“We measure loyalty in incremental gross margin, not in app downloads. Every Fundle dashboard is built so a CFO can argue with the marketer on the same number.”
- •Understand why DPDP 2023 fundamentally rewires how Indian retail brands collect and use consumer data on WhatsApp
- •Discover how Fundle's ConsentFirst CMP manages consents for over 1.33Cr consumer members ensuring privacy compliance across all WhatsApp loyalty programs
- •Map the five-step ConsentFirst implementation playbook from consent capture to real-time preference management
- •Compare legacy broadcast-first loyalty tools against a consent-first architecture and see why the latter wins on retention
- •Track the seven KPIs that separate compliant, high-performance WhatsApp loyalty from legal and reputational liability
India's retail loyalty landscape shifted the moment the Digital Personal Data Protection Act 2023 received Presidential assent. For the first time, Indian consumers have a statutory right to know exactly what data is being collected about them, why it is being collected, and how they can withdraw consent at any moment. For CMOs at Phoenix Marketcity, Select CITYWALK, Lifestyle, Manyavar, or FabIndia, this is not a compliance checkbox buried in the legal team's inbox. It is a marketing architecture decision that will define which brands build durable consumer relationships and which ones face penalties of up to ₹250 crore per breach under the DPDP framework.
WhatsApp is the channel where Indian retail loyalty actually happens. With over 530 million active users in India and open rates that comfortably sit above 90% versus email's 18-22%, WhatsApp Business API has become the default engagement rail for loyalty points notifications, personalised offers, cart recovery, and tier upgrade nudges. Brands like Tanishq have used WhatsApp to drive repeat purchase conversations. Apollo Pharmacy runs prescription reminders and health tips over the channel. Reliance Trends and Pantaloons have piloted WhatsApp-first member onboarding. The problem is that most of these deployments were architected before DPDP 2023 codified what valid consent actually looks like — and retrofitting consent onto a broadcast-first system is far harder than building consent-first from the start.
The WhatsApp loyalty platform DPDP compliance challenge is structural, not cosmetic. It is not enough to add a checkbox to a registration form. DPDP requires that consent be free, specific, informed, and unambiguous. It must be as easy to withdraw as it was to give. Data principals — your customers — must be able to access, correct, and erase their data on request. Every downstream use of that data, whether for personalised WhatsApp nudges, RFM segmentation, or lookalike modelling, must trace back to a lawfully obtained consent record. For brands running multi-brand mall loyalty programs or franchise retail networks, this means consent records must be granular, brand-specific, and channel-specific.
This is precisely the problem that Fundle built ConsentFirst to solve. As India's AI-first loyalty and customer engagement platform, Fundle recognised that consent management is not a legal formality sitting outside the loyalty engine — it is the foundation on which every personalised interaction must rest. Without a purpose-built Consent Management Platform integrated directly into the loyalty stack, brands are flying blind on compliance and building engagement campaigns on a foundation that regulators can pull out from under them.
The DPDP and WhatsApp Loyalty Landscape in India — By the Numbers
Understanding Consent Management Under DPDP 2023
The Digital Personal Data Protection Act 2023 is built on one foundational principle: consent must precede processing. Article 6 of the Act specifies that a data fiduciary — your brand or mall operator — may process personal data only when the data principal has given free, specific, informed, and unambiguous consent through a clear affirmative action. Silence, pre-ticked boxes, and bundled consent buried in terms and conditions are explicitly invalidated. This is a material departure from the implicit opt-in culture that Indian retail marketing normalised over the prior decade.
For WhatsApp loyalty specifically, the consent chain is multi-layered. A customer enrolling in the Lifestyle or Pantaloons loyalty program must consent separately to: enrolment and data storage, WhatsApp as a communication channel, each distinct purpose of processing such as transactional messages versus promotional offers versus third-party brand communications in a multi-brand mall context, and any cross-brand or cross-channel data sharing. In a mall loyalty program where a single visit might touch a food court operator, a fashion anchor, and a multiplex, the consent architecture must be granular enough to honour each member's preferences at the brand and channel level simultaneously.
The right to withdraw consent adds another layer of operational complexity. Under DPDP, withdrawal must be as easy as giving consent. If a member opted in via a WhatsApp message flow, they must be able to opt out via the same channel. This means brands cannot rely on a single annual consent refresh. Consent records must be living documents, updated in near-real-time, with every downstream system — the loyalty engine, the WhatsApp Business API gateway, the CRM, the analytics warehouse — reading from the same consent truth.
Data localisation requirements compound this further. The Act empowers the central government to designate certain categories of personal data that must be stored within India's borders. For retail loyalty programs that use global CRM platforms or cloud-based analytics tools, this creates a compliance dependency on the data infrastructure stack, not just the front-end consent UI. Brands that have historically piped loyalty data to AWS us-east or Google Cloud us-central need to audit their data residency posture before any DPDP-compliant WhatsApp loyalty campaign can go live. The operational lift is significant, but the WhatsApp loyalty platform DPDP compliance imperative leaves no room for deferral.
The ConsentFirst Member Journey: From WhatsApp Opt-In to DPDP-Compliant Engagement
Features of ConsentFirst for Privacy-First Engagement
ConsentFirst is Fundle's purpose-built Consent Management Platform, embedded natively within the Fundle AI Platform's loyalty and engagement stack. Unlike bolt-on consent tools from generic vendors or the rudimentary opt-out mechanisms built into platforms like MoEngage, WebEngage, or Xeno, ConsentFirst was architected from first principles around DPDP's specific requirements for Indian data fiduciaries. The distinction matters because DPDP's consent framework is not identical to GDPR's — and deploying a European consent framework template onto Indian retail loyalty programs creates both compliance gaps and unnecessary friction.
At the core of ConsentFirst is a granular, purpose-specific consent architecture. Rather than a single opt-in that covers all communications, ConsentFirst issues separate consent tokens for each processing purpose. A member at a Phoenix Marketcity mall might consent to transactional WhatsApp messages from the mall's loyalty program, decline promotional messages from fashion brands within the mall, but explicitly opt into personalised restaurant recommendations from the food court. Each of these preferences is stored as a discrete, timestamped record in the ConsentFirst ledger, with the member's mobile number as the primary key and DPDP Article references embedded in the record metadata.
The preference centre built into ConsentFirst deserves particular attention. Accessible via WhatsApp itself — the same channel where loyalty communications are delivered — it gives members a friction-free way to manage their data rights without leaving the messaging interface. This is operationally important: DPDP's requirement that withdrawal be as easy as consent means a preference centre buried three clicks deep on a mobile web portal is arguably non-compliant by design. By surfacing consent management within WhatsApp, ConsentFirst reduces withdrawal friction for members while simultaneously making it easier for brands to demonstrate compliance to regulators.
ConsentFirst also includes a real-time suppression engine that propagates consent changes across all connected systems within sub-60 seconds. When a member withdraws consent for promotional WhatsApp messages, that signal is immediately written to the consent ledger, which pushes a suppression flag to the Fundle AI Platform's campaign scheduler, to the WhatsApp Business API gateway, and to any integrated third-party systems such as GoFrugal POS or Petpooja for restaurant brands. This end-to-end propagation closes the gap between a member's stated preference and the actual cessation of communications — a gap that has historically been the source of the most egregious consumer complaints under data protection regimes globally.
Broadcast-First Legacy Tools vs. Fundle ConsentFirst Architecture
Integration with WhatsApp Loyalty Programs
The operational integration between ConsentFirst and a WhatsApp loyalty program requires careful orchestration across four distinct systems: the POS or order management system, the loyalty engine, the WhatsApp Business API gateway, and the consent ledger itself. Brands running on POSist, GoFrugal, Wondersoft, or Petpooja for their transaction capture have varying degrees of native webhook support, and ConsentFirst's integration layer is built to accommodate all four without requiring POS-side custom development.
The enrolment flow is where consent is first established. ConsentFirst supports three primary enrolment vectors: QR code at the point of sale that opens a WhatsApp conversation, a click-to-WhatsApp link in a post-purchase SMS, and an in-app deeplink for brands with existing mobile applications. In all three cases, the first interaction within WhatsApp is a consent flow — not a points balance or a welcome offer. The member sees a plain-language explanation of what data will be collected, for what purposes, and how they can manage their preferences. Only after explicit consent is recorded does the loyalty onboarding sequence begin.
For existing loyalty members enrolled before DPDP came into force, ConsentFirst includes a re-consent campaign module. This allows brands to send a structured WhatsApp message to their existing base, present the updated consent terms, and capture explicit consent for continued engagement. Critically, members who do not respond or who decline are automatically suppressed from future promotional communications, though transactional messages for existing loyalty balances may continue under DPDP's legitimate use provisions pending final regulatory guidance. This re-consent flow has been tested with members at scale across Fundle's platform, and Fundle's ConsentFirst CMP manages consents for over 1.33Cr consumer members ensuring privacy compliance across all WhatsApp loyalty programs.
At the campaign execution layer, ConsentFirst acts as a consent gate. Every campaign brief created in the Fundle AI Platform is tagged with one or more processing purposes. Before the campaign is dispatched to the WhatsApp Business API gateway, the Fundle Agentic AI performs a consent eligibility check against the ConsentFirst ledger for each target member. Members without a valid, non-withdrawn consent record for the tagged purpose are automatically excluded from the send list. This gate operates at the individual member level, not at a segment level, ensuring that even members who appear in a qualifying RFM segment are excluded if their consent record does not support the specific communication type.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
The ConsentFirst Five-Step DPDP Implementation Playbook
Consent Architecture Design
Map every data processing purpose in your WhatsApp loyalty program — transactional, promotional, analytics, third-party sharing — and define a corresponding consent purpose code. For mall operators, this includes brand-level and tenant-level purpose mapping. This design document becomes the schema for the ConsentFirst ledger.
POS and Loyalty Platform Integration
Connect ConsentFirst to your POS system (POSist, GoFrugal, Wondersoft, or Petpooja) and loyalty engine via ConsentFirst's webhook API. Configure the integration so that no loyalty record is written and no WhatsApp message is dispatched without a valid consent token from the ConsentFirst ledger.
WhatsApp Consent Flow Build
Deploy purpose-specific consent cards within your WhatsApp Business API conversation flow. Use plain language, not legal boilerplate. Each card must include: what data is collected, why, how long it is retained, and how the member can withdraw. A/B test message copy for consent acceptance rates — typically 68-74% for well-structured flows on the Fundle platform.
Preference Centre Activation
Launch the in-WhatsApp preference centre accessible via a persistent menu command or keyword trigger such as 'MANAGE PREFERENCES'. Ensure the centre covers all consent purposes, displays current consent status, and processes updates in real-time. Test the full withdrawal-to-suppression cycle before go-live, verifying sub-60-second propagation across all connected systems.
Re-Consent Campaign for Existing Base
Segment your existing loyalty member base by last active date and consent record completeness. Deploy phased re-consent WhatsApp campaigns starting with highest-value members. Set a 30-day response window. Auto-suppress non-respondents for promotional communications while preserving transactional message eligibility. Document all re-consent records in the ConsentFirst ledger for audit readiness.
Benefits for Brands and Consumers: Why Consent-First Pays
The business case for ConsentFirst extends well beyond regulatory avoidance. Brands that have shifted to consent-first engagement architectures consistently report higher engagement quality on the communications they do send, because those communications are reaching members who have actively chosen to receive them. On the Fundle platform, WhatsApp campaigns dispatched only to explicitly consented members show click-through rates 2.3 to 2.8 times higher than broadcast campaigns sent to full loyalty member bases. The reason is straightforward: members who have consciously opted into a specific type of communication are more receptive to it.
For mall operators running multi-brand loyalty programs — the operational model at properties like Phoenix Marketcity, DLF Malls, or Nexus Mall group — ConsentFirst solves a commercial problem that DPDP has made urgent. When a mall wants to share a Tanishq member's purchase behaviour with Cafe Coffee Day for a cross-brand offer, that sharing requires explicit, separate consent from the member. ConsentFirst's brand-level consent granularity makes this commercially viable by giving members the choice rather than forcing a binary opt-in-to-everything or opt-out-of-everything decision. Members who consent to cross-brand sharing are, by definition, higher-value targets for joint campaigns, and the response data from those campaigns can be fed back into the Fundle AI Platform's RFM models with full confidence in its compliance provenance.
For consumers, the benefits are concrete and immediate. Members of a ConsentFirst-powered loyalty program receive a WhatsApp message volume calibrated to their stated preferences, not to the brand's promotional calendar. They can adjust those preferences at any time without calling a customer care number or navigating a convoluted web portal. They have a clear, accessible record of what data the brand holds about them and the ability to request its correction or deletion. In a market where consumer trust in data handling by Indian brands has been eroded by years of unsolicited SMS spam and data broker activity, this level of transparency is a genuine differentiator.
The financial upside for brands is also measurable at the loyalty program economics level. Consent-verified member bases have materially lower churn rates — members who have consciously opted in are 34% less likely to go dormant within 90 days of enrolment compared to passively enrolled members on the Fundle platform's benchmarking data. Higher active member rates translate directly to higher redemption rates, which in turn drive repeat store visits and basket size. For a mall operator with 500,000 registered loyalty members, moving the active member rate from 28% to 38% — a realistic outcome of a well-executed ConsentFirst re-consent campaign — represents tens of thousands of additional monthly visit occasions, each with average spend implications in the ₹1,200 to ₹3,500 range depending on the mall's tenant mix.
- Consent Capture Rate: percentage of new loyalty enrolments that complete the full purpose-specific consent flow within 24 hours of registration — target 65%+
- Consent Validity Coverage: percentage of active loyalty members with at least one valid, non-withdrawn promotional consent record — monitor weekly, flag if below 55%
- Suppression Propagation Latency: time elapsed between a consent withdrawal event and full suppression across all connected systems — SLA target sub-60 seconds
- Data Principal Rights Fulfilment Rate: percentage of DPDP access, correction, and erasure requests fulfilled within the 72-hour statutory window — target 100%
- Re-Consent Campaign Acceptance Rate: percentage of pre-DPDP legacy members who provide explicit consent during re-consent outreach — benchmark 45-60% for active members
- Consent-Verified Engagement Lift: ratio of WhatsApp campaign CTR for consent-verified segments versus full-base broadcasts — target 2x or higher
- Dormancy Rate by Consent Cohort: 90-day dormancy rate compared across explicit opt-in members versus passively enrolled legacy members — use to quantify the financial value of consent quality
“In India, consent is not a legal formality you file and forget — it is the actual asset. The brand that owns verified, granular, real-time consent for 10 lakh members owns something no media buy can replicate.”
How Fundle solves this
Fundle's entire platform architecture was built on the premise that first-party data is only as valuable as the consent that governs it. The Fundle AI Platform integrates ConsentFirst as a native module — not an afterthought API call to a third-party consent vendor — meaning that every workflow within Fundle Loyalty, Fundle Mall Loyalty, and Fundle Brand Loyalty runs through a real-time consent gate before any personal data is processed or any communication is dispatched. This is architecturally different from what brands get when they bolt a consent plugin onto Capillary, Antavo, or Customer Capital: those are integrations across system boundaries, subject to latency, sync failures, and audit gaps. Fundle's consent gate is in-process, not inter-process.
The Fundle AI Agents that power personalised member engagement — from tier upgrade nudges to lapsed member win-back sequences — are consent-aware at the agent level. Each Fundle AI Agent carries a consent context object that specifies which processing purposes have been consented to for the target member. An agent tasked with sending a birthday offer via WhatsApp will first query the ConsentFirst ledger, confirm that the member has valid promotional consent, and only then compose and dispatch the message. If the consent check fails — because the member withdrew promotional consent the previous day — the agent logs the suppression event and escalates to a Fundle AI Workflow that schedules a re-consent outreach for the following week. The entire loop is automated, auditable, and DPDP-compliant without any manual intervention.
For mall operators, Fundle Mall Loyalty's multi-tenant consent architecture is particularly significant. ConsentFirst supports brand-level consent isolation within a shared mall loyalty program, meaning that a member's consent to receive communications from the mall operator does not automatically extend to individual tenant brands. Each tenant brand within the mall's Fundle Brand Loyalty deployment must obtain its own explicit consent from shared members before sending brand-specific WhatsApp communications. This architecture future-proofs mall operators against the scenario where DPDP's implementing rules impose stricter requirements on data sharing between joint controllers — a scenario that legal experts consider highly probable given the Act's text.
Vineet Narang's founding vision for Fundle was that loyalty in India would increasingly be won not by the brand with the largest promotional budget but by the brand with the deepest consumer trust. Fundle Agentic AI and Fundle AI Workflow make that vision operational by ensuring that every automated consumer touchpoint is traceable to an explicit consent record, every preference change is honoured in real-time, and every regulatory audit request can be answered with a complete, immutable consent history. For CMOs at Indian retail and mall brands who are building for the next decade of consumer relationships, that is not just compliance — it is competitive advantage built into the infrastructure.
Frequently asked
What is the DPDP Act 2023 and why does it affect WhatsApp loyalty programs in India?+
The Digital Personal Data Protection Act 2023 is India's primary data privacy law. It requires brands to obtain free, specific, informed, and unambiguous consent before processing any personal data, including using a customer's mobile number to send WhatsApp loyalty communications. Non-compliance can attract penalties of up to ₹250 crore per violation, making WhatsApp loyalty platform DPDP compliance a board-level issue for retail and mall brands.
How is Fundle's ConsentFirst different from simply adding an opt-out link to WhatsApp messages?+
An opt-out link is a unidirectional withdrawal mechanism. ConsentFirst is a full Consent Management Platform that handles consent capture, purpose-specific consent tokens, real-time preference management, automated suppression propagation, DPDP rights fulfilment workflows, and immutable audit logging. DPDP requires that consent be as easy to withdraw as it was to give and that every processing purpose be separately consented to — capabilities that a simple opt-out link cannot provide.
Does Fundle ConsentFirst work with existing POS systems like POSist, GoFrugal, and Wondersoft?+
Yes. ConsentFirst includes a webhook API integration layer that connects to major Indian POS and order management systems including POSist, GoFrugal, Wondersoft, and Petpooja. The integration ensures that no loyalty record is created and no WhatsApp message is dispatched without a valid consent token being present in the ConsentFirst ledger.
How does ConsentFirst handle consent for multi-brand mall loyalty programs where data is shared between tenant brands?+
ConsentFirst supports brand-level consent isolation within shared mall loyalty programs. A member's consent to communicate with the mall operator does not automatically extend to individual tenant brands. Each tenant within a Fundle Mall Loyalty deployment must obtain its own explicit consent before sending brand-specific WhatsApp communications, fully aligning with DPDP's requirements for data sharing between joint controllers.
What is the typical consent capture rate for a well-structured ConsentFirst WhatsApp onboarding flow?+
On the Fundle platform, well-structured ConsentFirst onboarding flows — using plain-language purpose descriptions rather than legal boilerplate, with a clear explanation of member benefits — achieve consent capture rates of 68-74% for new enrolments within 24 hours. Re-consent campaigns for legacy members typically achieve 45-60% acceptance rates among members who have engaged with the loyalty program within the prior 180 days.
How quickly does ConsentFirst propagate a consent withdrawal to prevent further WhatsApp sends?+
ConsentFirst's real-time suppression engine propagates a consent withdrawal across all connected systems — the Fundle Loyalty Platform, the WhatsApp Business API gateway, and any integrated third-party tools — within sub-60 seconds of the withdrawal event being recorded. This ensures that no residual WhatsApp messages are dispatched after a member withdraws consent, directly addressing one of the most common sources of consumer complaints under data protection regimes.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
