“Loyalty in India was never about points — it was about putting first-party retail data back in the hands of the brand and the mall.”
- •Understand how DPDP 2023 mandates explicit, purpose-specific consent before any loyalty data collection or automation trigger fires
- •Recognise that legacy loyalty stacks — point engines bolted onto bulk SMS platforms — are structurally non-compliant and expose operators to penalties up to ₹250 crore per instance
- •Adopt a ConsentFirst architecture where consent status is a live data attribute that gates every workflow step, not a checkbox ticked at sign-up
- •Benchmark your program against the five operational pillars: lawful basis, purpose limitation, data minimisation, grievance redressal, and cross-border transfer controls
- •Implement Fundle's DPDP compliant loyalty automation stack to automate compliance without slowing down campaign velocity
On 11 August 2023, the Digital Personal Data Protection Act received Presidential assent, ending nearly a decade of India's data privacy limbo. For mall operators running multi-brand loyalty programs across properties like Phoenix Marketcity or Select CITYWALK, and for retail CMOs at chains like Lifestyle, Pantaloons, Reliance Trends, and Manyavar, the Act is not a distant regulatory abstraction — it is an operational constraint that sits right inside the loyalty workflow engine.
The loyalty industry in India has, until now, operated on an implicit consent model. A customer hands over a mobile number at the Tanishq counter, gets enrolled in a points program, and within 48 hours receives WhatsApp messages, SMS blasts, and app push notifications — often without any documented record of what they consented to, for which purpose, and for how long. At scale, across a 200-brand mall ecosystem processing 50,000 daily footfalls, that informal model is now a liability with a ₹250 crore price tag attached to it per non-compliance instance.
DPDP 2023 introduces five obligations that directly intersect with loyalty workflow automation: lawful basis for processing, purpose limitation, data minimisation, the right to withdraw consent, and grievance redressal timelines. None of these are checkbox exercises. Each requires re-engineering how loyalty platforms collect, store, segment, trigger, and retire personal data. The challenge is doing this without adding friction to the enrolment funnel or hobbling the campaign automation that drives repeat visit revenue.
Fundle was built with this inflection point in mind. Before DPDP became enforceable law, the Fundle AI Platform was designed around a consent-first data architecture — meaning consent status is not a field in a CRM record but a live gate that every automated workflow queries before execution. This article is a practitioner's guide for mall CMOs and loyalty program managers who need to move from conceptual awareness of DPDP to operational compliance inside their loyalty stack, without dismantling the automation infrastructure they have spent years building.
Indian Retail Loyalty & DPDP: The Numbers That Frame the Urgency
Overview of DPDP 2023 Compliance Requirements for Loyalty Programs
The Digital Personal Data Protection Act 2023 is structured around the concept of a Data Fiduciary — the entity that determines the purpose and means of processing personal data. In a mall loyalty context, the mall operator or the anchor brand running the program is the Data Fiduciary. Every technology vendor — whether it is a POS system like POSist or Petpooja, a loyalty engine like Capillary or EasyRewardz, or a campaign platform like MoEngage or WebEngage — becomes a Data Processor operating under the Fiduciary's instructions.
This distinction matters enormously for liability. If a loyalty workflow automation rule fires a WhatsApp campaign to a member who has withdrawn consent, the legal exposure sits with the mall or retail brand, not the SaaS vendor. Operators cannot outsource compliance to their tech stack; they must own it.
The five DPDP obligations that loyalty teams must operationalise are precise. First, lawful basis: every personal data point — mobile number, purchase history, location, browsing behaviour on a mall app — must have a documented lawful basis, almost always explicit consent for loyalty programs since there is no other applicable ground. Second, purpose limitation: consent obtained for points accrual cannot be reused to run third-party brand surveys or sell data to advertising networks without fresh consent. Third, data minimisation: collecting date of birth, anniversary dates, and household income for a parking loyalty program is indefensible. Fourth, right to withdraw: members must be able to withdraw consent as easily as they gave it, and withdrawal must propagate to every downstream workflow within a defined window — the draft rules suggest 72 hours. Fifth, grievance redressal: a named Data Protection Officer and a working grievance mechanism must exist, not a dead email alias.
For loyalty workflow automation specifically, the implication is that every automation trigger — birthday offer, lapsed-member win-back, tier upgrade notification, cross-brand upsell — must first query: does this member have active, unexpired, purpose-specific consent for this communication channel and this campaign type? If the answer is no, the workflow must suppress, log the suppression, and route to a re-consent journey rather than firing anyway. Legacy systems that run a single consent flag at enrolment and never revisit it are structurally non-compliant under this framework.
The DPDP Compliance Funnel for Loyalty Workflow Automation
Importance of Data Privacy in Loyalty Workflows: Beyond Regulatory Risk
Compliance is the floor, not the ceiling. The more commercially interesting argument for DPDP-aligned loyalty workflow automation is what it does to campaign performance and member trust when you get it right.
Consider how bulk SMS campaigns work today at a mid-sized mall chain with 8–10 lakh enrolled members. The campaign manager runs a query, exports a list, uploads it to an SMS aggregator, and fires. Open rates hover around 4–6%. Conversion to footfall is unmeasurable because there is no attribution loop. Members who receive irrelevant messages — a Manyavar bridal offer sent to a 22-year-old male who has only ever purchased from the food court — develop notification fatigue and opt out, permanently. Opt-out rates in undifferentiated Indian loyalty programs run at 18–22% annually, meaning a program is destroying nearly a fifth of its engaged base every year through noise.
A consent-first, purpose-limited data architecture forces segmentation discipline. When you can only communicate with members who have consented to a specific purpose — say, promotions from fashion brands in the mall — you are automatically working with a cleaner, higher-intent audience. Campaigns sent to this cohort at Apollo Pharmacy, for example, consistently show redemption rates 2.4x higher than blanket promotional blasts, because the audience self-selected for relevance.
There is also a first-party data quality argument. When members understand exactly what they are consenting to and experience communications that match that consent, trust scores rise. In Fundle's platform data across mall loyalty programs, members who completed a structured ConsentFirst consent flow showed 31% higher 90-day retention rates than members enrolled via a quick POS swipe. Higher retention directly compounds lifetime value — and in Indian mall retail where average customer acquisition costs via digital advertising have crossed ₹180–₹220 per net new member, retention is the only economically rational strategy.
Finally, investor and institutional scrutiny is sharpening. Mall REITs, PE-backed retail groups, and foreign retail JV partners are beginning to include data governance diligence in their operational audits. A loyalty program running on unlawful data processing is a balance-sheet risk, not just a regulatory inconvenience. CMOs who front-run compliance are protecting enterprise value, not just avoiding fines.
DPDP Compliant Loyalty Automation vs. Legacy Loyalty Stack: Operational Reality
Features of ConsentFirst: India's DPDP Compliant CMP Built for Loyalty
Fundle's ConsentFirst is India's only DPDP-compliant consent management platform, safeguarding 1.33Cr+ user data privacy. That headline figure is not a marketing claim — it reflects the operational scale at which ConsentFirst has been deployed across mall loyalty programs and enterprise retail brand programs in India, managing live consent records that gate real-time automation workflows.
ConsentFirst operates on four architectural principles that distinguish it from generic international CMPs like OneTrust or Cookiebot, which were built for web cookie compliance and retrofitted for broader data use cases. First, it is purpose-graph native: rather than a binary consent-or-not model, ConsentFirst maps consent to a structured purpose graph. A member can consent to points-accrual communications, decline third-party brand offers, and accept birthday personalisation — all as separate, independently revocable consent nodes. This granularity is what DPDP's purpose limitation obligation actually demands.
Second, ConsentFirst is channel-aware. In Indian retail, the same member may interact across WhatsApp, SMS, a mall app, an in-store kiosk, and a brand's own app. Each channel is a distinct consent scope. ConsentFirst maintains a unified consent ledger that each channel reads before any communication is dispatched, eliminating the common failure mode where a member opts out of SMS but continues receiving WhatsApp messages because the two systems never synced.
Third, ConsentFirst includes a re-consent orchestration engine. When a member's consent expires — the platform supports configurable consent validity windows aligned to DPDP draft rules — or when a new processing purpose is introduced, ConsentFirst automatically triggers a re-consent journey via the lowest-friction channel the member has active consent for. This keeps the enrolled base actionable without requiring manual campaign manager intervention.
Fourth, ConsentFirst generates a real-time compliance dashboard for the DPO and CMO: consent coverage rate by member segment, suppression volume by campaign, withdrawal velocity trends, and grievance resolution SLA performance. For a mall CMO presenting to a REIT board or a retail brand reporting to a foreign JV partner, this dashboard is the audit artefact that demonstrates operational compliance — not a policy document, but live operational data.
Integration with existing loyalty stacks is handled via pre-built connectors for common Indian retail POS and loyalty platforms. Operators running Wondersoft or GoFrugal at POS, and Capillary or EasyRewardz as their loyalty engine, can connect ConsentFirst without rebuilding their tech stack — it sits as a consent orchestration layer that all other systems call before processing member data.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
Practical Steps to Achieve DPDP Compliance in Your Loyalty Program
Audit Your Current Consent Records
Map every member record in your loyalty database against its consent documentation. Identify records with no digital consent trail — typically POS-enrolled members — and classify them as consent-deficient. This cohort cannot be legally marketed to under DPDP without remediation. In most Indian mall programs, this cohort represents 50–70% of the enrolled base.
Define Your Purpose Graph
Work with your legal and loyalty teams to define the specific processing purposes your program requires: points accrual, personalised offers, third-party brand communications, analytics, cross-brand profiling. Each purpose needs a plain-language description that a member can genuinely understand and that maps to a specific data type and retention period.
Deploy ConsentFirst as Your Consent Orchestration Layer
Integrate Fundle's ConsentFirst CMP between your member-facing channels — app, kiosk, WhatsApp bot, web portal — and your loyalty engine and campaign automation platform. Configure consent validity windows, re-consent triggers, and suppression rules. Run a parallel operation period of 30 days to validate that suppression is working correctly before switching off legacy consent logic.
Run a Re-Consent Campaign for Existing Members
For the consent-deficient cohort, design a re-consent journey with a clear value exchange: explain what you are asking permission for, what the member gets in return (bonus points, exclusive access), and how they can manage their preferences. Expect 35–55% re-consent rates with a well-designed journey; the members who do not re-consent must be suppressed from marketing workflows immediately.
Operationalise Grievance Redressal and DPO Workflows
Appoint a named Data Protection Officer with a working intake mechanism — not a shared email, but a ticketed workflow with SLA enforcement. ConsentFirst's compliance dashboard automates the routing and tracking of member grievances, consent withdrawal requests, and data access requests. Review DPO performance metrics monthly alongside standard loyalty KPIs in your CMO reporting pack.
KPIs to Track DPDP Compliant Loyalty Automation Performance
Compliance without measurement is aspiration. Mall CMOs and loyalty program managers need a KPI framework that treats data privacy compliance as an operational metric sitting alongside redemption rate, visit frequency, and Net Promoter Score — not as a separate legal reporting exercise.
The primary compliance KPI is consent coverage rate: the percentage of your active loyalty member base with a valid, purpose-specific, digital consent record. A program that is genuinely DPDP-compliant should target 90%+ consent coverage among members contacted in any rolling 90-day period. Programs running below 60% are in material non-compliance territory and should pause outbound automation on non-covered segments immediately.
The second KPI is suppression rate by campaign: the percentage of members in a target segment who were suppressed at the consent gate before a campaign was dispatched. A high suppression rate is not a failure — it is evidence that the compliance layer is working. However, a persistently high suppression rate (above 40% on a core loyalty segment) signals that re-consent campaigns are underperforming and the actionable member base is shrinking, which requires a commercial response alongside the compliance response.
Third, track consent withdrawal velocity: the week-on-week rate at which members are withdrawing consent. A spike in withdrawal velocity is an early warning signal — it typically indicates either a poorly received campaign that prompted members to reassess their consent, or a negative brand event. Loyalty teams at FabIndia or Cafe Coffee Day, for example, should be monitoring this the same week a controversial campaign runs, not quarterly.
Fourth, grievance resolution SLA compliance: the percentage of data subject requests — access, correction, erasure, withdrawal — resolved within the regulatory window. DPDP draft rules indicate a 30-day response window for most requests. Programmes below 95% SLA compliance are exposed to regulatory scrutiny in any audit.
Fifth, re-consent conversion rate: the percentage of consent-deficient members who complete a re-consent journey and become actionable again. This is ultimately a revenue recovery metric — each re-consented member represents recovered campaign reach and potential repeat purchase revenue. Benchmarks from Fundle platform deployments show ₹420–₹680 in incremental annual spend per re-consented member in apparel and lifestyle retail categories.
- Conduct a full consent audit of your loyalty member database and classify records by consent documentation status before the next campaign run
- Define and document a purpose graph covering all processing activities in your loyalty program, reviewed and signed off by legal counsel
- Appoint a named Data Protection Officer with a live grievance intake workflow — not a shared email alias — and publish their contact details to members
- Deploy a DPDP-aligned consent management platform that maintains granular, purpose-specific, channel-aware consent records with full audit trail
- Configure automation suppression rules so that every workflow trigger queries live consent status before dispatching any communication
- Design and execute a structured re-consent campaign for consent-deficient members with a clear value exchange and a documented suppression plan for non-respondents
- Add consent coverage rate, suppression rate, withdrawal velocity, and grievance SLA compliance to your monthly CMO loyalty reporting dashboard
“In Indian retail, consent is not a legal formality — it is the new currency. The brands that earn it transparently will own the most valuable first-party data assets in the country.”
How Fundle Solves This
The Fundle AI Platform was architected from day one around the principle that personalisation and privacy are not in tension — they are, when designed correctly, mutually reinforcing. Vineet Narang's founding thesis was that Indian retail's next competitive moat would not be built on who has the most data, but on who has the most trusted data: first-party, consent-verified, purpose-limited, and therefore legally actionable at scale.
Fundle Mall Loyalty and Fundle Brand Loyalty both ship with ConsentFirst embedded as the default consent orchestration layer, not as an optional add-on. This means that from the moment a shopper enrols in a mall program at Phoenix Marketcity or a brand program at Lenskart, every data point collected is mapped to a consent node in the purpose graph, every downstream automation workflow is gated by live consent status, and every withdrawal or expiry event propagates automatically across all connected channels and workflow engines.
Fundle AI Agents handle the re-consent journey autonomously. When a member's consent expires or a new processing purpose is introduced, a Fundle AI Agent identifies the optimal re-consent channel, drafts a personalised re-consent message with a contextually relevant value offer, schedules it for the highest-engagement time window for that member, and routes the response back into the consent ledger — without any manual campaign manager intervention. This is what Fundle Agentic AI means in practice: compliance workflows that run at the speed of automation, not at the speed of a stretched loyalty team.
Fundle AI Workflow handles the suppression and grievance routing logic. Every workflow step — birthday offer, tier upgrade, win-back, cross-brand upsell — includes a pre-execution consent check node that is configured once and fires automatically across every campaign. Suppression events are logged to an immutable audit ledger that can be exported for any regulatory or internal audit. Grievance requests from members flow into a structured DPO dashboard with SLA timers, automated acknowledgement messages, and escalation paths if the resolution window approaches breach.
For operators currently running on Capillary, EasyRewardz, Xeno, or Almonds.ai as their primary loyalty engine, Fundle's ConsentFirst integrates via API without requiring a full platform migration. The Fundle AI Platform can function as the consent and compliance orchestration layer on top of an existing loyalty stack, de-risking the compliance gap without forcing a technology overhaul. For operators ready for a full-stack upgrade, Fundle Mall Loyalty delivers end-to-end loyalty workflow automation India-ready, with DPDP compliance built into every layer from POS enrolment to campaign dispatch to data retirement.
Frequently asked
What does DPDP 2023 specifically require from loyalty programs in India?+
DPDP 2023 requires loyalty programs to obtain explicit, purpose-specific consent before collecting or processing any personal data. Programs must document the lawful basis for each processing activity, limit data use to the stated purpose, allow members to withdraw consent easily, and resolve data subject grievances within defined timelines. Non-compliance can attract penalties up to ₹250 crore per instance.
What is ConsentFirst and how is it different from international CMPs like OneTrust?+
ConsentFirst is Fundle's DPDP-compliant consent management platform built specifically for Indian retail loyalty programs. Unlike OneTrust or Cookiebot, which were designed for web cookie compliance, ConsentFirst is purpose-graph native and channel-aware — meaning it manages granular, independently revocable consent nodes across SMS, WhatsApp, app push, email, and kiosk channels, and integrates directly into loyalty workflow automation triggers.
How should a mall loyalty team handle existing members who were enrolled without a documented digital consent record?+
Members enrolled without a documented digital consent record — typically via POS swipe — are consent-deficient under DPDP and cannot legally be targeted by outbound marketing automation. The correct approach is to suppress them from all campaigns immediately and run a structured re-consent journey with a clear value exchange. Expect 35–55% re-consent rates with a well-designed campaign. Non-respondents must remain suppressed.
Can Fundle's ConsentFirst integrate with our existing loyalty platform like Capillary or EasyRewardz?+
Yes. ConsentFirst integrates via API with major Indian loyalty platforms including Capillary, EasyRewardz, and others, as well as POS systems like POSist, GoFrugal, and Wondersoft. It operates as a consent orchestration layer that all other systems query before processing member data, meaning operators do not need to rebuild their loyalty stack to achieve DPDP compliance.
What KPIs should a loyalty program manager track to measure DPDP compliance operationally?+
The five core compliance KPIs are: consent coverage rate (target 90%+ for actively contacted members), suppression rate by campaign, consent withdrawal velocity (week-on-week trend), grievance resolution SLA compliance (target 95%+ within the 30-day regulatory window), and re-consent conversion rate for consent-deficient member recovery campaigns. These should sit in the standard monthly CMO reporting pack alongside commercial loyalty metrics.
What is the financial risk of running a non-compliant loyalty program under DPDP?+
The direct regulatory risk is a penalty of up to ₹250 crore per non-compliance instance — for example, a data breach or a bulk campaign sent to members without valid consent. The indirect risks include reputational damage that accelerates opt-outs, loss of institutional investor confidence for REIT-listed mall operators, and disqualification from foreign retail JV partnerships that include data governance due diligence. The commercial cost of non-compliance compounds over time as the enrolled base erodes through mass opt-outs driven by irrelevant communications.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
