“If you can't tie a loyalty rupee to an incremental sale, you don't have loyalty — you have philanthropy. Fundle's offline-attribution engine ends that ambiguity.”
- •Understand exactly which customer data fields DPDP mandates consent for inside loyalty workflows
- •Implement a ConsentFirst architecture that captures, stores, and withdraws consent in real time
- •Minimize data collection to only what drives loyalty ROI — birthday, spend tier, channel preference
- •Audit consent logs quarterly to avoid penalties under DPDP that can reach ₹250 crore per breach instance
- •Deploy Fundle AI Agents to automate consent-gated personalization without manual intervention
India's Digital Personal Data Protection Act, 2023 — commonly referred to as DPDP — is not a distant regulatory footnote. With the Data Protection Board expected to become operational in 2025 and the Rules framing underway, every CMO running a loyalty program across Phoenix Marketcity, Select CITYWALK, or a 200-store Reliance Trends network is sitting on a compliance time bomb. The question is not whether DPDP applies to your loyalty database. It does. The question is whether your loyalty workflow automation infrastructure was built to handle it.
Indian retail loyalty programs have historically operated in a data-collection frenzy. POS terminals at Pantaloons, Lifestyle, and Manyavar capture phone numbers, birth dates, tier status, and transaction histories — often with a checkbox consent buried in a welcome SMS that no customer ever reads. Under DPDP, that approach exposes the data fiduciary (your brand or mall entity) to penalties of up to ₹250 crore per breach instance. More practically, it destroys the trust equity you spent years building with your loyalty member base.
The stakes are highest in the mall context. A large Grade-A mall like Phoenix Marketcity Mumbai or DLF Promenade aggregates data from 150-200 brands, a central loyalty engine, food court operators, and parking systems — all touching the same customer. Each data flow is a potential DPDP consent obligation. The mall CMO must now think like a data protection officer: purpose limitation, data minimization, consent specificity, and withdrawal mechanisms are no longer IT concerns. They are loyalty strategy concerns.
This is precisely the architecture that Fundle was designed for. DPDP compliant loyalty automation is not about adding a compliance layer on top of an existing program. It requires rethinking the data collection logic, consent capture sequence, and workflow triggers from the ground up. This article lays out the exact playbook — what customer data DPDP governs, how consent management must work, what data minimization looks like in practice, and how to audit your way to ongoing compliance.
India Loyalty + DPDP: The Numbers That Matter
Overview of Customer Data Requirements Under DPDP
The DPDP Act classifies any information that identifies or can identify a natural person as 'personal data.' For a loyalty program, this means your entire member database — phone numbers, email addresses, names, transaction histories, location data captured at mall entry gates, browsing behaviour on your loyalty app, and even inferred data like spend tier and lifestyle segment — falls squarely under the Act's ambit.
DPDP requires that data be collected only for a 'specified, clear, and lawful purpose.' This single clause dismantles the common Indian retail practice of collecting 15 data fields at enrollment and activating all of them for every downstream campaign. If you enrolled a Lifestyle member to give them birthday rewards, you cannot silently use that same data for a third-party co-branded credit card offer without fresh, specific consent. Purpose specificity is non-negotiable.
For mall loyalty programs, the data flows are particularly complex. A customer who taps their loyalty card at a Tanishq store inside Phoenix Marketcity generates a transaction event that simultaneously feeds the brand's CRM (Capillary or Xeno, in many cases), the mall's central loyalty platform, and potentially an analytics layer like MoEngage or WebEngage. Under DPDP, each of these entities that processes the data — not just the one that collected it — has obligations. The mall operator, as the primary data fiduciary, must ensure that every downstream processor has a valid data processing agreement and operates within the consented purpose boundary.
Critically, DPDP mandates that consent be 'free, specific, informed, unconditional, and unambiguous.' Pre-ticked boxes, bundled consents, and consent buried in terms-and-conditions PDFs will not survive regulatory scrutiny. For loyalty workflow automation India-wide to work legally, consent must be an active, granular, per-purpose action by the customer — and it must be as easy to withdraw as it was to give. Brands operating on older POS-integrated loyalty stacks from GoFrugal, POSist, or Petpooja need to assess urgently whether their consent capture layer meets this bar.
DPDP Consent Funnel for Mall Loyalty Enrollment
Consent Management Fundamentals for Loyalty Workflow Automation India
Consent management in the context of DPDP compliant loyalty automation is not a one-time enrollment checkbox. It is a living data structure that must track: what consent was given, for which purpose, through which channel, at what timestamp, with which version of the consent notice, and whether it has since been modified or withdrawn. Every loyalty platform — whether it is a homegrown mall CRM or a third-party stack — must be able to surface this audit trail on demand.
The most practical architecture for Indian retail is a Consent Management Platform (CMP) that sits upstream of every data activation workflow. Before any loyalty trigger fires — a birthday campaign to Cafe Coffee Day members, a win-back sequence for lapsed Pantaloons shoppers, a tier-upgrade push for FabIndia regulars — the automation engine must check the CMP to confirm active, in-scope consent exists for that specific communication purpose. If consent has been withdrawn or never granted for that purpose, the workflow must skip that member, not merely suppress the message.
This is where most Indian loyalty operators will find their current stack insufficient. Platforms like EasyRewardz or older Capillary configurations were built for campaign execution, not consent-gated workflow logic. The CMP integration layer is often missing entirely, meaning consent status lives in a spreadsheet or a basic flag in the CRM — neither of which supports real-time consent checking at workflow trigger time.
Good consent management also means designing the withdrawal experience with the same care as enrollment. Under DPDP, a customer must be able to withdraw consent at any time, and the data fiduciary must action that withdrawal 'without delay.' For a mall loyalty program with 5 lakh members, this means automated propagation of withdrawal signals across every connected system — the POS, the campaign automation layer, the analytics platform, and any partner brand CRMs that received the member's data. Building this withdrawal propagation pipeline is non-trivial but legally mandatory. Brands that rely on Wondersoft or standalone Petpooja POS integrations will need middleware to bridge consent state changes in real time.
Legacy Loyalty Data Practices vs. DPDP-Compliant Architecture
Data Minimization and Security Protocols in Retail Loyalty Programs
Data minimization is one of DPDP's sharpest teeth for the retail loyalty sector. The principle is straightforward: collect only what you genuinely need for the stated purpose. The implementation is where most programs stumble. A typical Indian mall loyalty enrollment form asks for name, phone, email, date of birth, anniversary date, gender, pin code, income bracket, and sometimes occupation. Of these, a loyalty program that awards points on spend and sends birthday offers legitimately needs: name, phone (for identification), date of birth (for birthday trigger), and a spend tracking identifier. Everything else is data collection convenience dressed up as 'personalization.'
The business case for data minimization is stronger than most CMOs realize. Smaller, cleaner data sets are cheaper to store and secure, generate higher consent acceptance rates because members trust bounded requests, and reduce breach exposure dramatically. Apollo Pharmacy's loyalty program, for instance, operates in a sensitive category (health data adjacency) where data minimization is not just a legal imperative but a core trust signal to members.
On the security side, DPDP requires 'reasonable security safeguards' — a standard that the Rules will elaborate but that already implies encryption at rest and in transit, access controls based on role and necessity, breach notification to the Data Protection Board within prescribed timelines, and documented security policies. For mall operators running loyalty data on shared infrastructure with their property management systems, this requires immediate segregation review.
Practically, Indian retail loyalty programs should implement: AES-256 encryption for all stored member PII, TLS 1.3 for all data transmission between POS systems (Wondersoft, POSist, GoFrugal) and the central loyalty engine, role-based access controls so that store-level staff cannot view full member profiles, and tokenization of loyalty identifiers so that the POS never transmits raw phone numbers. These are not exotic requirements — they are table-stakes security hygiene that many programs have deferred. DPDP makes deferral untenable.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
5-Step Playbook: Implementing ConsentFirst in Loyalty Workflows
Map Every Data Touchpoint Across the Loyalty Journey
Document every point where customer data is collected, processed, or shared — POS enrollment, app registration, campaign response, partner brand transactions, parking integrations. For a mid-size mall, this typically yields 12-18 distinct data touchpoints. Each requires a mapped consent purpose and a data minimization assessment before you can build a compliant automation workflow.
Deploy a ConsentFirst CMP as the Single Source of Consent Truth
Implement a dedicated Consent Management Platform that stores member consent records with purpose taxonomy, timestamp, channel, notice version, and withdrawal status. This CMP must expose real-time APIs so that every downstream workflow engine — campaign automation, AI segmentation, partner data sharing — can query consent status before triggering any data use. Without this, DPDP compliance is performative rather than structural.
Redesign Enrollment Flows for Granular, Layered Consent
Rebuild the enrollment UX — whether on a mall app, a brand POS, or a WhatsApp onboarding flow — so that consent is captured per purpose category: basic program operation, personalized marketing, partner brand sharing, AI-based profiling. Use plain language (Hindi and regional language options where relevant), avoid bundled consents, and present withdrawal options at the same prominence as acceptance. Test for 70%+ consent acceptance on core purposes — if acceptance is lower, your value exchange is unclear, not your UX.
Wire Consent Gating into Every Automation Workflow Trigger
Every loyalty automation workflow — birthday campaigns for Manyavar members, lapse-prevention flows for FabIndia regulars, tier-upgrade nudges at Select CITYWALK — must include a consent-check node as the first gate. If the CMP returns no valid consent for the campaign's purpose, the workflow routes the member to a consent re-capture journey rather than suppressing them silently. This transforms compliance from a filter into an engagement opportunity.
Build and Test Withdrawal Propagation Pipelines
When a member withdraws consent — via the app, a customer care call, or a WhatsApp reply — that withdrawal signal must propagate to every connected system within the window prescribed by DPDP Rules. Build automated propagation pipelines to your POS systems, campaign tools, analytics platforms, and partner brand CRMs. Test these pipelines quarterly with synthetic withdrawal events to confirm end-to-end propagation within SLA. Document every test run for regulatory audit readiness.
KPIs to Track for DPDP Compliance in Loyalty Automation
Compliance is measurable. Mall CMOs and loyalty managers who treat DPDP as a legal checkbox rather than an operational discipline will discover their gaps first through a regulator's notice rather than their own dashboards. The right KPI framework makes compliance visible, improvable, and board-reportable.
The primary compliance KPIs to track are: Consent Coverage Rate (percentage of active loyalty members with valid, purpose-specific consent records in the CMP), Consent Withdrawal Response Time (average hours from member withdrawal request to full system propagation), Data Minimization Score (ratio of data fields actively used in automation workflows versus total fields collected — target below 1.3x), Breach Detection Time (hours from incident to internal detection, with a target under 4 hours for Significant Data Fiduciaries), and Audit Readiness Score (percentage of data processing activities with documented DPAs and processing records).
Operational loyalty KPIs must also be reframed through a compliance lens. Opt-in rates by consent purpose tell you whether your value proposition justifies the data ask. Re-consent campaign conversion rates measure how effectively you recover consent from members whose old opt-ins do not meet DPDP standards. Consent-active member revenue contribution tells you the commercial value of your compliant database versus your full member base — a figure that will concentrate executive attention faster than any compliance argument.
For mall operators managing multi-brand loyalty ecosystems, an additional KPI matters: Partner Compliance Coverage Rate — the percentage of partner brands with signed DPAs and verified DPDP-compliant data handling. At a mall like Nexus Seawoods or Ambience Mall, where 100+ brands share the loyalty infrastructure, partner compliance is a fiduciary responsibility of the mall operator. A single non-compliant partner brand's data handling can expose the mall entity to regulatory action. Audit your partners annually and make DPA execution a condition of loyalty program participation.
- Consent records stored with purpose taxonomy, timestamp, notice version, and channel for every active loyalty member
- Granular, per-purpose consent captured at enrollment — no blanket opt-ins covering all future data use
- Real-time consent-check API integrated into every loyalty automation workflow trigger
- Self-service consent withdrawal mechanism available via app, WhatsApp, and customer care — with <24hr system propagation SLA
- Data minimization audit completed — only fields with direct, documented loyalty purpose retained in active use
- Signed Data Processing Agreements in place with every POS vendor, campaign tool, analytics platform, and partner brand
- Quarterly compliance audit scheduled with documented outputs: consent coverage, withdrawal SLA, breach simulation test results, DPA status tracker
“In Indian retail, consent is not a compliance tax — it is the new loyalty currency. The brands that earn consent earn the customer. Everything else is borrowed time.”
How Fundle solves this
Fundle was architected from the ground up with the assumption that consent is infrastructure, not an afterthought. The Fundle AI Platform treats every member's consent record as a first-class data object — queryable, auditable, and propagatable across every workflow in real time. This is not a bolt-on compliance module. It is the operating logic of the entire platform.
At the core of Fundle's DPDP compliant loyalty automation capability is the ConsentFirst architecture — Fundle's proprietary approach to consent-gated data activation. Fundle's ConsentFirst platform already manages consent for 1.33 crore-plus users, ensuring DPDP compliant data handling at a scale that covers everything from single-brand retail programs to complex multi-tenant mall ecosystems. When a Fundle Mall Loyalty installation at a Phoenix Marketcity property fires a birthday campaign, the Fundle AI Workflow layer checks ConsentFirst consent state in real time before the message dispatches. Members without active consent for personalized marketing are automatically routed into a re-consent journey, not silently dropped — turning a compliance gate into an engagement touchpoint.
Fundle Brand Loyalty deployments for standalone retail chains — whether a 50-store ethnic wear brand like Manyavar or a pharmacy chain adjacent to Apollo's category — benefit from Fundle AI Agents that handle consent capture, renewal, and withdrawal propagation autonomously. These agents monitor consent expiry (where re-confirmation is the brand's policy), initiate re-consent flows through the member's preferred channel (WhatsApp, SMS, or in-app), and propagate withdrawal signals to all connected processors within the SLA window. The Fundle Agentic AI layer logs every action with a timestamped audit trail that is directly export-ready for regulatory review.
Vineet Narang's founding vision for Fundle was that AI in loyalty should make programs smarter and more trusted simultaneously — not trade compliance for conversion. The Fundle Loyalty platform's data minimization engine automatically flags data fields in a brand's schema that have no active workflow use, prompting quarterly data hygiene reviews. Fundle's partner compliance tracker allows mall operators to monitor DPA status and data handling certifications for every brand in the ecosystem from a single dashboard. For CMOs preparing for the Data Protection Board's operational phase, Fundle's compliance audit export generates the documentation trail — consent logs, processing records, withdrawal SLA reports — that a regulatory inquiry would require. In an environment where ₹250 crore penalties are on the table, that audit readiness is not a feature. It is the foundation.
Frequently asked
Does DPDP apply to loyalty programs that only collect phone numbers and names?+
Yes. DPDP applies to any personal data of Indian citizens processed by an Indian entity. A phone number and name combination is unambiguously personal data under the Act. If your loyalty program collects even these basic fields — and then uses them for SMS campaigns or tier tracking — you are processing personal data and consent obligations apply in full.
How specific does consent need to be for a mall loyalty program with multiple partner brands?+
Highly specific. DPDP requires purpose-linked consent, which means a member's consent to receive communications from the mall's central loyalty program does not automatically cover sharing their data with individual partner brands for those brands' own marketing. Each partner brand data-sharing purpose should ideally be a discrete consent item. Practically, you can group these into meaningful categories (e.g., 'fashion brand offers,' 'food and beverage offers') but the grouping must be genuinely purposeful, not a workaround for blanket consent.
What happens if a loyalty member withdraws consent — can they still earn and redeem points?+
This depends on the consent purpose they withdrew. If they withdraw consent only for personalized marketing communications, they can still participate in the loyalty program for basic earn and redeem functions — those can operate on contractual necessity grounds rather than consent. If they withdraw all consent including for transaction tracking, you may no longer be able to record their transactions, which effectively ends their program participation. Your terms of service must make these implications clear at enrollment.
How frequently should loyalty programs audit their DPDP compliance?+
At minimum, quarterly internal audits covering consent coverage rate, withdrawal SLA compliance, data minimization score, and DPA status for all processors. An annual third-party compliance review is advisable for programs with more than 1 lakh active members or those handling sensitive category data (health, financial). Any significant change to your loyalty tech stack — new POS vendor, new campaign tool, new analytics platform — should trigger an immediate compliance assessment of the new integration.
Can existing loyalty members' data be used under DPDP without re-obtaining consent?+
Only if you can demonstrate that valid, DPDP-standard consent was obtained at the time of enrollment — meaning it was free, specific, informed, unconditional, and unambiguous for the specific purposes you are currently using the data for. In practice, most pre-DPDP loyalty enrollments used blanket consent language that will not meet this bar. A re-consent campaign to your existing base, run before the Data Protection Board becomes fully operational, is the pragmatic path to compliance.
What is the difference between a Consent Management Platform and a standard CRM consent flag?+
A CRM consent flag is typically a single boolean field — opted in or out — with no purpose taxonomy, no version tracking, no channel record, and no real-time API. It cannot support granular per-purpose consent, cannot propagate withdrawal signals automatically, and cannot generate a DPDP-audit-ready log. A Consent Management Platform like Fundle's ConsentFirst is a dedicated system that stores consent as a structured, versioned, purpose-linked record with full event history — queryable by downstream workflow engines in real time and exportable for regulatory review. For DPDP compliance, the CRM flag approach is not fit for purpose.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
