Identity Portability Across Digital Ecosystems .
Identity Graph Monopoly Formation Mechanisms
1. Introduction
An identity graph is a digital system that links identifiers belonging to the same person, household, device, account, organisation, or behavioural profile across multiple environments. It may connect email addresses, telephone numbers, advertising IDs, cookies, device fingerprints, login credentials, transaction histories, location signals, browsing activity, social connections, purchase histories and inferred interests.
An identity graph monopoly arises when one undertaking obtains such a strong position over identity resolution and identity-linked data that competitors, advertisers, platforms, data intermediaries, or downstream services become substantially dependent upon it.
The competition concern is therefore not merely ownership of a database. It is the progressive accumulation of identity signals, cross-context matching capability, network effects, switching barriers and strategic control over access to identity information.
A useful analytical chain is:
Identity collection → identifier matching → graph expansion → cross-service integration → accuracy advantage → network effects → switching costs → exclusion of rivals → durable identity-market power.
2. Meaning of an Identity Graph
An identity graph can be represented conceptually as:
Person → Email → Phone → Device → Browser → Account → Location → Transactions → Interests → Relationships → Other identifiers
The graph becomes commercially valuable because the operator can determine that apparently separate data points belong to the same underlying individual or household.
For competition law, three characteristics are particularly important:
- Breadth – how many identifiers and datasets are connected.
- Accuracy – how reliably different identifiers are resolved to the same entity.
- Exclusivity – whether rivals can obtain comparable identity signals.
The third factor is often the most important for monopoly formation.
3. Mechanisms Through Which an Identity Graph Monopoly Forms
A. First-Party Data Accumulation
A dominant platform may begin with a large user base and collect extensive first-party information through:
- search;
- email;
- social networking;
- payments;
- operating systems;
- cloud services;
- mapping;
- e-commerce;
- video;
- advertising;
- authentication services.
The identity graph becomes progressively richer as additional services are connected.
The competitive advantage is cumulative: more users generate more identifiers; more identifiers improve matching; better matching attracts more commercial users; commercial adoption generates further data.
This can create a self-reinforcing data advantage.
B. Cross-Service Identity Linking
The next mechanism is the integration of information generated by different services.
For example:
Login identity + device identity + advertising identity + purchasing identity + location identity
may be converted into a unified profile.
Where competitors operate only one service, they may possess fragmented datasets. The integrated platform therefore obtains a structural advantage.
Competition concerns arise where the undertaking uses its position in one market to strengthen its position in another.
C. Identity Resolution as a Bottleneck
Identity resolution itself can become a bottleneck.
Suppose advertisers or publishers need to determine whether:
- user A
- device B
- email C
- cookie D
belong to the same individual.
If one company performs this matching substantially better than rivals, its identity-resolution infrastructure can become an essential input for downstream data-driven competition.
The important competition-law question becomes:
Can rivals realistically reproduce the identity-resolution capability without access to the incumbent's accumulated data?
If the answer is no, the identity graph can evolve from a useful asset into a strategic bottleneck.
D. Network Effects
Identity systems exhibit powerful network effects.
More users → more identity signals → greater matching accuracy → more valuable identity services → more customers → more users and data.
This can produce a positive feedback loop:
Scale → data → accuracy → adoption → greater scale.
Unlike traditional network effects based purely on the number of users, identity graphs can also exhibit data-quality network effects.
The larger graph may identify users more accurately because it contains more historical and cross-context information.
E. Data Network Effects
A particularly important mechanism is the data network effect.
Consider two identity providers:
- Provider A: 100 million identity records with extensive cross-context signals.
- Provider B: 10 million records with limited signals.
Even if both use similar algorithms, A may have a substantial advantage because its historical data enables:
- better matching;
- fraud detection;
- household identification;
- behavioural prediction;
- audience segmentation;
- attribution;
- identity verification.
The incumbent therefore does not merely possess more data; it possesses data that makes the identity system itself more effective.
F. Cross-Side Network Effects
Identity graphs frequently operate within multi-sided markets.
For example:
Users ↔ platform ↔ advertisers ↔ publishers ↔ data brokers
More users make the identity system attractive to advertisers. More advertisers make the platform commercially valuable. More commercial demand incentivises publishers and service providers to integrate with the identity infrastructure.
This can create a reinforcing ecosystem.
A competitor entering later may face a severe chicken-and-egg problem:
It cannot attract advertisers without users, but it cannot attract users without useful services, while the incumbent already possesses both.
G. Default and Pre-Installation Advantages
Identity monopoly formation can be accelerated through:
- default login systems;
- pre-installed applications;
- default browsers;
- operating-system accounts;
- automatic synchronization;
- default advertising identifiers;
- bundled authentication.
Defaults matter because users frequently do not actively choose identity providers.
A platform with a pre-existing distribution advantage can therefore turn a distribution monopoly into an identity-data advantage.
4. Authentication Lock-In
Identity graphs become particularly powerful when identity is tied to authentication.
A user may rely on one account to access:
- applications;
- cloud storage;
- payments;
- communications;
- professional services;
- government services;
- devices.
The account becomes a gateway identity.
Switching then becomes difficult because changing the identity provider may require:
- changing credentials;
- recreating accounts;
- losing historical information;
- re-establishing contacts;
- reconnecting applications;
- re-authenticating devices.
These switching costs can protect the incumbent from competitive entry.
5. Single Sign-On as a Monopoly-Formation Mechanism
Single sign-on can produce substantial economies of scale.
A platform providing authentication across thousands of services obtains information about:
- where users log in;
- which services they use;
- how frequently they use them;
- device relationships;
- account relationships.
The authentication layer can therefore become an identity-information collection mechanism.
Competition concerns become particularly serious where the authentication provider also operates competing downstream services.
It may potentially obtain information about rivals' users while simultaneously controlling access to those users.
6. Device–Identity Integration
Operating-system providers can connect:
device → account → application → location → advertising identity → purchasing behaviour.
This creates a highly persistent identity graph.
Device-level integration can be difficult for competitors to replicate because the operating-system provider controls:
- system APIs;
- identifiers;
- permissions;
- installation channels;
- authentication;
- security infrastructure.
Consequently, identity power may originate outside the identity market itself.
7. Acquisition of Data Brokers
Another mechanism is buying the identity graph rather than constructing it organically.
A large platform may acquire:
- consumer databases;
- credit-data businesses;
- advertising-data companies;
- identity-resolution companies;
- customer-data platforms;
- authentication providers.
The acquisition can combine previously separate identity ecosystems.
Competition authorities may therefore need to examine whether a transaction creates a data aggregation advantage even where the acquired company's conventional revenue is relatively modest.
8. Exclusive Data Access
Monopoly formation can occur when an undertaking obtains exclusive or preferential access to identity data.
Examples include:
- exclusive publisher agreements;
- exclusive authentication arrangements;
- exclusive retail-data partnerships;
- preferential access to payment data;
- contractual restrictions on data sharing.
The central issue is not simply data ownership.
It is whether competitors are deprived of equivalent competitive inputs.
9. Data Portability Limitations
Even where users theoretically own or control certain information, portability may be inadequate.
An identity graph can contain:
- inferred relationships;
- probabilistic matches;
- historical identifiers;
- device associations;
- confidence scores;
- behavioural classifications.
These elements may not be readily portable.
Consequently, a user may technically transfer their basic account information while being unable to transfer the functional identity graph.
This creates a significant switching barrier.
10. Algorithmic Matching Advantage
Modern identity graphs increasingly rely on machine-learning systems.
Algorithms may infer:
- whether two devices belong to one person;
- whether two accounts belong to one household;
- whether different identifiers refer to the same consumer;
- whether apparently separate users are connected.
More historical observations can improve model performance.
Thus:
More data → better model → better identity resolution → greater adoption → more data.
This can produce a particularly durable form of monopoly because the competitive advantage is embedded in both the dataset and the algorithmic infrastructure.
11. Privacy Controls as a Competitive Variable
Privacy-enhancing changes can have asymmetric competitive effects.
For example, restrictions on third-party tracking may reduce access to information that smaller competitors previously used to build alternative identity systems.
If the incumbent controls a large first-party identity ecosystem, it may remain able to collect information through authenticated interactions while rivals lose access to equivalent third-party signals.
The competition concern is therefore not necessarily that privacy protection is anti-competitive.
Rather, the question is:
Does a supposedly neutral privacy architecture disproportionately reinforce an incumbent's existing identity advantage?
This requires careful counterfactual analysis.
12. Self-Preferencing
A vertically integrated identity provider may operate both:
- the identity infrastructure; and
- downstream commercial services.
It could potentially favour its own services through:
- superior identity access;
- better authentication;
- preferential APIs;
- better matching;
- privileged analytics;
- earlier access to identity signals.
This creates a classic platform-as-infrastructure-and-competitor conflict.
13. Degradation of Rival Identity Providers
An identity monopolist can potentially weaken competitors by restricting:
- APIs;
- cookies;
- identifiers;
- authentication access;
- interoperability;
- data portability;
- identity-resolution interfaces.
The competitive effect can be greater than the loss of a particular API.
If rivals lose access to identity signals, their entire data-driven business models may become less effective.
14. Tying and Bundling
Identity services can also be tied to other products.
Examples include:
Operating system + identity account
Cloud service + authentication
Advertising service + identity resolution
Payment service + consumer identity
Marketplace account + identity verification
If customers cannot reasonably purchase one service without accepting the incumbent's identity infrastructure, the identity system can become entrenched.
15. Identity Graphs and Adjacent-Market Expansion
Once an undertaking controls a comprehensive identity graph, it can potentially expand into:
- advertising;
- payments;
- credit;
- insurance;
- employment;
- authentication;
- fraud prevention;
- e-commerce;
- content recommendation;
- financial services.
The graph therefore operates as a competitive launchpad.
Its importance lies not only in the identity market but also in its ability to facilitate entry into adjacent markets.
16. Relevant Competition-Law Theories
Identity graph monopolisation can potentially engage:
1. Abuse of dominance
Particularly:
- exclusionary conduct;
- discriminatory access;
- tying;
- refusal to supply;
- self-preferencing;
- exploitative conduct.
2. Essential-facility reasoning
Where identity resolution becomes indispensable and cannot reasonably be replicated.
3. Leveraging
Using identity power to obtain or protect dominance in adjacent markets.
4. Foreclosure
Preventing rivals from obtaining sufficient identity inputs to compete effectively.
5. Merger control
Especially acquisitions combining:
- identity data;
- authentication;
- advertising;
- payments;
- consumer databases.
6. Data-access remedies
Possible remedies include:
- interoperability;
- API access;
- data portability;
- non-discrimination obligations;
- separation of datasets;
- restrictions on cross-use of data.
17. Important Case Laws
The following cases do not all concern a legally defined "identity graph monopoly" as such. They provide the principal competition-law doctrines that can be applied to identity-graph formation and exploitation.
1. Google Search (Shopping) — European Commission / General Court
Google Search (Shopping), Case T-612/17, Google LLC v Commission
The case concerned Google's preferential positioning of its own comparison-shopping service.
Relevance to identity graphs
The broader principle is leveraging through a dominant digital infrastructure.
An identity provider could similarly use control over a foundational digital layer to advantage its own downstream services.
The case is particularly relevant to:
- self-preferencing;
- leveraging;
- platform foreclosure;
- discriminatory treatment of competing services.
2. Google Android
Google Android, Case AT.40099
The European Commission examined Google's contractual arrangements concerning Android, including tying and restrictions affecting competing search and browser services.
Relevance
The case demonstrates how control over an ecosystem can reinforce power across adjacent digital markets.
For identity graphs, comparable concerns can arise where:
operating system → account → authentication → identity data → downstream service
becomes an integrated chain.
3. Google Search (AdSense)
Google Search (AdSense), Case AT.40411
The Commission examined contractual restrictions concerning online-search advertising intermediation.
Relevance
The case illustrates how contractual restrictions can foreclose competing intermediaries where a dominant digital platform controls an important gateway.
An identity graph can function as such a gateway for:
- advertising;
- audience measurement;
- attribution;
- customer acquisition.
4. Facebook / Meta Data and Competition Investigation
Bundeskartellamt v Facebook, B6-22/16
The German competition authority examined Facebook's combination of user data obtained from different sources.
Relevance
This is one of the most directly relevant authorities to identity-graph theory.
The case demonstrates how competition law can examine the relationship between:
data collection → data combination → market power → user dependency.
The Bundeskartellamt's approach was particularly important because it treated extensive data combination as potentially connected to Facebook's dominance and exploitative conditions.
It therefore provides a strong analytical foundation for examining identity graphs created through cross-service data aggregation.
5. Google / DoubleClick
FTC review of Google–DoubleClick merger
The transaction raised questions concerning the combination of Google's information resources with DoubleClick's online advertising technology.
Relevance
The case is important historically because it illustrates merger-control concerns surrounding the combination of:
- user information;
- advertising technology;
- behavioural data;
- targeting infrastructure.
Identity-graph monopolisation can occur through precisely this type of data and infrastructure aggregation.
6. United States v. Google
United States v. Google LLC, 2024 district-court decision concerning search distribution
The U.S. litigation examined Google's agreements concerning distribution and default placement of search services.
Relevance
The case is relevant to identity monopolisation because defaults and distribution arrangements can reinforce network effects and entry barriers.
If identity services become default infrastructure across browsers, operating systems, devices, or applications, competitors may struggle to obtain the scale necessary to construct alternative identity graphs.
7. Microsoft / Internet Explorer
United States v. Microsoft Corp., 253 F.3d 34 (D.C. Cir. 2001)
Microsoft's conduct concerning Internet Explorer and Windows was examined under U.S. antitrust law.
Relevance
The case remains highly relevant to identity graphs because it establishes how a dominant infrastructure provider may use control over one technological layer to restrict competition in an adjacent layer.
Identity systems can create an analogous structure:
OS → authentication → identity → applications → advertising/data services.
8. United States v. Google — Ad Technology
The U.S. government's antitrust litigation concerning Google's advertising-technology ecosystem also illustrates the importance of controlling multiple layers of a digital value chain.
Relevance
Where identity resolution is integrated with:
- ad exchanges;
- publisher tools;
- advertiser tools;
- measurement systems,
the identity graph can become a strategic input capable of reinforcing vertical integration.
18. Case-Law Synthesis
| Case | Core doctrine | Identity-graph relevance |
|---|---|---|
| Facebook/Bundeskartellamt | Data combination and dominance | Cross-service identity-data aggregation |
| Google Shopping | Self-preferencing/leveraging | Preferential use of identity infrastructure |
| Google Android | Tying/ecosystem leveraging | OS-account-identity integration |
| Google AdSense | Contractual foreclosure | Restricting competing identity intermediaries |
| Microsoft | Leveraging technological dominance | OS/control layer used to protect adjacent market |
| Google/DoubleClick | Data + advertising concentration | Combining identity and advertising capabilities |
| Google Search | Defaults/distribution | Default identity systems and entry barriers |
| Google Ad Technology | Vertical digital integration | Identity as an input across advertising layers |
19. The Monopoly-Formation Cycle
The most important conceptual model is:
1. Acquire users
↓
2. Assign persistent identifiers
↓
3. Collect first-party data
↓
4. Link identifiers across services
↓
5. Improve identity resolution
↓
6. Attract advertisers, publishers and developers
↓
7. Generate additional identity signals
↓
8. Increase switching costs
↓
9. Restrict or disadvantage rival identity providers
↓
10. Expand into adjacent markets
↓
11. Reinforce the identity graph
↓
12. Create durable structural dominance
The critical point is that monopoly formation may be gradual rather than the result of one exclusionary act.
20. Why Identity Graph Monopoly Is Different From Ordinary Data Monopoly
An ordinary data monopoly may concern possession of a large quantity of information.
An identity-graph monopoly is potentially more powerful because the undertaking controls the relationships between pieces of information.
For example:
Knowing that A visited Website X is useful.
But knowing that:
A's email, phone number, device, browser, purchase history, location history and multiple online accounts all belong to the same person
creates a much more valuable competitive asset.
The monopoly therefore concerns identity linkage, not merely data volume.
21. Competition Risks
Identity graph monopolisation can produce:
A. Entry barriers
New competitors cannot reproduce the incumbent's historical dataset.
B. Data foreclosure
Rivals cannot access equivalent identity signals.
C. Reduced interoperability
Alternative identity systems cannot communicate effectively with the incumbent.
D. Increased switching costs
Users and businesses become dependent on one identity provider.
E. Cross-market leveraging
Identity power is transferred into advertising, payments, commerce or authentication.
F. Privacy-competition interaction
Privacy architecture may unintentionally strengthen already dominant first-party ecosystems.
G. Reduced innovation
Start-ups may be unable to construct competing identity infrastructures.
H. Increased surveillance capacity
The dominant undertaking can potentially observe activity across a greater number of economic contexts.
22. Possible Competition-Law Remedies
Authorities could consider:
- Interoperability obligations
- Identity portability
- API access
- Non-discrimination requirements
- Restrictions on combining datasets
- Separation of identity and downstream commercial operations
- Prohibition of discriminatory authentication practices
- Restrictions on exclusive identity contracts
- Merger remedies concerning data integration
- Data-access or data-sharing remedies where legally justified
However, mandatory access must be carefully designed because unrestricted sharing of identity data can itself create privacy and security risks.
23. Key Legal Test
A competition authority examining identity-graph monopoly formation should ask:
Market power
- Does the undertaking control a critical identity infrastructure?
- Are users or businesses dependent upon it?
Data advantage
- Is the identity dataset uniquely comprehensive?
- Can rivals reproduce the same identity graph?
Network effects
- Does additional scale improve identity accuracy?
Switching costs
- Can users realistically move their identity to another provider?
Foreclosure
- Does the undertaking restrict rival access to identity signals?
Leveraging
- Is identity power used to strengthen downstream markets?
Self-preferencing
- Does the operator favour its own services?
Entry barriers
- Would a new entrant need years of accumulated data to compete effectively?
Consumer effects
- Are privacy, quality, innovation, choice and price competition harmed?
24. Conclusion
Identity graph monopoly formation is fundamentally a process of converting fragmented identity signals into a self-reinforcing infrastructure of economic power.
The principal mechanisms are:
data accumulation + identity resolution + network effects + authentication control + ecosystem integration + defaults + switching costs + exclusivity + algorithmic advantage + vertical leveraging.
The most significant competition-law insight is that the monopolisation problem may not lie in the possession of any individual piece of personal data. It lies in controlling the mapping between millions of identifiers and real-world entities, and then using that mapping to obtain advantages across multiple digital markets.
The Facebook/Bundeskartellamt proceedings are especially important because they demonstrate how competition law can address the competitive implications of combining data across different sources. Google Shopping, Google Android, Google AdSense, Microsoft, Google/DoubleClick and the Google search/ad-tech proceedings complement that framework by illustrating leveraging, tying, defaults, foreclosure, vertical integration and ecosystem-based market power.

comments