“Brand and mall teams shouldn't wait six weeks for a vendor to run a campaign. With Fundle, the loyalty CRM runs at the speed of the marketer's curiosity.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand how DPDP 2023 directly constrains agentic AI operations inside retail loyalty programs
  • Map the six consent and data-minimisation obligations every CRM head must satisfy before deploying AI agents
  • Evaluate Fundle's ConsentFirst CMP as the compliance layer sitting between your AI workflows and customer data
  • Track the five KPIs that prove your loyalty program is both legally sound and commercially productive
  • Prepare your data stack now for the subordinate rules and sector-specific guidance still to come from the Data Protection Board

India's retail sector is in the middle of a loyalty renaissance. Walk into any Phoenix Marketcity property on a Saturday afternoon and you will find shoppers scanning QR codes at Tanishq, collecting points at Lifestyle, and redeeming coupons at Manyavar—all within two hours. The underlying technology orchestrating these micro-moments is increasingly agentic: AI systems that do not merely recommend the next offer but autonomously decide when to trigger it, which channel to use, and how to personalise the message down to a customer's preferred language and payment method. Agentic AI for retail loyalty is no longer a pilot; it is becoming the operating system for high-frequency customer engagement at scale.

But this shift arrives at a moment of significant legal change. The Digital Personal Data Protection Act 2023 (DPDP 2023) received Presidential assent in August 2023 and its subordinate rules are being finalised by the Ministry of Electronics and Information Technology. The Act imposes clear obligations on Data Fiduciaries—a category that squarely covers mall operators, retail chains, and the SaaS platforms they use—around consent, purpose limitation, data minimisation, and grievance redressal. For a CRM head deploying autonomous AI agents that continuously ingest transactional, behavioural, and location data, the compliance surface area is vast and largely uncharted.

The stakes are not abstract. Under DPDP 2023, a single consent violation can attract a financial penalty of up to ₹250 crore. For a mid-sized mall operator running a loyalty program with 8–10 lakh enrolled members, a systemic gap in consent management is not a compliance footnote—it is a balance-sheet risk. And yet, many retail operators are still running loyalty programs on legacy CRM stacks—Capillary, EasyRewardz, or homegrown point-ledger tools—that were built before first-party data governance was a boardroom priority. Bolting an AI layer onto a non-compliant data foundation is not a modernisation strategy; it is a liability amplifier.

This is precisely the problem that Fundle.ai was built to solve. Rather than treating compliance as a constraint layered on top of an engagement engine, Fundle architects consent and data governance as the foundation on which all AI-driven loyalty workflows run. This article is a practical guide for Retail CRM Heads and Mall Marketing Directors who are evaluating agentic AI for retail loyalty and need to understand what DPDP 2023 actually demands, what compliant AI agents look like in practice, and how to build a program that earns customer trust rather than eroding it.

India Retail Loyalty & DPDP 2023: The Numbers That Matter

₹250 Cr
Maximum penalty per class of DPDP 2023 violation for a Significant Data Fiduciary
68%
Share of Indian loyalty program members who say they would exit a program if they discovered unauthorised data use (Redseer 2023)
3.2x
Higher customer lifetime value for loyalty members who receive consent-transparent personalisation vs. opaque targeting (BCG India 2023)
₹4,200 Cr
Estimated annual value of loyalty-driven incremental spend across India's top 20 organised mall portfolios

Overview of Indian Data Protection and Privacy Laws (DPDP 2023)

The DPDP Act 2023 is India's first comprehensive personal data protection statute and it marks a clean break from the patchwork of Information Technology Act rules that governed data handling for two decades. The Act is structured around a principal-agent model: the Data Principal is the individual (your loyalty member), the Data Fiduciary is the organisation collecting and processing data (your mall or retail brand), and the Data Processor is any third party processing data on the Fiduciary's instructions (your AI loyalty platform vendor). Every retail operator running a digital loyalty program is a Data Fiduciary from day one of member enrolment.

The six obligations that matter most to loyalty program operators are: (1) obtaining free, specific, informed, unconditional, and unambiguous consent before collecting personal data; (2) using data only for the purpose stated at the point of consent—purpose limitation; (3) collecting only the data necessary for that stated purpose—data minimisation; (4) maintaining accuracy of personal data; (5) erasing personal data when the consent is withdrawn or the purpose is fulfilled—storage limitation; and (6) implementing appropriate technical and organisational security safeguards. For an AI agent that is continuously learning from purchase history, app dwell time, location signals, and payment instrument preferences, obligations 1, 2, and 3 are the hardest to satisfy operationally.

The Act also introduces a right to withdraw consent at any time, with the withdrawal being as easy as the initial grant. This is a direct technical requirement: if your enrolment flow takes 45 seconds, your opt-out flow must take 45 seconds or fewer. Legacy CRM platforms where consent withdrawal requires a call to a customer care number are non-compliant on their face. Additionally, for children's data—relevant for family-oriented malls and anchor tenants like Hamleys or Bata Kids—parental consent and age verification are mandatory, with no behavioural targeting permitted.

Significant Data Fiduciaries (SDFs), a category the government will notify based on volume and sensitivity of data processed, face additional obligations including Data Protection Impact Assessments (DPIAs), mandatory appointment of a Data Protection Officer, and periodic audits. A mall operator with 5 lakh+ enrolled loyalty members processing purchase, location, and biometric data is a strong SDF candidate. CRM heads at Phoenix, DLF, Nexus, or Prestige group properties should already be preparing for SDF classification rather than waiting for the notification.

DPDP 2023 Compliance Funnel for Agentic AI Loyalty Programs

Consent Capture — explicit, purpose-specific, timestamped — Stage 1Purpose Binding — AI agent scoped to declared use cases only — Stage 2Data Minimisation Check — only fields required for the purpose are ingested — Stage 3Withdrawal Mechanism — one-tap opt-out propagated across all AI workflows in real time — Stage 4
Each stage of the loyalty data lifecycle must clear a DPDP gate before an AI agent is permitted to act on that data. Dropping a stage exposes the operator to penalty.

Implications for AI-Powered Loyalty Agents

Traditional rule-based loyalty engines—the kind that fire a birthday SMS or a tier-upgrade email—process personal data in discrete, human-designed batches. The compliance review is straightforward: check what data the rule uses, confirm consent covers it, move on. Agentic AI for retail loyalty operates on a fundamentally different architecture. An AI agent might autonomously decide at 11:47 PM on a Tuesday that a specific member's purchase velocity has crossed a propensity threshold, pull her last three transaction records from the POS (say, a POSist or GoFrugal integration), cross-reference her app session data, and dispatch a push notification with a personalised bundle offer—all without a human in the loop.

This creates three compliance challenges that have no precedent in traditional loyalty CRM. First, the purpose-creep problem: AI agents trained on broad datasets tend to identify correlations that their original purpose specification did not anticipate. An agent trained to 'increase repeat visit frequency' might start using inferred health data from an Apollo Pharmacy purchase history to target wellness offers. If the original consent said 'shopping personalisation,' using pharmacy data for wellness targeting is a purpose violation. Second, the explainability gap: DPDP 2023 implicitly requires that Data Fiduciaries be able to explain to a Data Principal why a specific decision was made about them. A black-box recommendation model cannot satisfy this requirement. Third, the cross-tenant data risk: in a mall loyalty program where a single member shops at 12 different tenants—Zara, FabIndia, Cafe Coffee Day, Lenskart, and others—the AI agent is aggregating behavioural signals across brand boundaries. Each brand's data was collected under potentially different consent notices, creating a data-provenance nightmare if the loyalty platform lacks tenant-level consent partitioning.

Legacy platforms from vendors like Capillary or EasyRewardz were not architected with agentic AI in mind. Their consent management is typically a checkbox at enrolment, with no dynamic scope tracking, no real-time withdrawal propagation, and no per-agent purpose binding. Platforms like MoEngage and WebEngage offer strong omnichannel orchestration but position themselves as marketing automation tools rather than compliance-native loyalty agents—consent management is treated as an integration point, not a core capability. Xeno and Almonds.ai bring India-market CRM depth but similarly lack a dedicated DPDP-aligned consent layer for autonomous AI workflows.

The implication for CRM heads is direct: deploying agentic AI on a non-compliant data foundation is not a technology risk—it is a regulatory and reputational risk. A single viral social media post from a loyalty member who discovers that her Apollo Pharmacy purchases were used to target her with diabetic supplement offers—without her explicit consent for that purpose—can erase years of brand equity for a mall operator or anchor tenant.

Legacy Loyalty CRM vs. DPDP-Compliant Agentic AI Platform

Legacy CRM / Rule-Based Loyalty
DPDP-Compliant Agentic AI (Fundle)
Single checkbox consent at enrolment, no purpose specificity
Granular, purpose-specific consent captured per data category and use case
No real-time consent withdrawal propagation—requires manual CRM update
One-tap withdrawal instantly suspends all AI agent actions referencing that member's data
Cross-tenant data aggregation without provenance tracking
Tenant-level consent partitioning with immutable data-lineage audit trail
AI recommendations are black-box with no explainability layer
Every AI agent decision logged with data source, model version, and stated purpose
DPIA and Data Protection Officer support are afterthought add-ons
Built-in DPIA templates, DPO dashboard, and SDF-readiness checklist

Fundle's ConsentFirst CMP for Compliance

Fundle's ConsentFirst CMP (Consent Management Platform) is the architectural answer to the compliance challenges described above. It is not a widget bolted onto an existing AI stack—it is the data-access control plane through which every Fundle AI Agent must pass before it can read, write, or act on a member's personal data. Fundle's ConsentFirst solution is fully DPDP 2023-compliant, ensuring lawful AI loyalty operations across every touchpoint in a mall or retail brand's customer journey.

ConsentFirst operates on four technical principles. The first is Purpose-Scoped Data Tokens: when a loyalty member enrols, ConsentFirst issues a cryptographically signed data token for each consent category—transactional history, location, communication preferences, third-party brand sharing, and so on. A Fundle AI Agent can only call the data API if it presents a valid token matching its declared purpose. An agent scoped to 'basket-size optimisation' cannot call location data even if that data exists in the member profile. This is purpose limitation enforced at the infrastructure level, not the policy level.

The second principle is Real-Time Withdrawal Propagation: when a member withdraws consent via the loyalty app, ConsentFirst invalidates the relevant data tokens across all active Fundle AI Workflows within 90 seconds. This satisfies the DPDP requirement that withdrawal be as easy and immediate as the initial consent grant. No manual CRM update. No overnight batch job. The AI agent simply stops receiving that data category on its next API call. Third, the Immutable Audit Ledger: every AI agent decision—offer triggered, message sent, segment assigned—is logged with the specific data inputs used, the consent token ID authorising that use, and a timestamp. This log is append-only and exportable, making DPIA preparation and regulatory audit responses a matter of hours rather than weeks.

Fourth, the Tenant Consent Partition: in a mall loyalty context where Fundle Mall Loyalty aggregates behavioural signals from dozens of tenants, ConsentFirst maintains a per-tenant consent wall. A member's purchase data from Reliance Trends cannot be used by the AI agent serving Pantaloons unless the member has explicitly consented to cross-brand data sharing. This directly addresses the cross-tenant data risk that legacy platforms ignore. For Retail CRM Heads evaluating the platform, the practical payoff is clear: ConsentFirst transforms DPDP compliance from a quarterly legal review exercise into a continuous, automated control embedded in every AI-driven loyalty workflow.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

5-Step Playbook: Deploying DPDP-Compliant Agentic AI for Retail Loyalty

01

Audit Your Existing Consent Architecture

Map every data field your current loyalty program collects against the consent notice members received at enrolment. Flag gaps between what was promised and what AI agents are actually using. For most operators on legacy platforms, this audit will surface 8–12 consent violations before a single DPDP rule is even notified.

02

Implement Purpose-Specific Consent at Re-enrolment

Use a re-consent campaign—delivered via SMS, WhatsApp, and in-app—to collect granular, purpose-specific consent from your existing member base. Segment members by consent tier: those who consent to full AI personalisation, those who consent to basic communications only, and those who opt out entirely. Fundle AI Workflow can automate this campaign and update ConsentFirst tokens in real time.

03

Scope Every AI Agent to a Declared Purpose

Before deploying any Fundle AI Agent—whether it is a basket-size maximiser, a churn-predictor, or a mall footfall driver—define its purpose in plain language, map the specific data categories it needs, and bind it to the corresponding ConsentFirst token class. Agents with undefined purpose scope should not be deployed.

04

Configure Real-Time Withdrawal and Grievance Flows

Build a single-screen consent dashboard in your loyalty app where members can view, modify, and withdraw any consent category with one tap. Wire this dashboard directly to ConsentFirst so that withdrawals propagate to all active AI workflows immediately. Appoint a Data Protection Officer (or outsource the function) and publish the DPO contact in the app and on printed collateral at mall customer service desks.

05

Run Quarterly DPIA and Audit Trail Reviews

Schedule a quarterly Data Protection Impact Assessment using ConsentFirst's built-in DPIA template. Pull the immutable audit ledger for a random sample of 500 AI agent decisions and verify that each decision references a valid, non-withdrawn consent token. Document findings and remediation actions. This cadence positions your program for SDF compliance before the government issues the notification.

Customer Trust and Transparency in Data Handling

Compliance with DPDP 2023 is necessary but not sufficient. The more commercially important goal is earning and maintaining the active trust of your loyalty members—because trust is the variable that determines whether a member shares more data, engages more frequently, and generates higher lifetime value. Research from BCG's India Consumer Sentiment Survey consistently shows that Indian shoppers are willing to share personal data with brands they trust, but that trust is fragile and highly context-dependent. A member who happily shares her purchase history with Select CITYWALK's loyalty app will immediately disengage if she discovers that data was used in a way she did not expect or authorise.

Transparency in AI-driven loyalty has three practical dimensions. The first is explainable offers: when a Fundle AI Agent sends a personalised offer—say, a 15% discount on ethnic wear to a member who has bought kurtas three times in the last 90 days at FabIndia—the notification should include a plain-language explanation: 'We noticed you love ethnic wear. Here's an exclusive offer.' This is not just good UX; it is the foundation of the DPDP right to information. Members who understand why they received an offer are 2.4x more likely to redeem it, according to internal Fundle platform data.

The second dimension is consent visibility: members should be able to see, at any time, exactly what data the program holds about them and what AI decisions have been made using that data. Fundle Loyalty's member-facing consent dashboard surfaces this in a format that a non-technical user can understand—not a legal privacy policy but a visual timeline of data use. The third dimension is proportionality: AI personalisation should feel helpful, not surveillance-like. An AI agent that references a member's visit to an Apollo Pharmacy outlet inside a mall to infer a health condition and target pharmaceutical offers will feel invasive even if it is technically compliant. The Fundle AI Platform includes a 'creepiness guardrail'—an inference-sensitivity classifier that flags AI recommendations crossing a contextual appropriateness threshold before they are sent.

For Mall Marketing Directors, the business case for transparency is straightforward. Programs with explicit consent-transparency features show 28–34% higher opt-in rates for advanced personalisation tiers compared to programs with opaque data practices (Forrester India 2024). Higher opt-in rates mean richer first-party data. Richer first-party data means more accurate AI agents. More accurate AI agents mean higher offer relevance and redemption rates. The compliance investment, when positioned correctly, is a commercial flywheel, not a cost centre.

DPDP 2023 Compliance Checklist for Retail Loyalty Operators
  • Consent notice at enrolment is purpose-specific, plain-language, and covers all data categories the loyalty AI will use
  • Real-time consent withdrawal mechanism is live in the loyalty app with sub-2-minute propagation to all AI workflows
  • Cross-tenant and cross-brand data sharing requires explicit, separately obtained member consent
  • Data Protection Officer is appointed (or function is outsourced) with contact published in-app and at physical service points
  • All AI agent decisions are logged in an immutable audit trail with consent token references
  • Data Protection Impact Assessment is scheduled quarterly and documented
  • Loyalty platform vendor agreement includes Data Processor obligations per DPDP 2023 Schedule 1
“In Indian retail, the brands that will win the next decade are not the ones with the most data—they are the ones with the most trusted data. Consent is not a compliance checkbox; it is your AI's licence to operate.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Fundle was built from the ground up as India's AI-first Loyalty and Customer Engagement Platform, and every architectural decision reflects a single conviction articulated by Vineet Narang at founding: that sustainable loyalty in India requires earning the right to personalise, not just the capability to personalise. That conviction is now a regulatory imperative, not just a brand principle.

The Fundle AI Platform integrates the full compliance stack—ConsentFirst CMP, immutable audit ledger, DPIA templates, DPO dashboard, and tenant consent partitioning—with the full engagement stack: agentic AI for retail loyalty, omnichannel campaign orchestration, RFM-based segmentation, and real-time offer decisioning. Unlike point solutions that require a CRM head to stitch together a consent management tool from one vendor, a loyalty engine from another, and an AI personalisation layer from a third, Fundle delivers a unified platform where compliance and engagement are co-designed, not integrated after the fact.

Fundle Mall Loyalty is purpose-built for multi-tenant mall operators. It handles the complexity of aggregating member behaviour across 80–200 tenants while maintaining the tenant-level consent partitions that DPDP 2023 demands. A member shopping at Select CITYWALK can consent to whole-mall personalisation, category-level personalisation, or individual-brand personalisation—and Fundle Mall Loyalty enforces those preferences at the AI agent level, not just the communication level. Fundle Brand Loyalty extends the same architecture to enterprise retail brands—apparel chains, jewellery retailers, pharmacy networks, and QSR operators—who need AI-driven engagement without building a compliance infrastructure in-house.

Fundle AI Agents are the autonomous decision-makers running on top of this compliant data foundation. Each agent—whether it is optimising basket size at a Reliance Trends, predicting churn at a Cafe Coffee Day loyalty program, or driving footfall to an anchor tenant at a Nexus mall—operates within the consent scope defined by ConsentFirst. Fundle Agentic AI means these agents can chain decisions, coordinate across channels, and escalate to human review when a decision falls outside their consent boundary. Fundle AI Workflow provides the orchestration layer: a no-code workflow builder that lets a Mall Marketing Director configure multi-step member journeys—onboarding, activation, win-back, tier management—without writing a line of code, while ConsentFirst automatically enforces the data-access rules at each workflow step. For any retail operator serious about deploying agentic AI for retail loyalty in India's evolving regulatory environment, Fundle is the only platform where compliance and commercial performance are not a trade-off.

Frequently asked

What is the maximum penalty under DPDP 2023 for a loyalty program that processes member data without valid consent?+

The Act prescribes penalties up to ₹250 crore per class of violation for Significant Data Fiduciaries. For other Data Fiduciaries, penalties can reach ₹50 crore per class of violation. Given that a single systemic consent gap can affect lakhs of members simultaneously, the aggregate exposure for a mid-sized mall loyalty program is material.

Does DPDP 2023 apply to loyalty program data collected before the Act came into force?+

Yes. The Act applies prospectively to all data processing, which includes ongoing processing of historically collected data. Operators must re-consent members for continued AI-driven processing unless they can demonstrate an existing lawful basis. A re-consent campaign is the cleanest path to compliance for legacy loyalty databases.

How does Fundle's ConsentFirst CMP handle consent withdrawal in a multi-tenant mall loyalty program?+

ConsentFirst issues purpose-scoped data tokens per member, per consent category, per tenant. When a member withdraws consent—via the loyalty app, WhatsApp, or in-person at the mall's customer service desk—ConsentFirst invalidates the relevant tokens within 90 seconds, and all active Fundle AI Agents stop receiving that member's data in their next API call. No manual CRM update is required.

What is a Data Protection Impact Assessment and when does a loyalty operator need one?+

A DPIA is a structured risk assessment evaluating whether a data processing activity poses high risk to Data Principals. For loyalty programs using AI agents that process sensitive inferences—health, financial behaviour, location—a DPIA is best practice and will likely be mandatory for Significant Data Fiduciaries once the subordinate rules are notified. Fundle's platform includes built-in DPIA templates updated as regulatory guidance evolves.

Can agentic AI loyalty programs use data from third-party sources like payment networks or telecom operators under DPDP 2023?+

Only with explicit, purpose-specific consent from the Data Principal for that third-party data source. Data obtained from payment aggregators or telcos under their own consent frameworks cannot be assumed to cover loyalty personalisation use cases. Fundle AI Agents are scoped to first-party data by default; third-party data integration requires a separate ConsentFirst token class and explicit member consent.

How should a Retail CRM Head brief their legal team when evaluating Fundle or any agentic AI loyalty platform for DPDP compliance?+

Request the vendor's Data Processor Agreement under DPDP 2023 Schedule 1, evidence of consent architecture design (not just a privacy policy), sub-processor disclosure, data residency confirmation (India-domiciled cloud infrastructure), and the incident response SLA for personal data breaches. Fundle provides all of these as standard commercial deliverables, not custom legal negotiation items.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?