“The best campaign is the one that didn't run. Fundle's churn-prediction model has saved Indian retailers crores in unnecessary discounting on customers who were already coming back.”
- •Understand how India's DPDP Act fundamentally changes consent mechanics for loyalty programs
- •Audit your existing loyalty stack against DPDP's seven principal rights before Q2 2025
- •Shift from implicit opt-in to granular, purpose-linked consent across every touchpoint
- •Treat first-party data not as an asset to hoard but as a trust signal to earn
- •Evaluate DPDP compliant loyalty data platforms on consent versioning, data minimisation, and erasure SLAs
India's Digital Personal Data Protection Act, 2023 — the DPDP Act — is not a GDPR clone dressed in khadi. It is a purpose-built, consent-first framework designed for a country where 850 million internet users interact with brands through a chaotic mix of WhatsApp, POS terminals, mall kiosks, and third-party delivery apps. For retail CMOs and CIOs who have spent the last decade building loyalty databases on the implicit assumption that a phone number collected at checkout is fair game forever, the DPDP Act is a structural shock — not a compliance checkbox.
The scale of exposure is real. A mid-sized mall operator running a coalition loyalty programme across 200 brand partners may hold upward of 8–12 million member profiles. Each profile typically carries purchase history, location data, tier status, and marketing preferences collected across multiple touchpoints — many without explicit, granular consent. Under the DPDP Act, every one of those data points requires a lawful basis, a stated purpose, and — when the member asks — a clean erasure path. Brands like Pantaloons, Lifestyle, and Manyavar, which run their own loyalty initiatives inside malls, face an additional layer of complexity: they are simultaneously data fiduciaries managing member data and data processors handling transactional feeds from POS systems like POSist, Petpooja, GoFrugal, and Wondersoft.
The enforcement timeline is tightening. The Data Protection Board of India is expected to become operational through 2025, and the rules framed under the Act indicate that penalties for non-compliance can reach ₹250 crore per instance of significant breach. For a retail brand running a loyalty programme on an ageing CRM — or worse, on a patchwork of MoEngage automations, a WhatsApp Business API integration, and an Excel-fed point ledger — that exposure is not theoretical. It is a board-level risk.
Fundle was built with this moment in mind. As India's AI-first loyalty and customer engagement platform for shopping malls and enterprise retail brands, Fundle.ai has architected its consent management, data minimisation, and principal rights modules around the DPDP Act's specific requirements — not retrofitted them onto a legacy stack. This article is a working guide for retail leaders who need to understand what the Act demands, what their current platforms are likely missing, and what a genuinely DPDP compliant loyalty data platform looks like in practice.
India DPDP & Loyalty Data: The Numbers That Frame the Problem
DPDP Regulations Overview: The Architecture of Consent
The Digital Personal Data Protection Act, 2023 replaces India's patchwork of data handling norms — previously governed by IT Act Section 43A and the 2011 Sensitive Personal Data rules — with a unified, rights-based framework. Its core construct is the Data Principal (the loyalty member, the shopper) and the Data Fiduciary (the brand, the mall operator, the loyalty platform). The relationship between them is now governed by seven principal rights: the right to access information, the right to correction and erasure, the right to grievance redressal, the right to nominate a representative, the right to withdraw consent, the right to know what data is held, and the right to know with whom it has been shared.
For a loyalty programme, the most operationally disruptive of these rights is the right to withdraw consent coupled with the right to erasure. Today, most Indian loyalty platforms — whether operated by Capillary, EasyRewardz, or in-house teams at brands like Reliance Trends — do not have a self-service erasure flow. Deletion requests are handled manually, take days or weeks, and frequently leave residual data in downstream analytics warehouses or campaign tools like WebEngage or Xeno. The DPDP Act does not recognise these as acceptable timelines. A Data Principal who withdraws consent must be able to do so with the same ease with which they gave it — meaning a frictionless in-app or USSD-triggered flow, not a call to a customer care centre.
The Act also introduces the concept of purpose limitation with teeth. If a member shared their date of birth to receive a birthday discount at Select CITYWALK, that data cannot be used to model propensity scores for a fintech cross-sell campaign without fresh, specific consent for that new purpose. This is a direct challenge to the unified customer data platforms that many enterprise retailers built over the last five years — systems that were explicitly designed to pool all signals into a single profile for unrestricted activation.
Significant Data Fiduciaries — entities designated by the government based on data volume, sensitivity, or risk to national security — will face additional obligations including data audits, impact assessments, and the appointment of a Data Protection Officer. Given that a Phoenix Marketcity or a large mall REIT managing 10+ properties likely crosses the thresholds under discussion, CMOs and CIOs at these organisations should assume they will be classified as Significant Data Fiduciaries well before enforcement begins. Consent-based loyalty data management is not a feature enhancement. It is a core architectural requirement.
The DPDP Compliance Funnel for a Retail Loyalty Programme
Changes Required in Existing Loyalty Platforms for DPDP Readiness
Most loyalty platforms deployed in Indian retail today were architected between 2015 and 2020, when the dominant design principle was data maximisation — collect everything, store forever, activate later. The DPDP Act inverts this logic entirely. The new design principle is data minimisation with purpose binding. Every field in a member profile must justify its existence with a declared, consented purpose. If you cannot articulate why you store a member's pincode separately from their transaction location data, you should not be storing it.
The most immediate change required is the replacement of blanket opt-in checkboxes with layered, purpose-specific consent flows. A member enrolling in the Apollo Pharmacy loyalty programme, for example, should be able to separately consent to: health tips communication, prescription refill reminders, third-party health insurance offers, and anonymised data sharing with pharma brand partners. Today, most pharmacy loyalty enrolment forms present a single checkbox that implicitly covers all of the above. That single checkbox is now legally insufficient.
Second, loyalty platforms must implement a Consent Management Module (CMM) that is not just a database flag but a versioned audit trail. When a member's consent record changes — whether because they withdrew consent, updated their communication preference, or were re-consented after a purpose change — the platform must log the prior version, the timestamp, the channel through which consent was given or withdrawn, and the specific purposes affected. Platforms like Antavo or Customer Capital, which have European GDPR experience, have some version of this. Most India-native platforms, including several CRM tools used by brands at Ambience Mall or Orion Mall, do not.
Third, the right to erasure requires what engineers call a cascade delete — a deletion command that propagates not just to the core loyalty database but to every downstream system that has received that member's data: the email service provider, the WhatsApp Business API vendor, the CDP, the analytics warehouse, the advertising platform receiving lookalike audiences. Building this cascade architecture is a 6–9 month engineering project for most mid-sized retail tech teams. It is not a sprint. CMOs who have not already initiated this conversation with their CIOs are behind the curve. Platforms that cannot demonstrate cascade delete capability should be considered non-compliant by default.
Legacy Loyalty Platform vs. DPDP Compliant Loyalty Data Platform
Compliance Challenges for First-Party Data Management in Indian Retail
The structural challenge for Indian retail is not a lack of awareness about DPDP — most large brand CMOs and CIOs have read the Act. The challenge is the gap between policy intent and operational capability across a fragmented technology stack. A mid-market brand like FabIndia or Cafe Coffee Day typically runs its loyalty programme on one platform, its email campaigns on a second, its WhatsApp engagement on a third, its in-store POS on a fourth, and its analytics on a fifth. These systems were never designed to share a single consent state. When a member withdraws consent on the loyalty app, the email platform does not know. When the analytics warehouse runs a cohort query the next morning, it includes that member's data.
The consent fragmentation problem is compounded by India's channel diversity. Unlike Europe, where digital journeys are relatively consolidated, Indian loyalty members interact with brands across physical POS, mall kiosks, brand apps, WhatsApp chatbots, missed-call enrolment flows, and SMS redemption links. Each channel has its own consent capture mechanism — or more commonly, none at all. Building a unified consent identity that works across a ₹49 per month Wondersoft POS terminal at a Tier-2 city brand store and a sophisticated React Native loyalty app requires a middleware layer that almost no Indian retail brand has invested in.
The re-consent obligation compounds the operational burden. Under the Act, if a loyalty programme changes its data processing purpose — for instance, if a mall operator decides to start sharing anonymised footfall data with a retail analytics firm — it must seek fresh consent from all existing members for that new purpose, not just from new enrolees. For a programme with 5 million members, this is a full-scale re-enrolment campaign. Brands that have not maintained clean, channel-attributed consent records will find it nearly impossible to execute a compliant re-consent campaign because they cannot demonstrate to the Data Protection Board exactly how original consent was obtained.
Finally, India's loyalty ecosystem is heavily coalition-based. Phoenix Marketcity's Rewards programme, for example, involves dozens of brand partners, each of whom receives transactional data feeds. Under DPDP, each data transfer to a brand partner constitutes a disclosure that requires either the member's specific consent or a legitimate contractual necessity argument. Mall operators who have not structured their brand partner data sharing agreements with DPDP-compliant data processing clauses are exposed — and so are the brand partners who receive that data without a documented lawful basis. A first-party data platform for loyalty India must solve for coalition consent, not just individual brand consent.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
5-Step DPDP Compliance Playbook for Retail Loyalty Teams
Step 1: Data Inventory and Classification
Map every data field in your loyalty database against the DPDP Act's definition of personal data and sensitive personal data. Classify by source (POS, app, kiosk, partner feed), purpose (personalisation, analytics, third-party sharing), and current consent status. Most Indian retail teams will discover 30–40% of their member data fields lack any documented consent basis.
Step 2: Consent Architecture Redesign
Replace blanket opt-ins with purpose-specific, layered consent flows across every enrolment channel. Build a Consent Management Module with versioned audit trails. Ensure consent state is propagated in real time to all downstream systems — email, WhatsApp, CDP, analytics warehouse — via an API or middleware layer.
Step 3: Principal Rights Infrastructure
Build self-service flows for all seven DPDP principal rights, prioritising consent withdrawal, erasure, and data access. Define SLAs for each right — industry benchmark is 72 hours for erasure and 30 days for data access reports. Implement cascade delete architecture across all connected systems before enforcement begins.
Step 4: Partner and Vendor Audit
Review all data processing agreements with loyalty technology vendors, brand partners in coalition programmes, and analytics partners. Ensure every agreement includes DPDP-compliant data processing clauses. For mall operators, this means auditing data feeds sent to each tenant brand and restructuring agreements where member consent does not cover the disclosed purpose.
Step 5: Ongoing Monitoring and Re-consent Campaigns
Establish a quarterly consent audit process to identify members whose consent records are incomplete, expired, or predating the Act's operative date. Run structured re-consent campaigns via the member's preferred channel. Document outcomes for Data Protection Board readiness. Treat re-consent rate as a first-class loyalty KPI alongside NPS and redemption rate.
Enforcement and Penalties: Why the Risk Is Board-Level, Not Just Legal
The DPDP Act's penalty framework is calibrated to create genuine corporate accountability, not just procedural compliance. The Act specifies penalties of up to ₹50 crore for failure to implement adequate security safeguards leading to a data breach, up to ₹200 crore for failure to notify the Data Protection Board of a breach, and up to ₹250 crore for non-fulfilment of obligations related to children's data or for repeated, wilful violations. For context, ₹250 crore is a material sum even for a large mall REIT or a listed retail brand — it represents approximately 15–20% of annual technology and marketing spend for many mid-sized retail operators.
Critically, the Act holds Data Fiduciaries accountable for the actions of their Data Processors. This means that if a mall operator engages a loyalty technology vendor that suffers a breach due to inadequate data security — and that vendor's inadequacy can be traced to the operator's failure to contractually mandate appropriate safeguards — the operator faces penalty exposure, not just the vendor. This shifts the vendor selection criteria for loyalty platforms from feature lists and price points to demonstrable security architecture, SOC 2 certification, and contractual DPDP compliance guarantees.
The Data Protection Board of India is designed to be an adjudicatory body, not merely a registrar. It will accept complaints from Data Principals directly, investigate them, and issue orders including financial penalties and directions to cease processing. In a country where consumer complaints go viral on social media within hours, a Data Protection Board proceeding against a large loyalty programme — say, a mall rewards scheme used by 2 million members in a single city — would be reputationally catastrophic independent of the financial penalty. Retail brands that position their loyalty programmes as trust-building exercises with consumers cannot afford the contradiction of a public data compliance failure.
For CIOs evaluating their technology stack, the enforcement risk translates into a specific procurement mandate: any loyalty or CRM platform that cannot demonstrate DPDP-compliant consent architecture, principal rights fulfilment, and breach notification workflows should be treated as a liability, not an asset. The question to ask every vendor at the next renewal conversation is not 'what new features are you shipping?' It is 'show me your DPDP compliance documentation and your contractual data processing guarantees.' Vendors who cannot answer that question clearly should not be on the shortlist.
- Completed personal data inventory mapping every loyalty data field to a declared, consented purpose
- Replaced blanket opt-in forms with purpose-specific, layered consent flows across all enrolment channels including POS, app, and kiosk
- Implemented a versioned Consent Management Module with immutable audit trail across all downstream systems
- Built self-service principal rights flows for consent withdrawal and erasure with documented SLAs of 72 hours or less
- Executed cascade delete architecture ensuring erasure propagates to email, WhatsApp, CDP, analytics, and partner data feeds
- Reviewed and updated all brand partner and vendor data processing agreements with DPDP-compliant clauses
- Established a quarterly consent audit and re-consent campaign process with re-consent rate tracked as a loyalty KPI
“In Indian retail, loyalty data is not your asset — it is your member's data held in trust. DPDP just made that legal fact. The platforms that treat consent as infrastructure, not paperwork, will own the next decade of customer relationships.”
How Fundle Solves This
The Fundle AI Platform was architected from the ground up as a consent-first, DPDP-aware loyalty infrastructure — not a legacy points engine with a compliance layer bolted on after the Act passed. Fundle Loyalty and Fundle Mall Loyalty both ship with a native Consent Management Module that captures purpose-specific consent at the point of enrolment — whether that is a mall kiosk at Phoenix Marketcity, a branded app for a fashion retail chain, or a USSD flow for a Tier-3 city pharmacy. Every consent record is versioned, timestamped, channel-attributed, and propagated in real time to every connected downstream system via Fundle's consent state API.
Fundle Brand Loyalty extends this capability to enterprise retail brands operating both inside malls and in standalone formats. For brands like Manyavar or Lenskart that run loyalty programmes across hundreds of touchpoints, Fundle AI Agents handle consent lifecycle management autonomously — triggering re-consent campaigns when purpose declarations change, flagging member records with incomplete consent status before they enter any activation workflow, and executing erasure requests as cascade operations across all integrated systems within the platform's 72-hour SLA commitment. These are not manual processes supervised by compliance teams. They are AI-driven workflows that operate continuously at scale.
Fundle Agentic AI and Fundle AI Workflow introduce a new capability that no legacy loyalty platform in India offers: dynamic purpose validation before campaign execution. Before any communication is sent — whether a birthday offer, a tier upgrade notification, or a cross-brand coalition reward — Fundle AI Agents validate the consent state of every member in the target segment against the specific purpose of that campaign. Members without valid consent for that purpose are automatically excluded, and the exclusion is logged. This eliminates the compliance risk of batch campaigns inadvertently targeting members who have withdrawn consent for that use case — a risk that is live and material for any brand running campaigns through WebEngage or Xeno against a loyalty database that does not have real-time consent state.
Fundle supports compliant loyalty management across 123+ Indian malls post DPDP rollout — a network that spans major metro mall operators and regional mall REITs managing coalition programmes with 50–300 brand partners each. Vineet Narang's founding vision for Fundle was that trust, not points, is the real currency of loyalty — and DPDP has made that vision a regulatory reality. For retail CMOs and CIOs evaluating their loyalty stack in 2025, Fundle's DPDP-native architecture, its principal rights fulfilment infrastructure, and its Fundle AI Workflow-driven consent lifecycle management represent the clearest path from compliance risk to competitive advantage.
Frequently asked
Does the DPDP Act apply to loyalty programmes run by Indian retail brands?+
Yes. Any Indian retail brand that collects, stores, or processes the personal data of Indian residents — including loyalty programme members — is covered by the DPDP Act as a Data Fiduciary. This includes brands of all sizes, whether running independent loyalty apps or coalition programmes inside malls.
What is the difference between the old IT Act consent requirements and DPDP consent requirements for loyalty?+
The IT Act's 2011 rules required consent for sensitive personal data but were largely silent on purpose limitation and erasure rights. DPDP requires purpose-specific consent for all personal data, grants members seven enforceable rights including erasure, and mandates that withdrawal of consent be as easy as giving it — a standard that most existing Indian loyalty enrolment flows do not meet.
Can a mall operator legally share member transaction data with brand tenants under DPDP?+
Only if the member has specifically consented to their data being shared with that category of brand partner, or if a legitimate contractual necessity argument can be sustained. Blanket coalition data sharing agreements without member-level consent visibility are non-compliant under the Act.
What penalty does a retail brand face for a loyalty data breach under DPDP?+
Penalties under the DPDP Act for data breaches range from ₹50 crore for inadequate security safeguards to ₹200 crore for failure to notify the Data Protection Board. Repeat or wilful violations involving non-fulfilment of principal obligations can attract penalties up to ₹250 crore per instance.
How long does a retail brand have to fulfil a member's erasure request under DPDP?+
The Act does not specify a fixed number of days but requires erasure to be done without undue delay once the purpose for which data was collected has been fulfilled or consent has been withdrawn. Industry best practice and DPDP Board guidance points to 72 hours for digital loyalty systems as a defensible SLA.
How does Fundle help with DPDP compliance for first-party loyalty data?+
Fundle's AI Platform ships with a native consent management module, versioned audit trails, self-service principal rights flows, cascade delete architecture, and Fundle AI Agents that validate consent state before every campaign execution. Fundle supports compliant loyalty management across 123+ Indian malls post DPDP rollout, making it the most DPDP-ready loyalty infrastructure available for Indian retail operators today.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
