Identity Verification Platforms And Onboarding Gatekeeping

 

Identity Verification Platforms and Onboarding Gatekeeping

1. Introduction

Identity verification platforms are digital systems that determine whether an individual or business can establish an account, access a service, complete a transaction, or participate in a digital ecosystem. They may perform document verification, biometric authentication, liveness detection, database matching, sanctions screening, fraud detection, device analysis, credit or risk assessment, and continuous identity monitoring.

Onboarding gatekeeping arises when control over these verification systems becomes sufficiently important that a platform can effectively determine who may enter a market or digital ecosystem and on what conditions.

From a competition-law perspective, the critical question is not merely whether identity verification is a technical service. It is whether a verification provider has acquired market power over an indispensable or strategically important gateway through which competitors, merchants, consumers, financial institutions, or other businesses must pass.

The problem can therefore be framed as:

Control over identity verification → control over onboarding → control over participation → potential control over competition.

This can raise issues under abuse-of-dominance rules, essential-facility principles, refusal to deal, discriminatory access, tying, self-preferencing, exclusionary technical standards, interoperability restrictions, data advantages, and exploitative contractual conditions.

2. Meaning of Identity Verification Platforms

An identity verification platform generally performs several functions:

  1. Identity capture – collecting names, addresses, government identifiers, photographs or biometric information.
  2. Document verification – checking passports, identity cards, driving licences and other credentials.
  3. Biometric verification – facial recognition, fingerprints, voice or other biometric comparisons.
  4. Liveness detection – determining whether a person is physically present rather than using a photograph, video or synthetic identity.
  5. Database verification – matching information against public or private databases.
  6. Fraud detection – detecting identity theft, synthetic identities, duplicate accounts and anomalous behaviour.
  7. Risk scoring – assigning risk classifications to prospective users.
  8. AML/KYC screening – checking sanctions, politically exposed persons and other regulatory databases.
  9. Continuous authentication – periodically rechecking identity after onboarding.
  10. API-based verification – providing identity-verification functions to banks, platforms, marketplaces and applications.

The competitive significance increases where many downstream businesses rely upon the same verification infrastructure.

3. What Is Onboarding Gatekeeping?

Onboarding gatekeeping occurs when a firm can determine whether another person or business can enter a digital service or market.

For example:

Consumer → identity-verification platform → financial platform → access to financial service

or:

Merchant → verification platform → marketplace → access to customers

The verification provider therefore occupies an upstream position.

If alternative verification providers are readily available, this may simply be ordinary competition.

The concern becomes much greater where:

  • switching costs are high;
  • verification data are proprietary;
  • regulatory certification is difficult to obtain;
  • the platform has a large installed base;
  • downstream firms are technically integrated into its APIs;
  • verification results are accepted by regulators or major institutions;
  • the provider possesses unique datasets;
  • fraud models improve through network effects;
  • customers cannot easily port their verification history;
  • the platform controls an important authentication standard.

4. Competition-Law Theory of Onboarding Gatekeeping

The central competition concern is gateway power.

A firm may not directly compete in the downstream market but may nevertheless control an input necessary for participation.

For example:

Identity platform → verification decision → onboarding approval → access to marketplace.

If the identity platform also operates the downstream marketplace, conflicts become particularly serious.

It could potentially:

  • verify its own users more quickly;
  • impose higher verification standards on rivals;
  • delay verification of competing platforms;
  • deny API access;
  • provide inferior verification accuracy to rivals;
  • use verification data to compete downstream;
  • impose exclusivity;
  • tie verification to another service;
  • refuse interoperability;
  • discriminate between similarly situated customers.

5. Relevant Market Definition

Several markets may potentially be relevant.

A. Identity-verification services market

The market may include providers of:

  • KYC services;
  • biometric verification;
  • document authentication;
  • identity APIs;
  • fraud detection;
  • digital identity credentials.

B. Digital identity infrastructure

A broader market may encompass:

  • authentication;
  • identity management;
  • credential issuance;
  • verification;
  • access management.

C. A narrow gateway market

In exceptional circumstances, the relevant market might be defined around a particular identity-verification infrastructure if alternatives are not commercially or technically substitutable.

D. Downstream market

Competition authorities must also examine the market being affected.

Examples include:

  • online marketplaces;
  • financial services;
  • app ecosystems;
  • employment platforms;
  • digital healthcare;
  • ride-hailing;
  • e-commerce;
  • cryptocurrency services.

6. When Does Verification Become an Essential Input?

The concept of an essential facility is particularly important.

An identity-verification system is more likely to be regarded as strategically indispensable where:

  1. Access is objectively necessary for downstream participation.
  2. There is no realistic substitute.
  3. Replication is technically or economically impracticable.
  4. The verification provider controls access.
  5. denial would substantially impair competition.
  6. the provider itself participates in the downstream market.

However, mere usefulness is insufficient.

A competitor should generally not obtain compulsory access simply because another verification provider is cheaper, more accurate or commercially attractive.

The strongest case arises where the identity gateway is genuinely indispensable.

7. Refusal to Onboard

A dominant identity-verification provider may potentially engage in unlawful exclusion where it refuses to verify a rival's customers without objective justification.

Possible examples include:

  • refusing API access;
  • terminating a verification agreement;
  • denying credentials;
  • refusing to recognize another identity standard;
  • blocking verification requests;
  • systematically rejecting a rival's users.

The analysis depends upon whether the refusal:

  • eliminates effective competition;
  • concerns an indispensable input;
  • lacks objective justification;
  • causes downstream foreclosure.

8. Discriminatory Verification Standards

Gatekeeping may also occur through differential verification requirements.

Suppose:

Platform A receives automated verification within seconds.

while:

Platform B's customers are subjected to repeated manual checks and high rejection rates.

If the difference has no legitimate fraud, security or regulatory explanation, competition authorities may investigate discriminatory access.

This becomes particularly problematic where the identity provider also operates Platform A.

9. Self-Preferencing

A vertically integrated identity platform may possess the ability and incentive to favour its affiliated downstream business.

Potential conduct includes:

  • faster verification;
  • higher approval rates;
  • preferential API limits;
  • better fraud-detection models;
  • access to richer identity attributes;
  • lower verification prices;
  • privileged technical support.

The competition problem is not simply preferential treatment.

The critical question is whether the preferential treatment forecloses rivals or materially disadvantages them.

10. Tying and Bundling

A dominant identity provider could potentially require customers to purchase another service as a condition of obtaining identity verification.

For example:

"To access our identity-verification API, you must also use our authentication infrastructure."

or:

"A marketplace must use our payment service if it wants access to our verification system."

Such arrangements can potentially constitute tying or bundling where the relevant legal requirements are satisfied.

11. Data Advantages and Identity Verification

Identity platforms can accumulate enormous datasets.

Verification generates information concerning:

  • identity attributes;
  • device characteristics;
  • transaction history;
  • fraud patterns;
  • behavioural signals;
  • biometric matches;
  • account relationships.

This creates a feedback loop:

More customers → more verification data → better fraud detection → better service → more customers.

This can generate a data-driven network effect.

Competitors may therefore find it difficult to reproduce the incumbent's accuracy even if the underlying verification technology is theoretically replicable.

12. Network Effects

Identity systems exhibit several network effects.

Direct effects

More users make the identity network more useful.

Indirect effects

More merchants and institutions accepting an identity credential make it more valuable to users.

Data network effects

More verification events produce more data, which can improve algorithms.

Institutional network effects

Once banks, governments, marketplaces and large technology companies accept a verification standard, new entrants may find it difficult to establish alternatives.

This can create identity infrastructure lock-in.

13. Switching Costs

Switching may be difficult because customers have integrated:

  • APIs;
  • SDKs;
  • databases;
  • fraud rules;
  • compliance workflows;
  • customer records;
  • identity credentials;
  • verification histories.

A business might therefore technically be able to switch but find migration commercially prohibitive.

Competition law can distinguish between formal availability of alternatives and effective substitutability.

14. Interoperability and Portability

Interoperability is particularly important.

If identity-verification platforms refuse to communicate with competing identity systems, users may be forced to establish separate verification records.

This can produce:

verification duplication → higher onboarding costs → reduced multi-homing → stronger incumbent position.

Portability of verified identity attributes can reduce these barriers.

However, privacy, cybersecurity, fraud and data-protection concerns can legitimately restrict portability.

Thus, competition law must balance contestability against security.

15. Algorithmic Gatekeeping

Modern identity platforms increasingly use AI.

Algorithms may determine:

  • whether documents are authentic;
  • whether a face matches an identity document;
  • whether a user appears fraudulent;
  • whether a transaction should be blocked;
  • whether enhanced verification is required.

This creates a new competition issue:

Who controls the algorithm that determines market entry?

A dominant provider could theoretically embed discriminatory rules into its automated verification architecture.

Even without explicit discriminatory intent, systematic model effects may disadvantage competitors.

16. False Positives and Competitive Harm

A particularly important issue is false-positive verification failure.

Suppose an incumbent's customers experience:

1% verification failure

while a rival's customers experience:

12% verification failure.

If the difference results from technical or commercial discrimination rather than legitimate risk management, the verification system may function as an exclusionary instrument.

The competitive impact can be significant because users frequently abandon onboarding after repeated failures.

Thus:

technical error can become a competitive barrier when controlled by a dominant gateway.

17. Regulatory Certification as a Barrier to Entry

Identity providers may need:

  • government approval;
  • security certifications;
  • audit compliance;
  • data-protection compliance;
  • financial-sector accreditation;
  • biometric-security certification.

These requirements may be legitimate.

But an incumbent can acquire substantial structural advantages if:

  • certification is difficult to obtain;
  • the incumbent participates in standard-setting;
  • the incumbent influences certification criteria;
  • proprietary technology becomes effectively mandatory.

Competition authorities may therefore distinguish legitimate regulatory barriers from strategic regulatory or technical foreclosure.

18. Six Important Case Laws

The following cases do not all concern modern identity-verification platforms directly. They provide the principal competition-law doctrines that can be applied to identity-verification gatekeeping.

1. Commercial Solvents Corp. v. Commission

The Court of Justice of the European Communities established an important principle concerning refusal to supply.

A dominant undertaking controlling an important input could not simply discontinue supply where doing so could eliminate competition in a downstream market.

Relevance

For identity verification:

dominant verification provider → essential verification input → downstream rival → refusal of access.

The case supports scrutiny where control over an upstream input is used to exclude downstream competitors.

2. United Brands Co. v. Commission

Case 27/76, United Brands v Commission

United Brands is foundational for understanding dominance and market power.

The Court examined whether a powerful undertaking could use its position to impose conditions on customers and competitors.

Relevance

An identity-verification provider with substantial market power could potentially be assessed under the same broad dominance framework where its commercial practices exploit or exclude customers.

The case is especially useful for understanding:

  • market power;
  • dependence;
  • commercial freedom;
  • discriminatory conduct;
  • abuse of dominance.

3. Bronner v. Mediaprint

Case C-7/97, Oscar Bronner GmbH & Co. KG v Mediaprint

Bronner is one of the leading EU cases concerning refusal to provide access to infrastructure.

The Court imposed demanding conditions before a facility can be considered indispensable for purposes of compulsory access.

Relevance to identity verification

This is particularly important.

A rival should not automatically obtain access to a dominant verification platform merely because the platform is technologically superior or economically convenient.

The Bronner framework asks whether:

  • access is indispensable;
  • there is no real alternative;
  • duplication is impossible or excessively difficult;
  • refusal risks eliminating effective competition.

Thus, Bronner provides an important limiting principle against over-expanding the essential-facility doctrine.

4. IMS Health GmbH & Co. KG v. Commission

Cases C-418/01 P and related proceedings

IMS Health concerned access to an intellectual-property-protected system that had become highly important to competitors.

The Court's reasoning reinforced the exceptional nature of compulsory access while recognizing circumstances in which refusal to license/access protected infrastructure could amount to abuse.

Relevance

Identity platforms may possess:

  • proprietary identity graphs;
  • verification databases;
  • technical standards;
  • authentication protocols;
  • proprietary APIs.

IMS Health therefore provides an important analytical framework for determining when proprietary identity infrastructure can become sufficiently indispensable to attract competition-law intervention.

5. Microsoft Corp. v. Commission

Case T-201/04

The European Commission and General Court examined Microsoft's refusal to provide interoperability information to competitors.

The case is particularly important for digital markets because interoperability information can become a competitive bottleneck.

Relevance to identity verification

Identity systems are heavily dependent upon interoperability.

A dominant platform might restrict:

  • API access;
  • authentication protocols;
  • identity attributes;
  • interoperability documentation;
  • credential recognition.

Microsoft demonstrates how technical interoperability restrictions can have competitive significance where they substantially impede rivals.

6. Google Shopping

Google Search (Shopping), Case AT.39740

The European Commission found that Google had abused its dominant position by favouring its comparison-shopping service in general search results.

The case is important for the concept of self-preferencing.

Relevance

Consider an identity platform that also operates a downstream marketplace.

It might theoretically:

  • prioritize its own users;
  • give its affiliated marketplace superior verification;
  • provide competitors with slower verification;
  • offer richer identity information to its own business.

Google Shopping therefore supplies an important conceptual framework for analysing discriminatory treatment by a vertically integrated digital gateway.

19. Additional Relevant Case: Slovak Telekom

Case C-165/19 P, Slovak Telekom

The case concerns access conditions and exclusionary conduct involving telecommunications infrastructure.

Relevance

Identity verification can similarly constitute infrastructure where downstream businesses depend upon access to an upstream technical system.

The case helps illustrate how competition authorities may analyse:

  • access conditions;
  • foreclosure;
  • infrastructure dependence;
  • contractual restrictions.

20. Additional Relevant Case: MEO v. GDA

Case C-525/16, MEO

MEO is important for discriminatory pricing under EU competition law.

The Court emphasized that differential treatment is not automatically abusive; the assessment must consider whether the conduct places trading partners at a competitive disadvantage.

Relevance

An identity platform charging:

  • Bank A: ₹1 per verification
  • Bank B: ₹8 per verification

would not automatically violate competition law.

The critical question would be whether the differential treatment produces competitive disadvantage without objective justification.

21. Indian Competition-Law Perspective

In India, identity-verification gatekeeping can potentially engage Section 4 of the Competition Act, 2002, particularly where an enterprise enjoys a dominant position in a relevant market.

Potential theories include:

Section 4(2)(a)

Unfair or discriminatory conditions or prices.

Section 4(2)(b)

Limiting or restricting:

  • technical development;
  • production;
  • markets;
  • services.

Section 4(2)(c)

Denial of market access.

This provision is especially relevant to onboarding gatekeeping.

Section 4(2)(d)

Tying or requiring unrelated obligations.

Section 4(2)(e)

Using dominance in one relevant market to enter or protect another market.

This is particularly relevant where an identity-verification company also operates a downstream marketplace or financial platform.

22. Competition Harm Through Denial of Market Access

The most direct theory is:

Dominant verification provider

↓

Refuses verification/API access

↓

Rival cannot onboard customers

↓

Rival loses scale

↓

Rival becomes less attractive

↓

Incumbent gains further market power

This creates a foreclosure feedback loop.

23. Identity Verification as a Two-Sided Platform

Many identity platforms operate as intermediaries between:

  • users;
  • businesses;
  • financial institutions;
  • governments;
  • marketplaces.

Consequently, market power can operate across multiple sides.

For example:

Users → identity network ← businesses

The more businesses accepting the identity credential, the more valuable the system becomes to consumers.

The more consumers using the system, the more attractive it becomes to businesses.

This can create two-sided network effects.

24. Lock-In Through Verified Identity Histories

An especially significant emerging concern is the creation of a portable identity history.

Suppose a user has:

  • five years of verification history;
  • trusted-device history;
  • fraud reputation;
  • completed KYC;
  • verified credentials.

If the user cannot transfer these attributes to another provider, the incumbent gains a substantial advantage.

The result is:

identity verification → reputation accumulation → switching cost → lock-in.

This may be more important competitively than the initial verification itself.

25. Identity Verification and Ecosystem Control

The strongest gatekeeping risk occurs when identity verification is integrated into a broader ecosystem.

For example:

Identity → payment → marketplace → advertising → financial services

A firm controlling identity can potentially influence participation throughout the ecosystem.

This produces vertical leverage.

The competition-law concern is not simply monopoly over identity verification but the possibility of leveraging identity dominance into adjacent markets.

26. Legitimate Business Justifications

Competition authorities must recognize legitimate reasons for verification restrictions.

These may include:

  • fraud prevention;
  • cybersecurity;
  • AML compliance;
  • sanctions compliance;
  • protection of minors;
  • privacy;
  • biometric security;
  • regulatory requirements;
  • preventing identity theft.

Therefore, an identity provider should not be condemned merely because it rejects users or imposes different verification requirements.

The key question is whether the restriction is:

necessary, proportionate, objectively justified and consistently applied.

27. Possible Competition Remedies

Authorities could consider several remedies.

1. Non-discrimination

Require equivalent verification access for similarly situated businesses.

2. Interoperability

Require reasonable interoperability with competing identity systems.

3. API access

Prevent unjustified denial or degradation of verification APIs.

4. Data portability

Permit lawful portability of verified identity attributes.

5. Transparency

Require disclosure of material verification criteria.

6. Auditability

Permit independent auditing of discriminatory algorithmic outcomes.

7. Separation

In particularly serious cases, structural separation between verification infrastructure and downstream businesses may be considered.

8. Prohibition of tying

Prevent verification from being conditioned upon unrelated services.

28. Competition Risks from AI-Based Verification

AI creates additional concerns because the verification system may become opaque.

A provider could claim:

"The algorithm rejected the applicant."

If competitors cannot determine why rejection rates differ, it becomes difficult to detect discrimination.

Therefore, competition enforcement may require examination of:

  • model performance;
  • error rates;
  • rejection rates;
  • false-positive rates;
  • API latency;
  • verification accuracy;
  • customer-level treatment;
  • model updates.

This does not necessarily mean disclosure of source code. Auditable outcomes and independent testing may be sufficient.

29. Failure Taxonomy

Identity-verification gatekeeping risks can be divided into:

RiskCompetitive effect
Refusal to verifyDenial of market access
Excessive verification feesRaises rivals' costs
Slow verificationCustomer diversion
API throttlingTechnical foreclosure
Data exclusionWeakens rival verification
Self-preferencingFavours affiliated service
TyingExtends dominance
Exclusive contractsPrevents multi-homing
Interoperability restrictionsRaises switching costs
Algorithmic discriminationUnequal access
Data portability restrictionsIdentity lock-in
Certification controlEntry barriers

30. Overall Legal Test

A competition authority examining identity-verification gatekeeping would likely proceed through the following questions:

Step 1 — Define the relevant market

What identity-verification or identity-infrastructure service is being supplied?

Step 2 — Establish dominance

Does the provider possess substantial market power?

Step 3 — Identify the gateway

Does verification determine access to a downstream market?

Step 4 — Examine alternatives

Can customers realistically switch to another provider?

Step 5 — Determine indispensability

Is the verification infrastructure genuinely essential or merely advantageous?

Step 6 — Identify conduct

Is there:

  • refusal to deal;
  • discriminatory access;
  • tying;
  • self-preferencing;
  • interoperability restriction;
  • excessive pricing;
  • exclusivity?

Step 7 — Assess foreclosure

Does the conduct substantially restrict competitors' ability to compete?

Step 8 — Examine justification

Are security, privacy, fraud-prevention or regulatory reasons legitimate and proportionate?

Step 9 — Consider remedies

Would interoperability, non-discrimination, portability or other remedies restore contestability without undermining security?

31. Key Case-Law Principles at a Glance

CasePrincipleIdentity-platform relevance
Commercial SolventsRefusal to supplyDenial of verification access
United BrandsDominance and abusive conductGateway power
BronnerIndispensability for accessEssential identity infrastructure
IMS HealthExceptional compulsory accessProprietary identity databases/systems
MicrosoftInteroperability and foreclosureIdentity APIs and protocols
Google ShoppingSelf-preferencingFavouring affiliated platforms
Slovak TelekomInfrastructure/access foreclosureVerification infrastructure
MEOCompetitive disadvantage from discriminationDifferential verification pricing

32. Conclusion

Identity verification platforms can become powerful competition-law gatekeepers when they control a critical route through which businesses or consumers must pass before participating in digital markets.

The greatest concern arises where an identity provider combines:

dominant verification infrastructure + unique data + network effects + high switching costs + downstream commercial interests.

At that point, identity verification is no longer merely a compliance function. It can become a strategic competitive bottleneck.

The most important doctrines are refusal to deal, essential facilities, interoperability, discriminatory access, self-preferencing, tying, leveraging and denial of market access.

The cases of Commercial Solvents, United Brands, Bronner, IMS Health, Microsoft and Google Shopping provide particularly useful doctrinal foundations. Their application to identity verification must nevertheless remain sensitive to legitimate requirements of privacy, cybersecurity, fraud prevention and regulatory compliance.

The emerging competition-law question is therefore not simply "Who verifies identity?", but:

"Who controls the gateway through which identity verification determines who is permitted to participate in the digital economy?

LEAVE A COMMENT