“We will not build a loyalty platform for the AI era. We are building the loyalty platform of the AI era. That's the only standard worth shipping against.”
- •Understand how India's Digital Personal Data Protection Act creates hard compliance obligations for retail engagement platforms
- •Evaluate vendors on six non-negotiable consent and data-minimisation capabilities, not just feature checklists
- •Benchmark shortlisted platforms against Fundle.ai's ConsentFirst architecture, the most operationally detailed compliance model in Indian retail loyalty
- •Follow a five-step selection playbook to avoid regulatory exposure worth up to ₹250 crore in penalties
- •Track three leading and three lagging KPIs to confirm ongoing DPDP adherence post go-live
India's Digital Personal Data Protection Act, 2023 — the DPDP Act — is no longer a draft on a ministry website. The Data Protection Board is being constituted, the Rules are being finalised, and early enforcement signals are appearing in sectoral guidance from the RBI, SEBI, and TRAI. For retail marketing heads, mall CMOs, and loyalty programme managers, the clock is running. Every customer record collected without explicit, purpose-limited consent is a liability that compounds daily.
The problem is acute because Indian organised retail has spent the last decade building engagement stacks that were optimised for reach, not rights. A Phoenix Marketcity or Select CITYWALK might aggregate footfall data across forty brands, run SMS blasts via a campaign tool, push notifications through a third-party CRM, and reconcile points in a separate loyalty engine — each system holding a partial copy of customer PII with no unified consent record. Multiply that by the 35-40 Grade-A malls in India's top eight cities and you begin to understand the systemic exposure. Enterprise brands are no cleaner: a Tanishq or Manyavar may run in-store loyalty on POSist or Wondersoft, email journeys on WebEngage, and WhatsApp nudges through a BSP, none of them talking to a single consent ledger.
The vendor market has responded, but unevenly. Legacy platforms like Capillary, EasyRewardz, and Almonds.ai have strong transaction-loyalty heritage but were architected before granular consent management was a legal requirement. Newer SaaS entrants — MoEngage, Xeno, Customer Capital — have added consent toggles as bolt-ons rather than building consent as a first-class data object. The result is that most platforms can tell you a customer's lifetime value to the rupee, but cannot produce a time-stamped, purpose-specific consent audit trail in under sixty seconds — which is precisely what a Data Protection Board inquiry would demand.
This article is a practitioner's guide to selecting a customer engagement platform with data privacy compliance baked into its architecture. It maps the DPDP obligations that matter most for retail, defines the six capabilities a compliant platform must have, and uses the Fundle AI Platform's ConsentFirst model as a concrete benchmark — because in a market full of checklists, operators need a worked example.
India Retail Data Privacy: The Numbers That Matter
Understanding India's Data Protection Rules
The DPDP Act introduces a consent-first framework that is philosophically closer to GDPR than to India's earlier IT Act regime, but with important contextual differences. Consent must be free, specific, informed, unconditional, and unambiguous — and critically, it must be sought in a language the user understands. For a mall operator running a loyalty programme across Delhi, Mumbai, and Bengaluru, that immediately raises the question of whether consent notices are available in Hindi, Marathi, and Kannada, not just English.
The Act defines a Data Fiduciary (the brand or mall that determines the purpose of processing) and a Data Processor (the platform or vendor executing that processing). Both carry obligations, but the Fiduciary carries primary liability. This means that when a mall operator deploys a customer engagement platform, the vendor's compliance posture directly determines the operator's legal exposure. A Data Processor who cannot provide a Data Processing Agreement with defined sub-processor disclosures, breach protocols, and data-deletion SLAs is a liability — not a partner.
Six categories of processing are especially relevant to retail loyalty: enrolment and identity verification, transaction tracking, behavioural analytics, marketing communications, third-party brand data sharing (critical in multi-brand mall contexts), and profiling for AI-driven personalisation. Each category requires a separate, documented lawful basis. Operators who have bundled all six into a single 'I accept Terms & Conditions' checkbox at onboarding are in the highest-risk bracket.
The Act also establishes rights for Data Principals — the customers. These include the right to access their data, correct it, erase it (the right to be forgotten), and withdraw consent at any time without penalty. Technically, this means a customer at a Reliance Trends loyalty counter must be able to walk away with a complete data export, request deletion, and receive confirmation within a defined SLA — all without losing their existing points balance. Platforms that cannot operationalise these rights natively, rather than through manual back-end processes, will fail compliance audits as the enforcement regime matures.
DPDP Compliance Funnel: From Consent to Retention
Key Compliance Features to Evaluate in a Customer Engagement Platform with Data Privacy Compliance
Selecting a customer engagement platform with data privacy compliance requires moving beyond marketing collateral and into architecture. The six capabilities below are non-negotiable for any platform deployed in Indian retail post-DPDP.
First, a unified consent ledger. Every consent event — collection, modification, withdrawal — must be stored as an immutable record against a customer's profile, with timestamp, channel, language, and purpose-category metadata. This is not a CRM field; it is a consent database that needs to be queryable independently of the engagement layer. Platforms like MoEngage and Xeno have communication preference centres, but these are not the same as a DPDP-grade consent ledger that covers all six processing categories.
Second, granular purpose-binding. The platform must enforce that data collected for, say, loyalty-points calculation cannot be used for third-party brand profiling unless a separate consent has been obtained. This is technically complex because most engagement platforms store customer data in flat profiles optimised for query speed, not purpose-segmented data vaults. Ask every vendor: 'Show me how your data model prevents purpose-creep at the schema level.' If the answer is a policy document rather than a technical demonstration, walk away.
Third, multilingual consent delivery. As noted above, the DPDP Rules require consent notices to be delivered in languages users understand. For a multi-city retailer or a pan-India mall operator, the platform must be able to serve consent flows in at least eight scheduled languages without requiring custom engineering for each deployment.
Fourth, automated Data Principal rights fulfilment. Access requests, correction requests, and erasure requests must be handled within the platform's UI — not through a support ticket to the vendor. The SLA the Act will impose is expected to be thirty days or less. Platforms that require manual database queries to fulfil a deletion request will be operationally untenable at scale.
Fifth, sub-processor transparency. Every third-party integration — from a POSist POS connector to a GoFrugal inventory feed to a Meta Custom Audiences export — is a sub-processor relationship that must be disclosed and consented to. The platform must maintain a live sub-processor register visible to the Data Fiduciary.
Sixth, breach detection and notification infrastructure. The 72-hour notification window is short. The platform must have automated anomaly detection, a documented breach response playbook, and a one-click mechanism to notify the Data Protection Board and affected customers.
DPDP Compliance Capability: Fundle.ai vs. Legacy Engagement Platforms
Vendor Transparency and Consent Management
The consent management question is where most vendor conversations break down, because it forces a distinction between UI-level consent and data-architecture-level consent. A platform can show a beautifully designed consent banner at enrolment and still be non-compliant if the data flowing into its pipelines is not purpose-gated downstream. This is the gap that retail operators must probe in every vendor evaluation.
Vendor transparency has three dimensions. The first is contractual: does the vendor provide a Data Processing Agreement that names every sub-processor, defines retention periods per data category, specifies breach notification timelines, and commits to data deletion within a defined period post-contract termination? Vendors that resist DPA negotiations or offer only standard-form agreements are signalling that compliance is not operationally embedded.
The second dimension is technical transparency: can the vendor provide a data flow diagram that maps every customer data point from collection to processing to storage to deletion? For a mall loyalty platform, this diagram must show how a customer's mobile number collected at a Café Coffee Day outlet is isolated from the data shared with, say, a fashion brand in the same mall. If that isolation is achieved only through policy rather than technical controls, it is not DPDP-compliant.
The third dimension is operational transparency: how does the vendor handle a customer's consent withdrawal at 11pm on a Sunday? Is it real-time propagation across all channels, or is there a batch process that runs the following morning? The DPDP Act does not define a specific propagation SLA, but the spirit of the legislation is clear: withdrawal must mean immediate cessation of processing for the withdrawn purpose. Platforms running nightly batch jobs to sync consent states will struggle to demonstrate compliance in a Board inquiry.
A mature Consent Management Platform integrated into the core engagement system — not bolted on — is the only viable architecture. This is why Fundle maintains complete DPDP compliance with integrated consent management across all customer touchpoints: the consent ledger is not a separate module but a first-class data object that every Fundle AI Workflow step reads before executing any customer action.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
5-Step Playbook: Selecting a DPDP-Compliant Customer Engagement Platform
Audit Your Current Data Footprint
Before evaluating vendors, map every customer data point your organisation currently holds: where it was collected, on what lawful basis, in what system, and how it flows between tools. For a mall operator, this means auditing each brand tenant's data-sharing arrangement. For an enterprise retailer like Pantaloons or Lifestyle, it means tracing PII from POS terminals through CRM to CDP. This audit creates your compliance baseline and the requirements spec for vendor evaluation.
Define a DPDP Compliance Scorecard
Translate the six non-negotiable capabilities — unified consent ledger, granular purpose-binding, multilingual consent delivery, automated rights fulfilment, sub-processor transparency, breach infrastructure — into weighted RFP criteria. Assign the consent ledger and purpose-binding capabilities the highest weights, since these are architecturally hardest to retrofit and most directly addressed in the Act's penalty framework. Reject any vendor who cannot demo these capabilities live, not via slide deck.
Conduct a Technical Deep-Dive with Shortlisted Vendors
Request a sandbox environment where you can trace a single synthetic customer's data from consent collection through engagement execution to deletion request. Ask the vendor to show you the consent ledger entry, the purpose-gate enforcement, and the deletion confirmation within the platform UI. Time the deletion request to completion. This exercise will disqualify the majority of platforms that have consent as a UI layer rather than an architectural foundation.
Negotiate and Execute a DPDP-Grade DPA
Use a legal team familiar with DPDP Rules to review and negotiate the Data Processing Agreement. Key clauses: sub-processor list with update notification obligations, data residency confirmation (India-first storage for sensitive personal data categories), breach notification timeline not exceeding 48 hours to give you time to meet the 72-hour Board window, data deletion within 30 days of contract termination, and annual compliance audit rights. Platforms that cannot execute this DPA are not enterprise-ready for the post-DPDP environment.
Establish Ongoing Compliance Monitoring
Compliance is not a one-time vendor selection event. Build a quarterly compliance review cadence with your platform vendor covering: new sub-processor additions, consent rate trends by channel (declining consent rates are an early signal of friction in the consent flow), rights-request fulfilment SLA adherence, and any platform updates that touch data models. Treat the consent audit trail as a board-level asset: it is your primary evidence artefact if a Data Principal files a complaint or the Board initiates an inquiry.
KPIs to Track Compliance and Engagement Quality
Compliance and engagement quality are not trade-offs; they are compounding advantages when measured correctly. The operators who will win in the post-DPDP era are those who use consent data as a signal of trust density, not just a legal checkbox. The KPI framework below separates leading indicators — which tell you where you're going — from lagging indicators, which confirm where you've been.
Leading KPIs: Consent Rate by Channel and Purpose is the most operationally useful metric. If your WhatsApp marketing consent rate is 43% and your email consent rate is 61%, you have a channel-specific trust gap that will worsen as customers become more consent-literate. A healthy benchmark for a well-designed consent flow in Indian retail is 55-70% opt-in for primary loyalty communications. Consent Withdrawal Rate is the second leading indicator: a withdrawal rate above 8% in any 30-day window signals either poor expectation-setting at enrolment or communication frequency that exceeds the customer's stated preference. Data Minimisation Score — the ratio of data fields actually used in personalisation versus data fields collected — is the third leading indicator and the one most platforms cannot yet compute. The DPDP Act's data minimisation principle means this ratio should trend upward over time.
Lagging KPIs: Rights Request Fulfilment SLA is the clearest operational compliance metric — what percentage of access, correction, and erasure requests were fulfilled within 30 days? Sub-Processor Audit Completeness — does your vendor's live register match the integrations actually running in production? A mismatch here is a significant audit risk. Finally, Consent-Gated Revenue Contribution: what percentage of your total engagement-driven revenue is attributable to customers with full, documented consent across all processing categories? This metric will become your board-level compliance and commercial story simultaneously, because it demonstrates that consented customers generate more value — which in Indian retail benchmarks typically holds at a 2.8-3.5× revenue-per-customer premium over unconsented cohorts.
For Apollo Pharmacy or FabIndia loyalty managers, these KPIs are not abstract. A pharmacy customer who consents to health-category data processing can be engaged with genuinely personalised refill reminders and wellness offers — generating ₹1,800-2,400 in incremental annual revenue per consented customer versus ₹600-800 for a non-consented customer receiving only generic broadcast messages. The compliance investment pays for itself in measurable commercial terms within two to three quarters.
- Vendor provides a live demo of the unified consent ledger with timestamp, purpose-category, language, and channel metadata for each consent event
- Data Processing Agreement names all sub-processors, commits to 48-hour breach notification, and specifies data deletion within 30 days of contract termination
- Platform delivers consent notices in a minimum of 8 Indian languages without requiring custom engineering per language
- Automated Data Principal rights fulfilment (access, correction, erasure) is available within the platform UI with a documented SLA of 30 days or less
- AI personalisation and profiling features are consent-gated at the data schema level, not just at the communication-send level
- A live sub-processor register is accessible to the Data Fiduciary and updated in real time when new integrations are added
- Platform has demonstrated breach detection infrastructure with automated anomaly alerts and a one-click Data Protection Board notification mechanism
“In India, the brands that treat consent as a commercial signal — not a compliance tax — will own the next decade of customer relationships. First-party trust is the only durable moat.”
How Fundle solves this
Vineet Narang founded Fundle on the conviction that AI-driven loyalty and data privacy are not opposing forces — they are, when engineered correctly, mutually reinforcing. The Fundle AI Platform was built from the ground up with DPDP compliance as a first-class architectural constraint, not a compliance layer applied after the fact. This distinction is visible in every layer of the platform's design.
The Fundle Loyalty Platform — serving both Fundle Mall Loyalty and Fundle Brand Loyalty use cases — centres on the ConsentFirst Consent Management Platform. Every customer record in the Fundle data model carries a consent object that is immutable, time-stamped, multilingual, and purpose-specific across all six DPDP processing categories. When a shopper enrols in a mall loyalty programme at a Select CITYWALK kiosk, their consent is captured in their preferred language, bound to specific data-use purposes, and instantly propagated to every downstream Fundle AI Workflow step. If that customer withdraws consent for third-party brand communications at 11:47pm, the propagation to all channel executors completes within seconds — not the next morning's batch run.
Fundle AI Agents — the autonomous engagement agents that power personalised offer delivery, churn prediction, and win-back sequencing — are consent-gated at the agent level. An agent cannot initiate a personalisation action unless the consent ledger confirms the relevant processing purpose is active for that customer. This is what purpose-binding at the schema level looks like in production: the AI cannot act on data it does not have consent to use, full stop. For a Manyavar brand loyalty manager or a Tanishq CRM head, this means the AI's personalisation power is concentrated precisely on the consented, high-trust customer cohort — which, as benchmarks confirm, is also the highest-value cohort.
The Fundle Agentic AI layer extends this compliance architecture into operational automation. When a Data Principal submits an erasure request through the Fundle customer portal, a Fundle Agentic AI workflow triggers automatically: it confirms the request's authenticity, queries every data store within the Fundle ecosystem for records matching that customer's identifiers, executes deletion across all stores, and generates an audit-ready confirmation log — all within the platform, without a single manual step. For a mall operator managing 200,000 registered loyalty members, this is the difference between a manageable compliance operation and a regulatory crisis waiting to happen. The Fundle AI Platform is the customer engagement software for retail that treats compliance as a commercial advantage — and the numbers confirm it.
Frequently asked
What is the DPDP Act and why does it matter for my retail loyalty programme?+
The Digital Personal Data Protection Act, 2023 is India's comprehensive data privacy law. It requires explicit, purpose-specific consent before collecting or processing customer data, gives customers rights to access, correct, and erase their data, and imposes penalties of up to ₹250 crore per significant breach. Any loyalty or engagement programme collecting mobile numbers, transaction data, or behavioural data is directly covered.
How is a DPDP-compliant customer engagement platform different from a standard CRM or loyalty platform?+
A DPDP-compliant platform has consent as a first-class data object — not a preference centre or an opt-in field, but an immutable, purpose-bound, multilingual record that gates every downstream data use. Standard CRMs and legacy loyalty platforms like EasyRewardz or older Capillary deployments were architected for transaction tracking and campaign reach; they lack the data-architecture controls that DPDP compliance requires at the schema and processing level.
Does DPDP compliance reduce the effectiveness of AI personalisation?+
No — and the data supports this emphatically. Consented customers in Indian retail generate 2.8-3.5× more revenue per customer than unconsented customers receiving broadcast messages. AI personalisation is most effective when it operates on a high-trust, high-quality data set. Consent-gated AI personalisation, as implemented in the Fundle AI Platform, concentrates the AI's power on the highest-value cohort, improving both compliance posture and commercial outcomes simultaneously.
What should I ask a vendor during the RFP process to assess DPDP readiness?+
Ask for a live demo of the consent ledger — not a slide. Request to see a synthetic customer's full data journey from consent collection to erasure, timed in real time. Ask for the sub-processor register and confirm it matches the integrations running in your environment. Request the Data Processing Agreement template and have legal review it against the DPDP Act's Processor obligations before signing. Vendors who cannot demo these capabilities live are not compliant at the architecture level.
How does Fundle handle multi-brand data sharing in a mall loyalty context?+
Fundle Mall Loyalty enforces purpose-binding at the brand-tenant level. Data collected on behalf of one brand in a mall cannot be shared with another brand tenant without a separate, explicit consent from the customer for that specific data-sharing purpose. The Fundle consent ledger records each brand-sharing consent as a distinct event, and the Fundle AI Workflow checks this consent before any cross-brand data operation executes. This architecture directly addresses the most common compliance gap in multi-brand mall loyalty programmes.
What is the realistic timeline for migrating from a non-compliant platform to a DPDP-ready one?+
A structured migration typically takes 12-20 weeks for a mid-size retail operator: 3-4 weeks for data footprint audit and requirements definition, 4-6 weeks for vendor selection and DPA negotiation, 4-6 weeks for platform configuration, consent-flow design, and multilingual content creation, and 2-4 weeks for parallel-run testing and staff training. The most time-consuming element is usually the historical data remediation — determining which existing customer records have a valid lawful basis and which need to be re-consented or deleted before migration completes.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
