Fundle
“We will not build a loyalty platform for the AI era. We are building the loyalty platform of the AI era. That's the only standard worth shipping against.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • •Understand the specific DPDP 2023 obligations that apply to loyalty workflow automation in Indian retail and mall contexts
  • •Adopt Privacy by Design principles so consent, data minimisation, and purpose limitation are built into every automation trigger
  • •Deploy ConsentFirst CMP to capture, store, and honour granular user consent across all loyalty touchpoints
  • •Map the five-step implementation roadmap from consent audit to agentic AI orchestration before the DPDP rules are notified
  • •Track six KPIs — consent capture rate, withdrawal rate, data breach response time, RFM reachability, and more — to stay compliant and commercially effective

India's Digital Personal Data Protection Act, 2023 — commonly called the DPDP Act — is not a future compliance checkbox. The rules are being notified in tranches, and the Data Protection Board is expected to become fully operational within 2025. For Mall CMOs and Loyalty Program Managers at large retail chains — whether running a 200-brand tenant mix at Phoenix Marketcity or managing a 40-lakh member database for a Lifestyle or Pantaloons program — the clock is already ticking.

The problem is structural, not cosmetic. Most loyalty stacks in Indian retail were built between 2015 and 2022 when data collection was essentially unrestricted. Vendors like Capillary, EasyRewardz, and Xeno helped brands accumulate massive first-party datasets, but very few programs embedded granular, withdrawable, purpose-specific consent at the point of enrolment. Transactional SMS blasts, WhatsApp re-engagement, birthday coupon triggers, cross-tenant profiling inside malls — all of these automation workflows now carry legal risk if they cannot demonstrate a valid, auditable consent chain under DPDP.

The stakes are concrete: DPDP prescribes penalties of up to ₹250 crore per instance of non-compliance for significant data fiduciaries, a category that almost certainly captures any retailer or mall operator running a loyalty program with more than 10 lakh members. A poorly designed loyalty automation workflow — one that fires a re-targeting message to a customer who withdrew consent three months ago — is no longer just a CX embarrassment. It is a balance-sheet risk.

This is why DPDP compliant loyalty automation has moved from the IT team's backlog to the CMO's board agenda. Fundle.ai was architected from day one to make compliance and personalisation co-exist — not compete. This article gives loyalty operators a practitioner-level roadmap: what the law actually requires, what Privacy by Design means in a mall loyalty context, how ConsentFirst CMP works, and what a step-by-step implementation looks like before your next membership renewal cycle.

Indian Retail Loyalty & DPDP: The Numbers That Matter

₹250 Cr
Maximum penalty per non-compliance instance under DPDP for significant data fiduciaries
1.33 Cr+
Loyalty users covered by Fundle's ConsentFirst DPDP-compliant architecture
68%
Indian loyalty members enrolled before 2023 who lack granular, withdrawable purpose-specific consent records
₹4,200 Cr
Estimated annual GMV at risk across top-10 Indian mall loyalty programs if automation workflows are suspended for non-compliance

DPDP 2023: What Loyalty Managers Should Know

The DPDP Act establishes seven key principles that loyalty operators must internalise: lawful processing, purpose limitation, data minimisation, data accuracy, storage limitation, reasonable security safeguards, and accountability. For a loyalty program, each of these maps to a specific workflow risk.

Purpose limitation is the one that hits hardest. When a customer at Select CITYWALK enrolls in the mall's loyalty program to earn points on Fashion purchases, that consent does not automatically extend to sharing her purchase history with a beauty brand tenant for a separate re-targeting campaign. Cross-tenant data sharing — one of the most commercially attractive features of mall loyalty — requires explicit, separate, withdrawable consent for each purpose. Programs running on legacy stacks that fire 'you might also like' messages across tenant categories without granular purpose mapping are operating on borrowed time.

Data minimisation is equally disruptive for over-engineered CRM profiles. Many Indian loyalty programs collect 40-60 data fields at enrolment — PAN, vehicle number, anniversary date, spouse name — fields that have no direct relevance to earning and redeeming points. DPDP requires that collection be limited to what is 'necessary for the specified purpose.' Loyalty teams will need to audit their enrolment forms and data schemas with this lens.

Consent must be free, specific, informed, and unconditional. The Act explicitly bans consent bundled with terms-and-conditions acceptance. This means the checkbox at the bottom of a Manyavar or FabIndia POS enrolment screen that says 'I agree to receive marketing communications' as a condition of joining the program is no longer valid consent under DPDP. Operators must redesign their consent UX — both digital and in-store — before rules are notified. Finally, the right to withdraw consent must be as easy as the act of giving it. If a Pantaloons member can join the loyalty program in 90 seconds at the POS, she must be able to withdraw her marketing consent in an equally frictionless manner — not by calling a helpline or visiting a store.

DPDP Compliance Funnel for Loyalty Workflow Automation

Total Loyalty Members — 100%Members with Valid DPDP Consent Record — ~32%Consent Covers Specific Automation Purpose — ~21%Consent Not Withdrawn in Last 90 Days — ~18%
Each layer of the funnel represents a gate that loyalty automation must pass before a message or personalisation trigger is fired. Drop-off at any gate without a valid consent record creates regulatory exposure.

Privacy by Design in Loyalty Workflow Automation India

Privacy by Design is not a DPDP-specific term — it was coined by Ann Cavoukian in the 1990s — but the DPDP Act's accountability principle effectively mandates it. For loyalty workflow automation in India, Privacy by Design means consent and data governance are embedded in every automation trigger, not bolted on as a post-processing filter.

Consider a typical birthday reward workflow at an Apollo Pharmacy or Cafe Coffee Day loyalty program. The automation fires seven days before the member's birthday, sends a personalised WhatsApp message with a bonus points offer, and if unopened, escalates to an SMS. Under a Privacy by Design architecture, before this workflow fires, the system must verify: Does this member have an active, unrevoked consent record for 'birthday marketing communications' specifically? Has the member's data been processed only for the purposes they consented to? Is the data used to personalise the message — purchase category, spend tier, preferred channel — within the scope of the original consent? If any check fails, the workflow stops and logs the suppression event with a timestamp.

This is fundamentally different from how most Indian loyalty stacks work today. Platforms like MoEngage and WebEngage are excellent campaign orchestration tools, but they are consent-agnostic by default — they fire campaigns to whoever is in the audience segment, and compliance is assumed to be the brand's responsibility. The gap between a campaign orchestration tool and a DPDP-ready loyalty automation platform is precisely where operators are exposed.

For mall operators managing multi-tenant programs — Phoenix Marketcity, Nexus Malls, DLF Avenue — the complexity multiplies. A single member interacts with 8-12 tenant brands per visit. Each interaction potentially feeds a different data processing purpose. A Privacy by Design architecture must maintain a purpose-specific consent ledger per member per tenant, enforce data compartmentalisation so Tenant A cannot access Tenant B's interaction data without explicit cross-brand consent, and give the central mall operator a real-time view of consent coverage across the entire program. Without this, the mall operator — as the primary data fiduciary — carries liability for every tenant's automation workflow.

DPDP Compliant Loyalty Stack vs. Legacy Loyalty Stack

Legacy Loyalty Stack (Pre-DPDP)
DPDP Compliant Stack (Fundle ConsentFirst)
✗Consent captured as a single checkbox at POS enrolment, bundled with T&Cs
✓Granular, purpose-specific consent captured at enrolment and refreshed at each touchpoint via ConsentFirst CMP
✗No consent withdrawal mechanism at member level; requires helpline call or store visit
✓Self-serve consent dashboard in loyalty app; withdrawal reflected in automation suppression within 60 seconds
✗Cross-tenant data sharing enabled by default for mall operators; no member visibility
✓Cross-tenant data sharing requires separate, explicit consent per purpose; member sees full data-sharing map
✗Automation workflows fire to full audience segment; compliance assumed externally
✓Every automation trigger checks live consent ledger before firing; suppression events logged with audit trail
✗Data retention driven by CRM storage limits; no systematic expiry or deletion workflow
✓Automated data expiry aligned to storage limitation principle; member-initiated deletion fulfilled within 72 hours

Role of ConsentFirst CMP in DPDP Compliant Loyalty Automation

ConsentFirst is Fundle's proprietary Consent Management Platform — the layer that sits between your member database and every downstream automation workflow. Its core function is simple to state and hard to engineer: no loyalty automation trigger fires without a verified, purpose-matched, unrevoked consent record. Fundle's ConsentFirst ensures compliance with India's DPDP data privacy laws for 1.33 Cr+ loyalty users — a scale that spans standalone brand programs as well as complex multi-tenant mall environments.

Architecturally, ConsentFirst operates as a consent ledger service. Every consent event — grant, withdrawal, modification, expiry — is written as an immutable log entry with timestamp, channel of capture, consent version, and the specific purposes it covers. When the Fundle AI Workflow engine prepares to fire a trigger — say, a win-back campaign for a lapsed Reliance Trends member — it calls the ConsentFirst API in real time. The API returns a consent status object: valid or invalid, with the reason code if invalid (withdrawn, expired, purpose mismatch, or never captured). Only valid responses allow the workflow to proceed.

For in-store enrolment — still the dominant channel for Indian loyalty sign-ups, accounting for 60-70% of new member acquisition at brands like Lifestyle, Westside, and Manyavar — ConsentFirst integrates with POS systems including Petpooja, POSist, GoFrugal, and Wondersoft. The POS integration displays a consent collection screen that meets DPDP's 'free, specific, informed, unconditional' standard: each purpose (transactional alerts, marketing communications, cross-brand offers, research surveys) is presented as a separate, individually toggleable option, none of which is pre-selected. The member's choices are synced to the ConsentFirst ledger within the same POS session.

For existing members enrolled before DPDP rules are notified, ConsentFirst includes a consent refresh workflow — a sequenced outreach via WhatsApp, SMS, and app notification that presents each member with their current data usage and asks them to confirm, modify, or withdraw consent. This is not a one-time blast; it is a structured campaign with follow-up logic, suppression rules for non-responders, and a compliance deadline tracker that gives the CMO a daily view of what percentage of the active member base has a valid DPDP consent record.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

5-Step Playbook: Implementing DPDP Compliant Loyalty Automation

01

Consent Audit & Gap Analysis

Export your entire active member database and classify each record by consent completeness: full DPDP-valid, partial (missing purpose specificity), or absent (T&C checkbox only). For a 20-lakh member program, expect 60-70% to fall in the partial or absent category. This audit defines your compliance gap and prioritisation sequence — highest-spend members get consent refresh outreach first.

02

Redesign Enrolment Consent UX

Rebuild your POS and digital enrolment flows with purpose-specific, individually toggleable consent options. Test with a sample of 500 in-store enrolments across 3-5 locations before full rollout. Measure consent capture rate per purpose — expect marketing communications consent to clock at 55-65% of new enrolees, which is lower than your current 100% assumed rate but far more legally defensible.

03

Deploy ConsentFirst CMP and Integrate with Automation Stack

Integrate the Fundle ConsentFirst API with your CRM, campaign orchestration tool, and POS systems. Map every existing automation workflow to the consent purpose it requires. Workflows that cannot be mapped to an existing consent purpose must be paused until a compliant consent path is established. This step typically takes 6-8 weeks for a mid-sized retail chain.

04

Run Consent Refresh Campaign for Existing Members

Deploy a phased consent refresh campaign via WhatsApp Business API and SMS, segmented by member value tier. Offer a points incentive (500-1000 bonus points) for completing the consent refresh — this typically lifts refresh completion rates from 18% to 38% in Indian retail contexts. Set a hard compliance deadline and suppress non-responders from automation workflows after that date.

05

Monitor KPIs and Iterate with Fundle AI Agents

Post-deployment, track six KPIs weekly: consent capture rate for new enrolments, consent withdrawal rate, automation suppression rate (% of triggered campaigns blocked by ConsentFirst), data breach response time, RFM reachability (% of active members reachable under DPDP constraints), and consent refresh completion rate. Use Fundle AI Agents to flag anomalies — a sudden spike in withdrawal rate often signals a poorly received campaign that needs to be redesigned.

Challenges and Mitigation Strategies for DPDP Loyalty Compliance

The most common objection from Loyalty Program Managers when DPDP compliance is tabled is the reachability problem: 'If only 32% of my database has valid consent, I've just lost 68% of my automation audience overnight.' This is a real commercial concern, and it deserves a real answer rather than reassurance.

The mitigation strategy has two parts. First, the 32% with valid consent are almost certainly your highest-value members — they are the ones who engaged with your app, opted into notifications, and actively chose to receive communications. An RFM analysis on any large Indian loyalty program will show that the top 30-35% of members generate 65-70% of program revenue. You are not losing your best customers; you are losing the dormant tail that was generating noise, not revenue. Second, the consent refresh campaign — when designed well with a points incentive and clear value articulation — will recover 35-45% of the lapsed consent pool within 90 days, bringing your compliant reachable base to 55-60% within a quarter.

The second major challenge is POS integration complexity. Indian retail runs on a fragmented POS landscape: Petpooja dominates F&B, POSist is strong in quick-service restaurant chains, GoFrugal and Wondersoft cover general retail, and many large format retailers like Shoppers Stop and Lifestyle run proprietary POS systems. Each integration requires a different consent data schema mapping. Fundle's POS connectors handle the most common systems out of the box, but custom integrations for proprietary systems typically add 4-6 weeks to the project timeline.

The third challenge is staff training. In-store associates at Pantaloons or Manyavar who handle POS enrolment are not data privacy specialists. They need a simple, scripted explanation of why the consent screen looks different from last month and how to guide customers through it in 60-90 seconds without creating queue friction. This is an operations and training problem, not a technology problem, but it is consistently underestimated in DPDP implementation projects.

DPDP Compliance Readiness Checklist for Loyalty Program Managers
  • Completed a full consent audit of your active member database, classifying each record as DPDP-valid, partial, or absent
  • Redesigned enrolment consent UX at POS and digital touchpoints to meet DPDP's free, specific, informed, unconditional standard with individually toggleable purposes
  • Integrated a Consent Management Platform (ConsentFirst or equivalent) that checks consent status in real time before every automation trigger fires
  • Mapped every active automation workflow to the specific consent purpose it requires and paused workflows that lack a compliant consent path
  • Deployed and completed a consent refresh campaign for members enrolled before DPDP rules were notified, with a hard suppression deadline for non-responders
  • Established a member-facing consent withdrawal mechanism that reflects across all automation systems within 60 minutes of withdrawal
  • Defined and are tracking the six core DPDP loyalty KPIs: consent capture rate, withdrawal rate, suppression rate, breach response time, RFM reachability, and refresh completion rate
“In Indian retail, consent is not a compliance cost — it is a signal of intent. The member who explicitly opts in to five communication purposes is worth ten times the one who never chose anything.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

The Fundle AI Platform was designed from the ground up for the Indian retail and mall context — a market defined by high transaction volumes, multi-tenant complexity, fragmented POS infrastructure, and customers who interact with brands in Hindi, Tamil, Telugu, and a dozen other languages alongside English. Every architectural decision in the platform reflects these realities, and DPDP compliance is not a module added on top — it is the foundation layer.

Fundle Loyalty — the core program engine — connects member enrolment, points accounting, tier management, and reward fulfilment to ConsentFirst at the data layer. When a member's consent status changes, the change propagates across all downstream systems — the campaign queue, the personalisation engine, the cross-tenant data sharing rules — within 60 seconds. This is what 'real-time consent enforcement' means in practice, and it is what separates Fundle from platforms like Capillary or EasyRewardz, which were built before DPDP was a consideration and require significant custom development to retrofit compliance.

Fundle Mall Loyalty extends these capabilities to multi-tenant mall environments. Mall operators at Phoenix Marketcity or Select CITYWALK can see, in a single dashboard, the consent coverage across their entire tenant mix — which tenants have the highest consent capture rates, which automation workflows are being suppressed most frequently due to consent gaps, and what the compliance exposure is if a specific workflow is run today. This operator-level visibility is what CMOs need when they are accountable to the Data Protection Board.

Fundle AI Agents and Fundle Agentic AI take compliance beyond passive enforcement into active optimisation. The agents monitor consent refresh completion rates in real time, identify members who are approaching consent expiry dates, and automatically queue personalised renewal requests before expiry occurs — so the compliant reachable base stays as large as possible without human intervention. Fundle AI Workflow orchestrates these agentic loops within the guardrails set by ConsentFirst, ensuring that no automation — however sophisticated — can bypass the consent check layer.

Fundle Brand Loyalty serves standalone retail chains — Reliance Trends, Lifestyle, Lenskart, Tanishq — with the same ConsentFirst architecture scaled to single-brand programs. Vineet Narang's founding vision for Fundle was that India's retail operators should never have to choose between deep personalisation and responsible data stewardship. With DPDP compliant loyalty automation now a commercial and legal imperative, that vision has become the table stakes for any serious loyalty platform operating in India.

Frequently asked

When does DPDP compliance become mandatory for loyalty programs in India?+

The DPDP Act was notified in August 2023. Specific rules, including those governing significant data fiduciaries, are being notified in tranches throughout 2024-2025. The Data Protection Board is expected to be operational by 2025. Loyalty program managers should treat the compliance deadline as immediate — implementing consent infrastructure now is far less disruptive than doing it under a regulatory deadline.

Does every Indian loyalty program need to comply, or only large ones?+

DPDP applies to all data fiduciaries processing digital personal data in India. However, 'significant data fiduciaries' — a category defined by the government based on volume, sensitivity, and risk — face the highest penalties (up to ₹250 crore per instance). Any loyalty program with more than 10 lakh members should assume it will be classified as a significant data fiduciary and plan accordingly.

What is ConsentFirst CMP and how does it differ from a standard CRM consent field?+

ConsentFirst is Fundle's purpose-built Consent Management Platform. Unlike a CRM consent field (a single boolean that records whether the member opted in or out), ConsentFirst maintains a purpose-specific, time-stamped, immutable consent ledger per member. It integrates directly with automation workflows so that every trigger checks live consent status before firing. A CRM consent field is a record; ConsentFirst is an enforcement layer.

How does DPDP affect cross-tenant data sharing in mall loyalty programs?+

Cross-tenant data sharing — sharing a member's purchase history from one tenant with another for targeting — requires explicit, separately captured, individually withdrawable consent for each data-sharing purpose under DPDP. Mall operators cannot rely on a general enrolment consent to cover cross-tenant profiling. Fundle Mall Loyalty's ConsentFirst architecture enforces this at the data layer, so no cross-tenant automation fires without purpose-specific consent.

What happens to members who do not complete the consent refresh campaign?+

Members who do not complete the consent refresh by the compliance deadline should be suppressed from all marketing automation workflows. They can still earn and redeem points (transactional processing does not require marketing consent), but they cannot be targeted with campaigns. Fundle AI Agents automatically move these members to a suppressed segment and flag them for re-engagement via a minimal-touch outreach every 90 days.

Can we use DPDP compliance as a member engagement opportunity rather than just a cost?+

Yes — and the best Indian loyalty programs are doing exactly this. A well-designed consent refresh campaign, with a clear articulation of member benefits ('tell us what you care about and we'll only send you offers that match') and a bonus points incentive, consistently produces higher engagement scores than standard re-engagement campaigns. Members who consciously opt into specific purposes show 2.3x higher redemption rates than the average program member.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

A

Abhinav · Fundle.ai

Loyalty & ADSR Expert · Online

Hey 👋 I'm Abhinav from Fundle. Are you exploring loyalty for a brand or a mall?
Powered by Fundle AI · Replies in under 30 sec