Identity Verification Ecosystems And Gatekeeping Control .
Identity Verification Ecosystems and Gatekeeping Control
Introduction
Identity verification ecosystems are digital systems through which platforms, financial institutions, governments, marketplaces, telecommunications providers, and other intermediaries determine whether a person or business is genuinely who they claim to be. They may combine government-issued identifiers, biometric information, device signals, credit information, transaction histories, reputation scores, authentication credentials, fraud databases, and third-party verification APIs.
The competition-law concern arises when control over identity verification becomes a form of gatekeeping power. A dominant undertaking may not merely provide a verification service; it may control whether other businesses, users, developers, or competitors can obtain access to an important digital ecosystem.
The central question is therefore:
When does control over digital identity verification become a competition problem because access to verification is effectively necessary to participate in a market?
This issue connects essential-facilities doctrine, refusal to deal, self-preferencing, interoperability, data access, tying, discrimination, platform governance, and ecosystem foreclosure.
1. Meaning of an Identity Verification Ecosystem
An identity-verification ecosystem normally contains several interconnected layers.
A. Identity-data layer
This may contain:
- name and address;
- government identifiers;
- telephone numbers;
- email addresses;
- biometric identifiers;
- financial information;
- business-registration information;
- credit information;
- transaction histories.
B. Verification layer
The system checks whether submitted information corresponds to a real person or entity.
Examples include:
- KYC systems;
- AML verification;
- age verification;
- biometric authentication;
- business verification;
- document verification;
- fraud detection.
C. Identity-resolution layer
The system may determine whether different records belong to the same person.
For example:
Email A + phone number B + device C + bank account D → allegedly the same individual.
This creates substantial competitive significance because the operator can accumulate an identity graph.
D. Access-control layer
The verified identity may determine whether an individual or company can:
- open an account;
- advertise;
- make payments;
- sell goods;
- access an API;
- use a marketplace;
- participate in a financial service;
- access government services.
Thus verification can become an entry gate rather than merely a technical service.
2. What Is Gatekeeping Control?
Gatekeeping control exists where an undertaking can materially determine whether another undertaking or user can enter, participate in, or remain within an important digital ecosystem.
The gatekeeper may control:
- who can be verified;
- what evidence is accepted;
- which verification provider is permitted;
- how quickly verification occurs;
- whether verification decisions can be appealed;
- whether competitors receive equivalent verification access;
- whether verification data can be exported;
- whether third-party verification services can interoperate.
The competition problem becomes particularly serious where verification is effectively indispensable.
3. Why Identity Verification Can Become an Essential Facility
Traditional essential-facilities doctrine generally concerns an infrastructure or input that competitors cannot reasonably reproduce and whose denial of access can substantially impair competition.
An identity-verification system could theoretically acquire similar characteristics where it is:
1. Controlled by a dominant undertaking
The operator has substantial market power.
2. Difficult or impossible to duplicate
The system may possess:
- unique identity data;
- extensive historical records;
- government integrations;
- accumulated fraud intelligence;
- network effects;
- trusted credentials.
3. Necessary for effective competition
Without access, a competitor may be unable to:
- onboard users;
- process transactions;
- advertise;
- perform KYC;
- access a marketplace;
- satisfy regulatory requirements.
4. Capable of being supplied
There must be a technically and economically feasible method of providing access.
5. Denial capable of eliminating or substantially restricting competition
The refusal must have meaningful foreclosure effects.
4. Identity Verification as a Bottleneck
Identity verification can function as a bottleneck input.
Consider:
Government ID → Verification Provider → Platform Identity → Payment Account → Marketplace Access
If one company controls the verification stage, downstream competitors may become dependent upon it.
The bottleneck becomes more significant where the same company also operates the downstream platform.
For example:
Verification provider → verifies merchant → marketplace admits merchant → payment service processes merchant → advertising platform promotes merchant.
The company can therefore influence competition at several levels simultaneously.
5. Self-Preferencing Risks
Suppose a platform operates:
- an identity-verification service; and
- a competing marketplace.
It could theoretically verify its own merchants immediately while delaying or rejecting merchants seeking to participate in competing marketplaces.
This produces vertical foreclosure.
Potential strategies include:
- preferential verification speed;
- lower verification fees;
- superior fraud-risk scores;
- exclusive access to verification databases;
- superior API functionality;
- withholding verification signals from rivals.
The competitive concern is not merely that the platform owns a verification service, but that it can use verification control to disadvantage downstream competitors.
6. Refusal to Deal
A refusal to provide verification access may constitute an abuse where the applicable legal test is satisfied.
Possible examples include:
- refusing API access;
- refusing identity validation;
- refusing access to verification databases;
- terminating verification credentials;
- refusing interoperability;
- denying access to authentication infrastructure.
However, competition law does not normally impose a general duty on dominant firms to deal with every competitor.
The difficult issue is whether the verification resource satisfies the stringent requirements for intervention.
7. Interoperability and Data Portability
Gatekeeping power can also arise from the absence of interoperability.
Imagine:
Platform A Identity → cannot be recognized by Platform B.
Users may therefore have to create a new identity and repeat:
- KYC;
- biometric verification;
- business verification;
- reputation verification.
This creates switching costs.
The dominant platform can therefore make its identity system effectively sticky.
Competition authorities may consider:
- standardized authentication protocols;
- interoperable credentials;
- API access;
- portability of verification results;
- machine-readable verification certificates.
8. Tying and Bundling
A dominant ecosystem could require users to obtain identity verification from its own service as a condition for accessing another service.
For example:
"To advertise on our platform, you must use our identity-verification service."
This may raise tying or bundling concerns where the relevant legal conditions are satisfied.
The concern increases if independent verification providers are technically capable of performing the same function but are excluded.
9. Discriminatory Verification
Another important issue is discriminatory access.
A gatekeeper might apply:
| Treatment | Own service | Rival service |
|---|---|---|
| Verification fee | Low | High |
| Processing time | Immediate | Delayed |
| API access | Full | Restricted |
| Fraud data | Full | Limited |
| Appeals | Extensive | Limited |
| Verification threshold | Flexible | Strict |
Such asymmetry may become evidence of exclusionary conduct.
10. Data Advantages and Identity Moats
Identity verification produces enormous amounts of valuable data.
The operator may learn:
- who a user is;
- which accounts belong to the same person;
- transaction patterns;
- device associations;
- fraud patterns;
- geographic activity;
- business relationships.
This can create a data moat.
Competitors may be unable to reproduce the same dataset because they cannot observe the same number of users.
Consequently:
Data accumulation → better verification → greater trust → more users → more data → stronger verification
creates a self-reinforcing feedback loop.
11. Network Effects
Identity systems can display both direct and indirect network effects.
Direct network effects
More participants make the identity system more useful.
Indirect network effects
More businesses accepting the identity credential increase its value to users.
For example:
More merchants accept Identity X → more consumers want Identity X → more merchants want access to Identity X.
Eventually, competing identity providers may face a severe adoption barrier.
12. Competition Between Identity Ecosystems
The relevant market need not always be "identity verification."
Authorities may examine narrower markets such as:
- KYC verification;
- biometric authentication;
- digital identity credentials;
- business identity verification;
- age verification;
- fraud detection;
- identity-resolution services;
- identity APIs.
Market definition will depend on:
- substitutability;
- regulatory requirements;
- technical interoperability;
- switching costs;
- geographic scope;
- customer preferences.
13. Six Important Case Laws
The following cases provide important legal principles relevant to identity-verification gatekeeping, even where the underlying facts did not involve modern digital identity systems.
1. Commercial Solvents Corp. v. Commission
Court: Court of Justice of the European Communities
Principle: Refusal to supply by a dominant undertaking can constitute an abuse where it threatens to eliminate competition downstream.
Commercial Solvents stopped supplying an essential raw material to a downstream competitor.
Relevance
An identity-verification operator that controls a critical upstream input could potentially raise similar concerns if it refuses access to a downstream competitor and thereby threatens effective competition.
Key lesson: A dominant undertaking cannot necessarily use control over an upstream input to eliminate downstream competition.
14. United Brands v. Commission
Court: Court of Justice of the European Communities
The case is a foundational authority on abuse of dominance and discriminatory treatment.
United Brands' conduct involved discriminatory conditions imposed on trading partners.
Relevance
A dominant identity platform could potentially create competition concerns if it:
- provides superior verification to its own ecosystem;
- discriminates against rival platforms;
- selectively restricts verification;
- imposes unjustified discriminatory conditions.
Key lesson: Dominance creates heightened responsibilities concerning discriminatory commercial conduct.
15. Bronner v. Mediaprint
Case: Oscar Bronner GmbH & Co. KG v Mediaprint
Court: Court of Justice of the European Union
This is one of the most important EU cases concerning essential facilities and refusal to deal.
The Court established a demanding test for requiring a dominant undertaking to provide access to infrastructure.
Importance
The infrastructure must generally be indispensable, and duplication must not be realistically possible.
Identity-verification relevance
A claimant seeking access to a dominant identity-verification infrastructure would need to establish more than:
"The dominant provider has a better system."
It may need to demonstrate genuine indispensability.
Key lesson: Essential-facilities intervention is exceptional rather than automatic.
16. IMS Health v. Commission
Case: IMS Health GmbH & Co. KG v NDC Health GmbH & Co. KG
Court: Court of Justice of the European Union
IMS Health concerned access to a highly structured information system and intellectual-property-related refusal to license.
The case refined the circumstances under which refusal to provide access can constitute abuse.
Relevance
Identity-verification infrastructures may contain:
- proprietary databases;
- identity mappings;
- software interfaces;
- proprietary verification methodologies.
If competitors cannot realistically reproduce the relevant infrastructure, the IMS Health principles become particularly important.
Key lesson: Access remedies involving proprietary infrastructure require careful balancing of innovation incentives and competitive necessity.
17. Microsoft v. Commission
Court: General Court of the European Union
Microsoft involved refusal to provide interoperability information to competitors.
The case is highly relevant to modern digital ecosystems because interoperability information can determine whether competing products can effectively operate alongside a dominant platform.
Identity-verification relevance
Suppose a dominant identity platform controls:
- authentication protocols;
- APIs;
- identity credentials;
- interoperability documentation.
Withholding such information could make competing services technically inferior or impossible to operate.
Key lesson
Interoperability can itself become a competition-relevant input where control over technical interfaces gives a dominant undertaking the ability to foreclose competitors.
18. Google Shopping
Case: Google Search (Shopping)
Court: Court of Justice of the European Union
The case concerned Google's treatment of competing comparison-shopping services in its search ecosystem.
The broader principle concerns how a dominant platform can use control over a major gateway to favour its own downstream service.
Identity-verification relevance
A comparable structure could arise where:
dominant identity gateway → verification ranking → access to downstream ecosystem.
If the operator systematically privileges its own identity or downstream services while disadvantaging rivals, the conduct may raise self-preferencing and foreclosure concerns.
Key lesson
A platform controlling an important gateway may not necessarily be free to manipulate that gateway to disadvantage competing services.
19. Slovak Telekom v. Commission
Court: Court of Justice of the European Union
The case concerned access to infrastructure controlled by a dominant telecommunications undertaking and the conditions under which access arrangements can produce exclusionary effects.
Identity-verification relevance
Identity APIs can similarly become infrastructure connecting multiple downstream services.
A dominant provider could theoretically:
- provide inadequate API access;
- impose discriminatory technical conditions;
- make interoperability unnecessarily difficult;
- use access conditions to restrict downstream competition.
Key lesson
Access conditions imposed by a dominant infrastructure provider can have exclusionary consequences.
20. Additional Relevant Authority: Magill
Cases: RTE and ITP v Commission — commonly known as Magill
The case concerned refusal to license copyrighted information.
The Court recognized exceptional circumstances under which refusal to license can constitute abuse.
Relevance
Identity ecosystems may involve proprietary databases and information assets.
Magill is therefore relevant when a company argues:
"The identity database is proprietary, so competition law cannot require access."
The answer is that proprietary status is highly relevant, but it does not automatically immunize conduct from competition law.
21. Case-Law Principles Compared
| Case | Core principle | Identity-verification relevance |
|---|---|---|
| Commercial Solvents | Refusal to supply | Denial of verification input |
| United Brands | Discriminatory conduct | Differential verification treatment |
| Bronner | Essential-facilities test | Indispensability of identity infrastructure |
| IMS Health | Exceptional access to proprietary systems | Identity databases and proprietary mappings |
| Microsoft | Interoperability | Identity APIs and authentication protocols |
| Google Shopping | Gateway/self-preferencing | Preferential identity ecosystem treatment |
| Slovak Telekom | Infrastructure access | Verification APIs as bottleneck infrastructure |
| Magill | Exceptional refusal to license | Proprietary identity information |
22. When Does Identity Verification Become a Competition Bottleneck?
A useful analytical framework is:
Step 1 — Identify the gatekeeper
Who controls verification?
Step 2 — Identify the relevant market
Is the relevant market:
- identity verification;
- digital identity;
- KYC;
- authentication;
- fraud detection;
- platform access?
Step 3 — Establish market power
Consider:
- market share;
- switching costs;
- network effects;
- data advantages;
- regulatory recognition;
- interoperability barriers.
Step 4 — Determine indispensability
Could competitors reasonably reproduce the verification system?
Step 5 — Examine conduct
Possible conduct includes:
- refusal to supply;
- discriminatory access;
- self-preferencing;
- tying;
- exclusive dealing;
- interoperability restrictions;
- excessive access charges.
Step 6 — Assess foreclosure
Would the conduct:
- exclude rivals;
- raise rivals' costs;
- prevent entry;
- reduce innovation;
- increase switching costs?
Step 7 — Consider objective justification
The gatekeeper may invoke:
- fraud prevention;
- cybersecurity;
- privacy;
- AML obligations;
- regulatory compliance;
- legitimate technical limitations.
These defenses can be important because identity verification is intrinsically connected with security and privacy.
23. Privacy and Competition Law Interaction
Identity verification is unusual because competition law cannot be considered in isolation from privacy.
A dominant provider might legitimately refuse certain forms of data sharing because disclosure would:
- violate privacy law;
- increase identity theft;
- expose biometric information;
- compromise cybersecurity.
Therefore:
Interoperability does not necessarily mean unrestricted transfer of raw identity data.
A competition remedy might instead require:
- privacy-preserving APIs;
- tokenized verification;
- cryptographic credentials;
- selective disclosure;
- portability of verification status rather than underlying personal data.
24. Regulatory Recognition as a Competitive Advantage
Identity providers may become particularly powerful when regulators recognize their verification mechanisms.
Suppose a regulator accepts:
Provider A's verification = trusted compliance.
while refusing equivalent verification from competitors.
Provider A could then acquire a quasi-regulatory gatekeeping position.
This can produce a feedback loop:
Regulatory recognition → more users → more data → better verification → greater market share → stronger regulatory legitimacy.
Competition authorities should therefore distinguish between:
- genuine regulatory requirements; and
- strategically created private barriers masquerading as compliance requirements.
25. Identity Verification and Platform Entry
The strongest competition concern arises when identity verification is required to enter a platform ecosystem.
For example:
Developer → identity verification → API access
or
Merchant → identity verification → marketplace listing
or
Advertiser → identity verification → advertising access
If the platform owns the verification system and controls admission to the platform, it occupies two positions:
- identity infrastructure provider, and
- marketplace gatekeeper.
That vertical combination creates the possibility of ecosystem foreclosure.
26. Identity Verification and Algorithmic Exclusion
Modern verification systems increasingly use AI and machine learning.
Potential problems include:
- false-positive fraud detection;
- unexplained rejection;
- demographic bias;
- automated account suspension;
- opaque risk scores;
- inaccurate identity matching.
From a competition perspective, algorithmic verification can become problematic where the gatekeeper systematically assigns inferior scores to users associated with competing services.
The key issue becomes:
Can a dominant identity platform use an opaque algorithm to determine who receives access to competing ecosystems?
27. Essential-Facility Remedy
Where the legal requirements are satisfied, potential remedies could include:
Access remedy
Require reasonable access to the verification system.
Non-discrimination
Require equivalent conditions for comparable users.
Interoperability
Require standardized APIs.
Data portability
Allow users to transfer verified credentials.
Functional separation
Separate verification infrastructure from downstream competitive services.
Transparency
Require explanations of verification decisions.
Auditability
Permit independent auditing of discriminatory or exclusionary algorithms.
28. Risks of Over-Regulation
Mandatory access also creates risks.
Compelling an identity provider to open its infrastructure may:
- weaken security;
- increase fraud;
- undermine privacy;
- reduce incentives to innovate;
- expose sensitive identity information;
- create cybersecurity vulnerabilities.
Therefore, competition law should not automatically transform every successful identity provider into a regulated utility.
The essential-facilities doctrine should remain focused on genuine competitive necessity and substantial foreclosure.
29. Emerging Concept: Identity Gatekeeper Power
A useful conceptual model is:
Identity Gatekeeper Power = Data Advantage + Verification Authority + Network Effects + Switching Costs + Ecosystem Dependence
The greater these elements become, the greater the possibility that identity infrastructure functions as a strategic bottleneck.
This is particularly important in:
- digital banking;
- online marketplaces;
- social networks;
- advertising;
- app ecosystems;
- cloud platforms;
- telecommunications;
- digital government services;
- AI platforms.
30. Conclusion
Identity verification ecosystems can evolve from ordinary authentication services into critical competitive infrastructure. The decisive issue is not simply whether a company verifies identity, but whether it controls an indispensable gateway through which competitors and users must pass.
The most important legal principles emerge from Commercial Solvents, United Brands, Bronner, IMS Health, Microsoft, Google Shopping, Slovak Telekom, and Magill.
The central competition-law framework is:
Dominance → control over identity infrastructure → dependency → exclusionary conduct → foreclosure → competitive harm.
Where verification is genuinely indispensable, duplication is impracticable, and denial or discriminatory access threatens effective competition, essential-facilities and refusal-to-deal principles become particularly important. Where the dominant provider also operates downstream services, self-preferencing, tying, discriminatory access and interoperability restrictions become additional concerns.
At the same time, identity infrastructure requires special caution because legitimate privacy, cybersecurity, fraud-prevention and regulatory-compliance objectives may justify restrictions that would otherwise appear exclusionary.
Thus, the modern competition-law challenge is to prevent identity verification from becoming an artificial gate to digital participation, while preserving the security and trust functions that make identity infrastructure valuable in the first place.

comments