“We don't sell AI Agents. We sell business outcomes — increase repeat rate, reduce churn, raise basket size. The AI Agents are how Fundle gets there.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand exactly what DPDP 2023 demands from loyalty analytics platforms operating in Indian retail
  • Build consent collection flows that are legally watertight and commercially effective at the same time
  • Adopt AI loyalty analytics that anonymise, segment, and activate first-party data without breaching consent boundaries
  • Compare point-solution CRMs against purpose-built AI platforms before your next tech investment
  • Deploy Fundle's ConsentFirst and Fundle AI Workflow to operationalise DPDP compliance across every touchpoint

India's Digital Personal Data Protection Act, 2023 — the DPDP Act — quietly became the most consequential piece of retail technology legislation in the country's history. For the loyalty program manager at a Lifestyle or Pantaloons flagship, or the CMO running multi-city campaigns across a Phoenix Marketcity portfolio, the question is no longer philosophical: it is operational. You are collecting names, mobile numbers, purchase histories, visit frequencies, wishlist signals, and increasingly, behavioural data from app sessions and kiosk interactions. Every one of those data points now attracts a compliance obligation that carries penalties of up to ₹250 crore per breach under the new Act.

The Indian retail industry has historically treated loyalty data as a proprietary CRM asset — something to be hoarded, batch-exported into spreadsheets, and pushed through SMS blasts with zero personalisation logic. That model is over. The DPDP Act mandates explicit, informed, granular consent before any personal data can be collected or processed. It demands that the purpose of processing be stated clearly, that data not be used beyond that stated purpose, and that members be given a practical, frictionless way to withdraw consent at any time. For a chain running 200 stores across 18 states — each using a different POS system from vendors like POSist, GoFrugal, Petpooja, or Wondersoft — operationalising those mandates is an engineering challenge as much as a legal one.

The irony is that DPDP compliance, done well, is not a cost centre. It is a first-party data advantage. Retailers who build trust through transparent consent flows will see higher opt-in rates, richer declared data, and more predictable customer lifetime value than those who scrape implied consent from a buried terms-and-conditions checkbox. Brands like Tanishq and FabIndia already understand that their customer relationships are built on trust; DPDP simply forces every other retailer to catch up to that standard.

This is where DPDP compliant loyalty analytics becomes a platform problem, not just a policy problem. Fundle.ai has spent the past two years building the technical architecture, consent workflows, and AI analytics layer that Indian retail operators need to navigate this transition without losing campaign velocity or commercial insight. This article sets out exactly what that looks like — from technical requirements and consent best practices to data governance frameworks and AI-powered activation.

India Loyalty + DPDP: The Numbers That Matter

₹250 Cr
Maximum penalty per data breach under DPDP Act 2023 — per class of violation
67%
Indian loyalty program members who say they would share more data if they understood how it would be used (PwC India, 2023)
123+
Malls across India where Fundle's ConsentFirst and AI analytics platform deliver DPDP compliance
3.2×
Higher email and WhatsApp opt-in rate when consent is collected with clear purpose disclosure vs. generic T&C acceptance

Technical Requirements for DPDP Compliant Analytics Platforms

A loyalty analytics platform that claims DPDP compliance cannot bolt it on as a feature. Compliance must be structural — baked into the data model, the processing pipeline, and the API layer from the ground up. Here is what retail technology buyers need to audit before signing any loyalty platform contract.

First, consent state must be a first-class data entity. Every customer record must carry a consent object — not a boolean flag buried in a profile table, but a structured record that captures: the specific purpose for which consent was granted (e.g., 'marketing communications', 'personalised offers', 'third-party brand partners'), the timestamp and channel of consent capture, the version of the consent notice shown, and the current revocation status. When a Manyavar customer walks into a Select CITYWALK store and joins the loyalty program on a kiosk, the platform must record all of that in real time and propagate it to every downstream system — the CDP, the campaign engine, the analytics warehouse — before any processing begins.

Second, data minimisation and purpose limitation must be enforced at the pipeline level. The DPDP Act is explicit: you may only process personal data for the purpose for which consent was given. If a customer at a Cafe Coffee Day outlet consents to 'loyalty points tracking' but not 'personalised marketing', the analytics platform must ensure that customer's purchase data feeds the points ledger and nothing else. This requires attribute-level consent tagging — a capability that most legacy CRM platforms, including point solutions used widely in Indian retail, simply do not have. Vendors like Capillary Technologies and EasyRewardz have begun adding consent fields, but their data models were not designed for attribute-level purpose enforcement.

Third, the platform must support the Data Principal's rights under DPDP: the right to access their data, the right to correction, the right to erasure, and the right to grievance redressal — all within defined timescales. For a retail chain with 5 million loyalty members, managing those requests manually is impossible. The platform must expose self-service portals and automated fulfilment workflows. Finally, data residency matters: DPDP requires that certain categories of sensitive data be stored within India's borders. Any SaaS platform with cloud infrastructure hosted exclusively outside India is immediately non-compliant for sensitive personal data categories.

DPDP Consent Funnel: From Footfall to Compliant First-Party Profile

Customer Touchpoint (Store / App / Kiosk) — 100%Consent Notice Served (Purpose + Duration Disclosed) — 100%Explicit Opt-In Captured (Granular by Purpose) — 74%Consent Written to Consent Ledger + POS / CDP Sync — 74%
Each stage represents a checkpoint where consent state is verified before data is written or processed. Drop-off at any stage stops downstream analytics processing automatically.

Best Practices in Consent Gathering and Data Usage

Consent collection in Indian retail is almost universally broken. The standard playbook — 'give us your mobile number to earn points, and by doing so you agree to our privacy policy' — violates the DPDP Act's requirement for freely given, specific, informed, and unambiguous consent on at least three of those four dimensions simultaneously. Here is what good looks like.

Purpose granularity is non-negotiable. Instead of one blanket consent, present members with distinct, plain-language purposes: 'We will use your purchase history to calculate and credit loyalty points'; 'We would like to send you personalised offers via WhatsApp'; 'We will share your anonymised shopping behaviour with our brand partners to improve recommendations'. Each purpose should carry a separate toggle, and the member must be able to opt into some and not others without losing core loyalty program benefits. Apollo Pharmacy already applies a version of this for their health data processing — the model is proven and commercially viable.

Consent must be layered and contextual. At POS enrollment, capture minimal consent — mobile number for points, basic marketing opt-in — and defer enrichment to a second interaction. When the customer is browsing the app, prompt them to complete their profile with declared preferences (cuisine, fashion category, occasion type) and explain exactly what personalisation they will receive in return. Reliance Trends' app does a reasonable job of this progressive profiling; DPDP now makes it mandatory rather than optional.

Refusal must carry no penalty. Under DPDP, a customer who refuses to consent to marketing communications cannot be denied the core benefit of the loyalty program — points earning and redemption. Platforms that gate points issuance behind marketing opt-in are already non-compliant. Redesign your enrollment flow so that the minimum viable consent bundle covers only what is strictly necessary for program operation.

For data usage, implement purpose-bound data segmentation. A customer who consented to 'personalised offers' can receive AI-generated product recommendations. A customer who consented to 'loyalty tracking only' should be served only transactional communications — points balance updates, expiry reminders. Your campaign engine must be able to filter audiences by consent purpose at query time, not as a post-processing exclusion list. The difference is architectural: exclusion lists lag; consent-filtered queries are real-time and audit-safe.

Legacy CRM Platforms vs. DPDP-Native Loyalty Analytics Platforms

Legacy CRM / Point Solutions
DPDP-Native Platform (e.g., Fundle AI Platform)
Single boolean consent flag per member — no purpose granularity
Attribute-level consent ledger with purpose, timestamp, version, and channel for every data point
Consent state not propagated in real time to campaign and analytics engines
Consent changes propagated via event-driven architecture within seconds across all downstream systems
Data erasure handled manually by CRM admin — SLA measured in weeks
Automated erasure workflows triggered by member self-service portal — completed within 72 hours
Analytics queries run on full member dataset regardless of consent status
Every analytics query is consent-filtered at source; non-consented records are excluded before processing begins
Audit trail limited to campaign send logs; no consent change history
Immutable consent audit log with full history of grants, amendments, and revocations — ready for Data Protection Board review

Role of Modern Consent Management Platforms Like ConsentFirst

A Consent Management Platform (CMP) is the operational layer that sits between your customer touchpoints — app, web, kiosk, store associate tablet, WhatsApp bot — and your loyalty analytics infrastructure. Its job is to serve the correct consent notice for each context, capture the member's choice in a legally admissible format, store it in a tamper-proof ledger, and expose APIs that allow every downstream system to query consent state before processing any data. Without a CMP, DPDP compliance is a documentation exercise rather than a technical reality.

In the Indian market, the CMP landscape is nascent. Global players like OneTrust and Cookiebot were built for web cookie consent under GDPR and are poorly suited to the offline-first, multi-channel reality of Indian retail loyalty — where a member might enroll on a store kiosk, update preferences on a mall app, and interact via a WhatsApp chatbot in the same week. Indian-market CMPs need to handle SMS and WhatsApp consent flows, integrate with POS middleware from vendors like GoFrugal and POSist, and support regional language consent notices for members who do not read English — a non-trivial engineering challenge.

Fundle's ConsentFirst module was designed specifically for this environment. It operates as a consent orchestration layer within the Fundle Loyalty Platform, serving consent notices in 11 Indian languages, capturing explicit purpose-specific consent at every touchpoint, and writing every consent event to an immutable ledger that is queryable by the campaign engine, the analytics platform, and any Data Protection Board audit process. Fundle's ConsentFirst and AI analytics platform deliver DPDP compliance across 123+ malls in India — a deployment footprint that has surfaced every edge case the Indian retail environment can produce, from rural kiosk enrollments with feature phones to luxury mall members with complex cross-brand data sharing preferences.

The commercial case for a dedicated CMP is straightforward. Brands that use ConsentFirst-style purpose-specific consent collection report opt-in rates that are 3.2× higher than brands using generic T&C acceptance — because members who understand what they are consenting to are significantly more willing to share. Higher opt-in rates mean larger addressable audiences for AI-driven campaigns, which means better ROAS on loyalty spend. Compliance and commercial performance are not in tension; they are aligned when the consent architecture is right.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

5-Step Playbook: Operationalising DPDP Compliant Loyalty Analytics

01

Audit Your Current Data Inventory

Map every personal data field collected across POS, app, web, and offline forms. Tag each field with its processing purpose, its legal basis under DPDP, and its current consent coverage ratio. For most Indian retail chains, this audit reveals that 30-50% of existing member records lack valid DPDP-compliant consent — those records must be either re-consented or restricted before the Act's enforcement date.

02

Redesign Enrollment and Consent Flows

Rebuild your loyalty enrollment screens — on app, kiosk, and associate tablet — to present purpose-granular consent notices in plain language and regional languages. Separate the minimum consent needed for program participation from optional consents for marketing and data sharing. Test comprehension, not just click-through: run usability tests with actual store associates and members, particularly in Tier 2 and Tier 3 markets where literacy and language preferences vary significantly.

03

Deploy a Consent Management Platform with Real-Time API

Implement a CMP that writes every consent event to an immutable ledger and exposes a real-time consent query API. Integrate this API into your POS middleware, campaign engine (MoEngage, WebEngage, Xeno, or similar), CDP, and analytics warehouse. Every system that touches personal data must call the consent API before processing — this is the architectural guarantee that makes compliance auditable and defensible.

04

Retrofit Analytics Pipelines with Consent Filtering

Update every analytics query, segment definition, and ML model training job to apply consent filters at source. Segment 'members who purchased footwear in the last 90 days' must implicitly read 'members who purchased footwear in the last 90 days AND have valid consent for personalised marketing'. Enforce this at the data warehouse layer using row-level security policies, not as an application-level afterthought.

05

Establish a Data Rights Fulfilment SLA

Build automated workflows for Data Principal rights requests: access, correction, erasure, and grievance. Publish a self-service member portal where loyalty members can view their consent history, download their data, and submit erasure requests without contacting a call centre. Target a 72-hour SLA for erasure fulfilment — considerably tighter than DPDP's statutory maximum — as a brand trust differentiator.

Security and Data Governance Frameworks for Loyalty Analytics

DPDP compliance does not end at consent collection. The Act places significant obligations on how personal data is stored, transmitted, and protected once it is inside your analytics infrastructure. For retail loyalty platforms handling tens of millions of member records, the security and governance requirements are substantial.

Data encryption must be end-to-end. Member personal data — mobile numbers, purchase histories, location signals — must be encrypted at rest and in transit using current standards (AES-256 at rest, TLS 1.3 in transit). Encryption keys must be managed within India using a key management service that does not give foreign cloud providers access to unencrypted data. Pseudonymisation — replacing direct identifiers with tokens for analytics processing — should be applied wherever the analytics use case does not require direct identification, which is the vast majority of segmentation and propensity modelling work.

Role-based access control must be strict and audited. A Pantaloons store manager should have read access to their store's transaction aggregates, not to individual member mobile numbers. A campaign analyst at Lifestyle's head office should be able to build audience segments but not export raw PII to spreadsheets. Every access event must be logged, and logs must be reviewed regularly. Most Indian retail IT teams currently have no formal access review cadence for their loyalty platforms — DPDP makes this a compliance gap rather than just a best practice.

Data retention policies must be defined and enforced programmatically. DPDP requires that personal data not be retained beyond the period necessary for the stated purpose. For loyalty analytics, this means defining retention windows by data category — transaction records (typically 3 years for accounting purposes), behavioural event logs (12 months for personalisation models), and identity data (duration of active membership plus a defined post-exit window). These retention rules must be enforced by automated deletion jobs, not by manual processes that get deferred indefinitely.

Vendor risk management is a new compliance dimension that most Indian retail CMOs have not engaged with seriously. Under DPDP, you are responsible for how your data processors — your analytics vendor, your campaign platform, your cloud provider — handle your members' data. Contracts must include specific data processing agreements, audit rights, and breach notification timescales. If your current loyalty platform vendor cannot produce a signed Data Processing Agreement within 30 days of request, that is a significant compliance risk signal.

DPDP Compliance Readiness Checklist for Loyalty Program Managers
  • Consent ledger in place capturing purpose, channel, timestamp, and version for every member consent event
  • Purpose-granular consent notices available in at least 5 Indian languages, including Hindi, Tamil, Telugu, Kannada, and Bengali
  • Real-time consent query API integrated with POS middleware, campaign engine, and analytics warehouse
  • Analytics queries and ML training jobs consent-filtered at the data warehouse layer — not as application-level exclusions
  • Member self-service portal live for access, correction, erasure, and grievance requests with a 72-hour fulfilment SLA
  • Data Processing Agreements signed with all loyalty platform vendors, including CMP, CDP, and campaign automation providers
  • Encryption at rest (AES-256) and in transit (TLS 1.3) verified across all systems that store or transmit member personal data
“In Indian retail, the brands that earn the right to know their customers — through transparent consent, not data extraction — will own the next decade of loyalty economics. DPDP is not a constraint; it is a forcing function for building trust at scale.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Vineet Narang's founding thesis for Fundle was simple but radical for Indian retail: that loyalty should be built on earned trust, not accumulated data exhaust. That philosophy is now encoded into every layer of the Fundle AI Platform — from the ConsentFirst CMP module to the AI analytics engine that powers personalised offers across malls, brands, and channels.

Fundle Loyalty Platform is architected as a consent-first system from the database schema upward. Every member record in Fundle carries a structured consent object — purpose-tagged, timestamped, versioned, and propagated in real time to every downstream service via an event-driven consent bus. When a member at a Phoenix Marketcity outlet updates their WhatsApp consent preference at a kiosk, that change is reflected in the campaign engine, the AI segmentation layer, and the analytics warehouse within seconds — not in the next nightly batch. This is not a feature; it is a foundational architectural commitment.

Fundle Mall Loyalty and Fundle Brand Loyalty both inherit this consent infrastructure, which means a single deployment can handle the complex multi-tenancy of a mall environment — where Tanishq, Lenskart, and Cafe Coffee Day might each have their own brand-level consent preferences alongside the mall's umbrella program consent — without creating consent conflicts or data leakage between tenants. Fundle AI Agents handle member-facing interactions — WhatsApp flows, app nudges, kiosk dialogs — and are programmed to check consent state before executing any personalised communication, making DPDP compliance an autonomous, always-on operational capability rather than a periodic compliance review.

Fundle Agentic AI and Fundle AI Workflow take this further into the analytics layer. Propensity models, RFM segmentation, churn prediction, and next-best-offer engines all run inside a consent-filtered data environment. A member who has opted into 'personalised recommendations' but not 'third-party brand sharing' is automatically included in first-party AI models and excluded from co-marketing activations — without any manual intervention by the analytics team. For retail CMOs managing campaigns across 50+ stores and millions of members, this automation is the difference between DPDP compliance being theoretically possible and being operationally real. Fundle's ConsentFirst and AI analytics platform deliver DPDP compliance across 123+ malls in India, giving Indian retail operators the most battle-tested DPDP-native loyalty infrastructure available in the market today.

Frequently asked

What does DPDP 2023 specifically require from a retail loyalty program?+

The Digital Personal Data Protection Act 2023 requires that you collect explicit, informed, purpose-specific consent before processing any member's personal data. Members must be able to access their data, correct inaccuracies, withdraw consent at any time, and request erasure — all within defined timescales. You cannot deny core loyalty benefits (points earning and redemption) as a condition of marketing consent. Penalties for breach go up to ₹250 crore per class of violation.

How is DPDP different from GDPR, and why can't we just apply our GDPR framework?+

DPDP shares GDPR's consent-first philosophy but differs in several important ways for Indian retail. It does not include a 'legitimate interests' basis for processing — consent or contract are the primary bases. It applies to data processed in India regardless of where the data processor is headquartered. It has specific grievance officer requirements for Indian entities. And crucially, it must work for offline enrollment channels — store kiosks, paper forms, associate-assisted enrollment — which GDPR frameworks rarely address. Cookie consent tools built for GDPR web compliance are insufficient for India's offline-first retail loyalty reality.

What should a retail CMO do with existing loyalty member records that predate DPDP?+

Audit your existing member database and segment records by consent quality. Records with no documented consent basis must be either re-consented through an active outreach campaign (WhatsApp, SMS, app notification) or restricted — meaning they can be used for operational purposes like points tracking but not for marketing or analytics. Do not delete records indiscriminately; many members will re-consent when given a clear, purpose-specific ask. A re-consent campaign with proper purpose disclosure typically converts 40-60% of a legacy database within 90 days.

Can AI-based loyalty analytics still work effectively within DPDP consent constraints?+

Absolutely — and in most cases, consent-filtered AI analytics outperforms unconstrained analytics because the addressable audience is more engaged and accurately profiled. Propensity models trained on opted-in members who have actively declared preferences are more predictive than models trained on passive data from members who never knew their data was being used. The key architectural requirement is that consent filtering happens at the data warehouse layer, not as a post-processing exclusion. Platforms like Fundle AI Platform are designed for exactly this constraint and produce strong commercial results within it.

What is a Consent Management Platform and does every retail chain need one?+

A Consent Management Platform (CMP) is the technology layer that serves consent notices, captures member choices, stores them in an auditable ledger, and provides real-time APIs so that downstream systems can verify consent status before processing data. Any retail chain with more than 100,000 loyalty members — which covers most mid-to-large Indian retail operators — needs a CMP. Managing consent at that scale through manual processes or spreadsheets is not feasible and is not defensible in a Data Protection Board audit. The CMP does not need to be a standalone product; it can be a module within your loyalty platform, as with Fundle's ConsentFirst.

How long does it take to become DPDP compliant for a mid-size Indian retail chain?+

For a retail chain with 50-200 stores and 500,000 to 5 million loyalty members, a realistic DPDP compliance program runs 4-6 months end to end. The phases are: data audit and gap analysis (4-6 weeks), consent flow redesign and CMP deployment (6-8 weeks), analytics pipeline retrofitting with consent filters (4-6 weeks), and member-facing portal and rights fulfilment workflow deployment (4-6 weeks). These phases can run in parallel with appropriate resourcing. Working with a DPDP-native loyalty platform like Fundle compresses the timeline significantly because the consent infrastructure is pre-built and pre-integrated rather than requiring custom development.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?