GDPR Recital 64: Identity Verification

The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers. A controller should not retain personal data for the sole purpose of being able to react to potential requests.

Source text: EUR-Lex, Official Journal consolidated HTML (CELEX 32016R0679). Recital short titles are editorial labels from gdpr-info.eu editorial short titles (not official). Cross-checked against gdpr-info.eu (independent reproduction).