Name Matching & Revision (Part 3)

Our second article about name matching and revision dealt with minimizing the risk of false negatives. This third article is about measuring the risk in practice. This is frequently done by testing two or three names, but this kind of layperson’s test has its pitfalls when it comes to compliance. Although this test is non-representative, it can still have relevance for compliance. A layperson’s test is most suitable for checking whether a collection takes into account the recent removal of sanctions. This is not a question of minimizing risk, however, but of checking the fundamental operating efficiency of a name matching system.

Both matches (positives) and non-matches (negatives) need to be taken into account for a risk assessment. We must also differentiate between correct matches (true positives) and incorrect matches (false positives), as well as between correct non-matches (true negatives) and incorrect non-matches (false negatives). We want as few false negatives as possible, as these mean that potential risks are not being recognized. However, a high number of false positives is also undesirable if a lack of resources means that these cannot be verified and remain open issues.

Eurospider possesses a comprehensive list of pairs of different names that refer to the same person. For example, “Boris Yeltsin” and “Boris Nikolayevich Eltsin” both refer to the former Russian president. There is a significant difference between these two names, creating a challenge for any name matching system.

Data Protection Act

The Swiss Data Protection Act underwent a complete revision in 2020, and its new version took effect on September 1, 2023, along with the new Data Protection Ordinance (DPO). The revision itself is complete, but its practical application continues to evolve. The topic of AI is particularly relevant: On May 8, 2025, the FDPIC confirmed that the DPA is technology-neutral and applies directly to all AI applications. In practice, this means, among other things, that users must know whether they are interacting with AI (transparency requirement, Art. 19), and that a data protection impact assessment is mandatory in cases of high risk—such as profiling or facial recognition (Art. 22). The Federal Office of Justice (FOJ) is drafting a consultation document on AI regulation to be completed by the end of 2026. With this, Switzerland will implement the Council of Europe's AI Convention.

Eurospider Information Technology AG
Winterthurerstrasse 92
8006 Zürich

 

Cookies make it easier for us to provide you with our services. With the usage of our services you permit us to use cookies.
More information Ok Decline