ISTM the system you describe could lead to more data collection. I.e., a site like HN knows emails, pseudonyms, and posting history. What if they got a request like this from someone who claimed not to have access to the email they used to sign up? HN couldn't possibly comply.
Maybe that doesn't matter because posting history is public. One could easily envision another site that had some non-public data associated with email address, pseudonym, and no other PII. That site definitely violates the requirements you describe.
> ISTM the system you describe could lead to more data collection.
It really doesn't. What it does is attempt to gatekeep data (which these days is a huge risk) collection to organisations that are competent. You always have the option of not collecting data if you don't want to take that responsibility.
> What if they got a request like this from someone who claimed not to have access to the email they used to sign up? HN couldn't possibly comply
They wouldn't have to. If you're requesting your data from a company, you have to burden of proof that you are in fact the person about whom you're requesting the data. If you cannot prove it, you cannot get the data.
Maybe that doesn't matter because posting history is public. One could easily envision another site that had some non-public data associated with email address, pseudonym, and no other PII. That site definitely violates the requirements you describe.