“We don't sell AI Agents. We sell business outcomes — increase repeat rate, reduce churn, raise basket size. The AI Agents are how Fundle gets there.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand how DPDP Act 2023 directly constrains how Indian retailers collect, store and use loyalty member data on WhatsApp
  • Map the six consent obligations under DPDP to your existing WhatsApp loyalty workflows before penalties land
  • Implement a Consent Management Platform — not a checkbox — to capture purpose-specific, auditable opt-ins at scale
  • Benchmark your program against privacy-first engagement metrics: consent rate, withdrawal rate, and opted-in revenue share
  • Explore how Fundle's ConsentFirst CMP already manages DPDP-compliant permissions for 1.33 crore-plus WhatsApp loyalty members

India's Digital Personal Data Protection Act 2023 — the DPDP Act — received Presidential assent in August 2023 and its implementing rules are being finalized by the Ministry of Electronics and Information Technology. For most Indian retail CMOs, it has remained a compliance department talking point. That window is closing fast. Once the rules are notified, companies processing personal data of Indian residents face penalty exposure of up to ₹250 crore per breach of consent obligations and up to ₹200 crore for failing to implement reasonable security safeguards. For a mid-size mall operator running a 5-lakh member loyalty database built on WhatsApp opt-ins collected via QR codes at entry gates — consent collected with zero purpose specification — these are not theoretical numbers.

WhatsApp has become the dominant loyalty engagement channel in Indian retail. Brands like Manyavar, FabIndia, Apollo Pharmacy and Reliance Trends are routing everything from points balance notifications to personalised offers through WhatsApp Business API. Phoenix Marketcity and Select CITYWALK run conversational campaigns that clock open rates north of 60%, a figure that makes email and SMS look prehistoric. But WhatsApp engagement at scale means personal data flowing at scale: phone numbers, purchase history, location signals, browsing behaviour, tier status. Every one of those data points is a "personal data" touchpoint under the DPDP Act's definition.

The problem is structural. Most loyalty programs in India were architected in a pre-DPDP world. Consent was an afterthought — a fine-print checkbox during app install or a verbal acknowledgement at the store counter. The DPDP Act demands something fundamentally different: free, specific, informed, unconditional and unambiguous consent, tied to an explicit purpose, withdrawable at any time, and never bundled with a condition of service. Overlaying this obligation onto a live WhatsApp loyalty program with lakhs of active members is not a 48-hour compliance task.

This is precisely the operational challenge that Fundle was built to solve. The article that follows is a practitioner's guide for retail CMOs and Heads of Marketing: what the DPDP Act actually requires of a WhatsApp loyalty platform, what good consent architecture looks like in practice, where the legal risks concentrate, and how to build a privacy-first engagement engine that grows customer lifetime value instead of shrinking your legal exposure.

The Scale and Stakes of WhatsApp Loyalty in Indian Retail

50 Cr+
WhatsApp Monthly Active Users in India — the largest single-country user base globally (Meta, 2024)
₹250 Cr
Maximum penalty per breach of consent obligations under the DPDP Act 2023
1.33 Cr+
WhatsApp loyalty members covered by Fundle's ConsentFirst CMP with DPDP-compliant permissions
60-65%
Average open rate for WhatsApp Business loyalty messages in Indian retail vs. 18-22% for email

Overview of DPDP 2023 and Its Impact on Loyalty Programs

The DPDP Act 2023 establishes seven key rights for data principals — the customers whose data your loyalty program processes. These include the right to access information about processing, the right to correction and erasure, the right to grievance redressal, and critically, the right to withdraw consent at any time. For a WhatsApp loyalty platform, these rights translate into concrete engineering and operational obligations that most retail technology stacks are not built to handle today.

Consent under DPDP must be purpose-specific. You cannot collect a phone number for points redemption and then use it to send a birthday offer without separate consent for that second purpose. This collapses the standard loyalty program model where a single sign-up event is used to justify every communication downstream. Manyavar's WhatsApp loyalty flow, for instance, typically captures the mobile number at point-of-sale and then routes the customer into a multi-purpose engagement journey. Under DPDP, each purpose — points updates, promotional offers, personalised recommendations, third-party brand communications — needs its own consent record.

The Act also introduces the concept of a Consent Manager: a registered entity through which data principals can give, manage and withdraw consent across multiple data fiduciaries. This is directly relevant for mall operators who run a unified loyalty program spanning twenty or thirty tenant brands. When a member at Phoenix Marketcity earns points at both Lifestyle and Cafe Coffee Day, which brand is the data fiduciary? Who is responsible for maintaining the consent record? The DPDP framework requires this question to have a clear, documented answer.

Finally, the Act prohibits using children's data for behavioural tracking or targeted advertising, and requires verifiable parental consent for users under 18. For apparel retailers like Pantaloons or FabIndia that actively market kids' collections via WhatsApp loyalty programs, this creates a specific data segmentation and verification obligation that cannot be addressed with a simple age-gate checkbox. The compliance posture required is operational, not just legal.

DPDP Consent Funnel: From WhatsApp Opt-In to Compliant Loyalty Member

WhatsApp Opt-In Initiated (e.g. QR scan at store, cashier prompt) — 100%Purpose-Specific Consent Notice Presented (loyalty points, offers, personalisation listed separately) — 78%Granular Consent Captured per Purpose (not bundled) — 61%Consent Record Stored with Timestamp, Channel and Purpose ID — 61%
Each stage of a DPDP-compliant WhatsApp loyalty onboarding must be documented, purposeful and reversible. Drop-off at any stage is a signal, not a failure.

How WhatsApp Loyalty Platforms Ensure Data Protection

A WhatsApp loyalty platform that is genuinely DPDP-compliant is architecturally different from one that has simply added a consent checkbox to an existing flow. The difference sits in five layers: data minimisation, purpose binding, consent logging, withdrawal infrastructure, and data residency. Most platforms in the Indian market — including point solutions built on top of Meta's Business API — address at most two of these layers out of the box.

Data minimisation means collecting only what is necessary for the stated purpose. If a member opts in for points balance notifications, you are not entitled to store their browsing frequency, dwell-time at the mall, or inferred income bracket from their purchase patterns — unless you have separate consent for an analytics or personalisation purpose. This is a material constraint on the data architectures that platforms like Capillary, EasyRewardz or Xeno typically build, which are optimised for maximum data capture to feed segmentation models.

Purpose binding means that every data processing activity — a campaign send, a segmentation query, a third-party data share — must be traceable to a specific consent record. This requires a consent identifier to travel with the data through your CRM, your loyalty engine, your WhatsApp Business API calls, and any third-party analytics tools. Without this linkage, you cannot prove compliance in an audit. MoEngage and WebEngage, both widely used for loyalty communications in India, do not natively carry consent identifiers through their journey orchestration pipelines — that mapping has to be built by the retailer's technology team.

Withdrawal infrastructure is where most Indian loyalty programs will fail their first DPDP audit. Withdrawal must be as easy as giving consent. If a member opted in via a WhatsApp message, they must be able to withdraw via WhatsApp — a reply keyword, a menu option, a button — not by calling a toll-free number or filling a web form. The withdrawal must take effect within a reasonable timeframe (the rules will specify this, but industry best practice is 72 hours), and it must cascade across all downstream processing: CRM suppression, campaign exclusion, analytics blacklist and third-party notification. Building this cascade for a 10-lakh member program on a legacy POS-integrated loyalty stack like POSist, Petpooja or GoFrugal is a non-trivial infrastructure project.

Legacy Loyalty Consent vs. DPDP-Compliant WhatsApp Loyalty Architecture

Legacy Loyalty Consent (Pre-DPDP)
DPDP-Compliant WhatsApp Loyalty Platform
Single opt-in at POS covers all future communications
Purpose-specific consent captured per use case (points, offers, personalisation, third-party)
Consent record stored in POS or CRM with no purpose ID or timestamp
Immutable consent log with timestamp, channel, purpose ID and member identifier
Withdrawal requires calling customer care or visiting store
Withdrawal via WhatsApp reply keyword; cascades to CRM, campaigns and analytics within 72 hours
Children's data processed identically to adults; no age verification
Age-segmented data flows; verifiable parental consent required for under-18 members
No mechanism to honour data erasure requests from members
Automated erasure workflow triggered by member request; confirmed via WhatsApp acknowledgement

Consent Management with ConsentFirst: The WhatsApp Loyalty Platform DPDP Compliance Standard

ConsentFirst is Fundle's native Consent Management Platform, purpose-built for the Indian DPDP framework and designed to operate natively within WhatsApp loyalty workflows. It is not a cookie banner bolt-on repurposed from European GDPR tooling. It is an end-to-end consent orchestration layer that sits between the customer's WhatsApp session and the loyalty data infrastructure, ensuring that every data processing event is tied to a valid, auditable consent record.

Fundle's ConsentFirst CMP enables DPDP-compliant permissions for 1.33 crore-plus WhatsApp loyalty members. This is not a pilot number — it represents production-scale consent orchestration across mall and retail brand deployments in India, managing consent across multiple purposes, multiple brands in a mall ecosystem, and multiple communication channels. At this scale, the CMP processes millions of consent state changes monthly: new opt-ins, purpose additions, partial withdrawals and full erasure requests.

The ConsentFirst architecture operates on three principles. First, consent atomicity: each consent record is a discrete, immutable event — it cannot be edited, only superseded by a new record. This creates a tamper-proof audit trail that can be produced in response to a Data Protection Board inquiry. Second, purpose granularity: the CMP presents members with plain-language purpose descriptions — not legal boilerplate — in their preferred language, and captures a separate response for each purpose. A member can opt into points notifications and opt out of third-party brand offers in the same WhatsApp conversation. Third, withdrawal symmetry: the same WhatsApp interface used for opt-in exposes a live consent dashboard where members can see exactly what they've consented to and withdraw any purpose with a single tap.

For mall operators like those running Select CITYWALK or Phoenix Marketcity properties, ConsentFirst handles the multi-fiduciary complexity automatically. When a unified mall loyalty member earns points at Tanishq and Lenskart in the same visit, the system maintains separate consent records for each brand's data processing activities under the mall's umbrella program, while presenting a unified member experience on WhatsApp. This is the architectural problem that generic loyalty platforms — whether Antavo, Almonds.ai or Customer Capital — have not yet solved for the Indian mall context.

5-Step Playbook: Building a DPDP-Compliant WhatsApp Loyalty Program

01

Audit Your Existing Consent Records

Before building forward, assess what you have. Map every point of data collection in your current loyalty flow — POS sign-up, app install, WhatsApp opt-in, referral — and document the purpose disclosed at each touchpoint. For most Indian retailers using Wondersoft, GoFrugal or POSist POS systems, this audit will reveal consent records that are insufficient under DPDP. Quantify the gap: how many members have no purpose-specific consent record? This number drives your re-consent campaign budget.

02

Define and Register Your Processing Purposes

List every way your loyalty program uses member data: points calculation, balance notifications, promotional campaign targeting, personalised offer generation, cohort analytics, third-party brand sharing, and children's offer segmentation. Each purpose needs a plain-language description (in English and relevant regional languages), a legal basis under DPDP, a data retention period, and an owner inside your organisation. This registry becomes the source of truth for your Consent Management Platform.

03

Deploy a Native WhatsApp Consent Flow

Redesign your WhatsApp onboarding conversation to present purpose-specific consent options using WhatsApp's interactive buttons and list messages. Avoid paragraph-length legal notices — research shows consent comprehension drops below 20% when notices exceed 80 words. Present each purpose as a clear benefit statement: 'Get your points balance after every visit' is compliant and converts better than 'Consent to transactional data processing.' Capture and timestamp each response through your CMP.

04

Build the Withdrawal and Erasure Infrastructure

Implement a persistent WhatsApp menu option — accessible at any point in any conversation — that opens a consent dashboard. Members must be able to withdraw specific purposes without losing access to others. Map the withdrawal cascade: CRM suppression, campaign exclusion list update, analytics anonymisation, and any third-party notification. Test this cascade end-to-end before go-live; a withdrawal that suppresses WhatsApp messages but not email campaigns is a DPDP violation in itself.

05

Establish Ongoing Compliance Monitoring

DPDP compliance is not a one-time project. Appoint a Data Fiduciary owner for your loyalty program — likely your Head of CRM or a dedicated Data Protection Officer once the rules mandate one. Implement monthly consent health reporting: consent rate by acquisition channel, withdrawal rate by purpose, erasure request resolution time, and minor data flag accuracy. Integrate these metrics into your loyalty program dashboard alongside traditional KPIs like monthly active members and points redemption rate.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Best Practices for Privacy-First Customer Engagement on WhatsApp

Privacy-first engagement is not a constraint on growth — it is a growth strategy. Members who give informed, granular consent are demonstrably more engaged: they open more messages, redeem more offers and generate higher average transaction values. A 2023 Bain analysis of loyalty programs in Asia-Pacific found that members who actively manage their communication preferences have 1.4x the annual transaction frequency of members who were bulk-enrolled. In Indian retail terms, at an average basket of ₹1,800 for an apparel brand like Pantaloons or Lifestyle, that frequency lift is worth roughly ₹2,500 in incremental annual revenue per member.

The practical implication is that your re-consent campaign — the exercise of going back to your existing base and obtaining proper DPDP consent — should be designed as a member value event, not a legal obligation notice. Frame it as 'Tell us what you actually want to hear from us.' Give members who complete the preference update an immediate reward: bonus points, early access to a sale, a personalised offer based on their stated preferences. Manyavar ran a preference update campaign in late 2023 that achieved a 73% completion rate by attaching 200 bonus points to the exercise. Of those who completed it, 68% opted into more purposes than they had previously consented to.

For mall operators, privacy-first engagement also means rethinking how tenant brand data sharing works. Under DPDP, sharing a member's purchase history at Tanishq with a co-tenant like Lenskart for cross-targeting requires specific consent for that cross-brand data flow — it cannot be buried in the mall loyalty program's terms and conditions. The right architecture is a transparent preference centre where members can see which brands in the mall ecosystem they've authorised to use their data, and toggle that authorisation on or off. This kind of transparency, counterintuitively, increases cross-brand consent rates because it builds trust.

Finally, communication frequency governance becomes a compliance issue under DPDP, not just a marketing hygiene issue. Sending 14 WhatsApp messages a week to a member who consented to 'occasional offers' is a potential grievance waiting to happen. Build frequency caps into your campaign orchestration layer — MoEngage and WebEngage both support this — and tie them to the purpose description the member consented to. If your consent language said 'up to 2 messages per week,' your campaign system must enforce that limit.

DPDP Compliance Checklist for WhatsApp Loyalty Programs
  • All consent records include: member ID, timestamp, channel, purpose ID, language of consent notice, and consent version number
  • Every processing purpose is documented in plain language in a purpose registry accessible to both compliance team and CMP
  • WhatsApp onboarding flow presents granular, purpose-specific consent options — no bundled single opt-in
  • Withdrawal mechanism is available natively inside WhatsApp, requires no channel switch, and cascades to all downstream systems within 72 hours
  • Minor data identification process is in place; under-18 member records are flagged and excluded from behavioural targeting and third-party sharing
  • Cross-brand data sharing within mall loyalty ecosystems requires explicit, per-brand consent from members — not a blanket program T&C
  • Monthly consent health dashboard is operational: tracking consent rate, withdrawal rate, erasure SLA adherence, and opted-in revenue as a share of total loyalty revenue
“In Indian retail, consent is not a compliance box — it is the foundation of every rupee of loyalty revenue. The brands that own clean, purposeful consent will own the next decade of customer relationships.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

Legal Risks and Mitigation Strategies in Indian Retail

The DPDP Act creates four distinct penalty tiers, and retail loyalty programs sit squarely in the crosshairs of the top two. Tier 1: failure to take reasonable security safeguards to prevent personal data breaches — up to ₹250 crore. Tier 2: failure to notify the Data Protection Board and affected data principals of a breach — up to ₹200 crore. Tier 3: non-compliance with obligations regarding children's data — up to ₹200 crore. Tier 4: breach of any other provision — up to ₹50 crore. For context, a mid-sized Indian mall operator with 8 lakh loyalty members and a WhatsApp program generating ₹40 crore in annual attributable revenue could face penalties that dwarf the program's entire revenue contribution in a single breach event.

The three highest-probability legal risk scenarios for WhatsApp loyalty programs are: a bulk consent record that cannot prove individual purpose-specific consent (Tier 4 baseline, escalates to Tier 1 if a breach follows); a data breach of the WhatsApp member database without timely notification (Tier 1 and Tier 2 combined); and a minor's data being used for targeted advertising because the loyalty program had no age verification at sign-up (Tier 3). All three are entirely preventable with the right architecture, but all three are also almost universal in Indian retail loyalty programs built before 2024.

Mitigation strategy starts with a legal-technical mapping exercise: take your DPDP obligations and map each one to a specific technical control or process in your loyalty platform. Where a control does not exist, it becomes a roadmap item with a deadline and an owner. This is not optional — the DPDP rules are expected to include a compliance timeline, and organisations that can demonstrate a documented remediation roadmap will be treated materially differently by the Data Protection Board than those that cannot.

Contract risk is the second dimension. Every third-party vendor that touches your loyalty member data — your WhatsApp Business Solution Provider, your CRM platform, your analytics vendor, your campaign orchestration tool — becomes a Data Processor under DPDP. You, as the loyalty program operator, are the Data Fiduciary, and you are liable for their compliance. Data Processing Agreements that are compliant with DPDP must be in place with every vendor in that chain. For many Indian retailers, this is a procurement and legal exercise that has not yet begun.

How Fundle Solves This

Vineet Narang founded Fundle on a core conviction: that AI-native customer engagement and privacy-first data practices are not in tension — they are the same strategy, executed correctly. The Fundle AI Platform is built from the ground up around this principle. Every customer interaction, every data flow, every campaign decision that the platform automates is anchored to a valid, purpose-specific consent record. This is not a feature added to meet regulatory pressure; it is the structural foundation of how Fundle processes loyalty data.

The Fundle Loyalty Platform — which powers both Fundle Mall Loyalty for shopping mall operators and Fundle Brand Loyalty for enterprise retail brands — integrates ConsentFirst as a native layer, not a third-party add-on. When a new member joins a Fundle-powered WhatsApp loyalty program, the onboarding conversation is a ConsentFirst flow: purpose-specific, multi-language, interactive, and producing an immutable consent record that travels with the member's data through the entire platform. Fundle's ConsentFirst CMP enables DPDP-compliant permissions for 1.33 crore-plus WhatsApp loyalty members — making it the largest production-scale consent management deployment in Indian retail loyalty.

Fundle AI Agents and Fundle Agentic AI take this compliance foundation into the campaign execution layer. Every AI-driven personalisation decision — which offer to surface, which cohort to target, which message to sequence — is gated by a real-time consent check. If a member has not consented to personalised offer targeting, the Fundle AI Workflow automatically routes them to a non-personalised content stream, ensuring the campaign lands without a compliance breach. This consent-aware AI orchestration is unique in the Indian market; no competing platform — not Capillary, not EasyRewardz, not Antavo — has built consent checking into the campaign decision layer at this level of granularity.

For mall operators managing complex multi-brand loyalty ecosystems, the Fundle Mall Loyalty architecture handles multi-fiduciary consent mapping automatically. Each tenant brand in the ecosystem has its own consent record set per member, managed transparently through a member-facing consent dashboard accessible via WhatsApp. For retail brands running standalone programs — whether an apparel chain like Reliance Trends or a specialty retailer like Lenskart — Fundle Brand Loyalty delivers the same DPDP-ready consent architecture at brand scale. The result is a loyalty platform that a retail CMO can present to their Data Protection Officer and their Board with confidence: compliant by design, not compliant by retrofit.

Frequently asked

Does the DPDP Act 2023 apply to WhatsApp loyalty programs immediately?+

The DPDP Act received Presidential assent in August 2023 but comes into force in phases as the Central Government notifies the rules. The rules have not been fully notified as of mid-2025, but compliance preparation should begin now. The consent architecture, data processing agreements, and breach notification processes all require 6-12 months of implementation time for a mid-size loyalty program.

Can a retailer continue using its existing loyalty consent records after DPDP rules are notified?+

Only if those records meet the DPDP standard: free, specific, informed, unconditional and unambiguous consent tied to an explicit purpose. Most legacy opt-ins — verbal consent at POS, bundled app install checkboxes, QR code sign-ups with no purpose disclosure — will not survive scrutiny. A re-consent campaign targeting the existing base is almost certainly required.

What is the difference between a Consent Manager and a Consent Management Platform under DPDP?+

A Consent Manager under DPDP is a specific registered entity through which data principals manage their consents across multiple data fiduciaries — a government-defined role. A Consent Management Platform (CMP) like Fundle's ConsentFirst is the technology infrastructure that a Data Fiduciary (the retailer) uses to capture, store, and honour consent. These are related but distinct: the CMP is your internal compliance tool; the Consent Manager is a regulated intermediary in the broader ecosystem.

How does a mall operator manage DPDP compliance across multiple tenant brands in one loyalty program?+

This is the most complex DPDP scenario in Indian retail. The mall operator is typically the primary Data Fiduciary; each tenant brand is a separate Data Fiduciary for processing they conduct on member data. The loyalty platform must maintain separate consent records per brand per member, ensure cross-brand data sharing only occurs where specific consent exists, and surface a transparent multi-brand consent dashboard to members. Fundle Mall Loyalty is purpose-built for this architecture.

What are the children's data obligations for WhatsApp loyalty programs under DPDP?+

The DPDP Act prohibits processing children's data (under 18) for tracking, behavioural monitoring or targeted advertising without verifiable parental consent. For loyalty programs, this means age-verification at onboarding, separate data flows for minor members, and exclusion from behavioural segmentation and third-party data sharing. WhatsApp's minimum age policy (13 in India) creates an overlap that retailers must address explicitly in their data architecture.

How quickly must a WhatsApp loyalty platform process a consent withdrawal request?+

The DPDP rules will specify the exact timeframe, but industry best practice — aligned with GDPR precedent — is 72 hours for full cascade withdrawal: CRM suppression, campaign exclusion, analytics anonymisation and third-party notification. The withdrawal mechanism must be accessible through the same channel used for opt-in, meaning WhatsApp-native withdrawal is mandatory for programs where consent was captured via WhatsApp.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

A

Abhinav · Fundle.ai

Loyalty & ADSR Expert · Online

Powered by Fundle AI · Replies in under 30 sec