The Digital Governance Standards Institute (DGSI) has announced the release of the second edition of its national standard on the use of biometrics for authentication, which addresses considerations such as privacy, security, consent, transparency, accountability, and the protection of biometric information.
Amid the rising integration of biometric technologies into digital identity, authentication, and access systems, DGSI explained that organizations should consider the accuracy of these technologies and their ability to protect people, combat emerging attacks, and ensure trusted identity verification.
In its news release, DGSI also stressed the importance of safeguarding biometric information across its lifecycle through proper access controls, privacy impact assessments, audit trails, secure deletion protocols, and encrypted biometric templates if applicable.
DGSI explained that the national standard (CAN/DGSI 120) seeks to set minimum requirements for utilizing biometrics and to offer technology-agnostic guidance for organizations to implement biometric authentication in a responsible manner.
Changes in second edition of standard on biometrics use
Amid evolving security risks and established international practices, DGSI explained that the recent additions to the national standard aim to help organizations understand the wider context for biometric system implementation.
DGSI shared that the updated standard (CAN/DGSI 120:2026) introduces guidance to tackle the shifting technical and security landscape of biometric authentication, as well as emerging threats. Specifically, the new guidance covers:
- strong authentication utilizing biometric binding, including guidance regarding combining biometrics with public key cryptography and secure device possession
- biometric performance metrics, including requirements to assess and monitor false acceptance, false rejection, enrolment, and acquisition performance
- presentation attack detection (PAD) and attack resistance, including safeguards against spoofing, replay attacks, synthetic biometric inputs, and threats generated by artificial intelligence (AI) or based on deepfakes
- sensor and capture integrity, with requirements aiming to keep biometric capture processes safe from data injection, manipulation, and compromised devices or environments
In its news release, DGSI also noted that the revised standard adds informative annexes on:
- credential authentication
- functional uses of biometrics
- threats to biometric systems
- related biometric standards and frameworks
Revised national standard’s development
DGSI shared that its Technical Committee 15 on Biometrics, which has over 25 members, developed the updated national standard.
“DGSI extends its gratitude to the Technical Committee and all stakeholders who contributed their expertise and feedback to the development of this new edition,” DGSI’s news release stated.
More news from Digital Governance Standards Institute
Here are some other recent news stories from DGSI.
On Aug. 27, 2025, DGSI announced the publication of a first-of-its-kind national standard in Canada, providing implementation guidance and minimum requirements for responsibly designing, implementing, and using technologies that estimate or verify a person’s age.
On Apr. 15, 2025, DGSI urged stakeholders to participate in its maintenance review of “CAN/DGSI 120:2024 – Use of Biometrics for Authentication,” a national standard providing guidance for the responsible and secure use of biometric technologies.
Enjoy this story? Read the latest technology news on the main page!


