The increasing use of biometric authentication technologies, including facial recognition, fingerprint scanning, and iris recognition, has become a common feature of digital platforms for identity verification and service security. Biometric data are classified as specific personal data requiring a higher level of legal protection because they are permanent and cannot be replaced if compromised. This study aims to examine the legal framework, forms of protection, and effectiveness of Indonesian law in safeguarding users’ privacy rights concerning the processing of biometric data. This research employs a normative juridical method using statutory and conceptual approaches, analyzed through a prescriptive-qualitative method. The findings indicate that the Personal Data Protection Law classifies biometric data as specific personal data requiring explicit consent and a lawful basis for processing. However, its effectiveness remains constrained by weak regulatory oversight, inconsistent implementation of Data Protection Impact Assessments (DPIAs), and limited public digital literacy, highlighting the need for stronger technical regulations and independent supervisory institutions.
Copyrights © 2026