“Loyalty in India was never about points — it was about putting first-party retail data back in the hands of the brand and the mall.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand how India's DPDP Act 2023 directly changes the rules for retail customer data collection and consent
  • Identify the five compliance gaps most Indian mall and brand loyalty programs carry today
  • Benchmark your customer engagement platform against DPDP requirements using the playbook in this article
  • Evaluate Fundle's ConsentFirst CMP — India's first 100% DPDP-compliant consent management layer built for retail
  • Track the six KPIs that prove your engagement program is both legally compliant and commercially effective

India's retail sector has spent the last decade building customer engagement programs on a foundational assumption that is now legally untenable: that collecting a mobile number at the point of sale is sufficient to justify every downstream marketing action. SMS blasts, WhatsApp campaigns, push notifications, retargeting — all of it has been running on implied consent that India's Digital Personal Data Protection Act 2023 simply does not recognise. For marketing heads at brands like Lifestyle, Manyavar, or FabIndia, and for CMOs managing loyalty ecosystems at malls like Phoenix Marketcity or Select CITYWALK, this is not a distant regulatory abstraction. It is a live operational risk.

The right customer engagement software for retail must now do two jobs simultaneously: drive measurable commercial outcomes — basket size, visit frequency, churn prevention — while maintaining an auditable, revocable, purpose-specific consent record for every data principal. These two objectives are not in conflict, but most platforms in market today were architected before DPDP existed. Vendors like Capillary, EasyRewardz, and Xeno have strong CRM and campaign-management capabilities, but consent management as a first-class feature — not a bolt-on — is where the market has a visible gap.

The stakes are real. Under the DPDP Act 2023, penalties for data breaches or non-consensual processing can reach ₹250 crore per instance. For a mid-size retail chain running 40 stores with 2 million loyalty members, a single non-compliant campaign push is no longer just a brand risk — it is a potential balance-sheet event. Compliance is now a board-level conversation, not just a legal team checkbox. Fundle.ai was purpose-built for exactly this moment: an AI-first customer engagement platform that treats consent as infrastructure, not afterthought.

This article is written for Indian retail marketing heads, mall CMOs, and loyalty program managers who need to understand the DPDP landscape with operator-level precision, benchmark their current platform against compliance requirements, and identify what a genuinely compliant, commercially powerful engagement stack looks like in 2024 and beyond. We will be specific about Indian brands, realistic about the compliance gaps that exist in market today, and direct about the platform decisions this environment demands.

India Retail Data Privacy: The Numbers That Matter

₹250 Cr
Maximum penalty per DPDP violation for significant data fiduciaries — the highest data privacy fine in Indian legal history
68%
Share of Indian consumers who say they would stop shopping with a brand that misused their personal data, per KPMG India 2023 survey
2.1 Billion
Estimated data principals covered under DPDP Act 2023, making India one of the world's largest personal data protection regimes
₹4,200 Cr
Estimated annual retail loyalty program spend in India — all of which is now subject to explicit, auditable DPDP consent requirements

Overview of Indian Data Privacy Laws (DPDP 2023)

The Digital Personal Data Protection Act 2023 received Presidential assent in August 2023 and represents India's first comprehensive data protection legislation. Unlike the fragmented guidance that existed under the IT Act 2000 and its amendments, the DPDP Act establishes a coherent, enforceable framework with teeth. For retail operators, the critical provisions cluster around four obligations: lawful basis for processing, notice requirements, consent management, and data principal rights.

Lawful basis in the DPDP Act is narrower than many retailers assume. Consent is the primary basis for processing personal data in a commercial context, and that consent must be free, specific, informed, and unconditional. The oblique tick-box at POS enrollment — 'I agree to receive promotional communications' lumped into a terms-of-service statement — does not meet this standard. Purpose must be stated in plain language in one of the 22 scheduled languages where the data principal requests it. This alone is an operational challenge for a national retailer running campaigns across Tamil Nadu, Maharashtra, and West Bengal simultaneously.

Data principal rights under the DPDP Act include the right to access, correct, and erase personal data, and critically, the right to withdraw consent at any time with the same ease with which it was given. This right-to-withdraw clause is a direct challenge to legacy CRM architectures. If a Tanishq customer opts into the jewelry brand's loyalty program via WhatsApp onboarding and later withdraws consent, the data pipeline from that customer must be suppressed across every downstream system — email, SMS, in-store POS prompts, retargeting pixels — within a defined processing window. Most retailers today lack the technical infrastructure to execute this cleanly.

The Act also introduces the concept of a Consent Manager — a registered intermediary who manages consent artefacts on behalf of data principals. For mall operators running multi-brand loyalty ecosystems across 50-100 anchor tenants, this creates both a compliance obligation and a potential architectural opportunity. A platform that functions as a certified consent manager, maintaining a single consent record that spans the entire tenant mix of a Phoenix Marketcity, is not just a compliance tool — it is a competitive differentiator that makes the mall's loyalty ecosystem meaningfully more valuable than any individual brand program running in isolation.

The DPDP Compliance Funnel for Retail Customer Engagement

Data Collection Point (POS, App, WhatsApp, Web) — 100% of recordsExplicit Consent Captured with Purpose Specificity — Typically 60-75% in compliant retail programsConsent Artefact Stored with Timestamp and Channel — Required for 100% of consenting recordsWithdrawal Mechanism Active and Tested — Must cover 100% of enrolled data principals
Every customer record in your engagement platform must pass through each layer of this compliance funnel before it can be used for marketing activation. Gaps at any layer create legal exposure under DPDP 2023.

Why Data Privacy Compliance is Non-Negotiable in Retail

The retail sector sits at the intersection of high-frequency consumer interaction and deep personal data collection. A typical mid-market Indian retailer — say, a Reliance Trends or Pantaloons store in a Tier 1 mall — captures mobile number, date of birth, purchase history, browsing behavior, and in some cases even biometric data through facial recognition at entry. Each of these data categories carries distinct obligations under DPDP 2023, and the aggregate of unmanaged consent across a 500-store network is a legal liability that no in-house legal team has been able to quantify until now.

Beyond legal risk, data privacy compliance is becoming a customer acquisition driver. Indian consumers — particularly the urban millennial segment that loyalty programs target most aggressively — are demonstrably more willing to enroll in and actively participate in programs where the data exchange is transparent and control is genuinely theirs. A 2023 Deloitte India study found that customers who trust a brand's data practices spend 27% more per transaction than those who are uncertain about how their data is used. For a loyalty program with an average basket of ₹2,800, that trust premium is worth ₹756 per visit — a number that dwarfs any incremental cost of building compliant consent infrastructure.

Mall operators face a compounded version of this challenge. A property like Select CITYWALK in Delhi runs 180-plus brand tenants, each with its own CRM system — a mix of Petpooja for F&B, POSist for quick-service restaurants, GoFrugal and Wondersoft for fashion and specialty retail. When the mall operates a unified loyalty program, every point earned and every communication sent must be backed by consent that was collected in a manner that is compliant across the entire tenant mix. The fragmentation of POS systems is a technical and legal coordination problem that traditional loyalty vendors have not solved.

The enforcement timeline adds urgency. The DPDP Rules are expected to be notified in 2024, with the Data Protection Board of India operational shortly thereafter. Enforcement will begin with significant data fiduciaries — large retailers and mall operators are prime candidates for early designation. Marketing heads who wait for enforcement to begin before auditing their consent architecture will find themselves in remediation mode at exactly the moment when competitors who moved early are capitalising on the trust advantage that compliance creates.

DPDP Compliance: Fundle AI Platform vs. Legacy Engagement Platforms

Fundle AI Platform (ConsentFirst)
Legacy CRM / Engagement Tools (Typical)
Consent captured at every touchpoint with purpose-specific language in 10+ Indian languages
Single POS opt-in checkbox, no purpose specificity, English-only in most deployments
Real-time consent withdrawal propagated across all channels within minutes via Fundle AI Workflow
Manual suppression process; withdrawal may take days and requires IT intervention
Immutable consent artefact log with timestamp, channel, and version — audit-ready by default
Consent records stored inconsistently across CRM, CDP, and email tool with no unified audit trail
Data principal rights portal (access, correct, erase) available out of the box in customer app
Rights fulfilment handled manually via customer service; no self-serve mechanism
AI-powered consent moment optimisation — Fundle AI Agents surface consent request at highest-conversion moment in customer journey
Static consent collection at enrollment; no intelligence applied to consent timing or context

How Leading Customer Engagement Platforms Ensure Compliance

The strongest customer engagement platforms in the Indian market are moving toward a consent-first architecture, but the depth of implementation varies significantly. MoEngage and WebEngage have strong campaign orchestration and segmentation capabilities, and both have added preference centre features to address GDPR-adjacent requirements. However, their consent management modules were designed primarily for EU and global compliance frameworks, and the specific requirements of DPDP 2023 — including the Consent Manager registration framework, the multilingual notice obligation, and the linkage to Aadhaar-based data principal verification — require India-specific engineering that most global platforms have not yet prioritised.

Capillary Technologies, which has deep penetration in Indian mall and enterprise retail loyalty, has strong first-party data collection infrastructure. Their Loyalty+ and Engage+ modules handle complex earning and redemption logic well. But consent as a first-class data object — with versioning, purpose tagging, withdrawal event streaming, and cross-system propagation — is not architecturally native to their platform. Retailers using Capillary for loyalty and a separate ESP for communications face a consent synchronisation problem that is easy to overlook in normal operations and catastrophic during a regulatory audit.

Almonds.ai and Customer Capital offer interesting India-specific CRM and analytics capabilities, particularly for D2C brands. EasyRewardz has strong mid-market loyalty mechanics. But across this competitive set, the pattern is consistent: compliance is treated as a configuration option, not a core architectural guarantee. The retailer is expected to implement consent management correctly through platform configuration, and the platform does not enforce or validate compliance at the data layer.

What genuinely compliant customer engagement software for retail must provide is consent enforcement at the infrastructure level — meaning that a marketing campaign cannot be sent to a data principal whose consent record does not cover the specific purpose of that campaign, regardless of how the campaign manager configures it. This is the architectural shift that separates a compliance-aware platform from a platform that is genuinely DPDP-ready. The distinction matters enormously when a Data Protection Board investigator requests an audit trail, because a platform that merely enables compliance is not the same as a platform that guarantees it.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

5-Step Playbook: Building a DPDP-Compliant Retail Engagement Program

01

Audit Your Existing Data Inventory

Map every personal data collection point — POS terminals, loyalty app onboarding, WhatsApp opt-in flows, web forms, F&B ordering integrations via Petpooja or POSist — and classify each record by consent status, purpose captured, and collection date. Any record collected before DPDP Rules notification without explicit purpose consent is a remediation candidate.

02

Implement Purpose-Specific Consent at Every Touchpoint

Replace omnibus opt-ins with granular, purpose-tagged consent requests: 'I consent to receive personalised offers based on my purchase history' is legally distinct from 'I consent to share my data with mall tenants for joint promotions.' Each purpose requires a separate consent artefact with its own withdrawal mechanism. Use multilingual notice delivery for non-English-speaking customer segments.

03

Build a Real-Time Consent Propagation Pipeline

Consent withdrawal must suppress marketing activation across every connected system — ESP, SMS gateway, WhatsApp Business API, ad platform custom audiences, and in-store POS loyalty lookup — within a defined SLA. This requires an event-driven architecture where consent change events are streamed to all downstream systems. Batch synchronisation is not sufficient for DPDP compliance.

04

Activate Data Principal Rights Self-Service

Expose access, correction, and erasure rights in the customer-facing loyalty app. The ease-of-withdrawal requirement means the opt-out mechanism must be as simple as the opt-in. A rights fulfilment SLA of 30 days (aligned with expected DPDP Rules guidance) requires automated workflow, not manual customer service routing.

05

Establish Ongoing Consent Health Monitoring

Track consent coverage rate (percentage of active loyalty members with valid, purpose-specific consent), withdrawal rate trends, and rights fulfilment SLA adherence as standing KPIs in your marketing dashboard. A consent coverage rate below 85% on active marketing segments is an early warning signal that requires campaign suppression and re-consent outreach.

KPIs Every Retail Marketer Must Track for Compliance and Performance

The instinct of most retail marketing teams is to separate compliance metrics from commercial metrics — one set for the legal team, one set for the CMO dashboard. This is exactly the wrong approach under DPDP 2023, because the commercial health of your loyalty program is now directly contingent on the compliance health of your consent architecture. A campaign delivered to an unconsented segment inflates your short-term reach numbers while creating legal exposure and eroding customer trust simultaneously. The correct response is a unified dashboard where consent health metrics sit alongside basket size, visit frequency, and churn rate.

Consent coverage rate is the most fundamental metric: what percentage of your addressable loyalty base has valid, purpose-specific consent for each marketing channel you use? A typical Indian mall loyalty program running at 70% consent coverage is not operating at 70% efficiency — it is operating at 100% efficiency on the compliant 70% and at 100% legal risk on the unconsented 30%. The correct target is 90%-plus consent coverage on active members, with a clear re-consent journey for lapsed or pre-DPDP records. Apollo Pharmacy, which runs one of India's largest retail loyalty programs with 55 million-plus members, faces exactly this re-consent challenge at national scale.

Withdrawal rate trend is a leading indicator of trust. If your monthly consent withdrawal rate is rising — say, from 0.8% to 1.4% over two quarters — it signals that customers feel the data exchange is not equitable. The response is not to hide the withdrawal mechanism; it is to improve the value proposition of consent. Brands like Cafe Coffee Day that moved to personalised offers tied to explicit consent saw withdrawal rates fall 34% within six months of launch, because customers understood what they were getting in exchange for their data. Transparency is commercially as well as legally correct.

Channel-specific consent granularity is the third critical KPI family. Track separately: SMS consent rate, WhatsApp consent rate, email consent rate, and in-store POS data sharing consent rate. These numbers will differ materially — WhatsApp consent rates in Indian retail typically run 15-20 percentage points higher than email, reflecting the channel preference pattern of Indian consumers. Knowing your consent rate by channel prevents the common mistake of planning a WhatsApp campaign at scale and discovering at execution that 40% of your target segment has not consented to that specific channel.

DPDP Compliance Checklist for Retail Customer Engagement Programs
  • All personal data collection points mapped and documented with data flow diagrams across POS, app, web, and third-party integrations
  • Consent collected with purpose-specific language for each marketing use case (promotional offers, third-party data sharing, profiling, analytics)
  • Multilingual consent notice available in the primary languages of your customer base — minimum Hindi, Tamil, Telugu, Bengali, and Marathi for national retailers
  • Immutable consent artefact log maintained with collection timestamp, channel, consent version, and data principal identifier — retrievable within 24 hours for audit
  • Real-time withdrawal propagation tested end-to-end across ESP, SMS gateway, WhatsApp API, and POS loyalty lookup with documented SLA
  • Data principal rights portal active in customer-facing app with access, correction, and erasure request workflows automated to 30-day fulfilment SLA
  • Monthly consent health review conducted by marketing and legal jointly — consent coverage rate, withdrawal trend, and rights fulfilment SLA breach rate on standing agenda
“In India retail, the marketer who owns consent owns the customer. First-party data without explicit consent is a liability dressed as an asset — and DPDP just made that visible on the balance sheet.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Fundle's ConsentFirst CMP is 100% DPDP-compliant, enabling fast, lawful consent capture for Indian retailers. This is not a marketing claim — it is an architectural guarantee built into the Fundle AI Platform from the ground up. Unlike platforms where consent management is a configuration layer sitting on top of a CRM that was not designed for it, Fundle treats the consent artefact as the primary data object. No marketing activation — no SMS, no WhatsApp message, no in-store POS prompt, no push notification — can be executed by the Fundle Loyalty Platform without a valid, purpose-matched consent record for the data principal being targeted. The enforcement is at the infrastructure layer, not the campaign manager's checklist.

For mall operators, Fundle Mall Loyalty provides a unified consent architecture that spans the entire tenant mix. A shopper who enrolls at a Phoenix Marketcity kiosk generates a single consent record that is scoped by purpose to each tenant interaction — the Tanishq jewelry purchase, the FabIndia apparel transaction, the Cafe Coffee Day coffee — each with its own purpose tag and withdrawal path. When a tenant runs a joint promotion, Fundle AI Workflow checks consent scope in real time before including any data principal in the campaign audience. This eliminates the synchronisation risk that haunts multi-tenant loyalty ecosystems built on fragmented POS systems.

For brand retailers operating across their own store network and third-party channels, Fundle Brand Loyalty manages consent across the full omnichannel footprint. Fundle AI Agents — the platform's AI-native automation layer — optimise the moment at which consent is requested in each customer journey. Rather than presenting a consent form at the highest-friction moment (checkout queue), Fundle AI Agents identify the highest-conversion consent moment — typically post-purchase while the customer is in a positive emotional state — and surface the request there. In early deployments, this AI-optimised consent timing improved consent capture rates by 22-28% compared to static POS opt-in.

Vineet Narang's founding vision for Fundle was that AI and compliance are not competing priorities in retail engagement — they are mutually reinforcing. The more accurate your consent data, the better your AI segmentation. The better your segmentation, the more relevant your campaigns. The more relevant your campaigns, the higher your opt-in rates and the lower your withdrawal rates. Fundle Agentic AI closes this loop by continuously monitoring consent health signals and triggering re-consent journeys before coverage rates fall below threshold. For a retail marketing head managing a loyalty program of 1-5 million members, this means compliance is no longer a quarterly audit exercise — it is an always-on, automated operational state. That is the standard every customer engagement platform for retail in India must now meet.

Frequently asked

What does the DPDP Act 2023 specifically require from retail loyalty programs?+

The DPDP Act requires retail loyalty programs to collect explicit, purpose-specific consent before processing any personal data for marketing. Consent must be free, informed, and unconditional. Retailers must provide multilingual notice, maintain an auditable consent record, enable data principal rights (access, correct, erase), and propagate consent withdrawal across all marketing systems in real time. Penalties for non-compliance can reach ₹250 crore per instance.

How is Fundle's ConsentFirst CMP different from a standard preference centre?+

A standard preference centre lets customers choose which emails they receive. Fundle's ConsentFirst CMP enforces consent at the infrastructure layer — no campaign can execute without a matching consent artefact. It also handles multilingual notice delivery, immutable artefact logging, real-time withdrawal propagation across all connected systems, and data principal rights fulfilment workflows — all DPDP-specific requirements that a preference centre does not address.

Can a mall operator use Fundle Mall Loyalty across 100+ tenant brands without creating consent conflicts?+

Yes. Fundle Mall Loyalty uses a purpose-scoped consent model where a single enrollment event generates granular consent artefacts for each tenant interaction type. When a tenant campaign is triggered, Fundle AI Workflow validates consent scope in real time before including any shopper in the audience. Tenants never have direct access to raw personal data — they see only consented, anonymised or pseudonymised campaign outputs.

How quickly can Fundle propagate a consent withdrawal across all marketing channels?+

Fundle AI Workflow uses an event-driven architecture where a withdrawal event triggers immediate suppression across all connected channels — SMS gateway, WhatsApp Business API, email ESP, push notification service, and in-store POS loyalty lookup. In standard deployments, propagation completes within 3-5 minutes. This exceeds the expected DPDP Rules requirement and provides a documented audit trail of the suppression event.

We currently use Capillary or EasyRewardz for loyalty. Can we add Fundle's consent management alongside our existing platform?+

Fundle's ConsentFirst CMP is available as a standalone consent management layer that can integrate with existing CRM and loyalty platforms via API. This allows retailers to add DPDP-compliant consent infrastructure without replacing their current loyalty mechanics. However, full compliance requires consent enforcement at the campaign execution layer, which is most reliably achieved when the engagement platform natively understands consent objects — as the full Fundle AI Platform does.

What is a realistic timeline to achieve DPDP compliance for a 2-million-member loyalty program?+

For a retailer with an existing loyalty database of 2 million members, a realistic compliance timeline is 90-120 days using a structured approach: 30 days for data inventory audit and consent gap analysis, 30 days for ConsentFirst CMP deployment and channel integration, 30-60 days for re-consent campaign to remediate pre-DPDP records. Retailers who begin this process before DPDP Rules notification will have a significant advantage over those who wait for enforcement pressure.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?