“We didn't build Fundle to sell software. We built it to make first-party data productive — every campaign, every store, every shopper, every day.”
- •Understand how India's DPDP Act 2023 imposes consent-first obligations on every retail loyalty programme
- •Examine the technical architecture behind privacy-by-design customer engagement platforms
- •Compare legacy point-and-redeem stacks against modern consent-aware AI platforms
- •Follow a five-step playbook for achieving DPDP compliance without dismantling existing loyalty programmes
- •See how Fundle AI Platform processes consents at scale with top-grade encryption and audit trails ensuring DPDP adherence
For years, Indian shopping malls and retail brands operated loyalty programmes on a simple, unstated bargain: give us your phone number, collect your points, get a discount. Customer data — mobile numbers, purchase histories, email addresses, browsing behaviour — was captured, aggregated, and monetised with little friction and even less transparency. Platforms like Capillary, EasyRewardz, and MoEngage built large businesses on this model. Brands like Pantaloons, Lifestyle, and Manyavar enrolled tens of millions of members without ever surfacing a meaningful consent flow. That era is ending.
The Digital Personal Data Protection Act 2023 — India's DPDP Act — received Presidential assent in August 2023. Its implementing rules, expected to be notified by late 2024 or early 2025, will make explicit, informed, and revocable consent a statutory requirement for every Data Fiduciary operating in India. A Pantaloons member who never actively opted in? A liability. A Phoenix Marketcity loyalty database built on implied consent during POS sign-ups? An audit risk. The penalties under DPDP are not symbolic — they scale up to ₹250 crore per breach instance, with the Data Protection Board empowered to investigate complaints and impose fines without the slow machinery of civil court.
This creates an urgent, structural challenge for Indian retail marketing heads, mall CMOs, and loyalty programme managers. The question is not whether to comply — it is how to build or migrate to a customer engagement platform with data privacy compliance at its core without destroying the personalisation engines and revenue-driving mechanics that loyalty programmes depend on. Gutting your CRM to satisfy a legal team is not a strategy. Bolting on a consent checkbox to a decade-old stack is not compliance — it is theatre.
Fundle was built to answer precisely this question. Rather than treating privacy as a compliance layer applied after the fact, the Fundle AI Platform embeds consent management, data minimisation, encryption, and audit readiness into the foundational architecture of every loyalty and engagement workflow. This article dissects that architecture — the technical decisions, the design principles, and the operational playbook — so that retail operators can evaluate what genuine DPDP-readiness looks like inside a modern customer engagement platform.
India Retail Data Privacy: The Numbers That Matter
India's Data Privacy Landscape: Why DPDP Changes Everything
India's data protection journey has been long and contentious. The Supreme Court's 2017 Puttaswamy judgement established privacy as a fundamental right. The Personal Data Protection Bill went through multiple drafts over five years before being scrapped and replaced by the leaner, more operator-friendly DPDP Act 2023. The Act's architecture is deliberately modelled on GDPR's consent-first framework but adapted for Indian commercial realities — including a tiered classification of Data Fiduciaries, with Significant Data Fiduciaries (SDFs) facing the most stringent obligations around data localisation, periodic audits, and Data Protection Impact Assessments.
For retail and mall operators, the practical implications are significant. First, consent must be free, specific, informed, and unambiguous — the POS sign-up card that says 'By joining our loyalty programme, you agree to our terms' no longer qualifies. Second, every consent must be linked to a specific purpose, and data collected for one purpose cannot be processed for another without fresh consent. A Select CITYWALK member who consented to transaction-based point notifications cannot be retargeted with third-party brand offers without a separate, granular consent action. Third, and critically, consumers have a statutory right to withdraw consent at any time — and platforms must honour that withdrawal within a reasonable timeframe, erasing data in line with the defined retention period.
The DPDP Act also introduces the concept of a Consent Manager — a registered intermediary who can aggregate and manage consents across multiple Data Fiduciaries. For mall operators running multi-brand loyalty programmes across 100+ tenant brands, this is architecturally significant. A mall CMO managing Phoenix Marketcity's loyalty programme is simultaneously a Data Fiduciary for footfall analytics and a potential Data Processor for individual brand CRM campaigns run inside the mall. The consent chain must be traceable end-to-end.
What makes this moment particularly sharp for Indian retail is the convergence of regulatory pressure with a consumer sentiment shift. Indian shoppers — especially urban Tier 1 and Tier 2 consumers — are increasingly aware of how their data is used. Apollo Pharmacy's breach in 2023, which exposed prescription data, accelerated this awareness. Brands like Tanishq and FabIndia that have built equity on trust and craftsmanship face an asymmetric reputational risk from data mishandling. The compliance obligation and the commercial imperative are, for the first time, pointing in the same direction: build a customer engagement platform with data privacy compliance as a first principle, not an afterthought.
Consent Lifecycle in a DPDP-Compliant Loyalty Programme
Technical Architecture for Consent and Data Protection at Scale
The phrase 'privacy-by-design' is used loosely in vendor marketing. Its precise meaning — defined by Ann Cavoukian and codified into regulations like GDPR and now DPDP — means that privacy controls are embedded at the system design stage, not appended as a compliance module after the product is built. For a customer engagement platform handling tens of millions of loyalty transactions across malls like Phoenix Marketcity, Nexus Select Trust, or DLF Avenue, this distinction is architectural, not cosmetic.
A DPDP-compliant customer engagement platform requires at minimum five technical capabilities running in concert. First, a Consent Management Layer that is decoupled from the CRM core — meaning consent states are stored independently, versioned, and propagated as signals that gate downstream data access. If a member withdraws marketing consent, that signal must propagate to the email engine, the push notification system, the ML personalisation model, and the offline POS CRM simultaneously — not sequentially over 72 hours. Second, a Data Classification Engine that automatically tags ingested data by sensitivity level — personal identifiers, financial transaction data, health-adjacent data (relevant for pharmacy brands like Apollo), and behavioural inferences. Classification drives differential encryption and access control policies.
Third, end-to-end encryption — not just at rest and in transit, but at the field level for high-sensitivity attributes. A member's Aadhaar-linked phone number, for instance, should be tokenised at ingestion, with the raw value accessible only to authorised decryption services under audit-logged conditions. Fourth, an immutable Audit Trail that records every data access event — who queried the record, for what purpose, under which consent scope, and at what timestamp. This is not a log file on a server; it is a write-once, cryptographically signed event store that can be produced to the Data Protection Board on demand. Fifth, a Data Subject Rights Fulfilment Engine — the plumbing that handles access requests, correction requests, and erasure requests within statutory timeframes. For a programme with 5 million members, this cannot be a manual process.
Building these five capabilities on top of legacy POS-connected loyalty stacks — like those built on POSist, Petpooja, or older Wondersoft integrations — is where most retail operators are finding their current architecture insufficient. The integrations exist at the transaction layer but not at the consent propagation layer. This is the gap that a purpose-built platform like Fundle Loyalty is designed to close.
Legacy Loyalty Stack vs. DPDP-Compliant Customer Engagement Platform
Fundle's Privacy-By-Design Principles for Customer Engagement Platform
Fundle's architecture is built on seven privacy-by-design principles that map directly to DPDP obligations and go, in several cases, beyond them. The first is Data Minimisation at Source — Fundle AI Workflow is configured to collect only the data fields that have a defined, consented purpose at the time of collection. A mall loyalty enrolment for footfall analytics does not automatically collect email or date of birth unless those fields are tied to a specific, disclosed programme feature. This is enforced at the API schema level, not by policy documents.
The second principle is Consent-First Campaign Execution. Every campaign trigger in Fundle Brand Loyalty — whether a birthday offer for a Tanishq member, a cashback push for a Reliance Trends shopper, or a re-engagement sequence for a lapsed Cafe Coffee Day customer — begins with a consent validation call. If the member's marketing consent is inactive or withdrawn, the campaign node is bypassed without human intervention. This is not a suppression list; it is an architectural gate. The third principle is Differential Access Control — Fundle's internal role-based access system applies the principle of least privilege. A mall marketing executive can see aggregated footfall cohort data. She cannot query individual member transaction records without an elevated access reason logged to the audit trail. A tenant brand campaign manager can see campaign performance metrics for their brand's enrolled members. She cannot access cross-brand spend data for those same members.
The fourth principle is Algorithmic Transparency for AI-Driven Decisions. Fundle AI Agents that power personalised recommendations — next-best-offer, churn propensity scoring, RFM segmentation — are required to operate within consent-scoped data boundaries. A member who consented to transactional personalisation but not to behavioural profiling will receive recommendations derived only from purchase history, not from browsing or dwell-time signals. This is enforced at the feature engineering layer of the ML pipeline, not at the output layer.
Fifth is Retention Automation — Fundle AI Workflow automatically enforces data retention schedules by member segment and data type. Transactional data for active members is retained for 24 months by default. Data for churned members who have not re-engaged is flagged for deletion or anonymisation at the 12-month mark, with a consent reconfirmation prompt sent first. Sixth is Breach Response Readiness — Fundle's infrastructure is designed to isolate, contain, and notify within the 72-hour window that DPDP draft rules indicate for breach reporting. Seventh is Privacy Impact Assessment integration — every new Fundle AI Platform feature that touches personal data goes through an automated PIA checklist before deployment to production. As Fundle processes consents at scale with top-grade encryption and audit trails ensuring DPDP adherence, these principles are not aspirational — they are operationally enforced at the code level.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
5-Step Playbook: Achieving DPDP Compliance on a Customer Engagement Platform
Audit Your Current Consent Database
Map every data collection touchpoint — POS terminals (GoFrugal, Wondersoft, POSist integrations), app sign-ups, WhatsApp opt-ins, paper forms — and classify each consent record by validity under DPDP. Identify the percentage of your loyalty database that has no granular, purpose-specific consent. This is your exposure baseline. For most Indian mall programmes, expect 60-80% of legacy records to require re-consent.
Rebuild Consent Architecture, Not Just UX
Implement a dedicated Consent Management Layer decoupled from your CRM. Each consent record must carry: member ID, purpose code, channel of collection, timestamp, version of the privacy notice shown, and a cryptographic hash of the consent event. This is not a UI redesign — it is a data schema and API architecture change. Platforms like Fundle Loyalty have this built in; legacy stacks require custom engineering.
Encrypt and Tokenise High-Sensitivity Fields
Classify all personal data fields by sensitivity tier. Apply AES-256 field-level encryption to tier-1 identifiers (mobile, email, PAN-linked data). Tokenise mobile numbers at ingestion so that campaign engines, analytics systems, and ML models work with tokens — the raw value is only decrypted at the last-mile delivery point under audit-logged conditions. This limits blast radius in the event of a breach.
Implement Automated Data Subject Rights Fulfilment
Build or deploy a self-serve rights portal where members can access their data, correct errors, and withdraw consent or request erasure. The backend must propagate these requests across all connected data stores — transactional, behavioural, campaign history, ML feature stores — within a defined SLA. Manual workflows fail at scale. Fundle Agentic AI automates rights fulfilment orchestration across the full data estate.
Establish Continuous Compliance Monitoring
DPDP compliance is not a one-time audit. Deploy automated monitoring for consent expiry (re-consent prompts before expiry), data retention schedule breaches (automated flagging of overdue deletions), access anomaly detection (alerts when data is accessed outside defined purpose scope), and third-party data sharing logs (API call logs with consent scope validation results). Review compliance dashboards monthly; conduct formal DPB-style mock audits quarterly.
Data Security and Consumer Trust Measures That Actually Move the Needle
Technical compliance and consumer trust are related but not identical. A platform can be DPDP-compliant on paper while still eroding the trust that makes loyalty programmes commercially valuable. Indian consumers are, empirically, becoming more discerning. Younger shoppers at malls like Select CITYWALK or Nexus Elante — who grew up with UPI's transparency and TRAI's SMS consent framework — have baseline expectations around data control that older loyalty programmes were not designed to meet.
The trust measures that matter operationally fall into three categories. First, visible control — members should be able to see exactly what data a brand holds on them, update their preferences, and withdraw consent from within the loyalty app or WhatsApp channel, without needing to call a customer care number. This is not about regulatory box-ticking; brands like Lenskart and Nykaa that have built transparent preference centres report materially lower unsubscribe rates than those that bury opt-out in email footers. When members feel in control, they stay opted in.
Second, communication transparency — every marketing communication should identify the consent basis on which the member is being contacted, and provide a one-tap opt-down or opt-out mechanism that executes immediately. Not in the next batch cycle. Not in 48 hours. Immediately. This requires the campaign execution engine to be consent-aware at the send level, not just at the campaign setup level. Fundle Mall Loyalty's campaign engine is built with this immediacy as a design constraint, not a product feature to be toggled.
Third, breach communication readiness — in the event of a data security incident, brands that communicate quickly, specifically, and with a clear remediation plan retain consumer trust far better than those that delay or downplay. India's DPDP Act will mandate breach notification to the Data Protection Board and to affected individuals. Brands that treat this as a reputational opportunity — demonstrating that they take data stewardship seriously — will differentiate meaningfully from those that treat it as a crisis to be managed. This requires pre-scripted, board-approved breach communication templates and a clearly designated Data Protection Officer empowered to make disclosure decisions without navigating a twelve-person approval chain at 2 AM.
- Consent database audit completed — every record classified as valid, invalid, or requires re-consent under DPDP purpose-specific standard
- Granular, purpose-specific consent UI deployed at all enrolment touchpoints — POS, app, WhatsApp, web — with privacy notice version tracking
- Consent Management Layer decoupled from CRM core — consent signals propagate in real time to campaign, ML, and analytics systems
- Field-level AES-256 encryption and tokenisation applied to all tier-1 personal identifiers (mobile, email, PAN-linked, health data)
- Immutable, cryptographically signed audit trail operational — every data access event logged with purpose code and consent scope reference
- Automated Data Subject Rights fulfilment portal live — access, correction, withdrawal, and erasure processed within 48-hour SLA across all data stores
- Continuous compliance monitoring dashboards active — consent expiry alerts, retention schedule enforcement, access anomaly detection, and third-party data sharing logs reviewed monthly
“In Indian retail, the brands that treat consent as a commercial asset — not a legal checkbox — will build loyalty databases worth ten times those of brands still running on implied opt-ins.”
How Fundle solves this
Vineet Narang founded Fundle on a specific conviction: that the next decade of Indian retail loyalty would be won not by the brand with the most data, but by the brand with the most trusted data. The Fundle AI Platform is the operational expression of that conviction — a customer engagement platform with data privacy compliance built into its core architecture, not retrofitted onto a legacy transaction-processing stack.
At the foundation, Fundle Loyalty ships with a pre-built Consent Management Layer that integrates with India's leading POS systems — including GoFrugal, Wondersoft, POSist, and Petpooja — via certified API connectors. Every enrolment event — whether at a Phoenix Marketcity food court kiosk, a Manyavar in-store POS, or an FabIndia e-commerce checkout — generates a structured consent record with purpose codes, notice versioning, channel metadata, and a cryptographic event hash. These records are stored in an immutable audit ledger that is separate from the transactional CRM, producible to regulators on demand, and accessible to compliance teams via a real-time dashboard.
Fundle AI Agents — the intelligence layer that powers next-best-offer recommendations, churn prediction, RFM segmentation, and personalised re-engagement sequences — operate exclusively within consent-scoped data boundaries. An agent tasked with building a high-value member re-engagement campaign for a Lifestyle or Pantaloons tenant will query only the feature sets permitted by the member's active consent profile. Fundle Agentic AI orchestrates multi-step compliance workflows autonomously: scheduling re-consent prompts before consent expiry, triggering automated data deletion when retention windows close, and escalating access anomalies to the Data Protection Officer queue without human intervention in the detection step.
Fundle AI Workflow — the no-code automation builder used by mall CMOs and brand loyalty managers — enforces DPDP constraints at the workflow design stage. A marketing executive building a birthday cashback journey for Tanishq members at Select CITYWALK will find that the workflow canvas automatically validates consent scope before allowing personalisation nodes to be connected. There is no workaround. The compliance guardrail is the product. This is what distinguishes Fundle Mall Loyalty and Fundle Brand Loyalty from point solutions that offer consent management as an add-on module — on the Fundle AI Platform, privacy-by-design is the architecture, and the result is a customer engagement platform with data privacy compliance that Indian retail operators can deploy with confidence as DPDP rules are notified and enforcement begins.
Frequently asked
What is the DPDP Act and why does it matter for Indian retail loyalty programmes?+
The Digital Personal Data Protection Act 2023 is India's primary data protection legislation, mandating explicit, purpose-specific, and revocable consent for processing personal data. For retail loyalty programmes — which collect mobile numbers, transaction histories, and behavioural data at scale — DPDP creates statutory consent obligations, data subject rights (access, correction, erasure), and breach notification requirements. Non-compliance carries penalties of up to ₹250 crore per breach instance, making DPDP readiness a board-level commercial priority, not just a legal formality.
Can existing loyalty databases built on implied consent be migrated to DPDP compliance?+
Yes, but it requires a structured re-consent campaign, not just a notice update. The process involves auditing existing records to identify those without valid DPDP-grade consent, segmenting members by channel and engagement level, deploying purpose-specific re-consent flows across app, SMS, WhatsApp, and email, and retiring or anonymising records from non-responsive members after a defined window. Fundle Loyalty's consent migration toolkit automates the segmentation, communication orchestration, and audit trail generation for this process.
How does Fundle handle consent withdrawal in real time across connected campaign systems?+
Fundle's Consent Management Layer maintains a live consent state for every member that is propagated via event streaming to all connected systems — the email engine, push notification service, WhatsApp gateway, ML personalisation pipeline, and POS CRM integration. When a member withdraws marketing consent through the loyalty app or self-serve portal, the consent state update triggers an immediate suppression signal across all downstream systems. There is no batch processing delay. Campaign nodes that encounter a suppressed consent state are bypassed, and the bypass event is logged to the audit trail.
What encryption standards does the Fundle AI Platform apply to personal data?+
Fundle applies AES-256 encryption at the field level for tier-1 personal identifiers — mobile numbers, email addresses, and any financial or health-adjacent data. Data is encrypted at rest and in transit as a baseline. High-sensitivity fields are additionally tokenised at ingestion, meaning that campaign engines, analytics dashboards, and ML feature stores work exclusively with tokens. The raw personal value is decrypted only at the last-mile delivery point — for example, at the point of sending an SMS — under a logged, purpose-coded decryption event.
How does Fundle's platform handle multi-brand or mall loyalty programmes where data is shared across tenant brands?+
In a mall loyalty context, the mall operator is typically the Data Fiduciary and individual tenant brands are Data Processors for campaign-specific use cases. Fundle Mall Loyalty enforces consent scope validation at every API call that passes member data to a tenant brand's campaign system. A member who consented to mall-wide offers but not to individual brand retargeting will have their data withheld from brand-specific campaign APIs, with the gate decision logged to the audit trail. This gives mall CMOs a defensible, auditable data sharing framework that satisfies both DPDP requirements and tenant brand SLAs.
How does Fundle compare to competitors like Capillary, EasyRewardz, or MoEngage on DPDP compliance?+
Capillary and EasyRewardz are mature transaction-loyalty platforms with strong POS integration libraries, but their consent management capabilities are largely bolted-on rather than architecturally native — consent state is typically managed at the CRM layer and does not propagate in real time to campaign execution or ML systems. MoEngage and WebEngage are strong on campaign orchestration but were built primarily as marketing engagement tools, not as loyalty platforms with built-in data fiduciary obligations. Fundle AI Platform is purpose-built with DPDP's consent-first, data-minimisation, and audit-trail requirements as founding architectural constraints — making compliance a product outcome rather than an integration project.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
