“Brand and mall teams shouldn't wait six weeks for a vendor to run a campaign. With Fundle, the loyalty CRM runs at the speed of the marketer's curiosity.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand how the DPDP Act 2023 mandates explicit, purpose-limited consent before any loyalty data can be collected or processed
  • Map every data-processing activity in your loyalty stack to a specific, documented consent artefact — or risk penalties up to ₹250 crore per incident
  • Adopt a ConsentFirst architecture that separates raw PII from behavioural analytics so revocation is operationally clean
  • Benchmark your programme against the five pillars of compliant data governance: collection, storage, processing, sharing, and deletion
  • Deploy AI loyalty analytics that are privacy-preserving by design, not privacy-compliant by patch

India's Digital Personal Data Protection Act 2023 — the DPDP Act — is not a distant regulatory horizon. The rules framework dropped in early 2025, and enforcement timelines are tightening faster than most retail CMOs anticipated when they last reviewed their loyalty stack. For any brand running a points programme, a tiered membership, or a mall-wide rewards scheme, the DPDP Act introduces an obligation that sits squarely at the intersection of marketing and legal: you must obtain free, specific, informed, and unambiguous consent before collecting, storing, or processing a customer's personal data — and you must be able to prove it, in real time, to a regulator.

The loyalty industry in India has grown explosively. Organised retail penetration crossed 13% of total retail spend in FY24, and loyalty programme membership across modern trade — from Phoenix Marketcity in Mumbai to Select CITYWALK in Delhi — now exceeds 180 million enrolled members by conservative estimates. Behind those enrolments sit terabytes of purchase history, location dwell-time data, RFM scores, and AI-generated propensity models. Every row of that data is now a liability if the consent framework behind it does not meet DPDP standards. Penalties under the Act reach ₹250 crore per significant breach — a figure that concentrates the mind wonderfully.

Yet the business case for loyalty analytics has never been stronger. Brands that operate data-driven loyalty programmes report 2.3x higher repeat-purchase rates and 18–22% higher average transaction values compared to non-members, according to industry benchmarks tracked across mid-to-large Indian retail chains. The answer is not to collect less data — it is to collect data correctly, with consent architectures that are as sophisticated as the analytics engines they feed. DPDP compliant loyalty analytics is not a compliance checkbox; it is a competitive moat.

This is precisely the operating challenge that Fundle was built to solve. Across 270+ Indian retail brands, Fundle supports transparent data governance and consent management — turning a regulatory burden into a first-party data advantage. The pages that follow break down exactly what the DPDP Act demands, what a ConsentFirst architecture looks like in practice, how data governance frameworks should be structured, and what KPIs tell you whether your programme is genuinely compliant or merely optimistically so.

The Scale of the DPDP Compliance Challenge in Indian Retail Loyalty

₹250 Cr
Maximum penalty per significant data breach under the DPDP Act 2023 — the single largest regulatory risk retail CMOs face in FY25
180 Mn+
Estimated loyalty programme enrolments across organised Indian retail — every member record now requires a verifiable, purpose-specific consent artefact
270+
Indian retail brands for which Fundle supports transparent data governance and consent management, spanning malls, fashion, F&B, and pharmacy verticals
2.3x
Higher repeat-purchase rate for loyalty members versus non-members in Indian modern trade — the ROI that makes compliant analytics non-negotiable, not optional

DPDP Consent Requirements for Loyalty Data Processing

The DPDP Act establishes five cardinal requirements for valid consent: it must be free (no coercion), specific (tied to a named purpose), informed (the data principal understands what they are agreeing to), unconditional (not bundled with service access), and unambiguous (an affirmative act, not a pre-ticked box). For a loyalty programme, this creates operational complexity that most existing CRM stacks were simply not designed to handle. A customer enrolling at a Pantaloons counter, a Lenskart store, or a Manyavar boutique must be presented with a consent notice that names every downstream use case — personalised offers, third-party brand communications, AI-based propensity scoring, cross-mall analytics — before a single data point is written to the database.

Purpose limitation is the clause that bites hardest. If a customer consents to receive birthday discount offers, you cannot use their transaction data to build a lookalike audience for a new store opening without a fresh, separate consent interaction. In practice, this means loyalty programmes need a consent taxonomy — a structured library of processing purposes, each with its own consent flag, stored immutably with a timestamp and channel of collection. Brands running on legacy CRM platforms — many still on on-premise solutions or early-generation SaaS tools — have consent data scattered across enrolment forms, SMS opt-in logs, and paper-based store registers. That is not a consent record; that is a legal exposure.

The Act also mandates a right to withdraw consent at any time, with withdrawal being as easy as giving consent. For a loyalty platform, this means real-time propagation: when a member of a Phoenix Marketcity programme withdraws consent for AI-based personalisation, that flag must cascade to the analytics engine, the campaign scheduler, the recommendation model, and any third-party brand tenants sharing that data — within hours, not billing cycles. Vendors like Capillary, EasyRewardz, and Xeno have announced DPDP roadmaps, but the depth of consent propagation across their integrations varies significantly.

Finally, the Act introduces the concept of a Consent Manager — a government-registered intermediary through which data principals can manage permissions across multiple data fiduciaries. For mall operators running multi-brand loyalty programmes, this is particularly relevant: a shopper at Select CITYWALK interacts with the mall's central loyalty layer and with individual brand tenants (FabIndia, Cafe Coffee Day, Apollo Pharmacy) simultaneously. Each of those relationships is a separate fiduciary relationship under the DPDP Act, and consent must be captured, stored, and honoured at each layer independently.

The DPDP Consent Funnel for a Loyalty Enrolment

Customer Touchpoint (In-Store / App / WhatsApp) — 100% of prospectsConsent Notice Presented (Purpose-Specific, Plain Language) — ~92% reach noticeAffirmative Consent Given (Tick / OTP / Digital Signature) — ~74% consent rateConsent Artefact Stored (Timestamped, Immutable, Purpose-Tagged) — ~74% — must be 100%
Each stage of loyalty enrolment now carries a distinct consent obligation under the DPDP Act. Drop-off at any stage without a valid consent artefact creates a compliance gap and a data liability.

Role of ConsentFirst Architecture in Managing Customer Permissions

A ConsentFirst architecture inverts the traditional loyalty data model. Instead of collecting everything at enrolment and then worrying about permissions later, ConsentFirst places the consent record as the primary key — every downstream data object is a child of the consent event, not an independent entity. This is not merely a philosophical position; it has direct engineering implications for how a loyalty platform stores, queries, and deletes customer data.

In practice, a ConsentFirst loyalty platform maintains three distinct data layers. The first is the Identity Layer — hashed mobile numbers, email addresses, and loyalty IDs — which is the minimum data needed to recognise a returning customer and is governed by the most basic consent (service delivery). The second is the Behavioural Layer — transaction history, basket composition, dwell-time signals from mall footfall sensors, app navigation patterns — which requires explicit, purpose-named consent for each processing use case. The third is the Intelligence Layer — AI-generated RFM scores, churn propensity indices, next-best-offer recommendations — which requires both the underlying Behavioural Layer consent and an additional consent for AI-based automated profiling, as the DPDP Act's provisions around automated decision-making are among its most stringent.

When a customer like a regular Tanishq jewellery buyer or a Reliance Trends fashion shopper withdraws consent for AI profiling, a ConsentFirst architecture automatically degrades their data to the Behavioural Layer. They still earn and redeem points — service delivery is unaffected — but they are no longer included in AI model training batches or personalised offer algorithms. This is operationally clean because the data layers are architecturally separated, not logically filtered at query time (a distinction that matters enormously when a Data Protection Officer reviews your deletion logs).

The ConsentFirst model also transforms customer trust economics. Research from comparable GDPR markets in Europe shows that brands with transparent, easy-to-manage consent interfaces see 31% higher opt-in rates for marketing communications than brands with opaque all-or-nothing consent prompts. Indian consumers — particularly the urban millennial demographic that drives premium retail at malls like DLF Promenade or Palladium — are increasingly privacy-aware. A consent dashboard that clearly shows what data is held, what it is used for, and offers one-tap withdrawal is not a compliance burden; it is a brand differentiator that improves programme enrolment quality.

ConsentFirst Loyalty Architecture vs. Traditional Consent-Bolt-On Approach

ConsentFirst Architecture (DPDP-Ready)
Traditional Consent-Bolt-On (Legacy Loyalty Stack)
Consent record is the primary key; all data objects are children of the consent event
Consent is a field in the CRM record, often populated retrospectively or assumed from enrolment
Purpose-specific consent flags for each processing use case; AI profiling requires separate opt-in
Single blanket consent at enrolment covers all downstream uses, including analytics and third-party sharing
Withdrawal propagates to analytics engine, campaign scheduler, and brand-tenant systems within <2 hours
Withdrawal requires manual intervention across disconnected systems; propagation may take days or weeks
Three-layer data architecture (Identity / Behavioural / Intelligence) enables clean data degradation on withdrawal
Monolithic data model makes partial deletion technically complex and legally unprovable
Audit trail is immutable, timestamped, and purpose-tagged — regulator-ready by default
Audit trail is reconstructed from logs; gaps are common, especially for offline enrolment channels

Data Governance Frameworks to Ensure DPDP Compliance

Consent management is the front door of DPDP compliance; data governance is the entire building. A governance framework for a retail loyalty programme must cover five operational pillars: collection, storage, processing, sharing, and deletion — and each pillar must have documented policies, technical controls, and audit mechanisms that a Data Protection Board inspector could review without advance notice.

On collection: every data-collection touchpoint — POS integration with Petpooja or POSist in an F&B context, GoFrugal or Wondersoft at fashion retail, app onboarding flows, WhatsApp bot interactions — must be mapped to a Data Processing Agreement and a corresponding consent notice. The common failure mode in mid-market retail is that IT teams integrate new data sources (say, a new mall footfall sensor or a third-party e-commerce marketplace) without looping in the Data Protection Officer. By the time a CMO realises the analytics dashboard is ingesting unconsented data, the exposure is already historical.

On storage: personal data must be stored only for as long as the stated purpose requires. Loyalty programmes historically hoard data indefinitely — a member who last transacted at a Lifestyle store in 2019 may still have their full purchase history in the active database. Under DPDP, that is a retention violation unless the member has actively consented to long-term storage for personalisation. Retention schedules, automated deletion triggers, and pseudonymisation protocols must be built into the platform's data architecture, not managed manually by an analyst running a quarterly cleanup script.

On processing and sharing: data shared with brand tenants in a mall loyalty programme, with analytics vendors like MoEngage or WebEngage for campaign orchestration, or with AI model-training pipelines must each be covered by a specific Data Processing Agreement that names the sub-processor, the purpose, the data fields shared, and the retention period. The DPDP Act holds the primary data fiduciary — the mall operator or anchor brand — accountable for the compliance posture of every sub-processor in its ecosystem. This makes vendor selection a legal decision, not just a technical one. Platforms like Antavo or Customer Capital may offer compelling feature sets, but a CMO must verify their DPDP compliance posture with the same rigour applied to the primary platform.

On deletion: the right to erasure under DPDP is not merely a data-warehouse delete query. It requires proof of deletion across every system where the data was ever written — including backups, ML model training sets, and third-party sub-processors. This is the hardest pillar to implement retrospectively, which is why greenfield loyalty implementations in 2025 must design for deletion from day one.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

5-Step Playbook: Building a DPDP-Compliant Loyalty Analytics Programme

01

Conduct a Data Processing Inventory (DPI)

Map every data field collected across all loyalty touchpoints — POS, app, WhatsApp, web, in-mall kiosk — to its processing purpose, storage location, and downstream system. For brands running on Wondersoft or GoFrugal POS systems, this means auditing each API endpoint that feeds the loyalty platform. Flag every field that lacks a corresponding consent artefact. This inventory is the foundation of your DPDP compliance posture and typically takes 4–6 weeks for a mid-size retail chain with 50–200 stores.

02

Redesign Enrolment Flows with Purpose-Specific Consent Notices

Rewrite every enrolment touchpoint — in-store form, app signup, WhatsApp opt-in — to present purpose-specific consent notices in plain language (Hindi and regional language versions are strongly advisable, given DPDP's emphasis on informed consent). Separate consent for transactional data, marketing communications, AI-based personalisation, and data sharing with brand partners. Test comprehension with actual store staff and customers before rollout. Opt-in rates typically improve when consent notices are clear, because customers trust programmes that respect their choices.

03

Implement a Consent Management Platform with Real-Time Propagation

Deploy a consent management layer that stores consent artefacts in an immutable, timestamped ledger and propagates changes to all downstream systems — CRM, campaign engine, analytics warehouse, and AI model pipelines — within a defined SLA (target: under 2 hours). This layer must expose APIs that brand tenants and sub-processors can call to check consent status before processing any member's data. For mall operators, this is the technical spine of the entire multi-brand loyalty ecosystem's compliance posture.

04

Establish Data Retention Schedules and Automated Deletion Triggers

Define retention periods for each data category — transactional data (typically 36 months for active members), behavioural data (12–24 months), AI model training sets (anonymised, no PII). Configure automated deletion or pseudonymisation triggers at the end of each retention period. Document the deletion process end-to-end, including backups and sub-processor notifications, so that a deletion event can be proven to a regulator within 72 hours of request.

05

Train Frontline and Analytics Teams on DPDP Obligations

DPDP compliance breaks down most often not in the tech stack but at the human layer — a store associate who collects a phone number without a consent form, or a data analyst who adds a new data source to a dashboard without a DPA. Mandatory training for store managers, loyalty programme managers, and data analytics teams, with quarterly refreshers and incident reporting protocols, is the operational layer that holds the entire compliance framework together. Appoint a DPDP champion in each business unit with a direct line to the Data Protection Officer.

Building Customer Trust Through Transparent Loyalty Data Practices

Transparency is the DPDP Act's most underrated commercial opportunity. Indian retail brands have historically operated on an implicit data bargain — customers hand over their phone number at the checkout, and brands assume this covers all downstream marketing. That era is over, and the brands that acknowledge this first will be the ones that convert the regulatory shift into a loyalty advantage.

The mechanics of transparency in a loyalty context are specific. A member of a Manyavar loyalty programme or a Cafe Coffee Day frequency card should be able to open a self-service dashboard — via app or WhatsApp — and see exactly what data the programme holds, what it is being used for, and who it has been shared with. They should be able to download their data in a portable format, update their preferences, and withdraw specific consents without losing their points balance. This is the DPDP Act's vision of data principal empowerment, and it is also — not coincidentally — what builds the kind of programme trust that drives Net Promoter Scores and word-of-mouth enrolment.

Quantitative evidence from comparable GDPR implementations in the UK and Germany shows that brands which proactively communicated data transparency improvements saw a 19% increase in loyalty programme active engagement within 12 months of rollout. The Indian consumer is not starting from a position of trust in data-handling — high-profile data leaks, spam call industries built on purchased contact lists, and aggressive push notification practices have eroded baseline trust significantly. A loyalty programme that demonstrably respects consent is not meeting a low bar; it is clearing a meaningful one.

For mall operators, transparency has an additional dimension: the multi-brand data ecosystem. A shopper at Phoenix Marketcity Mumbai interacts with the mall's central loyalty layer, but her purchase data at an Armani Exchange store within the mall is commercially sensitive to that brand. Transparent data practices require a clear, published policy on exactly what data flows between the mall operator and brand tenants, what data is aggregated and anonymised before any tenant sees it, and what data is never shared under any circumstances. This policy — when communicated clearly in the loyalty app and at enrolment — is the difference between a programme members trust and one they merely tolerate.

DPDP Compliance Readiness Checklist for Retail Loyalty Programmes
  • Data Processing Inventory completed: every loyalty data field mapped to a purpose, storage location, and downstream system with a documented consent basis
  • Enrolment flows updated: purpose-specific, plain-language consent notices at every touchpoint (POS, app, WhatsApp, web) with no pre-ticked boxes or bundled consents
  • Consent Management Platform deployed: immutable, timestamped consent ledger with real-time propagation to CRM, analytics, campaign, and AI pipeline systems in under 2 hours
  • Retention schedules defined and automated: deletion or pseudonymisation triggers configured for each data category, with proof-of-deletion protocols covering backups and sub-processors
  • Data Processing Agreements signed: every analytics vendor, campaign platform, and brand-tenant data-sharing arrangement covered by a DPDP-compliant DPA naming purpose, fields, and retention
  • Member self-service portal live: customers can view, download, update, and withdraw consent for specific purposes without losing programme benefits or requiring staff intervention
  • DPDP training completed: all store managers, loyalty programme managers, and data analytics staff trained on consent obligations with quarterly refreshers and an incident reporting pathway
“In India, first-party data is only as valuable as the consent that underlies it. A million unconsented loyalty records is not an asset — it is a balance-sheet liability waiting for an audit.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle Solves This

The Fundle AI Platform was architected with the DPDP Act's requirements as a first-order design constraint, not an afterthought. Vineet Narang's founding vision for Fundle was explicit: India's loyalty industry needed a platform where consent and analytics were not separate modules bolted together, but a single, unified data operating system where every intelligence insight is traceable back to a specific, valid consent artefact. That architectural decision is why Fundle supports transparent data governance and consent management for 270+ Indian retail brands today.

Fundle Loyalty and Fundle Mall Loyalty are built on the ConsentFirst architecture described earlier in this article. The consent ledger is the structural core of the platform — not a side table in the database, but the primary key around which all member data is organised. When a shopper enrols in a mall-wide programme powered by Fundle Mall Loyalty, their consent preferences cascade in real time to every brand-tenant integration, every campaign trigger, and every AI model training pipeline. A withdrawal request at 11 PM on a Saturday propagates across the entire ecosystem before midnight — not at the next business-day batch job.

Fundle Brand Loyalty extends the same ConsentFirst framework to enterprise retail brands running independent programmes — fashion chains, jewellery retailers, pharmacy networks — where the data processing complexity includes e-commerce platforms, WhatsApp Business integrations, and offline POS systems from Wondersoft, GoFrugal, and POSist. The Fundle AI Workflow layer automates consent status checks as a pre-processing gate for every campaign — if a member's consent for marketing communications is inactive, the workflow routes around them automatically, eliminating the manual suppression lists that create compliance gaps in traditional CRM tools.

The intelligence layer — Fundle AI Agents and Fundle Agentic AI — operates exclusively on data that has cleared the consent gate. AI Agents that generate next-best-offer recommendations, churn risk alerts, or RFM segment migrations only ingest member data where the AI profiling consent flag is active. This is not a query-time filter that a developer could accidentally bypass; it is a platform-level enforcement that the Fundle AI Platform maintains independently of the end-user application. For a Retail CMO presenting to a board or responding to a Data Protection Board notice, this is the difference between a defensible compliance posture and a speculative one.

On the analytics and reporting side, Fundle's compliance dashboard gives Data Protection Officers and Loyalty Programme Managers a real-time view of consent coverage rates, pending deletion requests, data processing volumes by purpose, and sub-processor data-sharing logs — the exact evidence set a DPDP audit requires. Compared to piecing together this picture from Capillary's CRM exports, Almonds.ai campaign logs, and a separate MoEngage or WebEngage consent module, the integrated Fundle approach reduces compliance reporting time by an estimated 60–70% for a typical mid-size retail chain. DPDP compliant loyalty analytics is not a feature Fundle added to a marketing platform. It is the operating principle around which the entire platform was designed.

Frequently asked

What does the DPDP Act 2023 specifically require from retail loyalty programmes in India?+

The DPDP Act requires retail loyalty programmes to obtain free, specific, informed, unconditional, and unambiguous consent before collecting or processing any customer personal data. This means purpose-specific consent for each use case — transactional processing, marketing, AI profiling, third-party sharing — stored as an immutable, timestamped artefact. Penalties for significant breaches reach ₹250 crore. Consent withdrawal must be as easy as consent giving, with real-time propagation across all systems.

How does a ConsentFirst architecture differ from simply adding a consent checkbox to an existing loyalty enrolment form?+

A consent checkbox on an enrolment form is a single, static record. A ConsentFirst architecture makes the consent event the primary key of the entire data model — every downstream data object is a child of a specific consent record. This means that when consent is withdrawn or modified, the system can automatically degrade, suppress, or delete all dependent data across CRM, analytics, campaign, and AI systems. A checkbox approach requires manual intervention and leaves audit gaps that are very difficult to defend under DPDP scrutiny.

How should mall operators handle DPDP compliance when multiple brand tenants share a central loyalty platform?+

Each brand tenant in a mall loyalty ecosystem is a separate data fiduciary under the DPDP Act. The mall operator must maintain consent records that distinguish between data processed centrally (for mall-level analytics and rewards) and data shared with individual brand tenants. A Data Processing Agreement must cover each tenant relationship, specifying which data fields are shared, for what purpose, and for how long. The Fundle Mall Loyalty platform handles this through tenant-level consent flags and data-sharing logs that give the mall operator a single compliance view across the entire ecosystem.

Can AI-based loyalty analytics continue to function effectively under DPDP consent restrictions?+

Yes — but the AI must be designed to operate on a consented data subset rather than a full member universe. In practice, well-communicated consent programmes achieve opt-in rates of 70–80% for AI personalisation among active loyalty members, which is a statistically robust training and inference base. The quality of AI loyalty analytics on high-quality, consented data typically outperforms analytics on a larger but lower-quality, poorly consented dataset, because the consented members tend to be more engaged and behaviourally representative of the programme's core value segment.

What is the difference between DPDP compliance postures offered by platforms like Capillary or EasyRewardz versus Fundle?+

Platforms like Capillary and EasyRewardz have announced DPDP compliance roadmaps that typically involve consent modules added to existing CRM architectures. The depth of consent propagation across integrations, the real-time nature of withdrawal processing, and the audit trail completeness vary by implementation. Fundle's differentiation is architectural: the Fundle AI Platform was built with consent as a first-order data model constraint, not added on top of an existing system. This means enforcement is platform-level rather than application-level, which is materially more defensible in a regulatory review.

How long does it typically take an Indian retail chain to achieve full DPDP compliance for its loyalty programme?+

For a mid-size retail chain with 50–200 stores running an established loyalty programme, achieving full DPDP compliance typically requires 16–24 weeks end-to-end: 4–6 weeks for a data processing inventory, 4–6 weeks for consent flow redesign and tech implementation, 4–6 weeks for staff training and rollout, and 4–6 weeks for audit and gap remediation. Brands starting a new programme on a DPDP-ready platform like Fundle can compress this to 8–12 weeks since the platform's architecture handles the majority of the technical compliance requirements out of the box.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?