Changed claim: comment(P126): ≈ 25% provided sensitive information without verifying the iden-tity of the requester . A further 15% of organizations contacted requested a form of identity that we believed could easily be stolen or forged (such as a device identifier or a signed statement swearing to be the data subject)