“Indian retail is the most dynamic consumer market on the planet. The platforms it deserves should be the most dynamic too. That conviction is why Fundle exists.”
- •Understand the seven core DPDP obligations every Indian retail engagement platform must satisfy by 2025
- •Map consent collection, data minimisation, and grievance redressal to your existing loyalty tech stack
- •Audit third-party vendors — POS partners like POSist, GoFrugal, and Wondersoft — against DPDP data-processor rules
- •Track five measurable KPIs that prove compliance is operational, not just documented
- •Adopt Fundle AI Platform's ConsentFirst architecture to automate consent workflows and reduce breach-risk exposure
India's Digital Personal Data Protection Act 2023 — the DPDP Act — received Presidential assent in August 2023 and its rules are expected to be enforced with full teeth by late 2025. For every Marketing Head running a loyalty programme at a Phoenix Marketcity or a Select CITYWALK, and for every CMO at Lifestyle, Pantaloons, or FabIndia, the clock is ticking. The question is no longer whether your customer engagement platform with data privacy compliance needs to be in order — it is whether your current stack can even get there without a full rebuild.
The DPDP Act introduces a set of obligations that cut across the entire customer data lifecycle: from the moment a shopper scans a QR code to join a mall loyalty programme, to the moment that data is used to send a birthday offer via WhatsApp. Every touchpoint — POS capture, app sign-up, SMS opt-in, third-party analytics — now carries legal weight. Organisations that fail to appoint a Data Protection Officer, maintain a valid consent artefact per user, or honour a data-erasure request within the prescribed timeline face penalties of up to ₹250 crore per incident. That is not a rounding error on a quarterly P&L.
Yet most Indian retail marketing stacks were built for reach, not rights. Platforms that dominated the last decade — batch-and-blast email tools, legacy CRM systems, and point-accumulation engines — were designed to maximise data collection, not minimise data exposure. The compliance gap between where most mid-market mall operators and retail brands sit today and where the DPDP Act requires them to be is significant. Bridging it demands both a legal audit and a technology upgrade, ideally in parallel.
This is precisely the space where Fundle was designed to operate. Built from the ground up with consent-first architecture, Fundle's platform helps Indian retail operators — whether running a 40-brand mall or a single-category loyalty scheme — meet every DPDP obligation without sacrificing the personalisation and engagement metrics that drive revenue. This article provides a practitioner-grade compliance checklist, benchmarked against real Indian retail operations, so you can assess your current stack and understand what a compliant, AI-powered engagement platform actually looks like in 2025.
India DPDP & Retail Data: The Numbers That Matter
Why the DPDP Act Is a Structural Shift, Not a Checkbox Exercise
Most compliance conversations in Indian retail marketing begin and end with IT. The legal team sends a memo, the tech team adds a cookie banner, and everyone moves on. The DPDP Act 2023 breaks that pattern entirely because it assigns accountability to the Data Fiduciary — which, in retail terms, is the brand or mall operator, not the software vendor. If Apollo Pharmacy runs a loyalty programme and its engagement platform sends unsolicited promotional messages to members who never consented to marketing communications, Apollo Pharmacy is the liable party, even if a third-party SaaS vendor sent the messages.
This structural shift has three immediate implications for retail CMOs. First, consent is now a legal artefact, not a UX checkbox. The Act requires that consent be freely given, specific, informed, unconditional, and unambiguous — and that a clear record of when and how that consent was obtained is maintained. This rules out the industry-standard practice of burying consent in terms-and-conditions during app sign-up. Brands like Manyavar or Cafe Coffee Day, which run large franchise-based loyalty programmes, must now ensure that every franchise touchpoint captures consent in a manner that satisfies this standard.
Second, data minimisation is a legal requirement, not a best practice. Platforms that collect date of birth, income bracket, and purchase history 'just in case' are now in direct conflict with the Act's purpose-limitation principle. Every data field must map to a specific, declared processing purpose. This forces a fundamental re-architecture of how customer profiles are built inside customer engagement software for retail. Legacy platforms that store everything and decide later are immediately non-compliant.
Third, the right to erasure and correction creates an operational challenge that most Indian retail tech stacks are simply not designed to handle at scale. A shopper who joined the Select CITYWALK loyalty programme five years ago and now requests deletion of their data must have that request processed across every system — the POS, the CRM, the WhatsApp Business API integration, the email tool, the analytics database — within the statutory timeframe. Platforms that were not built with a unified customer ID and a consent-linked data graph will struggle to execute this reliably. The DPDP Act has effectively made bad data architecture a legal liability.
DPDP Compliance Funnel: From Data Collection to Enforcement-Readiness
Key Compliance Requirements: A Customer Engagement Platform with Data Privacy Compliance Must Do All Seven
The DPDP Act specifies obligations that translate directly into platform capabilities. Here is the practitioner-level breakdown that every Loyalty Programme Manager and Mall CMO needs to internalise before evaluating any customer engagement platform India shortlist.
Obligation 1 — Consent Management Architecture: Every consent event must be timestamped, user-attributed, purpose-tagged, and retrievable on demand. This is not a database column — it is a consent ledger. Platforms like Capillary or EasyRewardz were not originally built with this as a core data model; retrofitting it is expensive and often incomplete. A compliant platform must store not just whether a user consented, but which version of the privacy notice they saw, on which channel, at what time, and for which specific processing purposes.
Obligation 2 — Privacy Notice Delivery: The Act requires that a privacy notice be provided to the data principal before or at the time of consent. The notice must be in plain language, available in the user's preferred language among the 22 scheduled languages, and must describe the categories of data collected, the purpose, the retention period, and the rights of the data principal. For a mall loyalty programme enrolling shoppers via a WhatsApp chatbot in Tamil Nadu, this means the privacy notice must be deliverable in Tamil, legible on a 5-inch screen, and acknowledged before the enrolment flow proceeds.
Obligation 3 — Data Processor Agreements: If your engagement platform shares data with a third party — say, a campaign analytics tool, a WhatsApp Business Solution Provider, or a POS system like Petpooja — that third party is a data processor and must sign a contract that specifies the permitted processing activities, data security standards, and breach-notification timelines. Retailers who have not audited their vendor contracts in the last 12 months almost certainly have gaps here.
Obligation 4 — Breach Notification: The Act requires prompt notification to the Data Protection Board of India and to affected data principals in the event of a personal data breach. 'Prompt' will likely be defined as 72 hours in the final rules, mirroring GDPR. Customer engagement software for retail must therefore include real-time anomaly detection and an automated incident-response workflow, not a manual process dependent on an IT ticket being raised.
Obligation 5 — Grievance Redressal: Every Data Fiduciary must appoint a contact point for data principals to raise grievances. For retail brands, this typically means a dedicated email or in-app channel, with responses mandated within the timeframe specified in the rules. The platform must log, track, and close these requests within SLA — and the audit trail must be tamper-proof.
Obligation 6 — Children's Data Protections: For brands with significant youth audiences — Reliance Trends, FabIndia's kidswear, or gaming-linked loyalty programmes — additional obligations apply. Verifiable parental consent is required before processing data of anyone under 18, and behavioural tracking of children is prohibited outright.
Obligation 7 — Data Localisation (Significant Data Fiduciaries): Once the Government notifies Significant Data Fiduciaries — a category likely to include large mall operators and FMCG loyalty programmes — additional obligations including data localisation, algorithmic audits, and DPIA (Data Protection Impact Assessments) will apply. Planning your tech stack for this now, rather than scrambling post-notification, is the only defensible position.
Legacy Loyalty Platform vs. DPDP-Compliant Customer Engagement Platform
Privacy Notices and User Consent Mechanisms That Actually Hold Up in Court
Privacy notices are perhaps the most misunderstood obligation in the DPDP Act. Most Indian retail brands treat them as a legal formality — a paragraph drafted by the legal team, uploaded to the website, and forgotten. Under the DPDP Act, this approach is not just inadequate; it is a direct path to regulatory action because the Act requires that consent be informed, meaning the user must have genuinely received and acknowledged the notice before consenting.
For a mall loyalty programme operating across physical kiosks, a mobile app, a WhatsApp chatbot, and a brand website, this creates a multi-channel consent challenge. Each channel has different UX constraints. A kiosk enrolment flow has 30 seconds of attention. A WhatsApp onboarding flow is conversational. A mobile app sign-up is visual. The privacy notice mechanism must be adapted to each channel while maintaining legal equivalence. This is a product design problem as much as a legal one, and it requires a platform built to handle it natively rather than as an afterthought.
Granular consent is the other critical design requirement. The Act's specificity requirement means you cannot obtain a single 'I agree to all marketing' consent and use it to justify SMS campaigns, WhatsApp messages, email newsletters, and push notifications simultaneously. Each channel and each processing purpose — loyalty points calculation, personalised offers, third-party partner promotions, analytics — should ideally have its own consent flag. This granularity also creates a commercial advantage: users who explicitly consent to personalised offers are significantly more likely to convert than users who were mass-enrolled under a blanket opt-in.
Consent withdrawal must be as easy as consent grant. If a Tanishq loyalty member decides she no longer wants WhatsApp promotions, the withdrawal mechanism must be immediately accessible, must take effect within a defined SLA, and must cascade across every downstream system that was acting on that consent. Platforms that process consent withdrawal in batch overnight — a common implementation pattern — are non-compliant. Real-time consent propagation is not a nice-to-have; it is a statutory requirement. MoEngage and WebEngage, which are widely used for campaign delivery in Indian retail, must receive consent-revocation signals from the engagement platform in real time or they become instruments of a DPDP violation.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
5-Step DPDP Compliance Implementation Playbook for Retail Engagement Platforms
Step 1 — Consent Audit Across All Touchpoints
Map every channel where customer data is collected: POS (POSist, GoFrugal, Wondersoft, Petpooja integrations), mobile app, web, WhatsApp, in-store kiosk. For each touchpoint, document: what data is collected, under what consent mechanism, for which declared purposes. Identify gaps where data is collected without a valid consent artefact. This audit typically surfaces 30-50% more data collection points than compliance teams expect.
Step 2 — Redesign Consent Flows for DPDP Validity
Rebuild consent UX for each channel with purpose-specific opt-ins, plain-language privacy notices in at least Hindi and English (add regional languages for state-specific operations), and a consent ledger backend. Ensure that the enrolment flow cannot be completed without a valid consent event being recorded. Test withdrawal flows: time the end-to-end propagation of a consent revocation across all downstream systems.
Step 3 — Vendor Risk Assessment and Data Processor Agreements
List every third-party tool that receives, processes, or stores customer personal data. Include campaign platforms (MoEngage, WebEngage, Xeno), analytics tools, WhatsApp BSPs, POS vendors, and cloud hosting providers. Score each vendor against a DPDP data-processor checklist: data security certifications, breach-notification SLAs, sub-processor disclosure, data localisation commitments. Execute DPDP-compliant data processor agreements before the enforcement deadline.
Step 4 — Build the Grievance and Rights-Management Workflow
Designate a Data Protection Officer or contact point. Build an in-platform workflow for receiving, logging, processing, and closing data principal requests: access, correction, erasure, and consent withdrawal. Set internal SLA targets that are tighter than the statutory deadline to create buffer for edge cases. Run a quarterly drill of the erasure workflow across a test customer profile that spans all integrated systems.
Step 5 — Continuous Monitoring and Annual DPDP Audit
Implement real-time monitoring for consent-status anomalies (e.g., campaigns firing against profiles with withdrawn consent). Schedule an annual third-party DPDP audit covering all seven obligations. Maintain a living data-processing register updated every time a new vendor integration or processing activity is added. Assign ownership to a named individual — not just a team — for each DPDP obligation.
Vendor Due Diligence: Auditing Your Engagement Stack Before Regulators Do
The DPDP Act makes data processors — your vendors — a critical link in your compliance chain. A mall operator running a loyalty programme across 60 brands cannot afford to have even one data-processor vendor that fails to meet the Act's standards, because a breach originating from that vendor is still the mall operator's legal problem. Vendor due diligence is therefore not an annual formality; it is an ongoing programme.
Start with a data-flow map. Every customer engagement platform India operator should be able to answer, in under five minutes, the question: 'Where does a specific customer's mobile number travel after it is captured at our POS?' If the answer requires a cross-functional meeting, you have a data-governance problem. The mobile number may travel from the POS (POSist or GoFrugal) to the CRM, from the CRM to a campaign platform (Xeno or WebEngage), from the campaign platform to a WhatsApp BSP, and from the BSP to Meta's infrastructure. Each hop is a data-processor relationship that requires a contract.
For competitive context: platforms like Capillary, Antavo, and Customer Capital have varying levels of DPDP-readiness. None of them were purpose-built for the Indian legislative context in the way that a newer, AI-native platform can be. Almonds.ai and EasyRewardz are primarily campaign and points platforms respectively, and their data governance architectures were not designed with DPDP compliance as a foundational requirement. This does not mean they cannot be made compliant — but it does mean that compliance will require significant customisation, testing, and ongoing maintenance on your side, not theirs.
The due-diligence checklist for any customer engagement platform vendor should cover at minimum: ISO 27001 or SOC 2 Type II certification, a documented incident-response plan with breach-notification SLA of 72 hours or less, a sub-processor register that is current and accessible, contractual commitments on data deletion within 30 days of contract termination, and clear data localisation commitments for Indian customer data. Vendors who cannot provide these without a lengthy escalation are a regulatory risk, not just a procurement inconvenience.
- Consent ledger is operational: every consent event is timestamped, purpose-tagged, channel-attributed, and retrievable per user within 24 hours
- Privacy notices are available in plain language in at least Hindi, English, and the primary regional language of your customer base, and are delivered before consent is captured on every channel
- Data minimisation review is complete: every customer profile field maps to a declared, specific processing purpose — fields without a declared purpose are deleted
- Data processor agreements are signed with every third-party vendor that handles customer personal data, including POS providers, campaign platforms, and WhatsApp BSPs
- A grievance-redressal workflow is live with a named contact point, a logged request-management system, and an SLA of under 25 days for resolution
- An erasure workflow has been tested end-to-end: a test customer's data has been successfully deleted across all integrated systems (POS, CRM, campaign platform, analytics) within 30 days
- An annual DPDP audit is scheduled with a third-party assessor, and a living data-processing register is maintained and updated with every new vendor or processing activity
“In India, first-party data is not just a marketing asset anymore — it is a regulated liability. The brands that treat consent infrastructure as seriously as they treat campaign infrastructure will win both the regulator and the customer.”
How Fundle Solves This
Fundle's AI Platform was architected from day one around the principle that customer engagement and data privacy are not opposing forces — they are the same design problem. Vineet Narang's founding thesis for Fundle was that the Indian retail market would eventually be forced to choose between platforms built for compliance and platforms built for engagement, and that the right answer was to refuse that choice entirely.
Fundle's ConsentFirst platform handles comprehensive DPDP compliance checks for all client engagements. This is not a bolt-on compliance module — it is the data layer on which every other Fundle capability is built. When a shopper enrols in a Fundle Mall Loyalty programme at a Phoenix Marketcity property, the enrolment flow captures granular, purpose-specific consent in real time, records it to an immutable consent ledger, and makes that ledger queryable by the mall operator's compliance team within seconds. If the same shopper withdraws consent for WhatsApp marketing at 11 PM on a Tuesday, Fundle AI Agents propagate that revocation to every downstream system — the campaign platform, the WhatsApp BSP, the analytics database — before any further message is dispatched. The SLA is minutes, not hours.
Fundle Brand Loyalty and Fundle Mall Loyalty deployments include automated data-processor agreement templates that have been reviewed against the DPDP Act's processor obligations. Every new vendor integration added to a client's stack is screened against a risk scorecard before activation. Fundle AI Workflow automates the grievance-redressal process: when a data principal submits an erasure or access request via the loyalty app, Fundle Agentic AI classifies the request, initiates the cross-system resolution workflow, and generates a compliance-ready audit log — all without manual intervention from the client's IT team.
For retailers and mall operators who are simultaneously navigating DPDP compliance and trying to drive customer engagement KPIs, the Fundle AI Platform resolves a tension that legacy platforms cannot: the consent data itself becomes an engagement signal. A shopper who opts in to personalised recommendations is, by definition, a high-intent audience. Fundle's recommendation engine is consent-aware — it only personalises within the boundaries of what the user has explicitly permitted, which means every personalised communication is both legally sound and commercially targeted. In a market where 68% of loyalty members say they would exit a programme over data misuse, this is not just a compliance advantage — it is a retention advantage.
Frequently asked
What is the DPDP Act and when does it apply to retail loyalty programmes?+
The Digital Personal Data Protection Act 2023 received Presidential assent in August 2023. Its rules are expected to be enforced through 2025. Any Indian entity that collects, stores, or processes personal data of Indian residents — including mall operators and retail brands running loyalty programmes — is covered as a Data Fiduciary, regardless of company size.
What penalties does the DPDP Act impose for non-compliance?+
Penalties under the DPDP Act go up to ₹250 crore per incident for serious breaches, including failure to implement adequate security safeguards. Failure to notify a breach can attract up to ₹200 crore. Failure to honour a data principal's erasure or access request can attract up to ₹50 crore. These are per-incident caps, not annual caps.
Does a loyalty programme need separate consent for each marketing channel — SMS, WhatsApp, email?+
Best practice under the DPDP Act's specificity requirement is to obtain purpose-specific consent for each channel and each material processing activity. A blanket 'I agree to marketing' opt-in is legally fragile. Platforms like Fundle's ConsentFirst architecture support granular, per-channel consent that holds up under regulatory scrutiny.
How should mall operators manage DPDP compliance across multiple brand tenants?+
The mall operator is typically the Data Fiduciary for the central loyalty programme, while individual brand tenants may be joint fiduciaries for their own CRM data. Mall operators should publish a clear data-sharing protocol for tenants, ensure that tenant-level data collection also meets DPDP standards, and include DPDP compliance obligations in tenant lease and loyalty participation agreements. Fundle Mall Loyalty is designed to support this multi-brand, multi-fiduciary architecture.
What should a retail brand look for in a DPDP-compliant customer engagement platform?+
Look for: a native consent ledger (not a plugin), multilingual privacy notice delivery, real-time consent-revocation propagation, automated data processor agreements with all sub-vendors, a built-in grievance-redressal workflow with audit logging, and evidence of ISO 27001 or SOC 2 Type II certification. Ask the vendor to demonstrate an end-to-end erasure request execution in a sandbox environment before signing.
Is Fundle compliant with DPDP Act requirements?+
Yes. Fundle's AI Platform is built around a ConsentFirst architecture that addresses all seven core DPDP obligations: consent management, privacy notice delivery, data minimisation, data processor agreements, breach notification, grievance redressal, and rights-management workflows. Fundle AI Workflow and Fundle Agentic AI automate compliance operations so that retail clients maintain compliance continuously, not just at audit time.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
