The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers. A controller should not retain personal data for the sole purpose of being able to react to potential requests.

This recital of the General Data Protection Regulation clarifies article 15 GDPR (Right of access by the data subject).*

