“India does not need another global loyalty stack with an Indian wrapper. India needs a platform that thinks WhatsApp-first, Petpooja-first, cash-aware and vernacular-ready.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand why DPDP 2023 changes the rules for every Indian retail brand collecting customer data
  • See how Fundle's ConsentFirst architecture automatically manages consumer consent in line with DPDP 2023 regulations
  • Discover how friction-free consent UX actually increases opt-in rates rather than suppressing them
  • Track the exact KPIs — consent coverage, data minimisation score, audit response time — that regulators and CFOs both care about
  • Evaluate Fundle against point solutions and legacy CRM stacks on privacy readiness

For most Indian retail CMOs, data privacy has historically been an afterthought — something legal flagged once a year and marketing quietly filed away. That era ended on 11 August 2023, when India's Digital Personal Data Protection Act received Presidential assent. DPDP 2023 is not a guideline. It is statute, and its penalty framework — up to ₹250 crore per breach instance — makes the cost of non-compliance existential for mid-market retailers and potentially career-defining for the marketing heads who signed off on data collection campaigns that never captured consent correctly.

The problem is structural, not attitudinal. India's retail marketing stack evolved in layers: a POS system from GoFrugal or POSist, a WhatsApp broadcast tool, a third-party loyalty vendor, and maybe a CDP bolted on later. None of these layers were designed with a unified consent spine. Consent, when captured at all, was buried in a paper form at checkout or a checkbox no one read on a mobile app registration screen. Under DPDP 2023, that approach is not just insufficient — it is legally indefensible. The Act requires free, informed, specific, and unambiguous consent for every category of personal data processing, plus a clear mechanism for withdrawal at any time.

The MENA region — where UAE's PDPL and Saudi Arabia's PDPL are already enforced — offers a preview of what happens when brands scramble to retrofit compliance onto non-compliant stacks. Fines, reputational damage, and a sudden collapse in CRM database usability when customers exercise deletion rights en masse. Indian operators managing malls like Phoenix Marketcity or Select CITYWALK, or brands like Tanishq, Manyavar, and FabIndia with millions of loyalty members, cannot afford that scramble.

This is precisely the problem Fundle was built to solve. Fundle.ai's customer engagement platform with data privacy compliance is not a compliance module added to a marketing tool — it is a platform where compliance is the foundation, and marketing capability is built on top of it. This article walks through what that means in practice: the architecture, the user experience, the reporting, and the business case for getting this right before the enforcement clock starts ticking.

DPDP 2023 and Indian Retail: The Numbers That Matter

₹250 Cr
Maximum penalty per breach instance under DPDP 2023 — applicable to data fiduciaries of any size
68%
Share of Indian retailers still relying on paper-based or checkbox-only consent mechanisms as of 2024 (Nasscom-DSCI survey estimate)
3.2×
Higher customer lifetime value observed when opt-in consent is collected transparently with clear value exchange, versus implicit opt-in (Fundle platform data)
₹180 Cr+
Combined CRM database value at risk for a mid-size Indian mall operator if DPDP enforcement triggers mass deletion requests on improperly consented records

DPDP 2023: What Indian Brands Must Know

The Digital Personal Data Protection Act 2023 applies to any entity that processes digital personal data of Indian residents — inside or outside India. For retail brands and mall operators, this is not a narrow definition. A loyalty programme is personal data processing. A WhatsApp OTP for a bill-based points claim is personal data processing. A cross-brand offer sent by a mall's marketing team using footfall analytics is personal data processing. The Act covers all of it.

The key obligations for retail data fiduciaries are five-fold. First, consent must be obtained before processing — not after, not implicitly. The consent request must be clear, standalone, and written in plain language. Second, purpose limitation is mandatory: data collected for a loyalty programme cannot be reused for credit bureau scoring or sold to insurance partners without fresh consent. Third, data principals — your customers — have enforceable rights: the right to access their data, the right to correction, and critically, the right to erasure. Fourth, data retention must be limited to the period necessary for the stated purpose. Fifth, significant data fiduciaries (a category the Ministry of Electronics and IT will notify by sector) face additional obligations including Data Protection Impact Assessments and the appointment of a Data Protection Officer.

For brands like Apollo Pharmacy or Reliance Trends, which operate thousands of outlets and process health-adjacent or financial data respectively, the significant data fiduciary classification is a near certainty. For a mall operator running a coalition loyalty programme across 200+ brand partners, the data flows are even more complex — each partner brand processing data shared by the mall's central loyalty engine creates a web of processing relationships, each requiring documented consent and data-sharing agreements.

The compliance gap in India's retail sector is not about intent. Most marketing heads understand consent conceptually. The gap is operational: existing tech stacks have no mechanism to capture consent at the right moment, in the right format, and then propagate that consent signal — or its withdrawal — across every downstream system in real time. That is an infrastructure problem, and it requires an infrastructure solution. A customer engagement platform India operators choose today must solve this at the architecture level, not with a patch.

The DPDP Compliance Journey for Indian Retail Loyalty

1Stage 1: Audit2Stage 2: Consent Architecture3Stage 3: Data Minimisation4Stage 4: Rights Fulfilment5Stage 5: Continuous Audit
From unconsented data collection to a fully auditable, consent-first customer engagement stack — the five stages every Indian retail brand must navigate under DPDP 2023.

Fundle's ConsentFirst Architecture and Privacy Automation

Fundle's platform automatically manages consumer consent capturing in accordance with DPDP 2023 regulations. This is not marketing language — it is a description of a specific technical architecture. Every data collection event in the Fundle AI Platform triggers a consent evaluation before any record is written to the CRM layer. If valid, purpose-specific consent does not exist in the consent ledger, the data is not stored. Full stop. This ConsentFirst approach inverts the typical retail data model, where collection happens first and compliance is retrofitted.

The Fundle Loyalty platform's consent ledger is an immutable, timestamped record of every consent event: what was consented to, on which channel, in which language, at what time, and through which interface. When a customer registers for a Fundle Mall Loyalty programme at a Phoenix Marketcity kiosk, the consent is captured in the customer's preferred language — Hindi, Tamil, or English — with a plain-language explanation of exactly what data will be collected and for what purpose. The customer can consent to loyalty points accrual without consenting to personalised marketing communications. These are separate consent nodes, not bundled checkboxes.

Privacy automation in the Fundle AI Workflow layer handles the operational load that makes compliance sustainable at scale. When a data principal exercises their right to erasure, Fundle AI Agents automatically propagate the deletion signal across every integrated system — the loyalty engine, the communication stack, the analytics layer, and any connected brand partner systems — within a configurable SLA window. For a mall operator with 40 brand partners, this automation is the difference between a manageable compliance process and an operational crisis. Without it, a single erasure request could require manual coordination across 40 different tech teams.

Fundle Brand Loyalty deployments for single-brand retailers like Lenskart or Cafe Coffee Day benefit from the same architecture adapted for brand-level data models. Purpose limitation rules are configured at onboarding: health-related data from an Apollo Pharmacy integration, for example, is walled off from general marketing segmentation under a separate consent node with stricter retention policies. The Fundle Agentic AI layer monitors these configurations continuously and flags any processing activity that approaches the boundary of consented purposes — giving compliance teams early warning rather than post-hoc discovery.

Fundle vs. Legacy Loyalty and CRM Platforms on DPDP Readiness

Fundle AI Platform
Legacy CRM / Point Loyalty Vendors (Capillary, EasyRewardz, Xeno, MoEngage)
ConsentFirst architecture — consent evaluated before any data write operation
Consent captured as a field in the customer record, not as a gate on data processing
Immutable consent ledger with full audit trail per data principal
Consent stored in standard database tables — mutable, no tamper evidence
Automated erasure propagation across all integrated systems via Fundle AI Agents
Manual deletion workflows requiring coordination across multiple vendor systems
Purpose-specific, granular consent nodes — loyalty, marketing, analytics separated
Bundled opt-in consent at registration; no granular purpose separation
Real-time compliance dashboards with consent coverage, data age, and rights request SLA tracking
Compliance reporting requires custom SQL queries or third-party BI tools; no native DPDP reporting

User Experience: Designing Consent Collection That Customers Actually Complete

The most common objection from retail marketing heads when they hear 'explicit consent requirement' is a version of the same fear: if we ask customers to actively consent, opt-in rates will collapse and our CRM database will shrink to an unusable size. This fear is empirically wrong, but it is based on a real observation — poorly designed consent flows do suppress completion rates. The solution is better design, not compliance avoidance.

Fundle's consent UX framework is built on four principles drawn from behavioural economics and conversion rate optimisation research. First, consent must be offered at the moment of value exchange — when the customer is about to earn points or unlock a discount, not as a prerequisite to even enter the programme. Customers who have just experienced a benefit are measurably more likely to consent to future communications. A Pantaloons customer who just earned ₹200 cashback on a ₹2,000 purchase is in a different psychological state than one who is presented with a consent wall before seeing any value.

Second, language must be in the customer's vernacular and must communicate genuine value — not legal disclaimers. 'Allow us to send you personalised offers based on your purchase history' converts significantly better than 'Consent to processing of personal data for direct marketing purposes.' Fundle's platform includes a multilingual consent copy library covering 12 Indian languages, with A/B tested variants for different retail categories — fashion, pharmacy, food and beverage, jewellery.

Third, granularity is a feature, not a burden. When customers can choose to opt in to birthday offers but opt out of weekly promotional messages, they feel respected rather than surveilled. Fundle's consent management UI displays these choices as simple toggles with clear descriptions of what each consent enables. Brands running Fundle Mall Loyalty programmes at Select CITYWALK report that granular consent options increase overall opt-in rates by 15-22% compared to all-or-nothing consent flows, because customers feel safe making partial commitments. Fourth, re-consent flows are triggered automatically when a brand wants to expand data use to a new purpose — the Fundle AI Workflow sends a templated re-consent request via the customer's preferred channel, tracks completion, and updates the consent ledger automatically.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

5-Step Playbook: Implementing DPDP-Compliant Engagement on Fundle

01

Data Discovery and Consent Gap Audit

Map every touchpoint where customer data is collected — POS (GoFrugal, POSist, Wondersoft), app registration, web forms, WhatsApp OTP, in-store kiosks. Fundle's onboarding team runs a structured audit and generates a gap report showing which data streams lack DPDP-compliant consent. Typical Indian mall operators discover 6-9 unconsented data streams in this audit.

02

Configure Purpose-Specific Consent Nodes

Work with Fundle's implementation team to define the consent taxonomy for your business: loyalty accrual, personalised marketing, cross-brand offers, analytics, third-party sharing. Each node is configured with a retention schedule, a legal basis descriptor, and a withdrawal mechanism. This configuration is done once at onboarding and enforced automatically by the Fundle AI Platform thereafter.

03

Deploy ConsentFirst Collection Flows

Replace existing opt-in mechanisms with Fundle-hosted consent flows at every customer touchpoint. For in-store, this means QR-based consent on customer-facing screens. For apps, it means replacing checkbox registrations with Fundle's consent SDK. For WhatsApp-based loyalty like programmes used by Manyavar or FabIndia, it means DPDP-compliant consent capture before the first data-carrying message is sent.

04

Activate Automated Rights Fulfilment

Configure Fundle AI Agents to handle data principal rights requests — access, correction, erasure — within your chosen SLA window (recommended: 72 hours for erasure, 30 days for access). Test the erasure propagation flow across all integrated systems before go-live. Document the workflow for your DPO's records.

05

Monitor, Report, and Iterate

Use Fundle's compliance dashboard to track consent coverage rate (target: 95%+ of active records), consent withdrawal rate, data age distribution, and rights request SLA adherence. Schedule quarterly consent health reviews with your DPO. Use Fundle's A/B testing module to continuously improve consent UX and opt-in rates.

Audit and Compliance Reporting: What Regulators and CFOs Need to See

DPDP 2023 enforcement will, in all likelihood, follow a familiar pattern: the first wave of regulatory scrutiny will target organisations that cannot demonstrate compliance process — not just technical compliance. A brand that has made genuine good-faith efforts, documented its consent architecture, and maintained audit trails will be in a fundamentally different position than one that cannot produce a consent record for a specific customer interaction. The audit trail is the proof of compliance, and it needs to be accessible on demand, not reconstructed after the fact.

Fundle's compliance reporting module generates three categories of output. The first is the Consent Coverage Dashboard — a real-time view showing what percentage of active CRM records have valid, purpose-specific consent for each processing activity. For a loyalty programme with 500,000 members, this means knowing, right now, that 94.3% have consented to personalised marketing, 87.1% have consented to cross-brand offers, and 11,200 records are in a consent-pending state that prevents outbound communications. This granularity is what allows a marketing head to make confident decisions about campaign scope without legal review of every send.

The second category is the Rights Request Log — a complete, timestamped record of every access, correction, and erasure request received, the actions taken, the systems notified, and the SLA status. This log is exportable in formats suitable for regulatory submission and is maintained in an immutable state to prevent post-hoc modification. For a significant data fiduciary undergoing a MEITY audit, this log is the primary evidence of rights fulfilment compliance.

The third category is the Data Lineage Report — showing, for any given data field in the CRM, its origin (which touchpoint, which date, which consent version), its processing history (which campaigns it was used in, which analytics models it informed), and its current retention status. For brands like Lifestyle or Reliance Trends that have been operating loyalty programmes for 5-10 years and have data of uncertain provenance in their databases, the lineage report is the starting point for a systematic data hygiene programme that brings the historical database into DPDP compliance. Fundle's AI Workflow can automate the re-consent or archival process for records flagged in the lineage report, reducing what would otherwise be a multi-month manual project to a configurable workflow.

DPDP Compliance Readiness Checklist for Indian Retail CMOs
  • Every data collection touchpoint (POS, app, web, WhatsApp, kiosk) has a documented, purpose-specific consent flow in place
  • Consent records are immutable, timestamped, and linked to individual customer profiles — not stored as bulk batch files
  • Customers can withdraw consent for any purpose independently, and withdrawal propagates to all downstream systems within 72 hours
  • Data retention schedules are configured per data category and enforced automatically — no records are held beyond the consented retention period
  • Rights request fulfilment (access, correction, erasure) is automated with SLA tracking and a complete audit log
  • Consent coverage rate is monitored in real time and drops below 90% trigger automated re-consent workflows
  • All brand partners and technology vendors with access to customer data have signed DPDP-compliant data processing agreements
“In India, the brand that owns first-party data with clean consent will out-survive every competitor who bought reach. DPDP is not a compliance cost — it is a data quality forcing function, and retailers who get this right first will own the next decade of customer relationships.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Vineet Narang founded Fundle on a specific conviction: that in India's retail market, the companies that win the next decade will be those that turn first-party data into a genuine competitive asset — and that requires both AI capability and privacy integrity, not one at the expense of the other. Every architectural decision in the Fundle AI Platform reflects that conviction.

The Fundle Loyalty platform's ConsentFirst layer is the operational expression of this philosophy for mall and brand operators. Whether you are running a Fundle Mall Loyalty programme across a mixed-use mall with 150 brand tenants, or a Fundle Brand Loyalty programme for a single brand with regional store presence, the consent infrastructure is the same: purpose-specific, multilingual, channel-agnostic, and fully automated in its enforcement. The Fundle AI Agents that power rights fulfilment workflows do not require manual intervention for standard requests — they execute, document, and report autonomously, reducing the compliance operational burden on marketing and IT teams by an estimated 60-70% compared to manual processes.

Fundle AI Workflow brings the same automation to re-consent campaigns, data hygiene programmes, and retention schedule enforcement. When a data principal's consent is approaching its configured expiry — say, 24 months after initial capture for marketing communications — the workflow automatically generates a re-consent communication in the customer's preferred channel and language, tracks completion, and updates the consent ledger. Records where re-consent is not obtained within the configured window are automatically moved to an archived state that prevents processing but preserves the anonymised transaction data needed for analytics. This is data minimisation in practice, not in policy.

For Fundle Agentic AI capabilities, the compliance layer extends into real-time monitoring: AI agents continuously scan processing activities against the consented purpose map and flag anomalies — a campaign segment that inadvertently includes records consented only for loyalty accrual, for example, or an analytics query that pulls health-adjacent data outside its walled consent node. These flags go to the compliance dashboard with enough context for a marketing manager to make a decision, rather than to a legal team months after the fact. The Fundle AI Platform does not make compliance someone else's problem — it makes compliance everyone's visible, manageable daily reality. That is what a true customer engagement platform with data privacy compliance built in looks like, and it is why Indian retail operators choosing their engagement stack today should treat DPDP readiness as a first-order selection criterion, not an afterthought.

Frequently asked

Does DPDP 2023 apply to my loyalty programme if I am a smaller retail brand with under 50 outlets?+

Yes. DPDP 2023 applies to any entity processing digital personal data of Indian residents, with no size exemption. The distinction between standard data fiduciaries and significant data fiduciaries affects the intensity of obligations, not whether the Act applies. If your loyalty programme collects names, phone numbers, or purchase history — it is in scope.

What happens to my existing CRM database that was built before DPDP 2023?+

Historical records collected without DPDP-compliant consent are a legal risk. The safest approach is a structured re-consent campaign for active loyalty members, and archival or deletion of inactive records. Fundle's AI Workflow can automate this process, segmenting records by data age and consent status and running targeted re-consent flows to salvage as much of the database as possible.

How does Fundle handle consent in a multi-brand mall loyalty programme where data is shared between the mall operator and brand tenants?+

Fundle Mall Loyalty treats each data sharing relationship as a separate consent node. A customer consenting to the mall's central loyalty programme does not automatically consent to their data being shared with individual brand tenants for brand-level marketing. Each brand-level data sharing relationship requires its own consent, captured and managed in the Fundle consent ledger, with separate withdrawal mechanisms.

How long does it take to implement Fundle's DPDP-compliant consent architecture?+

For a mid-size retail brand with 3-5 data collection touchpoints, full ConsentFirst deployment typically takes 6-8 weeks including audit, configuration, consent flow design, integration testing, and staff training. Mall operators with multiple brand integrations should plan for 10-14 weeks. Fundle provides a dedicated implementation team and a structured onboarding playbook.

Can Fundle integrate with my existing POS system (GoFrugal, POSist, Petpooja, Wondersoft) without replacing it?+

Yes. Fundle's integration layer connects with all major Indian POS systems via API. Consent captured at the POS is passed to the Fundle consent ledger in real time. The POS system continues to handle transactions; Fundle handles the consent and loyalty data layer on top of it. No POS replacement is required.

How does Fundle compare to using a combination of MoEngage or WebEngage plus a separate consent management platform?+

Point solutions require custom integration work to propagate consent signals across systems — and every integration is a potential compliance gap. When a customer withdraws consent, that signal must travel from the consent tool to MoEngage, to WebEngage, to your analytics platform, to your loyalty vendor, in real time. Fundle's unified architecture means consent is enforced at the data layer before it reaches any communication or analytics tool, eliminating the integration gap entirely.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?