We report in this article on name matching experiments, in particular on hit rates. We matched a sample of 631’845 fictitious customers aigainst PEP profiles (Politically Exposed Person).  A hit is a match between a customer and at least one PEP profile independent of the correctness of the match. A correct match (also called true positive) means that the customer is eventually the PEP described in the profile. A false match (also called false positive) means that the customer and the PEP are two different persons with very similar or identical names. The hit rate is the portion of customers for which a match was found. The chart shows how the hit rate is affected by taking into account date of birth and country information.

The names of the fictitious customers including their date of birth and their nationality have been extracted from en.wikipedia.org. The PEP profiles do not include the profiles of relatives and close associates.

Matching Results 384

The hit rates shown in the charts above correspond to the following configurations:

Only politically exposed persons were considered for which their date of birth and their nationality are known, i.e. only high quality profiles (hqp) of PEP. Date of birth (dob) and country (nationality and country of residence) were required to match.

Date of birth (dob) and country (nationality and contry of residence) were required to match. In the case of missing dob or country information, the match was not excluded.

Date of birth (dob) and country (nationality and contry of residence) were *not* required to match.

Nothing but the family name were required to match. Thus, many matches are obtained with different first names, dates of birth, and country codes.

The last hit rate was included, because we are occasionally asked, why eCPM does not support checks without first names. From the very high hit ratio it is evident that checking without first names is not recommended.

Data Protection Act

The Swiss Data Protection Act underwent a complete revision in 2020, and its new version took effect on September 1, 2023, along with the new Data Protection Ordinance (DPO). The revision itself is complete, but its practical application continues to evolve. The topic of AI is particularly relevant: On May 8, 2025, the FDPIC confirmed that the DPA is technology-neutral and applies directly to all AI applications. In practice, this means, among other things, that users must know whether they are interacting with AI (transparency requirement, Art. 19), and that a data protection impact assessment is mandatory in cases of high risk—such as profiling or facial recognition (Art. 22). The Federal Office of Justice (FOJ) is drafting a consultation document on AI regulation to be completed by the end of 2026. With this, Switzerland will implement the Council of Europe's AI Convention.

Eurospider Information Technology AG
Winterthurerstrasse 92
8006 Zürich

 

Cookies make it easier for us to provide you with our services. With the usage of our services you permit us to use cookies.
More information Ok Decline