“The best campaign is the one that didn't run. Fundle's churn-prediction model has saved Indian retailers crores in unnecessary discounting on customers who were already coming back.”
- •Understand why India's DPDP Act 2023 creates immediate compliance obligations for retail loyalty programs collecting PII at scale
- •Discover how Fundle's ConsentFirst CMP enforces granular, auditable, withdrawable consent across every POS and digital touchpoint
- •Compare ConsentFirst's architecture against generic CMPs and point-solution consent tools that miss loyalty-specific data flows
- •Follow a five-step playbook to retrofit an existing loyalty program into a DPDP compliant loyalty data platform within 90 days
- •Track the six KPIs that prove your consent infrastructure is protecting both your customers and your brand's legal standing
India's Digital Personal Data Protection Act 2023 crossed a critical threshold in 2024 when the government released draft rules under the Act, signalling that the grace period for retail operators is shrinking fast. For a shopping mall operator running 200+ brand stores, or a fashion retailer with 40 lakh loyalty members enrolled via SMS opt-ins from 2017, the compliance gap is not theoretical — it is a ₹250 crore penalty waiting to happen. The DPDP Act mandates that every data fiduciary collect explicit, informed, specific, and freely given consent before processing personal data. Loyalty programs, which are by design personal-data-intensive, sit directly in the crosshairs.
The Indian retail sector has historically treated consent as a checkbox — a pre-ticked clause buried in a membership form at a Pantaloons billing counter or a WhatsApp opt-in for a Manyavar festive campaign. That era is over. Under the DPDP Act, consent must be granular (purpose-specific), withdrawable at any time without consequence, and backed by a demonstrable audit trail. For a brand like FabIndia with both a D2C website and 200+ physical stores, or Apollo Pharmacy with 5,500+ outlets each running its own loyalty terminal, building and maintaining that infrastructure internally is a multi-crore, multi-year project — if attempted from scratch.
This is where a purpose-built DPDP compliant loyalty data platform changes the equation entirely. Rather than retrofitting a generic consent management platform (CMP) onto a loyalty stack, the right architecture bakes consent into the loyalty data flow itself: at enrolment, at point of sale, at campaign send, and at every data-sharing event with a third-party brand partner or analytics vendor. Fundle was designed around exactly this principle — consent is not a bolt-on; it is the data rail that every loyalty transaction runs on.
ConsentFirst, Fundle's proprietary consent management module, is already deployed across 123+ malls supporting 270+ brands' data privacy — making it one of the largest consent infrastructure deployments in Indian organised retail. This article unpacks how ConsentFirst works, why the moment is now for Indian retail CMOs and CIOs to act, and what a 90-day migration path looks like for operators who are currently exposed.
India Retail Data Privacy: The Numbers That Define the Risk
Why DPDP Compliance Is a Loyalty-Specific Crisis, Not a Generic IT Problem
Most enterprise IT teams frame DPDP compliance as a data governance project — classify your data, map your flows, appoint a Data Protection Officer, and update your privacy policy. That framing works for an HR system or a CRM tool used internally. It fails catastrophically for a loyalty program, because loyalty data is simultaneously the most personal, the most commercially exploited, and the most consumer-facing category of data in retail.
Consider what a single loyalty profile at a Phoenix Marketcity-style mixed-use mall actually contains: name, mobile number, email, date of birth, vehicle registration (for parking integrations), transaction history across 80+ brands, visit frequency, food court preferences, cinema booking history, and in newer deployments, geolocation dwell data from the mall's Wi-Fi or BLE beacon network. Each of these data attributes was collected under a different interaction context. The DPDP Act requires that the purpose stated at collection time precisely matches the processing activity — you cannot use cinema preference data to send a jewellery offer from Tanishq unless the member explicitly consented to cross-category marketing.
This is not an edge case. It is the core business model of mall loyalty. And it is precisely why generic CMPs — tools built for cookie consent on websites — are architecturally inadequate. A web CMP captures a browser-level consent signal. It has no concept of a POS transaction, a WhatsApp campaign, an SMS-based OTP enrolment, or a brand-specific data-sharing agreement between a mall operator and a brand like Lenskart or Cafe Coffee Day. The consent taxonomy for loyalty is an order of magnitude more complex.
Operators who have deployed point solutions from players like EasyRewardz or Capillary for their loyalty engine, and then attempt to layer a generic consent tool on top, face a painful reality: the consent data and the loyalty data live in separate systems with no real-time synchronisation. A member who withdraws consent for promotional communications at 11 PM on a Tuesday will still receive a campaign SMS at 10 AM Wednesday because the suppression signal never reached the campaign scheduler. That is a DPDP violation. The only structural fix is a consent-native loyalty architecture — which is what Fundle's ConsentFirst delivers.
The ConsentFirst Loyalty Data Journey: From Enrolment to Audit Trail
Features of Fundle ConsentFirst CMP: Purpose-Built for Retail Loyalty
ConsentFirst is not a repurposed cookie banner tool. It was architected from the ground up as a consent management plane for loyalty-grade personal data, with five capabilities that no generic CMP offers.
First, purpose-layered consent capture. At enrolment — whether at a Reliance Trends billing counter, a Lifestyle store kiosk, or a D2C app signup — ConsentFirst surfaces a structured consent UI that separates at minimum six consent purposes: transactional communications, promotional marketing, cross-brand data sharing, analytics profiling, third-party partner marketing, and location-based services. Each purpose is independently toggleable. The underlying data schema stores not just the boolean yes/no but the exact consent text version shown, the channel, the timestamp, and the device or terminal ID. This creates the specific, informed, freely given consent record that the DPDP Act demands.
Second, real-time consent propagation. When a member updates a preference — say, opting out of third-party brand marketing while keeping transactional alerts active — that signal propagates across the Fundle AI Platform in under 200 milliseconds. The campaign scheduler, the data-sharing API, and the analytics pipeline all receive the updated consent state before the next processing event. This eliminates the dangerous lag that plagues bolted-on consent tools.
Third, consent-aware data tokenisation. Personal identifiers are tokenised at ingestion. Analytics and campaign tools operate on pseudonymised tokens. Raw PII is decrypted only when a consent-verified, logged business action requires it. This means that even if a campaign vendor or a brand partner is compromised, the exposed data is not directly re-identifiable — reducing both regulatory exposure and reputational damage.
Fourth, multi-modal consent withdrawal. Members can withdraw or modify consent through any channel: the loyalty app, a WhatsApp bot, a toll-free IVR, an in-store staff terminal, or a self-service kiosk. Every withdrawal path writes to the same ConsentFirst vault. There is no scenario in which a member who has withdrawn consent continues to receive processing that depends on that consent.
Fifth, DPO-ready audit exports. The Data Protection Officer tooling in ConsentFirst allows a retail chain's DPO to pull a full consent history for any individual member or any cohort in under 90 seconds, formatted as a structured JSON or PDF report suitable for regulatory submission. For a mall operator potentially managing 20 lakh loyalty members, this is not a nice-to-have — it is the difference between a manageable regulatory inquiry and a multi-week operational crisis.
ConsentFirst vs Generic CMPs and Bolt-On Consent Tools
Ensuring Transparent User Consent Collection Across Every Channel
The DPDP Act's requirement for 'clear and plain language' consent notices is harder to operationalise than it sounds when you are running 80+ brand stores in a single mall, each with its own billing system — a mix of POSist-powered F&B counters, Petpooja terminals at food courts, Wondersoft POS at fashion anchors, and GoFrugal systems at pharmacy outlets. Each terminal has a different UI, a different operator skill level, and historically a different consent flow. ConsentFirst solves this through a headless consent API that any POS system can call, rendering a standardised, brand-templated consent screen regardless of the underlying billing software.
Transparency in the DPDP context means three specific things. One, the member must understand what data is being collected. Two, they must understand why each category is being collected. Three, they must understand who it will be shared with. ConsentFirst's consent notice builder — accessible to mall operators and brand managers through the Fundle AI Platform dashboard — allows customisation of the plain-language notice text while enforcing a compliance template that has been reviewed against the DPDP draft rules. Brands cannot accidentally create a notice that omits the mandatory disclosure elements.
For digital channels, ConsentFirst integrates directly with WhatsApp Business API flows and app onboarding screens. A customer enrolling in the Manyavar loyalty program via WhatsApp, for instance, receives a structured consent card that mirrors the in-store consent taxonomy — same six purposes, same language, same withdrawal mechanism. The mobile number becomes the consent identity anchor, and all subsequent channels (email, push, SMS) inherit the consent state validated at enrolment.
One of the most underappreciated transparency requirements under DPDP is the obligation to notify members when consent purposes change — for example, when a mall operator signs a new data-sharing agreement with a fintech partner for EMI offers. ConsentFirst automates this through what the platform calls Consent Change Notifications: templated push or WhatsApp messages that inform affected members of the new data use, present a fresh consent toggle, and record the outcome. Brands that have historically just updated their privacy policy URL and called it done will find this requirement non-negotiable under the Act.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
90-Day Playbook: Migrating to a DPDP Compliant Loyalty Data Platform
Days 1–15: Consent Debt Audit
Map every active loyalty member record against the consent basis under which their data was collected. Classify records into three buckets: DPDP-compliant (explicit, purposeful, documented), remediable (enrollee can be re-consented via outreach), and unprocessable (no consent trail — these must be suppressed from all processing immediately). Typically 40-68% of pre-2022 loyalty databases fall into the remediable or unprocessable bucket.
Days 16–30: ConsentFirst Integration Across POS and Digital Channels
Deploy the Fundle ConsentFirst headless consent API to your primary POS systems — POSist, Petpooja, Wondersoft, or GoFrugal — using pre-built connectors. Configure the consent notice template with your brand legal team. Activate the WhatsApp and app consent flows. At the end of this phase, all new enrolments are DPDP-grade from day one.
Days 31–60: Re-Consent Campaign for Existing Members
Run a structured re-consent outreach to the remediable segment — typically via WhatsApp and SMS, with a clear value exchange (bonus points, exclusive offer) for completing the updated consent flow. Target a 55-65% re-consent rate. Members who do not respond within 45 days are moved to a suppressed-but-retained state: data preserved for internal analytics under legitimate interest, but excluded from all direct marketing.
Days 61–75: Campaign and Analytics System Consent Gating
Update all campaign scheduler integrations — whether MoEngage, WebEngage, Xeno, or Fundle's native AI Workflow — to call the ConsentFirst consent-check API before every outbound send. Implement consent-state filters in your analytics pipeline so that reporting cohorts automatically exclude suppressed members. Test every campaign flow against synthetic withdrawal events.
Days 76–90: DPO Tooling, Staff Training, and First Audit Simulation
Activate the DPO audit dashboard within Fundle AI Platform. Train store managers and customer service staff on the in-store consent update flow. Run a simulated regulatory inquiry: pull a full consent history for 100 randomly selected members and validate completeness. Document the drill findings and close any gaps before go-live sign-off.
Seamless Integration with Loyalty and POS Systems at Scale
One of the structural weaknesses of India's organised retail loyalty ecosystem is its extraordinary fragmentation at the technology layer. A single mall operator might have 60+ brand stores running six different POS platforms, three different loyalty engines, two different app providers, and a WhatsApp Business solution layer that was bolted on during COVID. For a consent management infrastructure to work, it must function as a horizontal plane across all of these — not as yet another silo.
ConsentFirst's integration architecture is built on three layers. The first is the POS Connector Library — pre-built, certified integrations with the major Indian POS platforms including POSist, Petpooja, GoFrugal, and Wondersoft. These connectors handle the consent UI rendering at the billing terminal, the real-time consent API call, and the response handling — all within the transaction flow without adding perceptible latency. Store staff do not need to understand consent management; the terminal guides them through a standardised interaction.
The second layer is the Loyalty Engine Middleware. Fundle's Fundle Brand Loyalty and Fundle Mall Loyalty modules natively consume consent state from ConsentFirst. For operators running a third-party loyalty engine — Capillary, EasyRewardz, or a custom-built solution — ConsentFirst exposes a webhook-based event stream that pushes consent state changes in real time. This means a brand on any loyalty platform can enforce consent-gated campaign execution without re-platforming.
The third layer is the Campaign Channel Adapter. ConsentFirst maintains a consent-verified suppression list that is pushed via API to connected campaign platforms. Whether a brand's marketing team sends campaigns through MoEngage, WebEngage, or Xeno, the suppression list ensures that no outbound communication reaches a member who has not consented to that specific communication purpose. The Fundle Agentic AI layer adds an additional check: AI Agents that orchestrate multi-step campaigns automatically validate consent state at each step of the journey, not just at the initial trigger. This eliminates the scenario where a member consents to transactional messages, receives a campaign journey trigger, and then gets promotional messages three steps later because the journey logic did not re-check consent mid-flight.
- Consent Coverage Rate: Percentage of active loyalty members with a valid, purpose-specific, DPDP-grade consent record on file — target >95% within 90 days of ConsentFirst go-live
- Consent Withdrawal Response Time: Time elapsed between a member withdrawal event and full suppression across all campaign and analytics systems — target <5 minutes end-to-end
- Re-Consent Campaign Conversion Rate: Percentage of pre-DPDP legacy members who complete the updated consent flow during re-consent outreach — industry benchmark is 55-65% for incentivised campaigns
- Consent Audit Readiness Score: DPO self-assessment metric measuring completeness of consent records for a random 500-member sample — target 100% records with timestamp, channel, consent text version, and purpose mapping
- Data Breach Blast Radius: Percentage of loyalty database that is tokenised and non-re-identifiable without a consent-verified decryption event — target >90% of PII fields tokenised
- Campaign Consent Violation Rate: Number of outbound campaign sends that reached a suppressed or non-consented member per million sends — target zero; any non-zero result triggers an immediate incident review
- Consent Freshness Index: Percentage of active consent records that have been positively reaffirmed (not just passively inherited) within the last 24 months — tracks against DPDP's implied requirement for ongoing, not one-time, consent validity
“In Indian retail, consent was always an afterthought — buried in fine print, never enforced. The DPDP Act doesn't just change the legal risk; it changes what it means to respect your customer. That is the platform we built.”
How Fundle solves this
Fundle was built on a foundational belief that first-party data is only as valuable as the trust it was collected with. Vineet Narang's vision for the Fundle AI Platform was never to build another points-and-rewards engine — it was to build the consent-native data infrastructure that makes loyalty genuinely valuable to members and genuinely defensible for operators. ConsentFirst is the most visible expression of that thesis.
The Fundle Loyalty Platform, encompassing both Fundle Mall Loyalty for multi-brand mall environments and Fundle Brand Loyalty for single-brand or multi-channel retail chains, has consent management woven into every data flow. There is no way to create a member profile, execute a campaign, share data with a brand partner, or run an analytics cohort without a valid consent record gating that action. This is not a compliance layer sitting on top of the product — it is the product's foundational data model.
Fundle AI Agents, the autonomous orchestration layer within Fundle Agentic AI, add a dimension that no legacy loyalty platform or standalone CMP can match. These agents monitor consent state across the entire active member base in real time, proactively identifying members whose consent is approaching expiry, whose withdrawal signals are ambiguous, or whose data usage has drifted beyond the originally consented purpose. The Fundle AI Workflow then triggers the appropriate re-consent or suppression action without requiring manual DPO intervention. For a mall operator managing 20 lakh members across multiple city assets, this level of automation is not optional — it is the only way to maintain compliance at operational scale.
ConsentFirst is already deployed across 123+ malls supporting 270+ brands' data privacy, making it the largest consent infrastructure deployment in Indian organised retail. The brands and operators on the platform — spanning fashion anchors, F&B operators, entertainment venues, and pharmacy chains — benefit from a shared consent technology investment that would cost multiples of the Fundle platform fee to build and maintain independently. For a CMO at a mid-sized retail chain spending ₹15-20 crore annually on loyalty program operations, the alternative to a platform like Fundle is not just a technology build cost — it is a ₹250 crore penalty exposure that no CFO will accept once the DPDP rules are formally notified. The question for India's retail leadership is not whether to invest in a DPDP compliant loyalty data platform. It is how quickly they can close the gap between where they are today and where the law requires them to be.
Frequently asked
What exactly does the DPDP Act 2023 require from a retail loyalty program in India?+
The Digital Personal Data Protection Act 2023 requires any entity processing personal data — including loyalty program operators — to collect explicit, informed, specific, and freely given consent before processing. Consent must be withdrawable at any time, the withdrawal must be honoured without delay, and the data fiduciary must maintain an auditable record of consent collection and any changes. For loyalty programs, this means purpose-specific consent for each data use category: transactional alerts, promotional marketing, analytics profiling, cross-brand data sharing, and so on. A single blanket opt-in at enrolment no longer meets the standard.
How is ConsentFirst different from a standard cookie consent management platform?+
Standard CMPs are built for web browser cookie consent — they manage a narrow set of tracking technologies in a single channel. ConsentFirst is built for retail loyalty data, which spans POS terminals, mobile apps, WhatsApp, SMS, in-store kiosks, and IVR. It manages six or more purpose-specific consent categories, integrates with POS systems like POSist and GoFrugal, propagates consent state changes in real time across campaign and analytics platforms, and provides DPO-grade audit exports. It is an entirely different product category solving an entirely different problem.
Can ConsentFirst work with our existing loyalty platform — we are already on Capillary or EasyRewardz?+
Yes. ConsentFirst exposes a webhook-based event stream and a REST API that can integrate with any existing loyalty engine. Operators running Capillary, EasyRewardz, or a custom-built loyalty system can connect ConsentFirst as the consent layer without re-platforming their loyalty infrastructure. The integration ensures that consent state changes propagate to the loyalty engine's suppression and segmentation logic in near real time.
What happens to legacy loyalty members enrolled before the DPDP Act rules were notified?+
Legacy members enrolled under pre-DPDP consent frameworks need to be re-consented. Fundle's recommended approach is a structured re-consent campaign using the 90-day playbook outlined in this article: audit your consent debt, suppress unprocessable records immediately, and run an incentivised re-consent outreach to remediable members. Members who do not respond within 45 days should be moved to a suppressed state — data retained for internal analytics under legitimate interest, but excluded from all direct marketing. A 55-65% re-consent rate is achievable with a well-designed campaign.
How quickly can a mall operator or retail brand deploy ConsentFirst?+
For operators already on the Fundle AI Platform, ConsentFirst activation for new enrolment flows takes 5-7 business days once the consent notice template is approved by the brand's legal team. POS connector deployment to existing terminals typically takes 10-15 days depending on the POS platform and the number of terminal locations. A full 90-day deployment including legacy re-consent campaign is the recommended timeline for complete DPDP compliance across an existing loyalty database.
What are the penalties for non-compliance with the DPDP Act for a retail operator?+
Under the DPDP Act 2023, the Data Protection Board can impose financial penalties of up to ₹250 crore for a significant data breach. For failure to implement reasonable security safeguards, the penalty is up to ₹200 crore. For failure to notify the Data Protection Board of a personal data breach, penalties reach ₹200 crore. For entities classified as Significant Data Fiduciaries — a category that large mall operators and retail chains are likely to fall into — additional obligations apply, including mandatory Data Protection Impact Assessments and periodic compliance audits. The penalty structure makes investing in a platform like ConsentFirst a straightforward financial decision.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
