Updated National Standard Strengthens Guidance for Secure and Responsible Biometric Authentication

The Digital Governance Standards Institute (DGSI) is pleased to announce the publication of the second edition of CAN/DGSI 120:2026, Use of biometrics for authentication.

As biometric technologies become increasingly integrated into digital identity, authentication and access systems, organizations must consider not only how accurately these technologies perform, but also how they protect individuals, resist emerging attacks and support trusted identity verification.

CAN/DGSI 120 establishes minimum requirements for the use of biometrics and provides technology-agnostic guidance to help organizations implement biometric authentication responsibly. The Standard addresses key considerations including privacy, security, consent, transparency, accountability and the protection of biometric information.


Key Updates in the Second Edition

The second edition introduces significant new guidance to address the evolving technical and security environment surrounding biometric authentication, including:

  • Strong authentication using biometric binding, including guidance on combining biometrics with public key cryptography and secure device possession.
  • Biometric performance metrics, including requirements for measuring and monitoring false acceptance, false rejection, enrolment and acquisition performance.
  • Presentation Attack Detection (PAD) and attack resistance, including protections against spoofing, replay attacks, synthetic biometric inputs and emerging AI-generated or deepfake-based threats.
  • Sensor and capture integrity, with requirements designed to protect biometric capture processes against data injection, manipulation and compromised devices or environments.

The new edition also introduces informative annexes covering credential authentication, functional uses of biometrics, threats to biometric systems, and related biometric standards and frameworks. Together, these additions provide organizations with broader context for implementing biometric systems while considering evolving security risks and established international practices.

The Standard also reinforces the importance of protecting biometric information throughout its lifecycle, including appropriate access controls, privacy impact assessments, encryption of biometric templates where applicable, audit trails and secure deletion protocols.

CAN/DGSI 120:2026 was developed by DGSI Technical Committee 15 (TC 15) on Biometrics, comprising more than 25 thought leaders and experts. DGSI extends its gratitude to the Technical Committee and all stakeholders who contributed their expertise and feedback to the development of this new edition.

You can download the new edition of this standard at CAN/DGSI 120.


About the Digital Governance Standards Institute

The Digital Governance Standards Institute develops digital technology governance standards fit for global use. The Institute works with experts, as well as national and global partners and the public to develop national standards that reduce risk to Canadians and Canadian organizations adopting and using innovative digital technologies in today’s digital economy. The Institute is an independent division of the Digital Governance Council. To learn more about the organization and its initiatives, visit www.dgc-cgn.org or contact info@dgc-cgn.org.

Share This Article

Scroll to Top

This website uses cookies to improve your experience. By using our website you agree to our Cookie Policy

This website uses cookies to improve your experience. By using our website you agree to our Cookie Policy