1The controller should use all reasonable measures to verify the identity of a data subject who requests access, in particular in the context of online services and online identifiers. 2A controller should not retain personal data for the sole purpose of being able to react to potential requests.