials + permissions + history

and switching requires:

manual re-registration + security reconfiguration + loss of historical data.

Provider A acquires substantial lock-in power.

Therefore, competition authorities may examine:

  • data portability;
  • credential portability;
  • API portability;
  • account portability;
  • interoperability;
  • standardisation; and
  • switching costs.

9. Discriminatory Authentication

A dominant identity provider could technically disadvantage competing services by:

  • delaying authentication;
  • imposing additional verification requirements;
  • limiting API calls;
  • reducing functionality;
  • requiring additional permissions;
  • degrading security signals; or
  • imposing discriminatory technical standards.

Such conduct can amount to technical foreclosure.

10. Privacy as a Competition Parameter

Identity management also introduces a particularly important form of non-price competition.

A dominant provider could potentially worsen privacy protection without losing substantial users because switching is difficult.

Thus:

Lower privacy + greater lock-in = potential non-price exploitation.

Competition authorities may therefore examine privacy quality as part of competitive conditions, particularly in digital markets where personal data is an important competitive parameter.

This connects competition law with data-protection and consumer-protection regulation.

11. Data Combination and Identity Power

Identity providers can potentially combine identity information with information from other businesses within the same corporate ecosystem.

For example:

Identity data + browsing data + advertising data + purchasing data

may produce a highly detailed commercial profile.

This can create:

  • data concentration;
  • entry barriers;
  • discriminatory personalisation;
  • advertising advantages;
  • surveillance advantages; and
  • exclusionary incentives.

The competition question is whether such data accumulation strengthens dominance or enables exclusionary conduct.

12. Identity Systems and Advertising Markets

Identity infrastructure can be particularly powerful in advertising.

A dominant identity provider may control the mechanism used to identify users across:

  • websites;
  • applications;
  • devices;
  • browsers; and
  • advertising platforms.

This creates a potential identity graph advantage.

Competitors may therefore face difficulty matching the incumbent's ability to:

  • recognise users;
  • measure advertising;
  • attribute conversions;
  • target audiences; and
  • prevent fraud.

Identity dominance can consequently become advertising-market dominance.

13. Identity Federation and Network Effects

Federation creates an especially strong competitive dynamic.

Suppose one provider becomes the identity layer for thousands of applications.

Each additional relying party increases the value of the provider's identity ecosystem.

This may produce:

More relying parties → more users → more identity data → better authentication → greater adoption → more relying parties.

A rival may therefore struggle to enter even if it offers technologically superior authentication.

14. Case Law

The following cases are particularly useful for analysing identity-management dominance even where the underlying disputes did not concern identity-management systems in the narrow technological sense.

1. United States v. Microsoft Corp. (2001)

The Microsoft litigation is foundational for analysing how control over an important technological platform can be leveraged into adjacent markets.

The case concerned Microsoft's dominance in PC operating systems and its conduct affecting browser competition.

Relevance to identity systems

An identity provider embedded into a dominant operating system can similarly use platform control to disadvantage competing services.

The broader principle is:

Control of an important technological platform can facilitate exclusion in adjacent markets.

This is highly relevant where authentication becomes integrated into operating systems or cloud ecosystems.

2. Bronner GmbH v. Mediaprint (1998)

The European Court of Justice established a stringent framework for refusal-to-deal claims involving allegedly indispensable infrastructure.

Relevance

An identity system may be argued to constitute an indispensable infrastructure where competitors cannot realistically reproduce it.

But Bronner demonstrates that mere usefulness or commercial desirability is insufficient.

The claimant would generally need to establish genuine indispensability and the absence of viable alternatives.

3. IMS Health GmbH & Co. OHG v. NDC Health GmbH (2004)

IMS Health concerned access to an indispensable data structure and is central to European essential-facilities doctrine.

Relevance to identity management

A dominant identity provider controlling an indispensable identity database or authentication architecture could face comparable arguments where:

  • access is indispensable;
  • refusal eliminates effective competition;
  • duplication is impracticable; and
  • access is necessary for a new product or service.

The case is particularly relevant to identity databases and interoperability.

4. Microsoft Corp. v Commission (2007)

The EU Microsoft decision concerned Microsoft's refusal to provide interoperability information to competing work-group server developers and the tying of Windows Media Player to Windows.

Relevance

This is perhaps one of the strongest analogies for identity-management systems.

It demonstrates that:

  • interoperability information can have competitive significance;
  • technical interfaces can become instruments of foreclosure;
  • tying can extend dominance into adjacent markets; and
  • technical integration may have exclusionary consequences.

An identity provider that deliberately restricts interoperability could therefore raise similar competition concerns.

5. Google Shopping (Google Search (Shopping)) (2024 judgment)

The EU courts upheld the essential substance of the Commission's finding concerning Google's favouring of its own comparison-shopping service within general search results.

Relevance

The case illustrates how a dominant digital gateway can give preferential treatment to its own downstream service.

An identity provider controlling the authentication gateway could theoretically prefer its own:

  • applications;
  • verification services;
  • advertising products;
  • security tools; or
  • payment services.

The key concern is leveraging gateway power into downstream markets.

6. Google Android (Commission decision, 2018; General Court judgment, 2022)

The Android proceedings concerned Google's contractual practices involving Android devices, including tying and restrictions affecting competing services.

Relevance

Identity services are increasingly integrated with:

  • mobile operating systems;
  • app stores;
  • browsers;
  • cloud services; and
  • device ecosystems.

The Android litigation therefore illustrates how control over a technological ecosystem can reinforce dominance through contractual and technical integration.

7. Google Search (AdSense) (European Commission, 2019)

The Commission found that Google had imposed contractual restrictions concerning search advertising intermediation.

Relevance

The broader significance is that contractual restrictions imposed by a dominant digital intermediary can protect its position in an adjacent market.

An identity provider could similarly impose contractual conditions that make it difficult for competing identity or verification services to obtain access to customers.

8. Apple App Store Cases and Commission Proceedings

Competition proceedings concerning Apple's App Store ecosystem are relevant to identity management because Apple controls important technical and commercial access points for applications.

Relevance

Where identity functionality is embedded into a dominant ecosystem, the platform operator can potentially determine:

  • which authentication mechanisms are permitted;
  • which APIs are available;
  • how third-party applications access credentials;
  • whether alternative authentication providers can compete.

The broader lesson is that technical control over an ecosystem can have competition-law consequences even where the controlled service is not itself the ultimate consumer product.

15. Applying the Cases to Identity Management

Competition principleRelevant authorityIdentity-management application
Platform leveragingMicrosoftOS-controlled identity system
Essential facilitiesBronnerIndispensable authentication infrastructure
Data/interoperability accessIMS HealthIdentity databases and verification data
Interoperability foreclosureMicrosoftRestriction of identity APIs
Self-preferencingGoogle ShoppingPreferential treatment of own identity services
TyingMicrosoft / Google AndroidMandatory identity-service bundling
Ecosystem foreclosureAndroidMobile identity ecosystem
Contractual exclusionAdSenseRestrictive identity-access agreements

16. Identity Management and Essential-Facility Doctrine

An identity infrastructure could theoretically satisfy essential-facility principles where:

  1. the undertaking possesses substantial market power;
  2. the identity infrastructure is indispensable;
  3. competitors cannot reasonably reproduce it;
  4. refusal substantially eliminates effective competition;
  5. access is technically feasible; and
  6. there is no adequate objective justification for refusal.

However, courts are cautious about converting competition law into a general obligation to share infrastructure.

Therefore, indispensability must be demonstrated rather than presumed.

17. Interoperability as a Competition Remedy

Where identity dominance produces foreclosure, authorities could consider:

A. API access

Require reasonable access to authentication interfaces.

B. Protocol interoperability

Require support for open federation standards.

C. Data portability

Allow users and enterprises to transfer relevant identity information.

D. Non-discrimination

Require equivalent technical access for competing identity providers.

E. Functional separation

Separate identity infrastructure from competing downstream businesses.

F. Transparency

Require disclosure of technical requirements and access conditions.

18. Competition Risks from Artificial Switching Costs

Dominant identity providers can increase switching costs through:

  • proprietary credentials;
  • proprietary APIs;
  • account-history restrictions;
  • contractual lock-ins;
  • incompatible authentication protocols;
  • non-portable permissions;
  • closed identity graphs; and
  • dependence on proprietary security infrastructure.

Competition authorities may distinguish between:

legitimate security-related switching costs

and

artificially created exclusionary switching costs.

This distinction is critical because identity management necessarily involves security and reliability.

19. Security Justifications

Identity providers can legitimately argue that interoperability requirements create security risks.

For example:

“Allowing third-party authentication providers to access the system increases fraud, credential theft and account-takeover risks.”

Such arguments may constitute objective justifications.

But the competition authority may examine whether:

  • the security concern is genuine;
  • the restriction is proportionate;
  • less restrictive alternatives exist;
  • the same standard is applied to the provider's own services; and
  • the restriction is actually necessary.

Thus, security cannot automatically justify discriminatory foreclosure.

20. Acquisitions and Killer-Acquisition Risks

Dominant identity platforms may acquire:

  • authentication startups;
  • biometric firms;
  • passwordless-login companies;
  • digital-wallet businesses;
  • identity-verification firms;
  • decentralised identity providers.

The concern is that the acquisition may eliminate a future competitive constraint.

Competition authorities may therefore examine:

  • nascent competition;
  • innovation;
  • interoperability technologies;
  • privacy-enhancing alternatives;
  • decentralised identity models; and
  • potential future ecosystem competition.

21. Algorithmic Identity Decisions

Modern identity systems increasingly use AI to decide:

  • whether an account is genuine;
  • whether authentication should be allowed;
  • whether additional verification is necessary;
  • whether a transaction appears suspicious;
  • whether a user should be blocked.

A dominant identity provider could potentially discriminate against competitors through algorithmic rules.

This creates a new form of algorithmic foreclosure.

For example:

Competitor's authentication method → lower trust score → additional verification → user abandonment.

The exclusion may therefore occur without an explicit contractual prohibition.

22. Identity Management as a Digital Essential Infrastructure

Identity systems increasingly resemble infrastructure because they facilitate access to multiple markets.

A dominant identity system can become a digital gatekeeper where it controls:

authentication + identity data + permissions + interoperability + user access.

At that stage, competition policy may move beyond traditional price-based analysis.

Relevant competitive parameters include:

  • privacy;
  • security;
  • interoperability;
  • innovation;
  • data portability;
  • user autonomy; and
  • quality of authentication.

23. Key Legal Tests

A competition authority examining identity-management dominance should ask:

Market power

  1. Is the provider dominant?
  2. Is identity infrastructure a separate relevant market?
  3. Are there realistic alternatives?

Conduct

  1. Is access discriminatory?
  2. Is identity tied to another service?
  3. Is interoperability restricted?
  4. Is the provider self-preferencing?
  5. Are switching costs artificially increased?

Effects

  1. Are competing identity providers foreclosed?
  2. Are downstream markets affected?
  3. Is innovation reduced?
  4. Are privacy or quality parameters deteriorating?

Justification

  1. Is the conduct necessary for security?
  2. Is the restriction proportionate?
  3. Are less restrictive alternatives available?

24. Competition-Law Theory

Identity management creates a particularly interesting form of infrastructure-based market power.

Traditional monopoly analysis focuses on control over:

production → distribution → consumers.

Identity dominance can operate differently:

identity → authentication → access → ecosystem participation → downstream competition.

Consequently, the identity provider may not need to control the downstream product itself.

Control over the gateway to the consumer may be sufficient.

25. Conclusion

Identity Management System Dominance Risks arise when control over digital identity becomes a source of power over multiple adjacent markets.

The most important risks are:

  1. identity-provider dominance;
  2. authentication bottlenecks;
  3. refusal to interoperate;
  4. identity-data foreclosure;
  5. tying and bundling;
  6. self-preferencing;
  7. artificial switching costs;
  8. discriminatory API access;
  9. identity-graph advantages;
  10. privacy degradation;
  11. algorithmic discrimination;
  12. ecosystem leveraging; and
  13. acquisition of emerging identity competitors.

The most useful authorities include Microsoft, Bronner, IMS Health, Google Shopping, Google Android and AdSense, because together they provide the principal competition-law frameworks for analysing platform leverage, interoperability, essential facilities, tying, self-preferencing, contractual foreclosure and ecosystem dominance.

The central proposition is:

When identity becomes the gateway through which users and businesses access digital markets, control over identity infrastructure can become control over market access itself.

That makes identity management a potentially significant digital competition-law infrastructure problem, particularly where authentication, identity data, federation and access controls are concentrated in one dominant ecosystem.

 

LEAVE A COMMENT