Earlier quoted context omitted.
Im Germany you generally need to send a real letter (or a fax) and it needs to contain your signature. "Authentication" for this is provided by harsh penalties on signature forgeries. Also, you'd only get one single data point and everything really sensitive has address data and they will* send their response to a known address.
If all information you have about a person is their email (and usage data) then this won’t make a difference though... The GDPR considers even an IP address personal data, even if you have no way to correlate it with a real person. So where does this leave you if you have to respond? Imagine I’m sending a request for information from a given IP address, requesting all the personal information you hold on that IP. I k…
Note that he's propably still risking jail time over this.