“The best loyalty programs aren't designed by consultants. They're built by the team running the store — given the right AI co-pilot. That's the Fundle thesis.”
- •Understand why India's Digital Personal Data Protection Act 2023 changes the rules for every loyalty programme running today
- •Separate privacy-by-design architecture from bolt-on compliance — they are not the same thing
- •Benchmark against what good looks like: consent rates, data minimisation, automated audit trails
- •Evaluate platforms — Capillary, EasyRewardz, MoEngage, Antavo — against a DPDP-readiness rubric
- •Adopt Fundle's five-step playbook to run a compliant, AI-powered loyalty programme that tracks real revenue
In April 2023, India's Digital Personal Data Protection Bill cleared Parliament and became law. By mid-2024, the rules were notified. By 2025, every brand running a loyalty programme — from Tanishq's Encircle members to Pantaloons' Green Card holders — faces a binary choice: rebuild your data stack around consent and purpose limitation, or face penalties of up to ₹250 crore per breach. This is not a distant regulatory horizon. The DPDP Act is the most consequential shift in Indian retail data since the introduction of GST, and it lands squarely on the loyalty function.
The irony is brutal. Loyalty programmes exist precisely to collect first-party data — purchase history, visit frequency, category affinity, contact details — and use it to drive repeat visits and basket growth. That same data is now the most scrutinised asset on the balance sheet. CMOs at brands like Lenskart, FabIndia, and Manyavar are being pulled in two directions at once: the CFO wants better attribution and personalisation ROI; the legal team wants airtight consent flows and data minimisation. Most platforms on the market were not architected for both simultaneously.
The challenge is compounded by India's structural retail complexity. A mid-size mall operator like Phoenix Marketcity runs forty to sixty brand stores, each with its own POS — POSist, Petpooja, GoFrugal, Wondersoft — each generating transaction data that flows into a central loyalty engine. Consent captured at a Café Coffee Day counter may not be valid for re-targeting by the mall's app unless the data sharing agreement and purpose is explicitly disclosed at point of capture. That is not a theoretical edge case; it is the daily operational reality of multi-brand loyalty in India.
This is precisely the gap that a purpose-built DPDP compliant loyalty data platform must close. Fundle was designed from the ground up to handle this tension — treating compliance not as a constraint layer bolted onto a marketing automation tool, but as a first-class architectural principle baked into every data flow, consent touchpoint, and AI inference engine. The rest of this article explains what that actually means, why it matters now, and what Indian retail operators should demand from any platform they evaluate.
India Retail Loyalty & DPDP: The Numbers That Define the Stakes
Balancing Regulatory Compliance with Technology Innovation
The conventional wisdom in enterprise software is that compliance and innovation exist on opposite ends of a spectrum — the more you invest in one, the more you sacrifice from the other. In loyalty technology, this false dichotomy has produced a generation of platforms that treat DPDP-readiness as a compliance module: a checkbox layer of consent pop-ups and opt-out flows stuck on top of a marketing automation engine that was architected to maximise data collection, not to honour data minimisation.
The DPDP Act 2023 does not allow this approach. It mandates purpose limitation — data collected for a loyalty programme cannot be repurposed for insurance upsell without fresh, specific consent. It mandates storage limitation — you cannot hold member data indefinitely because it might be useful someday. It mandates the right to erasure — when a member at Select CITYWALK asks to be forgotten, that request must cascade through every system that holds a copy of their data, including third-party analytics integrations. These are architectural requirements, not workflow requirements. You cannot retrofit them onto a platform that was not built with them in mind.
At the same time, innovation in loyalty has never moved faster. AI-powered next-best-offer engines, agentic campaign workflows, predictive churn models, and real-time personalisation at the POS are all commercially available today. The brands winning wallet-share — Reliance Trends with its JioPoints integration, Apollo Pharmacy with its Health Wallet, Lifestyle's Inner Circle — are deploying these capabilities aggressively. The question for a retail CMO or CIO is not whether to innovate, but how to innovate within a compliance envelope that keeps the business safe.
The answer lies in a concept borrowed from payment systems: compliance-native architecture. Just as Razorpay or Cashfree built PCI-DSS compliance into their core transaction flows rather than wrapping it around them, a modern loyalty platform must build DPDP compliance into every data ingestion pipeline, every AI inference call, and every customer communication trigger. Innovation then operates inside this envelope — not despite it. Brands that crack this balance will compound their first-party data assets year over year while competitors are busy firefighting regulatory audits.
The DPDP Compliance Funnel for Indian Loyalty Programmes
Use of AI and Automation in Compliance
The most underappreciated insight in retail data management is this: AI is not the enemy of compliance — it is the most practical tool for enforcing it at scale. Manual consent management across a programme with five hundred thousand members, forty brand integrations, and twelve communication channels is operationally impossible without automation. The brands that will succeed under DPDP are not those with the most restrictive data policies, but those with the most intelligent automated enforcement of whatever policies they have declared.
Consider consent lifecycle management. A member joins a Manyavar loyalty programme in December for a wedding purchase. She consents to promotional communications. Eighteen months later, that consent has not been refreshed. Under DPDP, continued communication requires either a renewed consent signal or a legitimate purpose that does not rely on consent. An AI-first data platform can monitor this lifecycle automatically — flagging members approaching consent expiry, triggering re-permission flows at the right moment (not a generic blast, but a contextually relevant touch timed to a purchase anniversary or a category browse signal), and suppressing communications for members whose consent has lapsed. EasyRewardz and Capillary can schedule campaigns; they cannot natively manage consent as a dynamic, AI-monitored data attribute.
Automated data lineage is equally critical. When a DPDP Data Fiduciary audit is triggered, the platform must be able to answer: who collected this member's data, under what stated purpose, at which touchpoint, on which date, and which downstream systems have accessed it since? This is a graph problem — a directed acyclic graph of data flows across POS integrations, campaign triggers, AI inference calls, and third-party enrichment. Platforms built on monolithic CRM architectures — and several well-known Indian loyalty vendors are — cannot produce this audit graph without significant manual reconstruction.
Finally, AI-driven anomaly detection plays a growing role in proactive compliance. If a campaign configuration would expose a member segment's data to a purpose not covered by their consent category, an agentic compliance layer can intercept the campaign before it launches — not as a human governance step, but as an automated pre-flight check. This is the operational definition of compliance-native AI: intelligence that enforces the rules as a background process, not as a bottleneck.
DPDP-Readiness Comparison: Fundle AI Platform vs. Market Alternatives
Privacy-by-Design Principles in Fundle's Platform
Privacy-by-design is a term that has been adopted so broadly by marketing teams that it has nearly lost meaning. In the context of a DPDP compliant loyalty data platform, it has a precise technical definition: the architecture must make it structurally impossible to process personal data outside a declared, consented purpose — not merely difficult, and not merely against policy, but technically prevented by the system's data access controls.
Fundle's architecture implements this through what the engineering team calls purpose-scoped data tokens. When a member's data is ingested from a POS integration — say, a Wondersoft terminal at a garment retailer in Phoenix Marketcity — the raw transaction record is immediately decomposed into purpose-labelled data atoms. An AI inference call for a next-best-offer recommendation can only access the atoms tagged with the purpose 'personalisation-consent-active'. A campaign for a third-party brand partnership can only access atoms tagged with 'third-party-marketing-consent-active'. If that consent category is absent or expired, the data atom is simply not returned by the API — the calling application receives a null response, not an error, not a workaround opportunity.
This approach also solves the multi-brand loyalty problem that is endemic to mall operators. A member at Select CITYWALK who shops at FabIndia, Café Coffee Day, and a jewellery boutique in the same visit generates transaction data that belongs to three separate brands, each with their own consent relationship with that member. The mall operator's central loyalty engine — if it is not privacy-native — will often aggregate this data into a unified member profile without verifying whether the inter-brand data sharing was covered by the consent terms presented at each touchpoint. Fundle's Mall Loyalty architecture maintains brand-scoped consent boundaries within the unified member graph, allowing the AI personalisation engine to operate on cross-brand behavioural signals only where explicit cross-brand consent has been captured.
The third pillar of Fundle's privacy-by-design approach is data minimisation at the model training layer. Every AI model trained on member data — churn prediction, category affinity scoring, visit frequency forecasting — undergoes automated feature selection that strips personally identifiable attributes before model training. The model learns from behavioural patterns, not from names and phone numbers. This is not just a regulatory nicety; it produces more generalisable models that perform better across new member cohorts.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
Five-Step Playbook: Launching a DPDP-Compliant AI Loyalty Programme
Consent Architecture Audit
Map every touchpoint where member data is currently collected — POS terminals (GoFrugal, POSist, Petpooja), mobile app enrolment, in-store kiosk, web signup — and document the consent language presented at each. Identify gaps where consent is absent, ambiguous, or does not cover the purposes for which data is currently used. This audit is your legal baseline and your product backlog in one document.
Purpose Taxonomy Design
Define a finite taxonomy of data processing purposes relevant to your loyalty programme: loyalty-points-management, personalised-offers, third-party-brand-marketing, analytics-reporting, AI-model-training. Every data collection touchpoint must map to one or more of these purposes. Every AI inference and campaign trigger must declare which purpose it relies on. This taxonomy drives all downstream access controls.
Data Minimisation Review
For each data field collected — date of birth, gender, PIN code, purchase category, visit timestamp — ask whether it is necessary for at least one declared purpose. Fields that cannot be justified must be dropped or anonymised. Indian loyalty programmes typically collect 30-40% more data than their actual AI use cases require. This review simultaneously reduces DPDP liability and improves model quality by eliminating noise features.
Consent Lifecycle Automation
Configure automated consent health monitoring: flag members approaching consent expiry windows, trigger re-permission campaigns calibrated to the member's highest-engagement channel (WhatsApp, push notification, in-store prompt at next visit), and suppress non-compliant communications in real time. Set consent refresh triggers at natural loyalty programme moments — anniversary, tier upgrade, large purchase — to maximise re-permission rates without bombarding members.
Compliance Pre-Flight Integration
Integrate automated DPDP compliance checks into your campaign launch workflow. Before any campaign executes, the platform should verify: (a) every member in the target segment has active consent for the declared campaign purpose; (b) no third-party data has been used without the appropriate consent category; (c) a full audit trail entry is written for the campaign configuration and member access. Failed checks should block launch and route to a human reviewer, not silently suppress affected members.
Driving Business Value in a Privacy-First Loyalty Programme
There is a persistent myth in retail marketing that privacy constraints necessarily reduce personalisation quality and therefore loyalty ROI. The data from privacy-native loyalty deployments tells the opposite story. Members who go through a transparent, purpose-specific consent flow — who understand exactly what data is being collected and why — show measurably higher engagement rates than those who were enrolled via blanket opt-in. The mechanism is straightforward: informed consent correlates with genuine interest in the programme, which correlates with higher response rates to personalised offers.
The commercial implication is significant. An AI first party data platform for retail loyalty that operates on a smaller but higher-quality consented dataset will typically outperform a platform operating on a larger but poorly consented dataset. A programme with four hundred thousand fully consented, actively engaged members will generate more incremental revenue than one with eight hundred thousand members who enrolled for a one-time discount and have since disengaged. This is a direct argument for investing in consent quality, not just consent coverage.
For mall operators and multi-brand retail groups, privacy-first architecture also unlocks a commercial capability that has historically been technically fraught: compliant data sharing with brand tenants. A mall like Phoenix Marketcity can, with properly architected consent flows, offer its brand partners aggregated, anonymised behavioural insights — which categories drive cross-brand visits, which day-parts generate the highest basket sizes, which member segments visit multiple anchor stores in a single trip — without ever exposing individual member PII to any individual brand. This is a new revenue stream for mall operators and a genuine competitive advantage over brands that rely solely on their own transaction data.
Fundle integrates AI and compliance to manage loyalty data for ₹2,329 Cr+ in tracked revenue — a figure that demonstrates the commercial scale at which privacy-native architecture can operate without performance degradation. The AI personalisation engine, the agentic campaign workflows, and the predictive churn models all operate within the consent and purpose boundaries described above. The revenue tracked is not despite the compliance architecture; it is enabled by the trust that architecture builds with members.
- Consent is stored as a versioned, purpose-specific data attribute — not a single opt-in boolean — and can be queried per member per purpose in real time
- Platform provides a one-click member data export in machine-readable format to honour DPDP right-of-access requests within the 72-hour regulatory window
- Right-to-erasure requests trigger automated cascade deletion across all integrated POS systems, analytics tools, and AI model training datasets — not just the central CRM
- Every AI inference call and campaign trigger declares a specific consent purpose and is blocked at the API level if the target member lacks active consent for that purpose
- A full, immutable audit log is maintained for every data access event — including which team member, which system, and which declared purpose — and is exportable for regulatory inspection
- Data minimisation is enforced at the model training layer: AI models are trained on anonymised behavioural features, not on personally identifiable attributes
- Consent re-permission workflows are automated and triggered by loyalty programme lifecycle events, not by manual marketing calendar scheduling
“India's best loyalty programmes will not be built on the most data — they will be built on the most trusted data. Consent is not a legal hurdle; it is the quality signal that separates signal from noise.”
How Fundle solves this
Fundle was built on a single architectural conviction: in Indian retail, the brands that will compound loyalty value over the next decade are those that treat first-party data as a fiduciary asset, not a marketing raw material. That conviction shapes every product decision across the Fundle AI Platform — from how consent is ingested at the POS to how Fundle AI Agents execute campaign workflows without ever accessing data outside a member's declared consent scope.
The Fundle Loyalty Platform unifies Fundle Mall Loyalty and Fundle Brand Loyalty under a single consent graph. This means a mall operator can manage the full complexity of multi-brand, multi-tenant data governance — with brand-scoped consent boundaries, cross-brand anonymised insights, and regulator-ready audit trails — from a single platform. A standalone brand like Apollo Pharmacy or Reliance Trends using Fundle Brand Loyalty gets the same privacy-native architecture applied to their own member base, with AI personalisation that operates within DPDP-compliant data boundaries by default, not by configuration.
Fundle Agentic AI and Fundle AI Workflow bring automation to the compliance operations layer that no manual process can match at scale. Consent lifecycle monitoring, pre-launch campaign compliance checks, data minimisation enforcement at the model training pipeline, and right-to-erasure cascade management are all executed by Fundle AI Agents operating as background compliance functions — not as human governance bottlenecks. This is what allows the platform to simultaneously power real-time personalisation at the speed of AI and maintain the data governance rigour that DPDP demands.
Vineet Narang's founding vision for Fundle was that compliance and commercial performance are not opposing forces in loyalty — they are the same force, measured at different time horizons. In the short term, consent-native architecture costs some data volume. In the medium term, it produces higher-quality member engagement and more defensible AI models. In the long term, it is the only architecture that survives regulatory scrutiny and member trust simultaneously. For Indian retail CMOs and CIOs evaluating a DPDP compliant loyalty data platform in 2025 and beyond, that is not an ideological argument — it is the only commercially rational one.
Frequently asked
What exactly does the DPDP Act 2023 require from a retail loyalty programme?+
The Act requires that personal data — including purchase history, contact details, and behavioural signals collected through loyalty programmes — is processed only for the specific purpose for which consent was given. It mandates that members can access their data, correct it, and request erasure. It requires that consent is freely given, specific, informed, and unambiguous — not buried in T&Cs. Penalties for non-compliance can reach ₹250 crore per incident.
How is a DPDP compliant loyalty data platform different from just adding a consent checkbox to my existing programme?+
A consent checkbox is a UI element. A compliant platform is an architectural guarantee. It means that data access controls, AI inference calls, campaign triggers, and third-party integrations are all technically prevented from operating outside consented purposes — not just governed by policy. The difference matters when a regulator asks for an audit trail or a member exercises their right to erasure across all connected systems.
Can AI-driven personalisation still work effectively with DPDP-compliant data minimisation?+
Yes — and in most Indian loyalty deployments, it works better. AI models trained on clean, minimised, consent-active datasets consistently outperform models trained on large but poorly governed data lakes. Noise features derived from borderline data collection — inferred demographics, third-party enrichment without explicit consent — typically degrade model performance. Minimised, high-quality first-party data produces sharper behavioural signals.
How does Fundle handle multi-brand consent in a mall loyalty context?+
Fundle Mall Loyalty maintains brand-scoped consent boundaries within a unified member graph. A member's consent to receive offers from a specific anchor tenant does not automatically extend to other brands in the mall. Cross-brand data sharing — for instance, anonymised visit pattern insights shared with brand tenants — is handled through aggregated, non-PII datasets. Individual member data is shared with a brand only where explicit cross-brand consent has been captured at enrolment or a subsequent touchpoint.
What should I look for when evaluating loyalty platforms against DPDP readiness?+
Ask five questions: (1) Is consent stored as a versioned, purpose-specific attribute or as a boolean flag? (2) Can the platform produce a full audit trail for any member's data in under 24 hours? (3) Does right-to-erasure propagate automatically to all integrated systems? (4) Are AI inference calls gated by consent scope at the API level? (5) Does the platform enforce data minimisation at the model training layer? Platforms that cannot answer yes to all five are not DPDP-ready — they are DPDP-adjacent.
Is DPDP compliance only relevant for large retail chains, or does it apply to mid-market brands too?+
The DPDP Act applies to any Data Fiduciary processing personal data of Indian residents — there is no turnover or member-count threshold that exempts smaller operators. A mid-size apparel brand with fifty thousand loyalty members has the same obligation to honour right-to-erasure requests and maintain purpose limitation as Reliance Trends. The commercial risk scales with size, but the legal obligation does not. Mid-market brands arguably face higher proportional compliance costs if they attempt to bolt compliance onto a non-native platform versus adopting a privacy-native platform from the outset.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
