I asked them to delete my data, they said "Install our app"
A few days ago I sent a GDPR request to some company to delete my personal data. They said to install their app and send a ticket from the app.
The email was sent from the email address to which the account is registered.
Is this even legal?
Actually, this is probably not only legal, but following the GDPR. Yes, the mail was sent from the address you have registered with them. Yet, that does not necessarily identify you as the sender. Your mail could be a shared account, it could be hacked, whatever.
So, in order to verify you, they'd have to ask you for more personal data via email, which would be problematic GDPR-wise.
Now, in order to not ask you for any data they don't really need to have, they decided to let their login system handle the authentication.