Attention to biometric data security has become urgent for protecting user privacy. In the context of the Protection of Data Privacy (PDP) Law, biometric data are classified as specific data, requiring extra protection due to their unique, non-exchangeable characteristics. This study uses a normative approach, analyzing legislation and legal comparisons through regional and international regulations, to examine two issues: the position of biometric data as specific data under the Electronic Information and Transactions Law and PDP Law, and the technical solutions through privacy by design to protect biometric data. The research findings are: (1) Biometric data are correlated with privacy and personal rights, classifying them as specific data. Their use for public and private interests raises the potential for privacy violations. (2) Technical solutions through privacy by design can begin with implementing consent at the registration stage by personal data controllers, ensuring the processing of biometric data achieves specific purposes.