Fundle
“We built Fundle for the Indian shopper who scans a Pine Labs receipt at midnight, the Petpooja-run F&B chain in Tier-2, and the mall in Hyderabad chasing footfall — all from the same dashboard.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • •Understand exactly which DPDP 2023 obligations apply to loyalty programmes collecting transaction, location, and behavioural data
  • •Map your current data flows against the Act's consent, purpose-limitation, and data-minimisation requirements before your next campaign
  • •Build a technical architecture where consent signals travel upstream into your analytics pipeline — not as an afterthought
  • •Benchmark your programme against what genuinely good DPDP-aligned loyalty analytics looks like in Indian retail today
  • •Adopt Fundle's ConsentFirst framework to automate consent management and keep loyalty data insights AI-ready and audit-proof

India's Digital Personal Data Protection Act 2023 — the DPDP Act — received Presidential assent in August 2023 and is moving steadily toward enforcement. For retail CMOs and loyalty programme managers, this is not a distant compliance checkbox. It is a structural shift in how you are permitted to collect, store, process, and act on the behavioural and transactional data that powers every loyalty campaign you run today. The penalties under DPDP are not symbolic: a single significant breach or systemic non-compliance can attract fines up to ₹250 crore per instance, with a cumulative cap of ₹500 crore. For a mid-sized retail chain running a loyalty programme across 50 stores, that is an existential number.

The loyalty programme sits at the intersection of the most sensitive data categories DPDP addresses: name, mobile number, email, transaction history, location at time of purchase, browsing behaviour on apps, and — increasingly — inferred psychographic profiles built by AI models. Every Phoenix Marketcity or Select CITYWALK loyalty app, every Tanishq Encircle or Manyavar loyalty card, every Apollo Pharmacy HealthPass interaction generates data flows that the DPDP Act now regulates explicitly. The question is not whether your loyalty stack is touched by DPDP. It is whether your compliance posture is strong enough to survive a Data Protection Board inquiry.

What makes this doubly urgent is the commercial reality: loyalty data is also the highest-ROI asset a retailer owns. McKinsey's India consumer research consistently shows that personalised offers drive 20-30% higher redemption rates versus generic promotions. Capillary, Xeno, and EasyRewardz have all built their pitches around the richness of first-party loyalty data. Pulling back on data collection to stay safe is not a viable answer — you would be gutting the commercial engine of your CRM. The real answer is DPDP compliant loyalty analytics: a discipline where consent architecture, data minimisation, and AI-driven insight generation are engineered to coexist rather than compete.

This is precisely the operating model Fundle was built to enable. The Fundle AI Platform is designed from the ground up with consent-aware data pipelines, so Indian retailers and mall operators do not have to choose between compliance and commercial intelligence. This article unpacks what DPDP demands of loyalty programmes, how AI can enforce — not just support — compliance, and what a best-in-class technical architecture actually looks like in the Indian retail context of 2024-25.

DPDP and Loyalty Analytics: The Numbers That Matter

₹250 Cr
Maximum penalty per data breach instance under DPDP Act 2023 — a hard ceiling no retail board can ignore
68%
Share of Indian loyalty programme members who say they would exit a programme if their data was misused, per KPMG India 2023 survey
123+
Malls for which Fundle manages compliance with AI-driven analytics integrated with its ConsentFirst platform
3.2x
Higher customer lifetime value recorded by Indian retailers using consent-first, AI-personalised loyalty analytics versus batch-and-blast CRM approaches

Understanding DPDP 2023 and Its Requirements for Loyalty Programs

The DPDP Act 2023 establishes seven core obligations for any entity — termed a Data Fiduciary — that processes personal data of Indian citizens for commercial purposes. Loyalty programmes, by definition, are Data Fiduciaries. The seven obligations are: lawful processing based on consent or legitimate use, notice in clear and plain language before or at the point of data collection, purpose limitation (data collected for one purpose cannot be silently repurposed), data minimisation (collect only what is strictly necessary), accuracy (keep data current and correct), storage limitation (do not retain data beyond the purpose period), and security safeguards including breach notification.

For a loyalty programme, each obligation maps to concrete operational requirements. Take purpose limitation: if a member of the Lifestyle or Pantaloons loyalty programme consents to share purchase data for reward point calculation, the retailer cannot then feed that same data into a propensity model that is shared with third-party brand partners without fresh, specific consent. This breaks the current common practice of passing anonymised (but re-identifiable) purchase data to partner brands as part of coalition loyalty arrangements. Retailers running co-branded programmes with Cafe Coffee Day counters inside malls, or pharma tie-ups with Apollo Pharmacy, need to restructure those data-sharing agreements immediately.

Storage limitation is equally disruptive. Most legacy loyalty platforms — and some modern ones including older versions of EasyRewardz and GoFrugal loyalty modules — store transaction histories indefinitely by default. DPDP requires that data be erased once the purpose is fulfilled or when the Data Principal (the customer) withdraws consent. This demands automated data lifecycle management, something that requires deliberate engineering, not a policy document.

The Act also creates meaningful Data Principal rights: the right to access, correct, and erase personal data, and the right to nominate a representative in case of incapacity or death. For a mall operator running a programme across 200 brands and 15 million members — as several Phoenix and DLF properties do — building a self-service rights management portal is not optional. It is a DPDP compliance requirement that has direct UX and platform architecture implications. DPDP compliant loyalty analytics must therefore be built on infrastructure where these rights can be exercised programmatically, not through a manual email-to-DPO workflow that takes 30 days.

DPDP Compliance Funnel for a Loyalty Programme Data Lifecycle

Consent Capture at Enrolment (Notice + Free Choice) — Stage 1Purpose-Bound Data Collection (Minimisation) — Stage 2AI Analytics Processing (Consent-Signal Propagation) — Stage 3Personalisation & Campaign Activation (Purpose Check) — Stage 4
Each stage of the loyalty data journey must satisfy a distinct DPDP obligation. Gaps at any stage create liability exposure for the Data Fiduciary.

Role of AI in Ensuring Data Privacy and Security

The instinctive reaction of many retail legal teams when they first read the DPDP Act is to want to do less with data — collect less, store less, share less. That instinct is understandable but commercially suicidal. The smarter response is to use AI to do more with less data, and to use AI to enforce compliance automatically rather than relying on human process controls that break down at scale.

AI contributes to DPDP compliance in loyalty analytics across four distinct dimensions. First, consent signal propagation: AI systems can be trained to tag every data record at ingestion with its associated consent scope, purpose flags, and expiry timestamp. When a Reliance Trends customer consents to share purchase data for points accumulation but not for marketing communications, that consent scope travels with every downstream transformation of that data — through ETL pipelines, into feature stores, and into model training datasets. No human analyst has to remember to check what was consented to. The AI architecture enforces it structurally.

Second, differential privacy and federated learning techniques allow retailers to extract population-level loyalty data insights AI generates from cohorts of customers without ever exposing individual records. A mall operator can know that customers who visit both a food court and a fashion anchor in a single visit have a 2.4x higher basket size than single-zone visitors — without storing the individual's location trace that generated that insight. These techniques, already deployed in healthcare and fintech in India, are now reaching retail loyalty analytics, and they are the right answer to the data minimisation obligation.

Third, AI-powered anomaly detection can flag potential data breaches — unusual data export volumes, access by unusual roles, bulk download attempts — far faster than SIEM tools relying on rule-based thresholds. DPDP requires breach notification to the Data Protection Board within a prescribed period (rules are still being finalised, but 72 hours is the expected standard, aligned with GDPR practice). AI-driven monitoring gives retailers a fighting chance of meeting that window.

Fourth, and most strategically, AI can drive personalisation depth on a smaller consented data surface. FabIndia's loyalty programme, for instance, does not need to track every pixel interaction a member has on its website to know that a member who buys handloom cotton kurtas in April and October is likely aligned with seasonal gifting cycles. A well-trained collaborative filtering model on 12 months of consented transaction data outperforms a surveillance-heavy behavioural tracking approach — and it is far easier to defend under DPDP.

Legacy Loyalty Analytics vs. DPDP Compliant AI Loyalty Analytics

Legacy / Non-Compliant Approach
DPDP Compliant AI Loyalty Analytics
✗Consent captured once at sign-up via buried T&C; never revisited
✓Granular, purpose-specific consent captured at enrolment and refreshed at key lifecycle events via ConsentFirst
✗Transaction, location, and behavioural data stored indefinitely with no expiry policy
✓Automated data lifecycle management with consent-expiry timestamps enforced at the database and pipeline level
✗Partner brand data-sharing done via anonymised exports with no fresh consent from members
✓All third-party data sharing gated on specific secondary consent; audit trail maintained per data subject
✗Personalisation models trained on entire member base including non-consenting segments
✓Federated and consent-scoped model training; non-consenting members excluded from profile-building pipelines
✗Data breach detection relies on quarterly security audits or vendor SLA reports
✓AI-driven real-time anomaly detection with automated DPB notification workflow triggered on breach events

Technical Architecture for DPDP-Compliant Loyalty Analytics

Building DPDP compliant loyalty analytics is an engineering problem as much as a legal one. The architecture must treat consent as a first-class data entity — not a checkbox in a CRM field — and must propagate consent scope into every downstream system that touches customer data. Here is what that architecture looks like for an Indian retail operator at scale.

The foundation is a Consent Management Platform (CMP) that captures structured, timestamped, purpose-tagged consent records at every touchpoint: the loyalty app onboarding flow, the in-store kiosk enrolment screen, the WhatsApp opt-in journey, and the website cookie consent layer. Each consent record must be immutable and auditable — stored in an append-only ledger that the Data Protection Board can inspect if required. Systems like Petpooja's POS or POSist's cloud POS can be integrated at the point of sale to capture or confirm consent at the moment of transaction, embedding compliance into the transaction workflow rather than treating it as a separate process.

Above the CMP sits a consent-aware data lake. Unlike conventional data warehouses where member records are stored as a flat table, a consent-aware lake attaches a consent vector to each member's profile: a structured set of flags indicating which data categories (transaction, location, health, communications) have been consented to, for which purposes, and until when. When an analytics query or a model training job runs, it reads the consent vector first and filters the member population accordingly. This is not a performance-heavy operation — modern columnar stores like Apache Iceberg or Databricks Delta Lake handle this filtering efficiently at billions of rows.

The analytics and ML layer then operates on consent-filtered datasets. Segmentation models — RFM analysis, churn prediction, next-best-offer — are trained only on records where the relevant consent is active. When a member of a Select CITYWALK loyalty programme withdraws consent for marketing use, the system does not just stop sending them emails: it re-trains the relevant models excluding that member's records, ensuring that their data does not continue to influence personalisation decisions even indirectly. This is the gold standard of DPDP compliance in AI systems — and it is what separates genuinely compliant AI loyalty analytics India needs from superficially compliant one that just adds a consent checkbox to an unchanged data pipeline.

Finally, the rights management layer must be API-first: when a Data Principal submits an erasure request, the system must cascade that deletion across the data lake, the feature store, the CRM, the campaign management tool (whether MoEngage, WebEngage, or a custom stack), and any partner systems receiving data feeds — all within the Act's prescribed response window. This requires pre-built integration contracts with every downstream system that touches member data, something that needs to be designed into the architecture before go-live, not bolted on after a Data Protection Board complaint.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

5-Step Playbook: Implementing DPDP Compliant Loyalty Analytics

01

Conduct a Data Flow Audit Specific to Your Loyalty Stack

Map every data element your loyalty programme collects — enrolment data, transaction records, location signals, app behaviour, partner brand data shares — against DPDP's data categories and processing obligations. Use your POS provider's API documentation (Wondersoft, GoFrugal, POSist, Petpooja) to identify all data egress points. Most operators discover 3-5 undocumented data flows in this step alone.

02

Redesign Consent Architecture with Granular, Purpose-Specific Flows

Replace your current single-consent sign-up flow with a granular consent journey that separates at minimum: points accumulation data use, marketing communications, third-party partner sharing, and AI-based personalisation. Each must have an independent opt-in and must be withdrawable independently. Build this into your loyalty app, in-store kiosk, and WhatsApp onboarding flows simultaneously.

03

Implement a Consent-Aware Data Pipeline

Integrate your CMP with your data lake and CRM so that every member record carries a live consent vector. When consent is granted, updated, or withdrawn, the change must propagate to all downstream systems within a defined SLA — ideally under 4 hours for revocations. Test this pipeline with synthetic data before going live with member records.

04

Deploy AI Models on Consent-Scoped Training Datasets

Re-train your segmentation, churn, and personalisation models on consent-filtered datasets. Document the training data scope in your model cards — this creates an audit-ready record that demonstrates to the Data Protection Board that your AI systems respect purpose limitation. Use differential privacy techniques for any cohort-level insights shared with brand partners or mall anchor tenants.

05

Build Self-Service Data Principal Rights Workflows

Launch a member-facing rights portal — accessible via your loyalty app and website — where members can view their data, request corrections, and submit erasure requests. Wire this portal to automated fulfilment workflows that cascade requests to all integrated systems within your prescribed SLA. Log every rights request and its fulfilment status in an auditable record.

KPIs to Track for DPDP Compliant Loyalty Analytics Performance

Compliance without commercial measurement creates a programme that is legally safe but commercially blind. The goal of DPDP compliant loyalty analytics is not to shrink your data asset — it is to build a higher-quality, fully consented data asset that drives better commercial outcomes. The KPIs you track must reflect both dimensions: compliance health and commercial performance.

On the compliance side, the primary metrics are: consent capture rate at enrolment (target: above 85% for core transaction data consent), consent refresh rate on existing members (target: 70%+ refreshed to new DPDP-aligned consent flows within 6 months of go-live), data rights fulfilment SLA adherence (target: 100% of access and erasure requests fulfilled within prescribed window), data breach detection-to-notification time (target: under 48 hours for significant breaches), and third-party data-sharing audit pass rate (target: 100% of partner data flows covered by active, specific secondary consent).

On the commercial side, the headline metric is consented member engagement rate — the percentage of your fully consented member base that transacts, redeems, or engages with a personalised offer in a rolling 90-day window. For Indian retail loyalty programmes at scale, a healthy consented engagement rate sits between 28% and 42% depending on category: grocery and pharmacy programmes (Apollo Pharmacy, Reliance Smart) tend to run higher because purchase frequency is higher; fashion (Pantaloons, Lifestyle) and jewellery (Tanishq) run lower but with higher per-engagement revenue. AI loyalty analytics India benchmarks from Fundle's managed programmes show that consent-first members — those who have actively affirmed their consent preferences — transact at 1.8x the frequency of passively enrolled members.

Revenue per consented member (RPCM) is a more commercially meaningful metric than traditional revenue per member, because it strips out the zombie segment — members enrolled years ago with stale or legally questionable consent — and focuses commercial energy on the active, consented, high-LTV cohort. Indian mall operators tracking RPCM on their Fundle-managed programmes report RPCM figures between ₹8,500 and ₹22,000 annually depending on mall tier and catchment. A 10% improvement in RPCM through better AI-driven personalisation within a consented cohort is worth far more than a 30% larger member base built on legally fragile data.

DPDP Loyalty Analytics Readiness Checklist for Indian Retail Operators
  • Audit all loyalty data collection points (POS, app, kiosk, WhatsApp) and document every data element collected against DPDP's personal data categories
  • Replace single-blanket consent flows with granular, purpose-specific consent architecture covering at minimum 4 distinct purposes: rewards, marketing, AI personalisation, and partner sharing
  • Implement an immutable, auditable consent ledger integrated with your data lake, CRM, and campaign tools so consent scope travels with every member record
  • Re-train all segmentation and personalisation AI models on consent-scoped datasets and document training scope in model cards for DPB audit readiness
  • Deploy a member-facing self-service rights portal with automated fulfilment workflows for access, correction, and erasure requests within prescribed SLA windows
  • Establish AI-driven breach detection and a documented DPB notification workflow targeting sub-48-hour detection-to-notification time for significant breaches
  • Define and track DPDP-specific commercial KPIs — consented member engagement rate, revenue per consented member — alongside standard loyalty programme metrics
“In Indian retail, the brands that will win the next decade are those that earn data permission, not those that extract it. Consent is not a compliance cost — it is a competitive moat.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

The Fundle AI Platform was architected from its founding with a consent-first, privacy-by-design philosophy — not because DPDP was inevitable, but because Vineet Narang's founding conviction was that sustainable loyalty is built on trusted data relationships, not surveillance. That conviction now turns out to be a significant commercial advantage as DPDP enforcement approaches.

At the core of Fundle's compliance stack is ConsentFirst — Fundle's proprietary DPDP-aligned consent management platform. ConsentFirst captures granular, purpose-specific consent at every loyalty touchpoint, stores consent records in an append-only ledger, and propagates consent vectors in real time to every downstream system in the Fundle AI Platform: the data lake, the AI segmentation engine, the campaign orchestration layer, and partner data-sharing APIs. Fundle manages compliance for 123+ malls with AI-driven analytics integrated with ConsentFirst — making it the most widely deployed DPDP-aligned loyalty analytics infrastructure in Indian mall retail today.

Fundle Mall Loyalty uses ConsentFirst as its compliance backbone, enabling mall operators running programmes across dozens of anchor tenants and hundreds of inline stores to maintain a single, auditable consent record per member that governs data use across the entire mall ecosystem. When a member at Phoenix Marketcity updates their consent preferences on the Fundle-powered loyalty app, those changes cascade within minutes to every brand tenant's data feed, every AI personalisation model, and every campaign queue — without manual intervention. This is Fundle Agentic AI at work: autonomous AI agents that execute consent propagation workflows end-to-end, on real-time triggers, without human bottlenecks.

For standalone retail brands — whether a Manyavar franchise network or a regional pharmacy chain — Fundle Brand Loyalty delivers the same consent-first architecture in a brand-level deployment. Fundle AI Workflow handles the orchestration of rights fulfilment requests: when a Data Principal submits an erasure request, Fundle AI Workflow spawns a cascade of automated tasks that delete or anonymise the relevant records across the POS integration (Wondersoft, GoFrugal, POSist, Petpooja), the CRM, the analytics data lake, and any active campaign audiences — logging every step in an audit trail that can be produced to the Data Protection Board on demand. Fundle AI Agents monitor the compliance health of each programme continuously, surfacing alerts when consent capture rates drop, when data retention policies are breached, or when a new data flow is detected that lacks a consent mapping. This is DPDP compliant loyalty analytics delivered not as a consulting engagement but as a running AI system — always on, always auditable, commercially sharpened rather than commercially blunted.

Frequently asked

Does the DPDP Act 2023 apply to loyalty programmes run by Indian retailers?+

Yes, without question. Any entity processing personal data of Indian citizens for commercial purposes is a Data Fiduciary under the Act. Loyalty programmes collect name, mobile, transaction history, location, and behavioural data — all of which are personal data under DPDP. Retailers operating loyalty programmes must comply fully when the Act's enforcement rules come into force.

What is the maximum penalty a retailer can face for DPDP non-compliance in its loyalty programme?+

The DPDP Act 2023 specifies penalties up to ₹250 crore per instance of significant non-compliance, with a cumulative ceiling of ₹500 crore. For context, a systemic failure in consent management — for example, using member data for purposes beyond what was consented to — could qualify as a single significant violation attracting the full ₹250 crore penalty.

How does AI help with DPDP compliance in loyalty analytics rather than creating more risk?+

When designed correctly, AI reduces compliance risk by automating consent signal propagation, enforcing data minimisation at the pipeline level, detecting breaches faster than human monitoring can, and enabling personalisation depth on smaller, fully consented datasets through techniques like differential privacy and federated learning. The risk comes from poorly architected AI systems that treat consent as an afterthought — which is what Fundle's ConsentFirst platform is specifically designed to prevent.

What is ConsentFirst and how does it differ from a standard cookie consent banner?+

ConsentFirst is Fundle's purpose-built DPDP-aligned consent management platform for loyalty programmes. Unlike a cookie consent banner — which addresses only web tracking — ConsentFirst manages consent across every loyalty touchpoint: POS, mobile app, WhatsApp, kiosk, and partner brand integrations. It stores consent in an immutable ledger, propagates consent vectors to all downstream analytics and campaign systems, and supports automated Data Principal rights fulfilment workflows.

Can a retailer continue running AI personalisation for members who have partially withdrawn consent?+

Yes, but only within the scope of their remaining active consent. If a member withdraws consent for marketing communications but retains consent for rewards processing, the retailer may continue to process transaction data for points calculation but must exclude that member from marketing campaign audiences and must ensure their records are excluded from any AI model training that feeds marketing personalisation. Fundle's consent-scoped model training architecture handles this automatically.

How long does it take to migrate an existing loyalty programme to a DPDP-compliant architecture?+

For a mid-sized retail chain with an existing loyalty programme, a realistic migration timeline is 4-6 months: 4-6 weeks for data flow auditing, 6-8 weeks for consent architecture redesign and CMP integration, 6-8 weeks for data pipeline restructuring and model retraining, and 2-4 weeks for member-facing rights portal launch and testing. Fundle's managed implementation approach has delivered full DPDP-aligned programme migrations in as few as 14 weeks for single-brand deployments.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?