“We measure loyalty in incremental gross margin, not in app downloads. Every Fundle dashboard is built so a CFO can argue with the marketer on the same number.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand the specific consent obligations DPDP places on loyalty programme operators in India
  • Map your existing data collection touchpoints against the Act's purpose-limitation and notice requirements
  • Adopt a consent lifecycle architecture that covers collection, storage, renewal, and revocation
  • Benchmark your tech stack against DPDP-grade requirements before the enforcement window closes
  • Explore how Fundle AI Platform operationalises ConsentFirst to keep 270+ brands audit-ready

India's Digital Personal Data Protection Act 2023 (DPDP) is not a distant regulatory cloud on the horizon — it is already shaping boardroom conversations at Phoenix Marketcity, Select CITYWALK, Reliance Trends, and every loyalty-driven retail brand in between. When the subordinate rules are fully notified and enforcement begins, the consequences for non-compliant loyalty programmes will be severe: penalties up to ₹250 crore for a single breach, and up to ₹10,000 crore for systemic violations. For a CMO running a 5-million-member programme or a CIO managing the data pipes feeding it, this is not a legal team problem. It is a data architecture problem, a customer experience problem, and ultimately a revenue problem.

Consent based loyalty data management sits at the precise intersection where DPDP's obligations collide with the commercial imperatives of Indian retail. Loyalty programmes are, by design, data-hungry. They ingest transaction history, location signals, browsing behaviour, wish-lists, family profiles, and increasingly, AI-inferred propensity scores. Every one of those data categories, if it relates to an identifiable individual, is personal data under DPDP. And every piece of personal data requires a lawful basis — for loyalty programmes, that basis is almost always explicit, informed, free, and specific consent.

Yet most Indian loyalty stacks were not built with consent at the core. They were built for points accumulation and campaign blasting. Consent was an afterthought — a checkbox on an enrolment form that nobody read and nobody could ever revoke gracefully. Platforms like EasyRewardz, Capillary, or older in-house stacks at brands like Pantaloons or Cafe Coffee Day were architected in an era when India had no sectoral data protection law. The DPDP Act fundamentally disrupts that architecture. Brands that do not rebuild their consent infrastructure before enforcement begins will face not just regulatory risk but accelerating customer distrust at a time when Indian consumers are rapidly becoming more privacy-aware.

This is the context in which Fundle was built — not as a retrofitted compliance module bolted onto a legacy CRM, but as a privacy-first loyalty platform where consent lifecycle management is a first-class feature. The following analysis gives Indian retail CMOs and CIOs a precise, operator-level playbook for aligning loyalty data practices with DPDP obligations, benchmarking their current stack, and executing a consent architecture that is both legally sound and commercially viable.

DPDP and Loyalty Data: Four Numbers Every Indian Retail Leader Must Know

₹250 Cr
Maximum penalty per data breach incident under DPDP Act 2023
270+
Brands for which Fundle manages end-to-end consent lifecycle ensuring DPDP alignment
68%
Indian loyalty members who say they would disengage if their data was used without clear notice (PwC India CX Survey 2023)
₹3,200 Cr
Estimated annual loyalty marketing spend across organised Indian retail at risk of non-compliance

Consent Requirements Under DPDP for Loyalty Programmes

The DPDP Act establishes a clear, non-negotiable framework for consent. Section 6 of the Act requires that consent must be free, specific, informed, unconditional, and unambiguous — expressed through a clear affirmative action. For a loyalty programme, this means a pre-ticked checkbox saying 'I agree to receive personalised offers' is not valid consent. Neither is burying data usage terms in a 4,000-word terms-and-conditions document that members click through during a two-minute store enrolment on a Saturday afternoon.

The 'specific' requirement is particularly disruptive for loyalty operators. It means consent must be sought separately for each distinct purpose: earning and redeeming points is one purpose; sharing data with mall tenants for targeted campaigns is a second purpose; using purchase history to train AI recommendation models is a third. A single omnibus consent tick cannot cover all three. This has immediate implications for how brands like Manyavar, FabIndia, or Apollo Pharmacy structure their enrolment flows. Each of these brands collects data for multiple downstream purposes — their consent architecture must reflect that granularity.

The 'informed' requirement mandates a consent notice that is clear, plain-language, and available in all 22 scheduled languages on request. For a brand like Tanishq operating across Tier 1 and Tier 2 India, this is a non-trivial localisation challenge. The notice must identify the Data Fiduciary (the brand), the categories of personal data being collected, the specific purposes for processing, and the member's rights including the right to withdraw consent at any time. Loyalty platforms that currently store consent as a binary flag in a database field are architecturally unfit for this standard.

Perhaps the most operationally demanding DPDP requirement is the consent renewal obligation. If a loyalty programme changes its data usage purpose — say, it integrates a new AI-driven personalisation engine, or it begins sharing anonymised cohort data with a third-party analytics provider — it must obtain fresh, specific consent from existing members before processing their data for the new purpose. For a programme with 3 million members across 200+ stores, this is a consent campaign at scale. Without automated consent lifecycle tooling, this is practically impossible to execute correctly.

The DPDP-Compliant Loyalty Consent Lifecycle

11. Notice Delivery22. Affirmative Capture33. Consent Record44. Preference Centre55. Purpose Change Alert
From first enrolment touchpoint to consent revocation, every stage in the loyalty journey now has a corresponding DPDP obligation. Brands must architect systems that handle all six stages without manual intervention.

Best Practices in Consent Management for Loyalty

The gap between minimum legal compliance and genuinely privacy-first loyalty design is where commercial advantage is won or lost. Brands that treat DPDP as a box-ticking exercise will implement the minimum — a consent checkbox at enrolment and a buried 'unsubscribe' link in emails. Brands that treat it as a trust-building opportunity will implement a consent architecture that actively improves member engagement metrics.

The first best practice is consent granularity by channel and purpose. Rather than a single 'I accept' moment, leading programmes are moving to a tiered enrolment flow: a fast track where the member consents only to core loyalty mechanics (earn/redeem), and an enrichment track where additional consents unlock richer personalisation and exclusive benefits. Lenskart's loyalty enrolment, for instance, can productively separate consent for 'eye health reminders' from consent for 'personalised frame recommendations' from consent for 'sharing your purchase history with our partner eyewear brands.' Each tier has a clear value exchange that makes consent feel like a choice, not a formality.

The second best practice is a persistent, accessible preference centre. DPDP requires that withdrawal of consent be as easy as giving it. In practice, this means your loyalty app or member portal must have a clearly labelled 'My Data & Privacy' section where any individual consent can be toggled off in under three taps, and where the downstream effect (e.g., 'switching this off means you will no longer receive personalised birthday offers') is clearly explained. Platforms like MoEngage and WebEngage have preference centre modules, but they are typically channel-preference tools (email, SMS, push), not purpose-consent tools. The distinction matters enormously under DPDP.

Third, consent versioning and audit trails are non-negotiable. When the Data Protection Board of India or a court asks you to prove that member ID 9,847,221 gave valid consent on 14 March 2024 for purpose category 'AI-driven cross-sell recommendations,' you need an immutable, timestamped record that includes the exact text of the consent notice presented, the channel, the member's affirmative action, and any subsequent modifications. This is a data engineering problem as much as a legal one. Most mall loyalty programmes running on older stacks — whether built in-house or on legacy platforms — store consent as a single boolean column in a member master table. That is not an audit trail. That is a liability.

Fourth, purpose-change re-consent automation is a competitive differentiator. When you add a new AI personalisation vendor, integrate a new data clean room partner, or start using behavioural signals from your mall's Wi-Fi analytics provider, DPDP requires fresh consent from existing members for those new purposes. Brands that have built this into their consent workflow as an automated campaign — triggered by a configuration change in the platform — will execute this in hours. Brands that rely on manual processes will face weeks of legal review, IT tickets, and campaign coordination before they can go live.

Legacy Loyalty Consent Architecture vs. DPDP-Compliant Consent Architecture

Legacy Approach (Pre-DPDP)
DPDP-Compliant Approach
Single omnibus consent at enrolment, stored as a boolean flag
Granular per-purpose consent with versioned text, timestamp, and channel stored in immutable audit log
No accessible preference centre; unsubscribe buried in email footer
In-app preference centre with purpose-level toggles and real-time downstream effect explanations
No process for re-consent when data use purpose changes
Automated re-consent campaigns triggered by purpose-change configuration events
Data deletion on request handled manually by CRM team in days or weeks
One-click revocation with automated data deletion cascade across all downstream systems within 72 hours
Consent notice in English only, embedded in T&Cs
Plain-language notice in member's preferred language, served contextually at each data collection touchpoint

Technological Tools to Support DPDP Compliance in Loyalty

The Indian market has several categories of technology that touch consent management for loyalty programmes, and understanding which layer does what is essential before any CIO begins a compliance architecture review. The categories are: Customer Data Platforms (CDPs), Loyalty Management Platforms, Consent Management Platforms (CMPs), and CRM and Marketing Automation tools. Each plays a role; none individually solves the full DPDP consent lifecycle for loyalty without significant integration work.

CDPs like Segment or Adobe Real-Time CDP can unify member profiles and tag consent attributes to individual records, but they are not natively designed for Indian regulatory requirements or for the specific consent semantics of DPDP — they do not understand 'purpose limitation' in the DPDP sense, and they do not have pre-built re-consent workflow engines. Loyalty platforms like Capillary or EasyRewardz handle points mechanics and campaign management well, but their consent frameworks were designed for GDPR at best, and several Indian deployments of these platforms have consent stored as campaign subscription flags rather than DPDP-grade purpose consents. Antavo, a global loyalty platform, has strong programme logic but no India-specific DPDP tooling whatsoever.

Standalone CMPs like OneTrust or Cookiebot handle web cookie consent effectively but were not designed for loyalty programme enrolment flows, in-store kiosk consent, or the post-enrolment consent lifecycle that DPDP mandates. They also do not integrate natively with the POS systems used across Indian retail — Petpooja, POSist, GoFrugal, Wondersoft — where the majority of loyalty enrolments actually happen in India's store-first retail environment.

Marketing automation tools like Xeno, WebEngage, MoEngage, or Customer Capital are excellent at campaign execution and customer journey orchestration, but they sit downstream of the consent layer. They consume consent signals; they do not manage the consent lifecycle. A brand using Xeno for WhatsApp loyalty campaigns still needs a separate, upstream consent management system to determine whether any given member has consented to WhatsApp marketing for purpose X versus purpose Y.

The CIO's practical conclusion: a DPDP-compliant loyalty data platform for India requires either assembling a four-layer tech stack and integrating it carefully, or adopting a purpose-built platform that natively handles consent lifecycle within the loyalty context from enrolment to erasure. This is the gap that Fundle AI Platform was architected to fill — an integrated loyalty and consent management stack where DPDP compliance is not a plugin but a foundational design principle.

Consumer Rights and Revocation Procedures Under DPDP

DPDP grants Indian data principals — your loyalty members — a set of enforceable rights that are materially stronger than what existed under IT Act rules. For loyalty operators, four rights have the highest operational impact: the right to access, the right to correction, the right to erasure, and the right to grievance redressal. Understanding the operational implications of each is essential before a CMO or CIO signs off on their compliance posture.

The right to access means any loyalty member can request a complete, machine-readable copy of all personal data you hold about them, the purposes for which it is being processed, and the entities with whom it has been shared. For a mall loyalty programme like the one operating at Select CITYWALK, this includes transaction history, dwell-time data from Wi-Fi analytics, AI-inferred persona labels, campaign interaction history, and any data shared with anchor tenants. Fulfilling this request manually, within the timeframe the rules will specify, is operationally impossible at scale without a data subject access request (DSAR) automation layer built into the loyalty platform.

The right to erasure — or the right to be forgotten in common parlance — is the most commercially disruptive. When a member withdraws consent and requests erasure, DPDP requires deletion of their personal data from all processing systems, not just the marketing database. This means the deletion must cascade to your CDP, your data warehouse, your AI training datasets, your BI dashboards, and any third-party data processors you have shared the data with — including analytics vendors, clean room partners, and mall Wi-Fi providers. Brands that have shared member data with external processors without adequate data processing agreements will find erasure requests extremely difficult and potentially legally exposing to fulfil.

The right to correction sounds straightforward but creates operational complexity when member data exists in multiple systems. A member who updates their mobile number or date of birth in the loyalty app must see that correction propagate consistently across every system that holds their data. In most retail tech stacks, this requires either a golden record architecture in a CDP or a manual reconciliation process. DPDP effectively mandates the former.

Grievance redressal is an often-overlooked obligation. DPDP requires every Data Fiduciary to designate a contact point for privacy complaints and to resolve them within a specified period. For loyalty programmes, this means member-facing communication must include a clear privacy contact — not a generic customer care email — and there must be an internal workflow for logging, escalating, and resolving data-related complaints within the regulatory window. Brands like Apollo Pharmacy or Reliance Trends, which run large loyalty programmes with millions of enrolled members, need ticketing and workflow systems purpose-built for DPDP grievance management, not generic customer service platforms.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

5-Step Playbook: Implementing DPDP-Compliant Consent Based Loyalty Data Management

01

Conduct a Loyalty Data Inventory and Purpose Mapping

Before any technical change, map every data element collected by your loyalty programme to a specific, documented processing purpose. For each purpose, determine whether the lawful basis is consent or legitimate interest (the latter has very narrow scope under DPDP for commercial loyalty). This inventory becomes the foundation for your consent notice architecture and your re-consent trigger logic.

02

Redesign Enrolment Flows for Granular, Purpose-Specific Consent

Audit every enrolment touchpoint — in-store POS on Petpooja or POSist, loyalty app onboarding, web registration, mall kiosk — and rebuild consent capture as a granular, purpose-level flow. Ensure the consent notice is plain-language, available in relevant regional languages, and served contextually at the moment of data collection, not hidden in T&Cs.

03

Build an Immutable Consent Audit Log and Preference Centre

Implement a consent record store that captures member ID, consent text version, purpose category, channel, timestamp, and affirmative action for every consent event. Simultaneously, deploy a member-facing preference centre accessible via app and web where any consent can be viewed or withdrawn within three taps or clicks. This must be a live, real-time system — not a batch-updated report.

04

Automate Re-Consent Campaigns for Purpose Changes and Renewals

Configure your loyalty platform to automatically trigger a re-consent campaign — via the member's preferred channel (WhatsApp, app push, SMS, email) — whenever a new data processing purpose is added, a third-party processor is onboarded, or consent for a purpose approaches an expiry threshold. Define the escalation logic: what happens to a member's data if they do not respond to a re-consent request within the defined window?

05

Implement DSAR Automation and Grievance Redressal Workflow

Integrate a data subject access request (DSAR) automation layer that can generate a complete member data export on demand, flag the request for legal review, and execute erasure cascades across all connected systems — CDP, data warehouse, AI model pipelines, third-party processors — within the regulatory timeframe. Appoint and publicise a Data Protection Officer or equivalent contact, and implement a ticketing workflow for DPDP grievances separate from general customer service.

KPIs to Track for DPDP-Compliant Loyalty Data Management

Compliance is not a binary state — it is a continuous operational posture that requires active measurement. For Indian retail CMOs and CIOs, the key performance indicators for consent based loyalty data management fall into three clusters: consent health metrics, rights fulfilment metrics, and commercial impact metrics.

Consent health metrics tell you whether your consent architecture is functioning correctly. Track consent capture rate at enrolment (what percentage of new members complete granular consent, not just a blanket checkbox), consent completeness score (what percentage of active members have valid, purpose-specific consent records for every active processing purpose), and consent decay rate (what percentage of consents are being withdrawn per month, and for which purposes — this is a leading indicator of trust erosion). A healthy loyalty programme should have a consent completeness score above 95% for core loyalty purposes and should be monitoring withdrawal rates by purpose category to identify pain points before they become regulatory issues.

Rights fulfilment metrics track your operational performance against DPDP obligations. Measure average DSAR response time (target: well within the regulatory window, likely 30-72 hours for digital-first programmes), erasure cascade completion rate (what percentage of erasure requests result in confirmed deletion across all connected systems within the required timeframe), and grievance resolution time. For large programmes at brands like Lifestyle or Pantaloons, these metrics need to be reviewed weekly, not quarterly.

Commercial impact metrics close the loop between compliance investment and business outcome. The hypothesis — supported by PwC India CX data — is that transparent, member-controlled consent architecture improves trust, and improved trust improves engagement and lifetime value. Track consent opt-in rates for enrichment purposes (personalisation, AI recommendations, partner offers) as a proxy for trust levels. Track campaign engagement rates segmented by consent tier — members who have given broad consent should show meaningfully higher engagement than minimum-consent members. Track churn rates among members who have withdrawn specific consents to understand whether the programme is offering sufficient value exchange to retain privacy-conscious members.

Finally, track programme-level compliance posture: number of open DPDP grievances, number of regulatory inquiries received, and completion status of annual consent architecture reviews. These are board-level risk metrics for any large retail operator and should be reported alongside financial loyalty programme KPIs in CMO and CIO dashboards.

DPDP Loyalty Compliance Readiness Checklist for Indian Retail Operators
  • Every processing purpose in your loyalty programme has a documented lawful basis under DPDP, with consent as the basis for all commercial personalisation and third-party sharing activities
  • Enrolment flows at all touchpoints (app, web, in-store POS, kiosk) serve granular, purpose-specific consent notices in plain language, and capture affirmative opt-in per purpose
  • An immutable, timestamped consent audit log exists for every active and historical consent event, accessible for regulatory inspection within 24 hours
  • A member-facing preference centre allows withdrawal of any individual consent within three interactions, with real-time downstream effect explanation
  • Automated re-consent campaigns are configured to trigger on purpose changes, new processor onboarding, and consent expiry thresholds
  • DSAR automation enables complete member data export and erasure cascade across all connected systems — CDP, warehouse, AI pipelines, third-party processors — within regulatory timeframes
  • A designated DPDP grievance contact and internal resolution workflow are documented, communicated to members, and reported on in monthly compliance dashboards
“In India, consent is not a legal checkbox — it is the currency of customer trust. Brands that treat DPDP as a compliance cost will lose the data war to brands that treat it as a product feature.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Fundle was designed from the ground up as a privacy-first loyalty platform for the Indian market — not retrofitted for DPDP after the fact, but architected with consent lifecycle management as a core product primitive. The Fundle AI Platform integrates loyalty programme mechanics, first-party data management, and DPDP-grade consent infrastructure into a single operational layer, eliminating the need for Indian retail operators to assemble and integrate four separate technology categories to achieve compliance.

At the consent capture layer, Fundle Loyalty delivers granular, purpose-specific consent flows that can be deployed across in-store POS integrations (including Petpooja, POSist, GoFrugal, and Wondersoft), the Fundle-powered loyalty app, and web enrolment. Every consent event is written to an immutable audit log with full metadata — member ID, consent text version, channel, timestamp, and affirmative action — that is accessible for regulatory inspection. The Fundle Mall Loyalty product extends this to multi-brand mall environments, managing consent across anchor tenants and specialty retailers within a single programme structure, with purpose-level consent tracked per brand and per data use case.

Fundle Brand Loyalty handles post-enrolment consent lifecycle for standalone retail brands: automated re-consent campaigns triggered by purpose changes, consent renewal workflows for programmes with time-bound consent architecture, and a member-facing preference centre where any consent granule can be viewed or withdrawn in real time. The preference centre is natively integrated into the loyalty member portal and app — it is not a separate CMP bolted on top, but a first-class feature of the member experience.

Fundle AI Agents and Fundle Agentic AI power the operational automation layer. When a new data processing purpose is added to a brand's programme configuration, Fundle Agentic AI automatically generates a re-consent campaign brief, routes it through the brand's preferred approval workflow, and schedules deployment across opted-in channels (WhatsApp, app push, SMS, email) — all without manual intervention from the compliance or CRM team. Fundle AI Workflow manages DSAR fulfilment: receiving a member's erasure or access request, generating the complete data export or executing the deletion cascade, and logging the fulfilment event for audit purposes.

Fundle manages consent lifecycle for 270+ brands ensuring DPDP alignment — a scale that has given the platform battle-tested architecture across the full range of Indian retail contexts, from single-brand D2C programmes to complex multi-tenant mall loyalty deployments. Vineet Narang's founding vision for Fundle was explicit: that the right to data privacy and the commercial value of personalised loyalty are not in tension — they are mutually reinforcing when consent is treated as a product feature rather than a compliance obligation. Every feature in the Fundle AI Platform reflects that conviction.

Frequently asked

Does DPDP apply to loyalty programmes run by Indian retail brands?+

Yes. If your loyalty programme collects, stores, or processes personal data of Indian residents — which includes names, phone numbers, purchase history, location data, and behavioural inferences — you are a Data Fiduciary under DPDP and all consent obligations apply to your programme.

Can I use a single consent checkbox at enrolment to cover all loyalty data uses?+

No. DPDP requires consent to be specific, meaning a single omnibus consent cannot cover multiple distinct processing purposes. You must obtain separate consent for core programme mechanics, personalisation, third-party sharing, and AI profiling, among others.

What happens if a loyalty member withdraws consent — do I have to delete all their data?+

If consent is the sole lawful basis for a processing activity and a member withdraws it, you must cease that processing and, if requested, delete the data related to that purpose. This deletion must cascade across all connected systems including CDPs, data warehouses, and third-party processors.

How is a DPDP-compliant loyalty consent platform different from a standard CMP like OneTrust?+

Standard CMPs are designed for web cookie consent and GDPR-style compliance. They do not handle loyalty enrolment flows, in-store POS consent capture, re-consent lifecycle automation, or the DSAR fulfilment workflows specific to loyalty programme data. A DPDP compliant loyalty data platform like Fundle integrates all of these within the loyalty product itself.

How long do I need to retain consent records under DPDP?+

The Act requires consent records to be retained for as long as the data is being processed for the consented purpose, and for a regulatory inspection period thereafter. Your consent audit log must be queryable and producible on short notice. Specific retention periods will be defined in the subordinate rules.

What are the commercial risks of getting consent management wrong in a loyalty programme?+

Beyond regulatory penalties of up to ₹250 crore per breach, the commercial risks include member trust erosion leading to programme disengagement, inability to use first-party data for AI personalisation (because consent records are insufficient to demonstrate lawful basis), and exclusion from data clean room partnerships with mall operators or FMCG brands that require DPDP-grade consent documentation from their retail partners.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?