“Brand loyalty rewards what you bought. Fundle Mall Loyalty rewards where you spent your day — and that data is 10x more valuable to the next campaign.”
- •Understand how India's DPDP Act 2023 changes consent obligations for loyalty programs
- •Audit your current loyalty stack against the seven data principal rights under DPDP
- •Build a consent-based loyalty data architecture that collects only what you need
- •Measure the business impact of privacy-first loyalty using RFM and opt-in rate KPIs
- •Migrate to a purpose-built first party data platform for loyalty India like Fundle.ai
India's loyalty landscape has never faced a compliance inflection point quite like this. The Digital Personal Data Protection Act 2023 — DPDP — received Presidential assent in August 2023 and its rules are expected to be enforced in phases beginning 2025. For any Indian retail CMO or CIO running a points programme, a coalition mall loyalty scheme, or a brand CRM, the law is not a distant regulatory abstraction. It is a hard deadline sitting inside your FY26 technology roadmap.
The core disruption is this: loyalty programmes are, by definition, data-hungry. A mid-sized mall operator running a coalition scheme across 200 brand partners — think Phoenix Marketcity or Select CITYWALK — may be sitting on 15–20 million member records, each carrying purchase history, demographic data, communication preferences, and increasingly, inferred behavioural segments. Under the old Personal Data Protection Bill drafts, the compliance bar was debated but never enforced. Under DPDP, it is law. Consent must be free, specific, informed, and unconditional. Data principals — your loyalty members — have the right to access, correct, and erase their data on demand. Violations can attract penalties of up to ₹250 crore per breach.
For brands like Tanishq, Lenskart, Manyavar, and Apollo Pharmacy that have invested heavily in CRM and loyalty over the last five years, the question is not whether to comply — it is how to comply without cannibalising the personalisation engine that drives repeat purchase. That is the strategic tension this article unpacks. A first party data platform for loyalty India needs to do two things simultaneously: give regulators the consent architecture they demand, and give marketers the behavioural signals they need to move a Pantaloons shopper from two visits a year to six.
Fundle was built for exactly this moment. Across mall loyalty, brand loyalty, and enterprise retail CRM, the Fundle AI Platform is designed around consent-first data collection without forcing operators to choose between compliance and customer intelligence. The sections that follow offer a practitioner's guide to navigating DPDP, evaluating platforms, and building a loyalty data architecture that is both legally sound and commercially productive.
India Loyalty & DPDP: The Numbers That Matter
DPDP Regulatory Changes Affecting Loyalty Data
The DPDP Act 2023 introduces four structural changes that directly impact how loyalty programmes operate in India. First, and most consequentially, it replaces implied consent with explicit, purpose-specific consent. Today, most Indian loyalty schemes enrol members at the point-of-sale with a single checkbox or verbal confirmation — a practice that was commercially convenient but legally grey. Under DPDP, every distinct purpose of data processing requires a separate, granular consent notice. Collecting a mobile number to issue points is one purpose. Using that number to send a Diwali campaign is another. Sharing purchase history with a brand partner inside a mall coalition is a third. Each requires its own consent record with a timestamp and channel attribution.
Second, the Act establishes seven data principal rights that loyalty operators must operationalise — not just acknowledge in a privacy policy. These include the right to access a summary of personal data held, the right to correct inaccurate data, the right to erasure, the right to grievance redressal within a defined SLA, and the right to nominate a representative. For a mall operator running a loyalty scheme on legacy software — many still run on on-premise tools from vendors like Petpooja, POSist, GoFrugal, or Wondersoft — building a self-service member portal that honours these rights is a non-trivial engineering project.
Third, the Act requires data localisation for certain categories of sensitive personal data. While the final rules are awaited, loyalty data that includes financial transaction history, health-adjacent purchase data (relevant for Apollo Pharmacy or pharma retail loyalty), or children's data will almost certainly fall under heightened protection requirements. This has direct implications for cloud hosting architecture and any offshore data processing arrangements.
Fourth, the consent manager framework introduced in the Act creates a new intermediary layer. Consent managers — registered with the Data Protection Board — will allow consumers to manage all their data consents from a single interface, potentially cutting across multiple brands and loyalty programmes. For CIOs, this means loyalty platforms must expose consent APIs that are interoperable with these registered consent managers. Platforms that cannot support this integration will face structural obsolescence within two to three years. The shift from permission-by-default to permission-by-design is not cosmetic — it requires re-architecting the data collection layer of every loyalty programme in India.
DPDP Consent Funnel for Indian Loyalty Programmes
Requirements for First Party Data Platforms
Not every CRM or loyalty platform qualifies as a first party data platform for loyalty India under the DPDP framework. The compliance gap between what most platforms offer and what the law demands is significant, and CMOs evaluating vendors need to ask hard technical questions before FY26 budgets are locked.
The foundational requirement is a consent ledger — an immutable, timestamped record of every consent event for every data principal. This is distinct from a standard opt-in log. A DPDP-grade consent ledger must record the exact consent notice shown to the member (versioned), the channel on which consent was collected (POS terminal, app, SMS, WhatsApp), the purpose for which consent was given, and any subsequent withdrawal or modification. Platforms like Capillary, EasyRewardz, and Xeno have strong CRM capabilities but were not architecturally designed around DPDP's consent-ledger requirement. Retrofitting consent management onto an existing CDP or loyalty engine is technically complex and carries audit risk.
The second requirement is a member-facing data rights portal. This is not a static privacy policy page. It is a live, authenticated interface where a Reliance Trends or FabIndia loyalty member can view their data, request correction, download a structured export, or submit a deletion request — with the platform completing the request within the DPDP-mandated timeline and generating a compliance event log. Building this on top of a platform that was not designed for it means custom development that creates maintenance debt.
Third, the platform must support purpose-bound data activation. When a loyalty marketer at Lifestyle wants to run a re-engagement campaign targeting lapsed members, the platform must automatically filter the audience to members who have consented to that specific communication purpose. This is not a manual segmentation step — it must be enforced at the data layer, not the campaign execution layer. The distinction matters enormously for audit readiness.
Fourth, for mall coalition programmes, the platform must enforce consent at the brand-partner level. A member who shops at Cafe Coffee Day inside a Phoenix mall and consents to points issuance has not necessarily consented to CCD receiving their cross-mall purchase history. The consent architecture must be granular enough to honour these distinctions, which requires a data model that is materially more complex than what most coalition loyalty engines in India currently run.
Finally, the platform must support API-level integration with POS systems. India's retail POS ecosystem is fragmented — POSist, GoFrugal, Wondersoft, Petpooja, and dozens of proprietary systems all co-exist within a single mall. A DPDP-compliant loyalty platform cannot rely on manual data uploads or batch ETL jobs that obscure consent chain-of-custody. Real-time POS integration is not just a feature — under DPDP, it is a compliance necessity.
DPDP-Ready vs Legacy Loyalty Platforms: Capability Gap
Transparency and Consumer Rights under DPDP
The DPDP Act's consumer rights provisions are, in practical terms, a customer experience challenge as much as a legal one. Retailers who treat the data rights portal as a compliance checkbox will miss the commercial opportunity embedded in the obligation. Brands that build genuinely transparent, easy-to-use data control experiences will differentiate on trust — a scarce commodity in Indian retail CRM, where most consumers have no idea what data their loyalty programme holds.
Consider the access right. Under DPDP, a loyalty member can request a summary of what personal data the operator holds. For a Manyavar loyalty member who has transacted across six cities over three years, this summary might include transaction history, demographic data, communication preferences, inferred lifestyle segments, and partner-shared data from a coalition programme. Delivering this in a readable, jargon-free format within a statutory timeline is an engineering and UX challenge. Platforms that expose raw database exports will frustrate members and attract regulator attention. Platforms that deliver a clean, human-readable data summary through a branded member app will build trust.
The erasure right presents the sharpest operational challenge. When a member requests deletion, the loyalty operator must purge personal data from the primary system, from any partner systems where data was shared, and from backup and analytics environments — while retaining only what is necessary for legitimate legal or financial record-keeping. For a mall coalition scheme where data flows across 50 or more brand partners, operationalising erasure requires a data lineage map that most current platforms do not maintain.
The correction right is commercially underrated. Inaccurate data — wrong mobile numbers, misattributed transactions, outdated addresses — silently destroys loyalty programme ROI. A DPDP-mandated correction workflow, if designed well, becomes a data quality improvement mechanism. Operators who encourage members to verify and correct their data through the rights portal will find their first-party data assets become meaningfully more accurate over 12–18 months.
The grievance redressal obligation requires appointing a Data Protection Officer and publishing a contact mechanism with a defined response SLA. For mid-sized mall operators and single-brand retailers, this is often the most overlooked DPDP requirement. A consumer who cannot reach the DPO within a reasonable time has a direct escalation path to the Data Protection Board — and a ₹10,000 per-day penalty clock starts running on the operator.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
5-Step Playbook: Building DPDP-Compliant Loyalty Data Architecture
Consent Architecture Audit
Map every data collection touchpoint in your current loyalty programme — POS, app, WhatsApp, in-mall kiosks, brand partner APIs — and document the consent basis for each data flow. Identify gaps where processing occurs without a valid, purpose-specific DPDP consent record. This audit typically takes 4–6 weeks for a mid-sized mall operator and is the prerequisite for every subsequent step.
Consent Ledger Implementation
Deploy an immutable consent ledger at the data layer of your loyalty platform. Every consent event — grant, withdrawal, modification — must be written as an append-only record with consent notice version, timestamp, channel, member identifier, and purpose code. Ensure the ledger is queryable for regulatory audit within 24 hours. Integrate consent status as a mandatory attribute in your member master data model.
Member Data Rights Portal Build
Build or procure a self-service member portal — mobile-first, vernacular-supported — that allows data principals to exercise all seven DPDP rights. Set internal SLA targets 20% tighter than statutory deadlines to absorb operational variance. Integrate the portal with your data erasure workflow, your partner data-sharing APIs, and your DPO ticketing system. Test with a 500-member pilot before full rollout.
Purpose-Bound Segmentation Enforcement
Re-architect your campaign and segmentation tooling so that consent status is enforced automatically at query time, not manually by the campaign manager. Every audience segment must be pre-filtered to include only members who have consented to the specific communication purpose being activated. Log every campaign execution against the consent records used, creating an auditable activation trail.
POS and Partner API Consent Passthrough
Upgrade POS integrations to pass consent metadata — member ID, consent timestamp, purpose codes — in real time with every transaction event. For coalition programmes, implement partner-level consent gates that prevent brand partners from accessing member data beyond what the member has explicitly consented to share. Conduct quarterly consent-chain audits across all active partner integrations.
Tools and Technologies to Ensure Compliance
The Indian martech and loyalty-tech vendor landscape has matured rapidly but DPDP compliance capability varies enormously across the field. CMOs and CIOs evaluating platforms in 2025 need to assess vendors across five technology dimensions: consent management infrastructure, data rights workflow tooling, POS integration depth, consent-aware AI activation, and audit reporting.
On consent management, the dominant CRM platforms in Indian retail — MoEngage, WebEngage, and Capillary — have added consent fields and preference centres to their products but these implementations are typically layered on top of existing architectures rather than native to the data model. The practical risk is that consent status can fall out of sync with campaign execution in ways that are not immediately visible in the campaign dashboard but are clearly visible in an audit log. Almonds.ai and Customer Capital offer niche loyalty capabilities but similarly lack purpose-built DPDP consent ledger infrastructure at this stage.
For POS integration, depth matters more than breadth. A platform that claims to integrate with 50 POS systems via generic webhooks is not the same as one that has certified, real-time API integrations with POSist, GoFrugal, and Wondersoft that pass consent metadata alongside transaction data. The former creates compliance gaps at the most important data collection point in retail — the moment of purchase.
Consent-aware AI activation is the emerging differentiator. As Indian retailers invest in AI-driven personalisation — next-best-offer engines, churn prediction, basket size optimisation — the AI models must operate only on data for which the necessary consent exists. A loyalty platform that runs AI on the full member dataset without consent filtering is creating regulatory liability with every model run. The architecture requirement is a consent-aware feature store that automatically excludes non-consented data attributes from model training and inference.
Audit reporting capability is often assessed last but matters first in a regulatory examination. The platform must be able to produce, on demand, a complete data processing record for any individual member — every consent event, every data access, every campaign inclusion, every partner data share — in a format that satisfies a Data Protection Board inquiry. Platforms that cannot produce this report within hours are not DPDP-ready regardless of their other capabilities.
Fundle's platform supports Indian POS and brand integrations ensuring DPDP compliance — a design principle that runs from the consent collection layer through to campaign activation and audit reporting, rather than being bolted on as a compliance module.
- Purpose-specific consent notices drafted, versioned, and deployed for every distinct data processing activity in the loyalty programme
- Immutable consent ledger implemented at the data layer with timestamp, channel, purpose code, and notice version for every consent event
- Self-service member data rights portal live, mobile-first, supporting access, correction, erasure, and grievance with statutory SLA tracking
- Data Protection Officer appointed and DPO contact published across all member-facing loyalty touchpoints including app, mailer, and POS receipts
- POS integrations upgraded to pass consent metadata in real time — verified for POSist, GoFrugal, Wondersoft, and any other active POS systems
- Partner data-sharing APIs governed by member-level, purpose-bound consent gates — no coalition partner receives data beyond explicit member consent
- Consent-aware segmentation enforced at data query layer — campaign managers cannot build audiences without consent status auto-filtering being applied
“In Indian retail, consent is not a legal checkbox — it is the foundation of a loyalty relationship. The brands that build trust at data collection will own the customer for the next decade.”
How Fundle solves this
Fundle was designed from inception as a consent-first, AI-native loyalty platform — not a legacy CRM with a compliance module stapled to the side. The Fundle AI Platform treats the consent ledger as a core data primitive, not an afterthought. Every member record in the Fundle Loyalty database carries a live consent state object that is updated in real time as members grant, modify, or withdraw consent across channels. This consent state is not a flag in a CRM field — it is a versioned, append-only ledger entry that satisfies DPDP audit requirements without any additional reporting configuration.
For mall operators, Fundle Mall Loyalty delivers the coalition consent architecture that India's complex mall ecosystem demands. A member shopping at a Phoenix Marketcity or Select CITYWALK property can consent to points issuance, mall-level marketing, and individual brand-partner communications as separate, independently revocable permissions. Fundle Mall Loyalty enforces these permissions at the brand-partner API layer — no brand receives data beyond what the member has explicitly permitted, regardless of what the brand's own marketing team requests. This is not a policy commitment — it is a technical enforcement that creates an audit trail.
For enterprise retail brands — whether a single-brand CRM for a Lifestyle or a multi-format loyalty scheme for a large pharmacy chain — Fundle Brand Loyalty delivers purpose-bound AI personalisation. The Fundle AI Agents that power next-best-offer, churn prediction, and win-back campaigns operate exclusively on consent-approved data attributes. The Fundle AI Workflow orchestrates campaign execution so that every audience segment is certified consent-compliant before a single message is dispatched. Fundle Agentic AI can autonomously detect when a member's consent state changes — a withdrawal, for instance — and immediately suppress that member from all active campaign queues without waiting for a nightly batch job.
Vineet Narang's founding vision for Fundle was that Indian retail loyalty had conflated data volume with data value for too long. A consent-based loyalty data management architecture, properly implemented, produces a smaller but exponentially more actionable first-party data asset. The brands on the Fundle AI Platform are already seeing this in practice: opt-in rates above 70% among members enrolled through the Fundle consent flow, versus industry averages of 30–40% for legacy enrolment methods. Higher opt-in rates mean larger activated audiences, more accurate AI models, and loyalty economics that improve as the consent base compounds — precisely the opposite of what most compliance teams fear when they hear 'DPDP'.
Frequently asked
What is a first party data platform for loyalty India and how does it differ from a standard CRM?+
A first party data platform for loyalty India is a purpose-built system that collects, stores, and activates member data collected directly by the loyalty operator — not bought or rented from third parties. Unlike a standard CRM, a DPDP-compliant first party data platform enforces consent at the data layer, maintains an immutable consent ledger, supports member data rights workflows, and ensures purpose-bound data activation across every campaign and AI model run.
When does DPDP enforcement begin for Indian loyalty programmes?+
The DPDP Act 2023 received Presidential assent in August 2023. Enforcement rules are expected to be notified in phases during 2025, with larger data fiduciaries — likely those processing above a threshold volume of personal data — facing earlier compliance deadlines. Loyalty operators running programmes with more than one million members should treat FY26 Q1 as the practical compliance deadline and begin platform assessments immediately.
Can we add DPDP compliance to our existing loyalty platform or do we need to migrate?+
Most legacy loyalty and CRM platforms in India — including well-known names in the Indian market — were not designed with a consent ledger as a core data primitive. Adding DPDP compliance as a module typically addresses surface requirements like preference centres but leaves structural gaps in audit trail completeness, purpose-bound segmentation enforcement, and partner data-sharing governance. For programmes with more than 500,000 members, a migration to a purpose-built platform is usually the lower-risk long-term path.
How does consent-based loyalty data management affect personalisation and AI model performance?+
Counterintuitively, consent-based loyalty data management tends to improve AI model performance over 12–18 months. Consented data attributes are more accurate because members have actively verified them. Consented audiences are more engaged because they have opted in to communication. AI models trained on clean, consented data outperform models trained on large, noisy datasets that include passive or lapsed members. Fundle platform benchmarks show 3.2x higher customer lifetime value for consent-enrolled members versus passively enrolled ones.
What POS systems does a DPDP-compliant loyalty platform need to integrate with?+
India's retail POS ecosystem is highly fragmented. A DPDP-compliant loyalty platform needs certified, real-time API integrations — not batch file transfers — with the major platforms: POSist, GoFrugal, Wondersoft, Petpooja, and major proprietary POS systems used by large format retailers. The integration must pass consent metadata alongside transaction data so the consent chain-of-custody is preserved from the point of collection through to campaign activation and audit reporting.
How does Fundle handle the right to erasure for mall coalition loyalty programmes where data is shared across brand partners?+
Fundle Mall Loyalty maintains a complete data lineage map for every member record, tracking every instance of data shared with coalition brand partners. When a member submits an erasure request, the Fundle AI Platform initiates a cascading deletion workflow that covers the primary member record, all partner-shared data instances, and backup environments — while preserving only what is required for statutory financial record-keeping. The entire erasure workflow is logged and timestamped to satisfy Data Protection Board audit requirements.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
