“First-party data isn't a sticker on your homepage. It's a daily discipline — capture, reconcile, model, activate. Fundle is the discipline, productised.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand how DPDP 2023 fundamentally changes consent, data storage, and grievance redressal for loyalty programs
  • Identify the five platform features that separate compliant loyalty stacks from legally exposed ones
  • Benchmark your current loyalty data architecture against a DPDP-ready standard
  • Recognize the real cost of non-compliance: penalties up to ₹250 crore per violation under the Act
  • Adopt a phased 90-day implementation playbook to achieve full DPDP readiness without killing campaign velocity

India's retail loyalty landscape sits at an inflection point. For two decades, mall operators like Phoenix Marketcity and Select CITYWALK, along with enterprise brands from Tanishq to Pantaloons, have built their customer engagement engines on transactional data collected with minimal friction and even less explicit consent. A shopper's phone number, purchase history, and home pin code flowed freely into CRM systems, campaign tools, and third-party enrichment databases — often with nothing more than a checkbox buried in fine print at the billing counter.

That era is over. The Digital Personal Data Protection Act 2023 (DPDP Act) received Presidential assent in August 2023 and is moving toward full enforcement. It is India's most consequential privacy legislation since the IT Act, and it lands directly in the middle of every loyalty program, every points redemption flow, and every personalisation engine that Indian retail currently operates. Unlike GDPR, which felt distant to most Indian operators, DPDP is domestic, enforceable, and carries penalties of up to ₹250 crore per instance of breach or non-compliance. The Data Protection Board of India will have teeth.

For a CMO at a multi-brand retailer running 3–5 million loyalty members, or a CIO overseeing the POS and data infrastructure across 400 stores, the question is not whether DPDP applies to you — it does — but whether your current loyalty data platform can handle the consent architecture, data minimisation obligations, purpose limitation rules, and grievance redressal timelines the Act demands. Most legacy platforms cannot. Point-solution CRMs bolted onto POS systems like POSist, GoFrugal, or Wondersoft were never designed with a Data Fiduciary model in mind. Competitive loyalty vendors including Capillary, EasyRewardz, and Xeno are only now beginning to publish their compliance roadmaps.

This is precisely the gap that a purpose-built DPDP compliant loyalty data platform must fill. Fundle was designed from the ground up as a consent-first, AI-native engagement platform for Indian retail — malls, mono-brand retailers, and multi-brand enterprise operators alike. This article is a practitioner's guide: what DPDP actually demands of your loyalty stack, what good compliance looks like in practice, and what you need to implement before the enforcement clock runs out.

India Loyalty & DPDP: The Numbers That Frame the Stakes

₹250 Cr
Maximum penalty per DPDP violation for significant data fiduciaries — enough to wipe out a mid-size retailer's annual EBITDA
72%
Share of Indian loyalty program members who say they would stop sharing data if they didn't understand how it was being used (KPMG India, 2023)
270+
Brands whose data privacy is secured by Fundle's ConsentFirst CMP, which is fully DPDP compliant
₹1,200 Cr
Estimated annual revenue at risk across India's top 50 mall operators if loyalty data practices are found non-compliant and programs are suspended

Overview of DPDP 2023 and Its Implications for Retail Loyalty

The Digital Personal Data Protection Act 2023 is built on six foundational obligations that every Data Fiduciary — which includes any retailer or mall operator that determines the purpose and means of processing personal data — must meet. These are: lawful purpose with valid consent, purpose limitation, data minimisation, accuracy, storage limitation, and accountability. For loyalty programs, each of these bites in a specific and operationally significant way.

Consent under DPDP must be free, specific, informed, unconditional, and unambiguous. That means the consent checkbox at the Reliance Trends billing counter that says 'I agree to receive offers' is not sufficient. Consent must be granular: a customer must be able to consent separately to their transaction data being used for points calculation, to their behavioural data being used for personalised offers, and to their contact details being shared with third-party brand partners within a mall ecosystem. Each of these is a distinct purpose, and each requires a distinct consent signal — collected, stored, and auditable.

Purpose limitation means that data collected for loyalty points redemption cannot be repurposed for, say, credit scoring or insurance upsell without fresh consent. This has immediate implications for retailers like Apollo Pharmacy, which may want to use purchase data to recommend health products, or for FabIndia, which might want to cross-sell across its food and fashion verticals. Every new use case is a new consent event. Storage limitation means you cannot keep a churned loyalty member's data indefinitely — the Act contemplates defined retention periods tied to the stated purpose, after which data must be purged or anonymised. For a brand running a 10-year-old loyalty database with millions of dormant records, this is a significant data hygiene challenge.

The grievance redressal clause is often overlooked but operationally demanding: a Data Fiduciary must acknowledge a data principal's complaint within 48 hours and resolve it within a defined timeline. For a mall loyalty program with 500,000 members, this means your platform must have a member-facing portal or in-app mechanism where customers can view their data, correct it, withdraw consent, or request erasure — and your backend must action those requests automatically, not through a manual support ticket. The Act also introduces the concept of 'consent managers' — entities that can aggregate and manage consent on behalf of data principals — which creates a potential new infrastructure layer between your loyalty platform and your customers.

DPDP Compliance Funnel: From Data Collection to Audit-Ready Loyalty

Consent Capture (Granular, Purpose-Specific) — Gate 1Data Minimisation & Classification — Gate 2Purpose Binding & Usage Controls — Gate 3Retention Policy Enforcement & Auto-Purge — Gate 4
Every loyalty interaction must pass through five compliance gates before it can drive a campaign or personalisation event. Platforms that skip a gate create legal exposure at scale.

Why DPDP Compliance Is Non-Negotiable for Loyalty Platforms in India Right Now

Indian retail leadership has a historical habit of treating compliance as a legal department problem, not a technology or marketing problem. DPDP breaks that pattern completely. The Act creates direct liability for the Data Fiduciary — the brand or mall operator — not just for the technology vendor processing the data. If your loyalty platform collects and processes customer data on your behalf, and that platform is not DPDP compliant, you are the one facing the ₹250 crore penalty exposure, not Capillary or EasyRewardz.

The enforcement timeline matters. While the DPDP Act received Presidential assent in August 2023, the rules and the establishment of the Data Protection Board are expected to be finalised in 2024–2025. Most large retailers and mall operators will be classified as Significant Data Fiduciaries — a designation that triggers additional obligations including Data Protection Impact Assessments, the appointment of a Data Protection Officer, and periodic audits. The Ministry of Electronics and IT has signalled that the government will move quickly once the rules are notified. Brands that wait for enforcement to begin before building compliance infrastructure will be scrambling.

The commercial case for compliance is equally strong. Consider the data: 72% of Indian loyalty members say they would stop sharing data if they didn't understand its use. That is not a fringe concern — it is a majority sentiment that directly threatens the data acquisition engine of every loyalty program in the country. Brands like Manyavar, Cafe Coffee Day, and Lenskart that build visible, member-facing consent controls will earn a trust premium that translates into higher opt-in rates, richer data, and better campaign performance. Privacy-first loyalty is not a compliance tax; it is a competitive differentiator.

There is also the question of data quality. Loyalty databases built without consent architecture are filled with stale, inaccurate, or duplicated records. A DPDP-compliant platform that enforces data minimisation and regular consent refresh cycles will, by design, maintain cleaner, higher-intent member data. Campaigns sent to consented, recently verified members consistently outperform bulk blasts to legacy databases — open rates on consented WhatsApp campaigns in Indian retail average 45–60% versus 8–12% for unconsentented email blasts. The compliance work pays for itself in campaign ROI within two quarters.

Legacy Loyalty Platform vs. DPDP Compliant Loyalty Data Platform

Legacy / Non-Compliant Platform
DPDP Compliant Loyalty Data Platform
Single blanket consent at enrolment, never refreshed
Granular, purpose-specific consent captured, stored, and refreshed at defined intervals
Data retained indefinitely; no auto-purge for dormant members
Retention policies enforced per data category; automated purge workflows for churned or consent-withdrawn members
No member-facing data rights portal; erasure requests handled manually via support team
Self-service member portal: view, correct, withdraw consent, request erasure — all within DPDP timelines
Data shared with third-party brand partners or analytics vendors without member awareness
Third-party data sharing requires explicit, auditable consent; consent log available for regulatory audit
Compliance is a legal afterthought; no Data Protection Officer integration or DPIA workflow
Built-in DPIA templates, DPO dashboard, grievance redressal ticketing with 48-hour SLA enforcement

Features That Define a Best-in-Class DPDP Compliant Loyalty Data Platform

Not all 'DPDP-ready' claims are equal. As vendors across the competitive set — from MoEngage and WebEngage on the marketing automation side to Customer Capital and Almonds.ai on the loyalty side — begin adding compliance features to their roadmaps, Indian retail leaders need a precise feature checklist to evaluate readiness. There are five categories of capability that separate a genuinely compliant platform from one that has simply added a consent checkbox to its enrolment form.

First is the Consent Management Platform (CMP) layer. This is not a simple opt-in toggle. A purpose-grade CMP must support multi-purpose consent taxonomy — points accrual, personalised offers, third-party sharing, cross-brand targeting within a mall ecosystem, and marketing communications across channels (SMS, WhatsApp, email, push) must each be independently consented. The CMP must generate a tamper-evident consent log with timestamps, channel of collection, version of privacy notice shown, and the specific purposes accepted. This log is what you present to the Data Protection Board in an audit.

Second is data minimisation and classification. The platform must know what data it holds, categorise it by sensitivity (contact data, transaction data, behavioural data, inferred data), and enforce collection rules that prevent fields from being captured unless they are necessary for the stated purpose. A mall loyalty program does not need a member's date of birth to calculate points on a ₹2,000 apparel purchase at Lifestyle — and a compliant platform will enforce that boundary by design, not by policy memo.

Third is automated rights fulfilment. When a member of a Pantaloons loyalty program submits a data erasure request through the app, the platform must automatically propagate that erasure across every connected system — the POS integration, the campaign tool, the analytics warehouse, and any third-party brand partners — within the Act's prescribed timeline. Manual processes cannot scale to handle this at 500,000-member volumes.

Fourth is purpose binding in the campaign engine. Before any campaign brief can be activated — a birthday offer, a win-back sequence, a cross-sell push — the platform must validate that every member in the target segment has provided valid, current consent for that specific purpose. If consent has lapsed or been withdrawn, those members must be automatically excluded without the campaign manager needing to manually filter. Fifth is a DPO and audit dashboard: a real-time view of consent coverage rates, pending rights requests, data retention compliance, and breach notification readiness — the kind of operational intelligence that a CIO needs to maintain ongoing compliance, not just pass a point-in-time audit.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

90-Day Playbook: Achieving DPDP Compliance for Your Loyalty Data Platform

01

Days 1–15: Data Inventory and Gap Assessment

Map every personal data element in your loyalty database — name, mobile, email, transaction history, behavioural signals, inferred attributes. Classify by sensitivity and identify which data has a valid, purpose-specific consent record attached. Quantify the gap: what percentage of your member base has compliant consent? For most legacy programs, this number will be below 20%.

02

Days 16–30: Consent Architecture Design

Define your purpose taxonomy: list every use case for which you process member data. Build consent notice versions for each channel (in-app, WhatsApp, in-store kiosk, web). Engage your legal and DPO team to ensure notices meet the DPDP standard of being 'plain language, specific, and unconditional.' Integrate the consent taxonomy with your loyalty platform's CMP layer.

03

Days 31–50: Consent Re-permissioning Campaign

Launch a phased re-permissioning campaign to your existing member base. Use the channels where you already have permission (typically SMS or app push) to invite members to review and update their consent preferences. Offer a meaningful value exchange — bonus points, early access, exclusive offer — for members who actively re-consent. Target a 40–60% re-consent rate in the first 30 days.

04

Days 51–70: Rights Fulfilment and Retention Policy Implementation

Build or configure the member-facing data rights portal. Set up automated erasure and data correction workflows. Define retention periods for each data category and configure auto-purge rules. Audit your third-party data sharing agreements — any brand partner or analytics vendor receiving member data must be notified of the new consent-gated sharing model and must sign a Data Processing Agreement.

05

Days 71–90: Audit Readiness and Staff Training

Conduct a mock audit using the Data Protection Board's anticipated inspection framework. Review consent log completeness, rights fulfilment SLA adherence, and breach notification readiness. Train your CRM, campaign, and store operations teams on what they can and cannot do with member data under the new consent model. Establish a quarterly compliance review cycle.

KPIs to Track DPDP Compliance Health in Your Loyalty Program

Compliance is not a project with a finish line — it is an ongoing operational state that must be monitored with the same rigour as campaign performance or member churn. Indian retail CMOs and CIOs need a dedicated compliance health dashboard embedded in their loyalty platform, not a quarterly legal review. These are the metrics that matter.

Consent Coverage Rate is the foundational KPI: what percentage of your active loyalty members have a valid, current, purpose-specific consent record for each data use category? A program with 3 million members and 60% consent coverage has 1.2 million members whose data cannot legally be used for personalised campaigns. That is direct revenue impact. Target: 80%+ coverage within 6 months of DPDP enforcement, trending toward 90%+ for tier-1 members.

Consent Freshness measures the age of consent records. A member who consented at enrolment in 2019 under a non-DPDP notice may need to be re-permissioned. Track the percentage of consent records that are less than 24 months old — this proxy for 'freshness' reduces the risk of consent being challenged as outdated. Rights Fulfilment SLA Compliance tracks the percentage of data erasure, correction, and access requests resolved within the DPDP-mandated timeline. Any breach of the 48-hour acknowledgement SLA is a reportable event.

Data Minimisation Score audits how many data fields are being collected per enrolment event versus how many are actually required for the stated purpose. A program collecting 14 data fields when 6 are sufficient is over-collecting — a clear DPDP risk. Target a minimisation score that reduces unnecessary field collection by 40% within 90 days. Finally, Third-Party Consent Coverage measures what percentage of your data-sharing events with brand partners (common in mall loyalty ecosystems where anchor tenants share member data with specialty retailers) have a valid consent record authorising that specific sharing. This is the most under-tracked metric in Indian mall loyalty today and the one most likely to attract regulatory scrutiny first.

DPDP Readiness Checklist for Indian Retail Loyalty Leaders
  • Conduct a full data inventory: map every personal data element in your loyalty stack and classify by sensitivity and consent status
  • Implement a granular, purpose-specific Consent Management Platform that generates a tamper-evident, timestamped consent log
  • Launch a re-permissioning campaign for legacy loyalty members with a clear value exchange to drive consent refresh rates above 60%
  • Deploy a self-service member data rights portal supporting access, correction, erasure, and consent withdrawal with automated backend fulfilment
  • Configure retention period rules and automated purge workflows for each data category, including dormant and churned member records
  • Audit all third-party data sharing relationships — brand partners, analytics vendors, campaign tools — and gate data flows behind explicit consent signals
  • Establish a monthly compliance health review using consent coverage rate, rights fulfilment SLA, and data minimisation score as lead indicators
“In India retail, consent is not a legal checkbox — it is the new currency of customer trust. The brands that build consent-first loyalty infrastructure today will own the richest first-party data assets tomorrow.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle Solves This

Fundle was architected as India's AI-first loyalty and customer engagement platform with DPDP compliance built into its foundation — not retrofitted as a compliance patch after the fact. The Fundle AI Platform treats consent as a first-class data object: every member record in the Fundle Loyalty engine carries a structured consent profile that tracks purpose-specific permissions, the channel and timestamp of collection, the version of the privacy notice presented, and the current status of each permission. This is not a summary flag — it is a full audit trail that satisfies the Data Protection Board's anticipated inspection requirements.

Fundle's ConsentFirst CMP is fully DPDP compliant, securing 270+ brands' data privacy. This is the consent management layer that sits above the Fundle Brand Loyalty and Fundle Mall Loyalty modules, governing every data collection event — whether it originates at a POS integration, an in-app enrolment, a mall kiosk, or a WhatsApp opt-in flow. The CMP supports multi-purpose consent taxonomy out of the box, including separate consent tracks for points accrual, personalised offers, cross-brand data sharing within mall ecosystems, and third-party analytics. Consent notices are served in plain language across 10 Indian languages, meeting the DPDP requirement for comprehensible disclosure.

The Fundle Agentic AI layer takes compliance further by automating rights fulfilment at scale. When a member submits a data erasure request through the Fundle-powered member portal, Fundle AI Agents automatically propagate the erasure across every connected system — POS, campaign engine, analytics warehouse, and brand partner data feeds — within the 48-hour acknowledgement SLA. No manual intervention, no support ticket queue. The Fundle AI Workflow engine also runs continuous consent health checks: it flags members whose consent records are approaching 24 months of age, triggers automatic re-permissioning nudges through the most-consented channel, and updates campaign audience segments in real time as consent status changes. This means a campaign manager at Manyavar or Lenskart running a segment on the Fundle platform will never inadvertently send a personalised offer to a member who has withdrawn consent — the audience is dynamically consent-gated before every send.

Vineet Narang's founding vision for Fundle was that privacy and personalisation are not in tension — they are mutually reinforcing when the technology is built correctly. The Fundle AI Platform's data minimisation engine enforces collection rules at the point of enrolment, preventing over-collection across integrated POS systems including GoFrugal, Petpooja, and Wondersoft. The DPO dashboard gives CIOs at enterprise retail groups a real-time view of consent coverage rates, pending rights requests, and third-party data sharing compliance across every brand in their portfolio. For mall operators running Fundle Mall Loyalty across anchor tenants and specialty retailers, the platform handles the complexity of multi-brand consent architecture — where a single customer may have different consent profiles for different brands within the same mall — without requiring manual configuration for each brand-tenant relationship. This is the infrastructure that transforms DPDP compliance from a legal cost centre into a genuine competitive advantage.

Frequently asked

What does DPDP 2023 specifically require from a retail loyalty program?+

The DPDP Act requires that personal data collected through loyalty programs be processed only with valid, purpose-specific consent. Retailers must maintain a consent log, honour member rights (access, correction, erasure, withdrawal) within prescribed timelines, appoint a Data Protection Officer if designated a Significant Data Fiduciary, and ensure data is not retained beyond the period necessary for the stated purpose. Non-compliance can attract penalties of up to ₹250 crore per violation.

Does DPDP apply to loyalty programs run by malls, or only to individual brands?+

It applies to both. Any entity — mall operator or brand — that determines the purpose and means of processing personal data is a Data Fiduciary under DPDP. In a mall loyalty ecosystem where the mall operator shares member data with tenant brands, both the mall operator (as the primary Data Fiduciary) and the tenant brands (as Data Fiduciaries for their own processing) have compliance obligations. Data sharing between them requires member consent for that specific purpose.

Can we use our existing loyalty member database without re-permissioning?+

Only if the consent obtained at the time of enrolment meets the DPDP standard: purpose-specific, plain language, unambiguous, and separately given for each use case. Blanket consents obtained through fine-print checkboxes at billing counters — the standard in Indian retail until now — are unlikely to meet this standard. A re-permissioning campaign for your existing member base is strongly recommended before DPDP enforcement begins.

How is Fundle's approach to DPDP compliance different from what Capillary or EasyRewardz offer?+

Fundle's ConsentFirst CMP is built as a native layer of the Fundle AI Platform, not an add-on module. This means consent status is a live, queryable attribute that governs campaign audience construction, data sharing, and analytics access in real time. Competing platforms that are adding compliance features to existing architectures typically implement consent as a flag on the member record — a much weaker model that cannot support dynamic consent-gating of campaign sends or automated multi-system rights fulfilment.

What is a consent refresh cycle, and how often should we run one?+

A consent refresh cycle is a proactive outreach to loyalty members asking them to review and re-confirm their data sharing preferences. Under DPDP, there is no fixed statutory interval, but industry best practice — and the standard Fundle recommends — is to refresh consent every 18–24 months, or whenever you introduce a new data use purpose. Regular refresh cycles also improve data quality by identifying churned or disengaged members whose records should be subject to retention policy review.

What KPIs should a CIO use to monitor ongoing DPDP compliance health?+

The five key metrics are: Consent Coverage Rate (% of active members with valid, current, purpose-specific consent), Consent Freshness (% of records under 24 months old), Rights Fulfilment SLA Compliance (% of access/erasure/correction requests resolved within DPDP timelines), Data Minimisation Score (fields collected vs. fields required), and Third-Party Consent Coverage (% of brand-partner data sharing events backed by explicit member consent). Fundle's DPO dashboard tracks all five in real time.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?