“Dynamic coupons aren't a discount tool — they are a margin-protection tool. Fundle's AI never sends a 20% off when 10% would have converted.”
- •Understand how India's DPDP Act 2023 directly impacts WhatsApp-based loyalty and CRM programs for malls and retail brands
- •Identify the five non-negotiable consent and data-handling requirements every WhatsApp loyalty platform must meet
- •Benchmark your current program against DPDP-ready platforms before enforcement kicks in
- •Follow a five-step playbook to retrofit or rebuild a privacy-first WhatsApp loyalty architecture
- •Adopt Fundle's ConsentFirst CMP — fully DPDP-compliant, securing consumer consent on WhatsApp — as the operational standard
India's loyalty marketing industry has been built on a quiet assumption: that a customer who shared their mobile number at a Pantaloons billing counter or scanned a QR code at Phoenix Marketcity implicitly agreed to receive promotional WhatsApp messages forever. That assumption is now legally untenable. The Digital Personal Data Protection Act 2023 — India's first comprehensive data privacy legislation — received Presidential assent in August 2023 and its rules are expected to be notified and enforced through 2024-25. For every Mall CMO, Head of Loyalty, and CRM Manager running a WhatsApp-first engagement stack, this is not a compliance checkbox. It is a structural rethink.
The scale of the exposure is not trivial. India has approximately 530 million WhatsApp users as of 2024, and an estimated 60-70% of organised retail loyalty communication in metros now flows through WhatsApp — whether through broadcast lists, Business API flows, or chatbot journeys. Platforms like Capillary, EasyRewardz, Xeno, and MoEngage have built deep WhatsApp CRM pipelines for brands like Lifestyle, Reliance Trends, Manyavar, and FabIndia. None of those pipelines were architected with DPDP's granular consent requirements in mind, because the law did not exist when most of them were deployed.
DPDP compliant WhatsApp loyalty is therefore not a feature. It is a new operational baseline. The Act creates a clear hierarchy: explicit, informed, specific, and revocable consent is required before a Data Fiduciary — which includes every retailer, mall operator, and loyalty platform — can process personal data for a commercial purpose. WhatsApp's own Business Policy already requires opt-in consent for marketing messages, but DPDP goes further by mandating that the consent record be maintained, that the purpose be disclosed at point of collection, and that the Data Principal — your customer — can withdraw consent at any time with immediate effect on your systems.
This is the moment platforms like Fundle were built for. The Indian retail market needs an AI-first loyalty infrastructure that treats consent as a first-class data object, not an afterthought buried in terms and conditions. The operators who move first will not just avoid regulatory fines — they will build the kind of trust-led engagement that drives repeat visits, higher basket sizes, and genuine brand affinity in a post-cookie, post-spam world.
India's WhatsApp Loyalty & DPDP Exposure: Key Numbers
Overview of India's DPDP 2023 Framework
The Digital Personal Data Protection Act 2023 is India's answer to GDPR — but it is calibrated for Indian realities. It applies to the processing of digital personal data of Indian residents, whether that processing happens inside India or outside. For retail operators, the critical definitions are straightforward: your customer is the Data Principal; your brand or mall entity is the Data Fiduciary; and if you outsource CRM or loyalty processing to a vendor like Capillary, Xeno, Almonds.ai, or Fundle AI Platform, that vendor becomes a Data Processor operating on your instructions.
The Act mandates seven core obligations for Data Fiduciaries. First, consent must be free, specific, informed, unconditional, and unambiguous — a pre-ticked box or a buried clause in a membership form does not qualify. Second, the notice accompanying the consent request must be in plain language and must specify exactly what data is being collected and for what purpose — 'marketing communications' is not specific enough; 'sending you WhatsApp messages about points balance, offers at Phoenix Marketcity, and brand partner promotions' is. Third, consent must be as easy to withdraw as it was to give. Fourth, personal data may only be used for the stated purpose and must be deleted once that purpose is fulfilled. Fifth, Data Fiduciaries must maintain a verifiable record of every consent obtained.
For WhatsApp loyalty programs, these obligations translate into concrete engineering and process requirements. The opt-in flow on WhatsApp cannot be a single 'Hi' message that auto-enrolls a customer. It must present a structured notice, capture an explicit affirmation, log the timestamp and version of the consent notice shown, and connect that record to the customer's loyalty profile in your CRM or CDP. When a customer texts 'STOP' or clicks an unsubscribe button inside a WhatsApp flow, your system must immediately suppress all outbound communication and flag the withdrawal in the consent ledger — not in 48 hours, not after a campaign has already gone out, but in real time.
Significant Data Fiduciaries — a category likely to include mall operators managing data at scale, large retail chains, and major loyalty platforms — face additional obligations: appointment of a Data Protection Officer, periodic Data Protection Impact Assessments, and data localisation requirements. The Government of India has indicated that the rules under the Act, which will specify thresholds, timelines, and enforcement mechanics, will be notified by late 2024 or early 2025. Operators who wait for full enforcement before acting will find themselves both legally exposed and technically scrambling.
DPDP-Compliant WhatsApp Consent Journey for Retail Loyalty
Requirements for WhatsApp Loyalty Platforms Under DPDP
Not all WhatsApp loyalty platforms are built equally when it comes to DPDP readiness. Most enterprise CRM and loyalty tools in India — including several that power programs for Cafe Coffee Day, Apollo Pharmacy, and Reliance Trends — were designed in the 2015-2020 era when India had no data protection law and consent was a soft courtesy, not a legal requirement. Retrofitting them for DPDP is not simply a policy update; it requires architectural changes to how consent data is stored, queried, and enforced across every outbound workflow.
A DPDP-ready WhatsApp loyalty platform must meet five hard requirements. First, it must have a native Consent Management Platform — or CMP — that stores consent records as structured data objects, not as a boolean flag in a customer table. The record must capture: the consent timestamp, the exact version of the notice shown, the channel through which consent was given, the specific purposes consented to, and the status — active, withdrawn, or expired. Second, the platform must support granular purpose-based consent, meaning a customer can consent to transactional messages (points balance, redemption confirmations) while declining promotional messages, and your system must honour that distinction at the campaign level.
Third, the platform must provide a self-service consent dashboard accessible to the customer — ideally within the WhatsApp conversation itself — where they can view, modify, or withdraw consent without calling a helpline or visiting a store. This is both a DPDP requirement and a trust signal that drives long-term engagement. Fourth, the platform must integrate withdrawal signals in real time with the campaign suppression list, ensuring that a customer who opts out at 11:47 PM is not included in the 11:50 PM batch campaign. Fifth, the platform must generate audit-ready consent reports for regulatory review or internal Data Protection Impact Assessments.
Platforms that lack these capabilities — even well-funded ones like MoEngage or WebEngage, which are strong on journey orchestration but were not built around consent-as-infrastructure — will require significant customisation to meet DPDP's bar. Mall operators running multi-brand loyalty programs face a compounded challenge: they may be processing data on behalf of 80-150 brand tenants simultaneously, each with their own consent scope, making the consent ledger problem orders of magnitude more complex than a single-brand retailer. This is precisely the architecture problem that purpose-built platforms like Fundle Loyalty are designed to solve.
DPDP Readiness: Legacy CRM Approach vs. DPDP Compliant WhatsApp Loyalty Platform
How ConsentFirst Ensures DPDP Compliance on WhatsApp
Fundle's ConsentFirst CMP is fully DPDP-compliant, securing consumer consent on WhatsApp. That single capability statement carries significant operational weight when you unpack what it actually means for a mall operator or retail chain running a WhatsApp loyalty program India-wide.
ConsentFirst operates as a consent infrastructure layer that sits between your customer-facing WhatsApp flows and your loyalty CRM or CDP. When a new customer initiates a conversation — whether through a QR code at Select CITYWALK, a missed-call opt-in promoted by Tanishq, or a Lenskart post-purchase WhatsApp trigger — ConsentFirst intercepts that session and serves a structured, DPDP-compliant consent notice before any personal data is written to the loyalty system. The notice is templated for WhatsApp's message format, available in English and eight regional Indian languages, and specifies exactly which data is being collected, for which purposes, and how long it will be retained. The customer's affirmative response — a button tap, not a passive message receipt — is logged as a consent event with a cryptographic timestamp and the exact notice version displayed.
For existing loyalty members — the millions of customers already enrolled in programs before DPDP enforcement — ConsentFirst supports a re-consent campaign workflow. This is a delicate operational moment: you are asking customers to actively re-affirm what they previously gave implicitly, and some will not respond. Industry experience from GDPR re-consent campaigns in Europe suggests that 40-60% of legacy subscribers re-consent when the ask is clear, branded, and offers an immediate value exchange — a bonus points offer, an exclusive preview, or a personalised recommendation. The customers who do not re-consent must be suppressed, but they represent the lower-engagement segment of your base whose departure actually improves your campaign metrics.
Beyond the initial consent capture, ConsentFirst maintains a live consent graph for every Data Principal. When a Fundle AI Workflow triggers a campaign — say, a 'visit lapsing' re-engagement sequence for customers who have not visited a mall in 45 days — the Fundle AI Agents query the consent graph before any message is dispatched. If the customer's promotional consent is active, the message goes out. If it has been withdrawn or has expired, the customer is automatically excluded and routed to a non-WhatsApp re-engagement channel if an alternative consent exists. This real-time consent enforcement is what separates a genuinely DPDP-ready platform from one that simply adds a consent checkbox at onboarding and ignores it thereafter.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
Five-Step Playbook: Building a DPDP Compliant WhatsApp Loyalty Program
Audit Your Existing Consent Inventory
Pull every record in your loyalty database and classify consent quality: structured opt-in with purpose disclosure, implied opt-in from POS number capture, or unknown origin. Quantify the gap — for most Indian retail programs, 60-80% of records will need re-consent under DPDP. This audit is your baseline for remediation planning and regulatory defensibility.
Architect Purpose-Based Consent Categories
Define the distinct consent purposes your program requires: transactional notifications (points, redemptions), promotional offers (brand and mall), third-party partner offers, profiling for personalisation, and survey or feedback requests. Each category must be independently consentable and independently revocable. Work with legal and your loyalty platform vendor to align these categories to DPDP's purpose-specification requirement.
Deploy a DPDP-Ready Consent Management Platform
Implement a CMP — such as Fundle's ConsentFirst — that captures structured consent events, stores them as auditable records, and integrates in real time with your campaign suppression logic. Ensure the CMP supports multi-language notices for Tier 2 and Tier 3 markets where Hindi, Tamil, Telugu, Marathi, and Kannada are the primary languages of your loyalty base.
Run a Re-Consent Campaign for Legacy Members
Design a phased re-consent outreach for your existing WhatsApp loyalty database. Segment by engagement recency: high-frequency visitors get a personalised re-consent message with a bonus points incentive; lapsed members get a simpler ask. Use WhatsApp's interactive button templates for frictionless opt-in. Set a 30-day window, suppress non-responders, and document the suppression for your DPDP audit trail.
Establish Ongoing Consent Governance and KPI Tracking
Embed consent health metrics into your loyalty dashboard: consent rate by channel, withdrawal rate by campaign type, re-consent campaign performance, and days-to-deletion on withdrawn records. Assign ownership of consent governance to a named Data Protection Officer or equivalent. Schedule quarterly consent audits aligned with your Data Protection Impact Assessment cycle.
KPIs to Track for DPDP Compliant WhatsApp CRM for Retail
Compliance without measurement is a posture, not a programme. Mall CMOs and Heads of Loyalty who are serious about DPDP-compliant WhatsApp CRM for retail need to add a new layer of consent health KPIs alongside their standard engagement metrics. These are not vanity metrics — they are operational signals that tell you whether your compliance architecture is functioning and whether your consent-based engagement is outperforming your previous broadcast approach.
The first metric to track is the Explicit Consent Rate: the percentage of active loyalty members who have a structured, purpose-specific consent record in your CMP. For a program that is genuinely DPDP-compliant, this should be at or near 100% of the active communication-eligible base. Any gap represents regulatory exposure. The second metric is the Consent Withdrawal Rate by campaign type. If customers are withdrawing consent at higher rates after promotional campaigns than after transactional messages, that tells you something important about communication quality and frequency — and it is a signal to reduce promotional volume or improve personalisation before regulators notice the pattern.
Third, track the Time-to-Suppression metric: the elapsed time between a customer's withdrawal signal and the moment they are fully excluded from all outbound flows. Under DPDP, this should be effectively real-time. If your platform has a batch processing architecture — common in older loyalty systems like some configurations of POSist-integrated CRM setups or GoFrugal-connected programs — you may have gaps of hours or even days, which creates legal exposure. Fourth, track Consent Re-engagement Rate: the percentage of lapsed or withdrawn customers who re-consent following a structured re-consent campaign. This metric tells you the health of your brand trust and the effectiveness of your consent-era value proposition.
Finally, measure the Revenue Contribution of Consented Base vs. Total Base. Operators who have run clean consent campaigns consistently find that the consented base — even when smaller than the legacy broadcast list — drives disproportionate revenue. A programme run by a Lifestyle or Pantaloons format with 800,000 active consented WhatsApp members will typically outperform a programme blasting 2 million poorly-consented records, because message relevance, delivery rates, and engagement quality are all materially higher. Fundle Brand Loyalty's analytics layer surfaces these metrics in a unified dashboard, allowing CMOs to make the commercial case for consent-first investment to their boards.
- Structured consent record exists for every WhatsApp-enrolled loyalty member, with timestamp, notice version, and purpose categories documented
- Consent notice is available in the customer's preferred language — minimum English, Hindi, and the dominant regional language of each operating geography
- Granular purpose-based consent is operational: transactional, promotional, and third-party communications are independently controlled by the customer
- Self-service consent management is accessible inside the WhatsApp conversation — no helpline or store visit required for withdrawal
- Real-time suppression is confirmed: withdrawal signal triggers campaign exclusion in under 60 seconds across all outbound channels
- Automated data retention and deletion policies are configured — data not retained beyond stated purpose or consent expiry
- Quarterly consent audit process is owned by a named Data Protection Officer or equivalent, with DPDP Impact Assessment scheduled annually
“In India, consent is not a legal footnote — it is the opening line of every customer relationship. The brands that earn it explicitly will own the next decade of retail engagement.”
How Fundle solves this
Vineet Narang's founding thesis for Fundle was that Indian retail needed a loyalty platform that treats data ethics and commercial performance as the same problem, not competing priorities. That thesis has never been more timely. As DPDP enforcement approaches, the Fundle AI Platform is the only India-built, AI-first loyalty infrastructure that has architected consent as a core data object from the ground up — not bolted on as a compliance module after the fact.
Fundle Mall Loyalty is purpose-built for the multi-brand, multi-tenant complexity of Indian shopping malls — Phoenix Marketcity, Select CITYWALK, and their peers — where a single customer's loyalty profile may interact with 30+ brand touchpoints in a single visit. ConsentFirst, Fundle's consent management infrastructure, maintains a unified consent graph for each Data Principal across all brand touchpoints within the mall ecosystem. When Tanishq's boutique inside a mall wants to send a WhatsApp message about a jewellery care offer, the Fundle AI Agents query the customer's consent record to confirm that the customer has consented to brand partner promotions — before the message is ever composed, let alone dispatched. This is consent enforcement at the workflow level, not the campaign level.
Fundle Brand Loyalty extends the same architecture to standalone retail chains — fashion, pharmacy, food and beverage, eyewear — where WhatsApp CRM for retail is the primary engagement channel. Fundle Agentic AI powers dynamic consent-aware journey orchestration: if a customer in a re-engagement sequence withdraws promotional consent mid-journey, the Fundle AI Workflow automatically reroutes them to a transactional-only track rather than silently suppressing all communication. This preserves the relationship while honouring the legal boundary — a nuance that most legacy CRM platforms cannot execute because their journey engines were not built to query a live consent graph mid-flow.
For CRM Managers and Heads of Loyalty who are evaluating their DPDP readiness right now, the commercial case for Fundle is clear: programs running on Fundle's ConsentFirst infrastructure have measurably higher delivery rates, engagement rates, and redemption rates than broadcast-first programmes, because every message reaches a customer who has explicitly said they want to hear from you. The compliance benefit and the commercial benefit are the same benefit. That is the insight Fundle was built to operationalise across Indian retail.
Frequently asked
What is DPDP compliant WhatsApp loyalty and why does it matter for Indian retail?+
DPDP compliant WhatsApp loyalty refers to loyalty programs and CRM communication delivered via WhatsApp that fully adhere to India's Digital Personal Data Protection Act 2023. The Act mandates explicit, purpose-specific, revocable consent before any personal data — including a mobile number — can be used for marketing. For Indian retailers and mall operators, non-compliance carries penalties of up to ₹500 crore per breach instance, making it a material business risk, not just a legal formality.
Does WhatsApp's own opt-in policy satisfy DPDP requirements?+
No. WhatsApp Business Policy requires opt-in consent for marketing messages, but it does not satisfy DPDP's requirements for purpose-specific consent, structured consent records, or real-time revocation enforcement. A customer consenting to receive WhatsApp messages from your brand has not necessarily consented to profiling for personalisation, third-party partner offers, or data sharing — each of which requires a separate, documented consent under DPDP.
How should a mall operator handle the millions of existing loyalty members enrolled before DPDP?+
Existing members enrolled before DPDP's enforcement date represent a re-consent challenge. Operators should run a structured re-consent campaign via WhatsApp using DPDP-compliant notice templates, offering a value incentive for re-consent. Members who do not respond within a defined window — typically 30 days — must be suppressed from outbound communication and their data flagged for deletion review. Fundle's ConsentFirst CMP includes a purpose-built re-consent campaign workflow for exactly this scenario.
What is a Consent Management Platform (CMP) and do loyalty platforms like Capillary or EasyRewardz have one?+
A CMP is a system that captures, stores, manages, and enforces consent records as structured data objects. Most legacy Indian loyalty platforms, including several market-leading ones, do not have a native CMP — they store consent as a simple flag in the customer record with no audit trail, no purpose granularity, and no real-time enforcement integration. A genuine DPDP-ready CMP, like Fundle's ConsentFirst, maintains a full event log of every consent grant, modification, and withdrawal.
How quickly must a retailer act on a customer's consent withdrawal under DPDP?+
The DPDP Act does not specify an exact time limit for suppression, but the standard of 'as easy to withdraw as to give' implies real-time or near-real-time effect. Best practice — and the standard Fundle Loyalty enforces — is suppression within 60 seconds of a withdrawal signal across all active outbound workflows. Batch-processing architectures that suppress in 24-48 hours create clear legal exposure under the Act's intent.
Will DPDP compliance reduce my WhatsApp loyalty programme's reach and revenue?+
Short-term, yes — re-consent campaigns typically result in a smaller active communication base than a legacy broadcast list. Long-term, no. Programmes running on a consented base consistently show higher open rates, higher redemption rates, and lower opt-out rates than broadcast programmes. Industry benchmarks indicate a 3.2x higher redemption rate on consent-based WhatsApp messages versus unselected broadcasts. The revenue per reachable customer improves significantly when every message goes to someone who has said they want it.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
