Fundle
“The best campaign is the one that didn't run. Fundle's churn-prediction model has saved Indian retailers crores in unnecessary discounting on customers who were already coming back.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • •Understand how DPDP Act 2023 directly affects loyalty program data collection, profiling and automated communication workflows
  • •Identify the five highest-risk privacy failure points in retail loyalty pipelines — from point-of-sale capture to third-party enrichment
  • •Implement a ConsentFirst approach to loyalty automation that converts compliance into a measurable trust signal
  • •Benchmark your program against DPDP-ready standards using the KPI framework outlined in this article
  • •Adopt Fundle AI Platform's embedded consent and workflow tools to future-proof loyalty operations at scale

India's Digital Personal Data Protection Act 2023 — the DPDP Act — quietly crossed from parliamentary gazette to operational reality. For most mall operators and retail loyalty managers, the reaction has oscillated between mild panic and willful ignorance. Neither response is viable. The Act imposes specific obligations on every entity that collects, stores, processes or shares personal data of Indian citizens, and a loyalty program — almost by definition — does all four, at scale, every single day.

Consider the data surface area of a mid-size mall loyalty program. At enrollment, you collect name, mobile number, date of birth, email and home pin code. Every transaction appends SKU-level purchase data, visit frequency, dwell time (if you're running Wi-Fi or footfall analytics), and spend-per-category. Automated workflows then slice this data to trigger birthday offers via SMS, abandoned-cart nudges via WhatsApp, tier-upgrade emails and geo-fenced push notifications. Third-party brand partners inside the mall — Tanishq, Lenskart, FabIndia, Manyavar — receive anonymized (or not-so-anonymized) cohort reports. At no point in this chain did most programs ask: does the member actually consent to each of these specific uses?

The DPDP Act answers that question with uncomfortable clarity. Consent must be free, specific, informed and unambiguous. It must be obtained before processing — not buried in a 4,000-word terms-and-conditions scroll at the bottom of an app onboarding screen. A member who signed up for a loyalty card at Select CITYWALK in 2019 under an older consent framework has not necessarily consented to a 2024 AI-driven behavioral segmentation engine that predicts churn and auto-triggers win-back offers. Re-consent campaigns are not optional; they are legally mandated.

This is precisely the operational complexity that Fundle was built to solve. Fundle.ai's position is that DPDP compliance is not a legal cost center — it is a first-party data strategy that compounds over time. Programs that get consent architecture right now will own cleaner, higher-quality data than competitors who are scrambling to re-paper consent in 2025 after the first regulatory notices land. This article is the operator-level playbook for getting there.

DPDP and Loyalty Data: The Numbers That Frame the Urgency

1.33 Cr+
Loyalty members whose consent Fundle manages via its embedded ConsentFirst platform — ensuring DPDP compliance at enterprise scale
₹250 Cr
Estimated maximum penalty per instance of non-compliance under India's DPDP Act 2023 for significant data fiduciaries
68%
Indian shoppers in a 2023 LocalCircles survey who said they had no idea how their data was being used after loyalty program enrollment
3.2x
Higher customer lifetime value observed in loyalty programs that display explicit consent confirmation at point-of-enrollment, per Fundle's internal cohort benchmarks

Understanding India's DPDP Act 2023 for Loyalty Operators

The Digital Personal Data Protection Act 2023 is India's first comprehensive data protection law, and it borrows heavily from GDPR's architecture while adapting to India's mobile-first, vernacular-heavy retail context. The Act defines a Data Principal (your loyalty member), a Data Fiduciary (your mall or brand entity that determines the purpose of processing) and a Data Processor (your CRM, ESP, SMS gateway, or AI workflow engine). All three roles have distinct obligations under the law — and loyalty automation platforms sit squarely in the Data Processor category.

For mall CMOs, the most operationally significant provisions cluster around four obligations. First, lawful basis for processing: loyalty programs cannot rely on 'legitimate interest' the way EU companies do under GDPR. In India, consent is the primary lawful basis for processing personal data in a commercial loyalty context. Second, purpose limitation: if a member consented to receiving offers from your mall, that consent does not automatically extend to sharing their profile with a co-branded credit card partner or an insurance aggregator. Third, data minimisation: you cannot collect date-of-birth 'just in case' you want to run birthday campaigns later if you haven't told the member that's the specific use. Fourth, the right to erasure and correction: a member who asks to be forgotten must be erased from your CRM, your CDP, your SMS suppression lists, your third-party enrichment databases and your AI training datasets — within a defined timeframe.

The Act also designates 'Significant Data Fiduciaries' — entities processing large volumes of personal data — who face enhanced obligations including appointment of a Data Protection Officer, mandatory data impact assessments and stricter breach notification timelines (currently proposed at 72 hours). Any mall operator running a program with more than a few lakh active members is almost certainly in this category. Phoenix Marketcity, with loyalty programs spanning multiple cities, or a national retailer like Reliance Trends or Pantaloons with tens of millions of members, would qualify immediately.

The implementation rules under the Act are being finalized by India's Data Protection Board, but waiting for final rules before acting is a strategic error. The consent framework — the core architectural requirement — is already clear. Programs that build consent management into their loyalty workflow automation now will need zero re-engineering when enforcement begins. Programs that don't will face the dual cost of retroactive re-consent campaigns (expect 40-60% member attrition in poorly managed re-consent flows) plus potential regulatory exposure.

Where Loyalty Data Breaks DPDP Rules: The Compliance Funnel

Enrollment — Missing purpose-specific consent for each data use case — Stage 1Behavioral Tracking — Dwell time, app events, Wi-Fi analytics without explicit notice — Stage 2Third-Party Sharing — Brand partner cohort reports without member consent — Stage 3AI Profiling — Predictive segmentation and churn models on unconsented data — Stage 4
Each stage of the loyalty data lifecycle introduces a potential DPDP violation. Operators must instrument consent gates at every transition — not just at enrollment.

Privacy Risks Hidden Inside Loyalty Workflow Automation

The loyalty automation stack of a typical Indian mall or retail chain is a patchwork. POS data flows from POSist, Petpooja or GoFrugal into a loyalty engine. Member profiles are enriched in a CDP or CRM — often Capillary, EasyRewardz or a homegrown system. Marketing workflows are orchestrated through MoEngage, WebEngage or Xeno. SMS and WhatsApp messages are dispatched via one or two gateway vendors. Analytics reports are generated in Power BI or Tableau and shared with category managers and brand partners. At no point in this stack does a single unified consent record travel alongside the data. Consent is captured once — usually at enrollment — and then effectively forgotten as data moves between systems.

This architecture creates five specific risk vectors under DPDP. The first is consent fragmentation: the enrollment consent record lives in the loyalty engine, but the AI workflow engine and the email platform have no real-time visibility into whether a member has withdrawn consent, modified their preferences, or requested deletion. A member who opts out of WhatsApp communications on a Monday can still receive an automated win-back message on Wednesday if the suppression signal hasn't propagated across the stack.

The second risk is purpose creep. A Cafe Coffee Day member who signed up for a stamp-card equivalent loyalty program almost certainly did not consent to having their visit patterns used to build a geo-behavioral profile that is then sold to a mall operator's advertising monetization team. But this is exactly how several retail data monetization programs currently operate — without the member's knowledge.

The third risk is data retention without policy. Most Indian loyalty databases contain millions of records for members who haven't transacted in three or more years. Under DPDP, you cannot retain personal data beyond the period necessary for the stated purpose. Running a loyalty program does not give you a perpetual license to hold a member's data indefinitely.

The fourth risk is third-party processor agreements. If your SMS gateway, CDP or AI vendor processes personal data on your behalf, you are responsible for ensuring they meet DPDP standards. Many Indian loyalty operators have no Data Processing Agreements with their technology vendors — a gap that creates direct fiduciary liability.

The fifth, and most commercially dangerous, risk is AI model training on unconsented data. Churn prediction models, next-best-offer engines and personalization algorithms trained on behavioral data are processing personal data. If that data was not explicitly consented for use in automated decision-making, the training and deployment of these models is non-compliant — full stop.

DPDP Compliant Loyalty Automation vs. Legacy Consent Approaches

Legacy Loyalty Programs (Pre-DPDP)
DPDP Compliant Loyalty Automation
✗Single blanket consent at enrollment, buried in T&Cs
✓Granular, purpose-specific consent captured at each data use trigger
✗Consent record stored in loyalty engine only; siloed from marketing stack
✓Unified consent record propagated in real-time across all integrated platforms
✗No withdrawal mechanism; member must call a helpdesk to opt out
✓Self-service consent dashboard accessible via app or WhatsApp bot; withdrawal actioned within minutes
✗Third-party brand partner data sharing governed only by commercial contracts
✓Member-level consent gates enforced before any data leaves the platform boundary
✗AI profiling and behavioral segmentation run on all available member data
✓AI workflows operate only on consented data segments; non-consented members excluded from model training

ConsentFirst: Fundle's Approach to Consent Management in Loyalty

Fundle's answer to the consent architecture problem is ConsentFirst — an embedded Consent Management Platform (CMP) built directly into the Fundle AI Platform rather than bolted on as an afterthought. Fundle ensures DPDP compliance across 1.33Cr+ loyalty members via its embedded ConsentFirst platform — making it one of the largest consent-managed loyalty data estates in Indian retail today.

ConsentFirst operates on three architectural principles. The first is consent as a first-class data object. Every piece of member data in the Fundle Loyalty platform carries a consent metadata tag: what was consented to, when, on which channel, at which version of the privacy notice, and whether it has been modified or withdrawn. This consent record travels with the data as it moves through Fundle AI Workflow — into segmentation, into campaign triggers, into AI model inputs. No workflow step can access personal data without first validating the consent record against the requested processing purpose.

The second principle is real-time propagation. When a member updates their consent preferences — say, opting out of third-party partner communications but retaining mall-level offers — that change is propagated across all connected systems within seconds. Fundle AI Agents monitor consent state changes and automatically suppress affected workflow steps, ensuring that the member's updated preference is honored before the next automated trigger fires. This solves the single biggest operational risk in multi-platform loyalty stacks: the lag between consent withdrawal and suppression enforcement.

The third principle is vernacular-first consent notices. India's retail shopper base is not a homogeneous English-reading cohort. A loyalty member at a Phoenix Marketcity in Pune may prefer Marathi. A Lifestyle store member in Chennai is more likely to engage with a Tamil-language consent notice than an English one. ConsentFirst supports multi-language consent notice delivery — currently covering 12 Indian languages — ensuring that the DPDP requirement for 'informed' consent is actually met in practice, not just on paper.

For mall operators managing multiple brand tenants — each with their own data processing relationships — Fundle Mall Loyalty's ConsentFirst module supports federated consent management: a single member-facing consent interface that governs data sharing with each individual brand tenant, with tenant-specific consent records maintained separately. This is the architecture that makes consent-based data monetization commercially viable without legal exposure.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

5-Step Playbook: Building DPDP Compliant Loyalty Workflow Automation

01

Audit Your Existing Data Estate

Map every data point you currently collect — at enrollment, at transaction, via behavioral tracking and through third-party enrichment. For each field, document the original consent basis, the stated purpose and every downstream system that touches it. This data inventory is a DPDP legal requirement and the foundation of any compliant automation build. Most Indian loyalty operators will discover 30-50% of their current data collection has no defensible consent basis.

02

Redesign Consent Architecture at Enrollment

Replace blanket T&C consent with a layered, purpose-specific consent flow. At minimum, separate consent for: (a) core program operation — points earning and redemption; (b) marketing communications by channel — SMS, email, WhatsApp, push; (c) behavioral profiling and AI personalization; (d) third-party brand partner data sharing. Use plain language. Test comprehension with real members. Deploy in the member's preferred language from day one.

03

Instrument Consent Propagation Across the Stack

Integrate your consent record store with every platform in the loyalty stack — POS, CRM, CDP, email ESP, SMS gateway, WhatsApp Business API provider and AI workflow engine. Establish webhook-based real-time consent state synchronization so that a withdrawal at any touchpoint suppresses processing across all connected systems within a defined SLA — target under 60 seconds for channel suppression, under 24 hours for AI model exclusion.

04

Run a Structured Re-Consent Campaign for Existing Members

Segment your existing member base by original consent vintage and consent coverage. Members enrolled before DPDP's effective date under legacy T&C frameworks require active re-consent for any processing that goes beyond the original stated purpose. Design a re-consent journey that leads with value — explain what the member gains by consenting — rather than framing it as a legal formality. Expect 55-70% re-consent rates for programs with high engagement; 25-40% for dormant segments. Model the attrition before you launch.

05

Establish Ongoing Compliance Monitoring and DPO Governance

Appoint a Data Protection Officer if you meet the Significant Data Fiduciary threshold. Build monthly consent health dashboards — tracking consent coverage rate by member segment, withdrawal velocity, and data retention age distribution. Run quarterly DPDP impact assessments for any new data use case, campaign type or technology integration before go-live. Treat compliance as a continuous operational discipline, not a one-time project.

KPIs to Track for DPDP Compliant Loyalty Automation

DPDP compliance in a loyalty context is not a binary state — compliant or not. It is a set of measurable operational metrics that should be tracked with the same rigor as campaign open rates or redemption ratios. Mall CMOs and loyalty program managers need a compliance KPI framework that runs alongside commercial performance metrics.

The first KPI cluster covers consent coverage. Consent Coverage Rate measures the percentage of active members who have a current, purpose-specific consent record covering each processing activity. Target: 95%+ for core program operation; 70%+ for marketing communications; 50%+ for third-party data sharing. Programs running below these thresholds on AI profiling and partner sharing are carrying active legal risk. Track this monthly and segment by enrollment vintage, channel and geography.

The second cluster covers consent lifecycle velocity. Withdrawal-to-Suppression Latency tracks how quickly a consent withdrawal propagates to channel suppression across the full stack. The operational target should be under 60 seconds for real-time channels (WhatsApp, push notification) and under 4 hours for batch channels (email, direct mail). Re-Consent Response Rate measures member participation in re-consent campaigns — a leading indicator of member trust and program health.

The third cluster covers data minimisation hygiene. Stale Data Ratio tracks the percentage of member records with no transaction activity in the last 24 months — members whose data you are legally obligated to either re-purpose with fresh consent or delete. Orphaned Data Records tracks personal data sitting in ancillary systems (analytics exports, partner reports, BI tools) that have not been covered by the central deletion workflow. This is typically the highest-risk category in a DPDP audit.

The fourth cluster — and the one most directly linked to commercial outcomes — covers Trust-Adjusted Engagement Rate. Members who have actively confirmed granular consent consistently show higher email open rates (typically 18-24% vs. 8-12% for the broad base), higher campaign conversion rates and lower unsubscribe rates. Tracking engagement metrics segmented by consent tier gives you a live read on the commercial value of consent-first data quality. Almonds.ai, Customer Capital and Xeno have begun surfacing similar segmentations in their analytics, but Fundle AI Platform integrates consent tier directly into the campaign workflow engine — so compliant segments are automatically prioritized for high-value automations.

DPDP Compliance Readiness Checklist for Loyalty Program Managers
  • Complete a full data inventory mapping every personal data field to its collection point, stated purpose and downstream processing system
  • Replace blanket enrollment T&C consent with purpose-specific, layered consent flows covering at minimum five distinct processing categories
  • Establish real-time consent propagation between your loyalty engine, CRM, marketing automation platform and all SMS/WhatsApp/email delivery systems
  • Run a structured re-consent campaign for all members enrolled under pre-DPDP consent frameworks, with a documented retention model for expected attrition
  • Implement a self-service member consent dashboard accessible within the loyalty app and via WhatsApp, allowing withdrawal and modification without helpdesk dependency
  • Execute and document a Data Processing Agreement with every third-party vendor — POS, CDP, SMS gateway, AI platform — that processes member personal data
  • Schedule quarterly DPDP impact assessments for any new data use case, campaign type or technology integration before production deployment
“In India, consent is not a legal hurdle — it is the beginning of a trust relationship. Programs that collect it honestly will own data that actually works. Programs that skip it will own liability.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Vineet Narang's founding thesis for Fundle was that Indian retail loyalty had a fundamental data quality problem disguised as a technology problem. The real bottleneck was not the absence of AI or automation — it was the absence of trustworthy, high-consent data on which AI and automation could operate without legal or commercial risk. The Fundle AI Platform was architected from day one with consent as a first-class infrastructure layer, not a feature added to satisfy a compliance team's checklist.

Fundle Loyalty — deployed across mall operators and enterprise retail chains — embeds ConsentFirst at every stage of the member lifecycle. At enrollment, the Fundle onboarding flow presents purpose-specific consent choices in the member's preferred language, with plain-language explanations of each use case. This is not a popup that members dismiss in two seconds; it is a structured consent journey that takes 45-90 seconds to complete and achieves documented consent coverage rates of 88-94% for core processing categories in Fundle's deployed programs. The consent record is stored as a structured data object within the Fundle platform and synchronized to every connected system via real-time webhooks.

Fundle Mall Loyalty extends this architecture to the multi-tenant mall context, where a single member interacts with dozens of brand tenants across a mall estate. The ConsentFirst federated consent model maintains separate, auditable consent records for each brand tenant's data sharing relationship while presenting the member with a single unified preference center — dramatically reducing the compliance complexity for mall operators managing 80-150 brand partners across a portfolio of properties like Phoenix, Nexus or DLF malls.

Fundle Brand Loyalty serves enterprise retail chains — national players like Apollo Pharmacy, Lifestyle or regional powerhouses — with the same consent infrastructure scaled to single-brand, multi-location deployments. Fundle AI Agents automate consent lifecycle management: monitoring withdrawal events, triggering re-consent journeys for at-risk consent records, and generating monthly compliance health reports for the Data Protection Officer. Fundle Agentic AI and Fundle AI Workflow ensure that every automated campaign, every AI-generated personalization decision and every third-party data share is gated against a live consent record before execution — not as a batch check after the fact, but as an inline validation step in the workflow itself. For Indian retail's most data-intensive loyalty programs, this is the architecture that makes DPDP compliant loyalty automation operationally real.

Frequently asked

Does India's DPDP Act 2023 apply to loyalty programs run by shopping malls?+

Yes, unambiguously. A mall loyalty program collects personal data — name, mobile number, transaction history, behavioral data — for commercial purposes. This makes the mall operator a Data Fiduciary under the DPDP Act. If the program processes data of a large number of members, it likely qualifies as a Significant Data Fiduciary with enhanced obligations including a Data Protection Officer and mandatory impact assessments.

What is the maximum penalty under DPDP Act 2023 for a retail data breach?+

The DPDP Act 2023 provides for penalties up to ₹250 crore per instance of non-compliance for significant data fiduciaries. Penalties can be assessed by the Data Protection Board of India for failures including processing without valid consent, failure to notify breaches within required timelines, and failure to honour data principal rights such as erasure and correction.

What is ConsentFirst and how does it differ from a standard cookie consent banner?+

ConsentFirst is Fundle's embedded Consent Management Platform built specifically for loyalty program data workflows — not website cookies. Unlike a generic CMP, ConsentFirst manages purpose-specific consent for transactional data processing, behavioral profiling, AI model training and third-party brand partner data sharing. It propagates consent state in real time across all systems in the loyalty stack and supports 12 Indian languages for compliant informed consent delivery.

How should loyalty managers handle existing members who signed up before DPDP was enacted?+

Existing members enrolled under pre-DPDP consent frameworks require active re-consent for any processing activity that goes beyond what was explicitly stated at the time of enrollment. The recommended approach is a structured re-consent campaign that leads with member value — communicating what benefits are unlocked by consenting — rather than framing it as a regulatory formality. Plan for 25-70% re-consent rates depending on program engagement levels and model expected attrition before launch.

Can AI-driven personalization and churn prediction models be used under DPDP without separate consent?+

No. AI profiling — including behavioral segmentation, churn prediction, next-best-offer models and lifetime value scoring — constitutes automated processing of personal data. Under DPDP, this requires explicit, informed consent that specifically mentions automated decision-making as a processing purpose. Running AI models on behavioral data covered only by a generic loyalty T&C consent is a compliance risk. Fundle AI Workflow enforces consent gating inline before any member data enters an AI processing step.

How does Fundle support mall operators who share loyalty data with brand tenants?+

Fundle Mall Loyalty's ConsentFirst module supports federated consent management — maintaining separate, auditable consent records for each brand tenant's data sharing relationship while presenting the member with a unified preference center. This means a member can consent to receiving offers from specific brand tenants while blocking others, and the platform enforces those choices at the data sharing boundary. It converts brand partner data access from a blanket arrangement into a consent-governed relationship — commercially viable and legally defensible.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

A

Abhinav · Fundle.ai

Loyalty & ADSR Expert · Online

Hey 👋 I'm Abhinav from Fundle. Are you exploring loyalty for a brand or a mall?
Powered by Fundle AI · Replies in under 30 sec