“Indian retail is the most dynamic consumer market on the planet. The platforms it deserves should be the most dynamic too. That conviction is why Fundle exists.”
- •Understand why India's DPDP Act 2023 imposes strict consent obligations on every AI-powered loyalty agent platforms India operator
- •Recognise the five consent management gaps that expose mall loyalty programs to regulatory penalties up to ₹250 crore
- •See how Fundle's ConsentFirst CMP handles granular, revocable, multilingual consent at scale across 1.33 crore loyalty members
- •Quantify the business impact: higher opt-in rates, faster AI model retraining, and audit-ready data trails
- •Map a five-step playbook to future-proof your loyalty compliance before the DPDP enforcement clock runs out
Indian retail is living through a once-in-a-generation data reckoning. For decades, mall operators and retail chains collected shopper data with little more than a checkbox buried in a membership form. A phone number here, an email there, sometimes a PAN for high-value purchases — all aggregated into CRM silos that fed batch SMS blasts and quarterly mailers. That era is ending. India's Digital Personal Data Protection Act 2023, notified in August 2023, places explicit, informed, and revocable consent at the centre of every data transaction. For loyalty programs powered by AI-powered loyalty agent platforms India operators are now deploying, the compliance stakes are existential.
Consider the scale. Phoenix Marketcity malls collectively host tens of thousands of members per property. Select CITYWALK in Saket alone sees over 40,000 footfalls on a busy weekend. Lifestyle, Pantaloons, Manyavar, and FabIndia each run multi-million-member loyalty databases that feed real-time personalisation engines. Multiply those touchpoints by the new requirement to capture purpose-specific, language-comprehensible, freely withdrawable consent — and you have an operational challenge that no legacy CRM or point-of-sale system was designed to handle. Platforms like Capillary, EasyRewardz, and Xeno have strong transactional loyalty features but were architected before agentic AI and DPDP-grade consent management became non-negotiable. The consent layer is simply bolted on, not built in.
Agentic AI makes this harder, not easier. When an AI loyalty agent autonomously sends a Tanishq customer a gold-price alert, cross-sells a Lenskart lens upgrade based on purchase history, or triggers a re-engagement flow for a churned Apollo Pharmacy member, each action involves processing personal data for a specific inferred purpose. Under DPDP, that purpose must have been explicitly consented to at enrollment — or the member must be re-consented before the agent fires. Without a consent management platform (CMP) that is natively wired into the AI orchestration layer, every autonomous agent action becomes a potential regulatory breach.
Fundle was built from the ground up to solve this intersection of agentic AI and data privacy. The Fundle AI Platform's ConsentFirst architecture treats consent not as a legal checkbox but as a first-class data entity that gates every AI workflow, every personalised offer, and every cross-brand communication inside the mall ecosystem. This article breaks down what DPDP actually demands, where legacy loyalty platforms fall short, and how ConsentFirst operationalises compliance at scale.
India Loyalty + DPDP: Four Numbers Every Mall CMO Must Know
Overview of India's DPDP 2023 Data Privacy Law
The Digital Personal Data Protection Act 2023 is India's first comprehensive data privacy statute, and it is structurally different from the patchwork of sectoral rules that preceded it. The Act defines a 'Data Principal' — the individual — as the sovereign owner of their personal data, and a 'Data Fiduciary' — the company collecting and processing it — as the responsible steward. For a mall operator or retail chain running a loyalty program, you are a Data Fiduciary the moment you store a member's phone number, purchase history, or location ping.
The consent obligations under DPDP are specific and non-negotiable. Consent must be free — no bundling loyalty benefits with a forced data grab. It must be specific — you cannot collect a single omnibus consent for all future uses. It must be informed — the purpose must be explained in plain language, and by rule, in at least one of India's 22 scheduled languages if the member requests it. It must be unconditional — you cannot make loyalty enrollment contingent on consent to marketing. And crucially, it must be revocable — a member can withdraw consent at any time, and you must honour that withdrawal within a defined window, erasing downstream processing from AI models and recommendation engines.
For AI-powered loyalty agent platforms India operators are adopting, the 'specific purpose' requirement creates a layered compliance architecture. A consent to 'receive offers' does not cover an AI agent inferring a customer's pregnancy from purchase patterns and sending maternity-wear promotions. A consent to 'transaction alerts' does not cover a cross-brand recommendation engine suggesting a competitor's product category. Each AI workflow must map back to a named, consented purpose — and the consent record must be queryable in real time before the agent fires.
The penalties make this urgent. The DPDP Act allows the Data Protection Board to impose fines of up to ₹250 crore for significant violations and up to ₹50 crore for failures to implement reasonable security safeguards. More immediately, a member's right to grievance redressal means that any loyalty brand — Reliance Trends, Cafe Coffee Day, FabIndia — could face reputational damage from a single viral complaint about misused data, long before a formal regulatory proceeding begins. The compliance window is not infinite: the government has signalled that the Data Protection Board will be constituted within 18 months of the Act's notification, meaning enforcement is approaching.
The DPDP Consent Funnel: From Enrollment to AI Agent Action
Consent Management Challenges in Loyalty Programs
Loyalty programs have a structural consent problem that predates DPDP. They were designed to collect data, not to manage its permissions. The typical enrollment flow at a Lifestyle checkout counter, a Pantaloons loyalty kiosk, or a mall app onboarding screen presents a single 'I agree to terms and conditions' checkbox. The T&Cs — often 3,000 words in English, displayed in 8-point font — serve as the legal cover for everything from SMS marketing to third-party data sharing with anchor brands. This model is now illegal under DPDP and, frankly, it was always a fiction of consent rather than genuine member agreement.
The first challenge is consent granularity. A modern AI loyalty program needs to process member data for at least six distinct purposes: transaction recording, personalised offers, cross-brand recommendations, location-based triggers, predictive churn modelling, and aggregated analytics. Each of these is a separate purpose under DPDP and requires a separate consent signal. Legacy CRM platforms like POSist, Wondersoft, and GoFrugal — excellent at point-of-sale transaction recording — have no native consent taxonomy for AI-driven use cases. Integrating a compliant consent layer on top of these systems post-hoc is expensive and brittle.
The second challenge is consent revocation propagation. When a Manyavar loyalty member withdraws consent for personalised marketing, that signal must instantly cascade through every downstream system: the email platform, the SMS gateway, the AI recommendation engine, the data warehouse feeding lookalike modelling, and any third-party brand partners sharing that member's data. In a typical mall loyalty stack — which might involve three POS systems, two campaign platforms (MoEngage or WebEngage), and a separate analytics layer — this propagation is manual, slow, and error-prone. The member's right under DPDP to stop processing within a defined period cannot be met by a spreadsheet-driven deactivation workflow.
The third challenge is multilingual consent comprehension. India's retail geography spans Tamil-speaking shoppers in Chennai's Express Avenue, Hindi-dominant members in Lucknow's malls, Marathi-speaking customers at Pune's Phoenix, and Bengali members at South City Kolkata. DPDP's language accessibility requirement means consent notices must be genuinely comprehensible, not just technically available in translation. A poorly translated consent notice that a member cannot understand is, under the Act's spirit and likely its enforcement practice, equivalent to no consent at all. Building and maintaining 12-language consent flows, keeping them current with product changes, and serving them dynamically based on member preference is an infrastructure challenge that most loyalty platforms have not even begun to address.
ConsentFirst vs. Legacy Consent Approaches in Indian Loyalty
How Fundle's ConsentFirst CMP Works
Fundle's ConsentFirst is not a standalone consent banner bolted onto a loyalty app. It is a consent orchestration layer embedded inside the Fundle AI Platform that governs every data processing action taken by Fundle AI Agents, Fundle AI Workflow, and Fundle Agentic AI. The architecture rests on three principles: consent as a data entity, consent as a gate, and consent as a living record.
Consent as a data entity means that every consent signal — given, modified, or withdrawn — is stored as a structured record with five attributes: the member's unique identifier, the specific processing purpose, the version of the notice presented, the timestamp of the action, and the channel through which consent was captured (app, web, in-store kiosk, WhatsApp, or SMS). This record is versioned: if Fundle Mall Loyalty updates its personalisation policy, every affected member is re-consented on next touchpoint, and the old and new records are both retained for audit. The audit trail is exportable in a format ready for Data Protection Board scrutiny — no manual reconstruction required.
Consent as a gate means that before any Fundle Agentic AI action executes — a birthday offer push, a cross-brand recommendation from a mall anchor to a mid-market tenant, a churn-risk re-engagement SMS — the AI agent queries the consent engine in real time. If the member has not consented to that specific purpose, the action is suppressed and logged. This is architecturally non-bypassable: the consent check is a pre-execution hook in the Fundle AI Workflow orchestration layer, not a downstream filter that can be misconfigured. This is what makes Fundle Brand Loyalty deployments genuinely DPDP-compliant rather than just DPDP-aspirational.
Consent as a living record addresses revocation. When a member taps 'withdraw consent' in the Fundle app — or calls the brand's customer care line and triggers revocation through an in-store terminal — ConsentFirst fires a revocation event across the entire Fundle ecosystem simultaneously. AI recommendation models stop processing that member's data for the relevant purpose. Campaign queues drop the member from pending sends. Data warehouse exports for the next model training cycle are flagged to exclude that member's records for the relevant purpose category. Fundle's ConsentFirst manages user consent compliantly for over 1.33 crore loyalty members at this level of granularity — a scale that makes manual or semi-automated consent management architecturally impossible. The multilingual layer serves consent notices in 12 Indian languages, dynamically selected based on the member's registered app language, with a fallback to Hindi or English if no preference is set.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
Five Steps to Deploy DPDP-Compliant AI Loyalty: The ConsentFirst Playbook
Audit Your Current Consent Inventory
Map every data collection point in your loyalty stack — POS enrollment, app registration, WhatsApp opt-in, loyalty kiosks — and document the consent language presented at each. Identify which purposes you are currently processing data for without specific, DPDP-grade consent. This gap analysis is the baseline for your compliance roadmap and should be completed before any AI agent deployment.
Define Your Consent Taxonomy
Work with legal and marketing teams to enumerate every distinct processing purpose your AI loyalty program requires: transaction history, personalised offers, location-based triggers, cross-brand recommendations, predictive analytics, and third-party brand data sharing. Each purpose needs a plain-language description reviewed for comprehensibility by non-legal readers in each of your target languages. Fundle AI Platform provides a standard DPDP-aligned purpose library as a starting template.
Implement ConsentFirst at Every Enrollment Touchpoint
Deploy the ConsentFirst consent collection UI across all member touchpoints — app onboarding, web registration, in-store POS kiosk, and WhatsApp enrollment flows. Each touchpoint presents the relevant purpose toggles in the member's preferred language. Critically, loyalty benefits must not be bundled with marketing consent: a member must be able to earn and redeem points without agreeing to AI-personalised offers. Configure the consent capture flow to write structured records to the ConsentFirst data store in real time.
Wire Consent Gates into AI Agent Workflows
For every Fundle Agentic AI campaign or trigger — churn re-engagement, cross-sell, birthday offer, footfall incentive — embed a pre-execution consent gate that queries the ConsentFirst API before the action fires. This wiring happens inside the Fundle AI Workflow orchestration layer and requires no custom engineering from the mall CMO's team. Set suppression logging so that blocked actions are recorded for both compliance audit and agent performance analysis.
Test Revocation End-to-End and Train Your CX Teams
Before go-live, run a full revocation simulation: have a test member withdraw consent for one purpose and verify that within five minutes, the signal has propagated to every downstream system — campaign queue, recommendation engine, data warehouse, and third-party brand partner feeds. Train your in-store CX team and call centre staff on how to handle verbal revocation requests and enter them into the ConsentFirst system. Document the process for your compliance officer and ensure it is reviewable by the Data Protection Board on request.
Impact on AI Loyalty Agent Deployments Across Indian Retail
The business case for DPDP-compliant AI loyalty is not just risk avoidance — it is a measurable performance uplift. Members who give explicit, informed consent to personalisation are categorically higher-quality data subjects than those whose data is processed under ambiguous omnibus clauses. They are more likely to engage with offers, less likely to mark messages as spam, and more likely to trust the brand enough to share richer behavioural data over time. The consent conversation, done well, is also a brand-building moment.
Fundle AI Agents deployed on the ConsentFirst architecture consistently show higher campaign engagement rates compared to batch-blast campaigns run on unconsented data. When a Tanishq customer at a Phoenix Marketcity mall consents specifically to 'gold price alerts and occasion-based jewellery recommendations,' the AI agent's trigger is matched to a stated preference — not an inferred one. The open rate and conversion rate on that trigger are structurally higher because the member is primed to receive exactly that communication. This is what separates Fundle Brand Loyalty's personalisation from generic CRM automation.
For mall CMOs managing multi-brand loyalty ecosystems, ConsentFirst also solves the cross-brand data sharing problem that has stymied many mall-wide loyalty programs. A member who consents to 'cross-brand recommendations within the mall ecosystem' explicitly authorises the AI recommendation engine to suggest a Lenskart frames offer to a Lifestyle apparel customer who has demonstrated an accessory purchase pattern. Without that explicit consent, cross-brand AI recommendations are a legal liability. With ConsentFirst, the consent record is the authorisation token that unlocks the AI agent's cross-brand action — making the entire mall loyalty ecosystem both smarter and safer.
On the AI model training side, DPDP's purpose limitation principle means that member data can only be used to train AI models for the purposes consented to. ConsentFirst's structured consent records feed directly into Fundle AI Platform's model training pipelines, automatically excluding members who have not consented to 'analytics and model improvement' from training datasets. This keeps AI models clean from a regulatory standpoint and, counterintuitively, often improves model quality by ensuring training data comes from genuinely engaged, consent-positive members whose behaviour is more representative of your target segment.
- Map all data collection touchpoints and document the consent language currently presented at each one
- Define a DPDP-aligned purpose taxonomy covering every AI agent action in your loyalty program
- Ensure loyalty benefits are decoupled from marketing consent so members can enroll without agreeing to AI personalisation
- Deploy multilingual consent notices (minimum 8 Indian languages) across all digital enrollment channels
- Wire real-time consent gates into every AI agent workflow before the agent executes any data processing action
- Implement automated consent revocation propagation that reaches all downstream systems within a defined SLA
- Maintain versioned, timestamped, audit-ready consent records exportable for Data Protection Board scrutiny
“In Indian retail, consent is not a legal footnote — it is the foundation of every profitable AI interaction. The brands that earn genuine permission will own the next decade of customer relationships.”
How Fundle solves this
Vineet Narang's founding vision for Fundle was always that AI in loyalty must be trustworthy before it can be powerful. That principle is architecturally encoded in the Fundle AI Platform, where ConsentFirst is not a module you can turn off or configure around — it is the operating system underneath Fundle AI Agents, Fundle Agentic AI, and Fundle AI Workflow. Every autonomous action, every personalised offer, every cross-brand recommendation in the Fundle Mall Loyalty and Fundle Brand Loyalty ecosystems runs through a consent verification step that is invisible to the end member but ironclad from a regulatory standpoint.
The Fundle Loyalty platform approaches DPDP compliance as a product discipline rather than a legal obligation. The ConsentFirst CMP was designed with input from Indian data privacy counsel and tested against the DPDP Act's draft rules to ensure that the consent flows, the purpose taxonomy, the multilingual notice library, and the revocation propagation architecture meet the Act's requirements as currently drafted and are adaptable as the Data Protection Board issues further guidance. For a mall CMO at a Phoenix Marketcity, Select CITYWALK, or DLF Mall of India property, this means deploying AI loyalty agents without needing to build a dedicated privacy engineering team.
Fundle Agentic AI's consent-gated architecture also creates a competitive advantage in member acquisition. When a new member enrolls at a Reliance Trends or Manyavar counter and encounters a clean, transparent, multilingual consent flow that explains exactly what data will be used for and gives them genuine control, the enrollment conversion rate improves and, more importantly, the quality of the enrolled member improves. These members are more likely to engage, more likely to refer, and more likely to consent to richer data sharing over time as they build trust with the brand. The Fundle AI Workflow then uses this expanding consent surface to safely unlock more sophisticated personalisation — not because the AI has inferred permission, but because the member has granted it.
For Indian retail chains evaluating AI-powered loyalty agent platforms India vendors — comparing Fundle against Capillary's newer AI features, Antavo's enterprise tier, or Customer Capital's analytics-led approach — the ConsentFirst architecture is the clearest point of differentiation. Compliance is not a future upgrade on the Fundle roadmap; it is the current state of every Fundle deployment. With 1.33 crore loyalty members already managed under ConsentFirst, the platform has the scale evidence, the audit infrastructure, and the product maturity to be the compliance-first choice for any Indian mall operator or retail chain that takes DPDP seriously.
Frequently asked
What is India's DPDP Act 2023 and why does it matter for loyalty programs?+
The Digital Personal Data Protection Act 2023 is India's first comprehensive data privacy law. It requires every organisation that collects and processes personal data — including loyalty programs — to obtain free, specific, informed, and revocable consent from members before using their data. Non-compliance can attract penalties up to ₹250 crore per violation instance.
How is Fundle's ConsentFirst different from a standard cookie consent banner?+
ConsentFirst is a full consent orchestration layer embedded inside the Fundle AI Platform. Unlike a cookie banner, it manages granular purpose-specific consent for AI agent actions, stores consent as a versioned data entity, gates every AI workflow against live consent status, propagates revocations automatically across all downstream systems, and serves consent notices in 12 Indian languages.
Can a mall member still earn loyalty points if they withdraw marketing consent?+
Yes. Under DPDP, loyalty benefits cannot be made conditional on marketing consent. Fundle's ConsentFirst architecture decouples transaction recording — necessary to award and redeem points — from AI personalisation and marketing communications. A member can opt out of all personalised offers and still participate fully in the loyalty points economy.
How does ConsentFirst handle consent revocation in real time?+
When a member withdraws consent — via the Fundle app, website, WhatsApp, or in-store terminal — ConsentFirst fires a revocation event that propagates automatically to all connected systems: campaign queues, AI recommendation engines, data warehouse exports, and third-party brand partner feeds. The propagation SLA is under five minutes for digital touchpoints and same-business-day for in-store verbal revocations.
Which Indian regional languages does ConsentFirst support?+
ConsentFirst currently supports 12 Indian languages including Hindi, Tamil, Telugu, Marathi, Bengali, Gujarati, Kannada, Malayalam, Punjabi, Odia, Assamese, and English. Consent notices are served dynamically based on the member's registered app language preference, with a fallback to Hindi or English.
How does Fundle's ConsentFirst affect the performance of AI loyalty agent campaigns?+
Positively. Members who give explicit, purpose-specific consent to personalisation show higher open rates, lower spam complaint rates, and better conversion rates than members processed under ambiguous omnibus consent. ConsentFirst also ensures that AI model training datasets include only members who have consented to analytics use, producing cleaner models that generate more accurate personalisation recommendations.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
