rec_64
GDPR
(64) The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers. A controller should not retain personal data for the sole purpose of being able to react to potential requests.
← rec_63 · All articles · rec_65 →
Source: EUR-Lex (Cellar) · retrieved 2026-09-25 · Text as adopted (Official Journal); later amendments are not incorporated in this text.