“Agentic AI in loyalty means the platform argues with you about your own assumptions. If your AI agrees with everything you say, it's just an autocomplete with a logo.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand DPDP's seven data principal rights and map each to your loyalty touchpoints before writing a single line of code
  • Audit every consent record in your CRM — most Indian retailers will find 40-60% of their loyalty base lacks a lawful basis for marketing
  • Select a platform that separates consent management from campaign execution so a withdrawn consent auto-suppresses across every channel in real time
  • Implement role-based access controls and data residency on Indian soil to satisfy both DPDP and your enterprise infosec policy
  • Monitor compliance continuously with automated dashboards, not quarterly spreadsheets — regulators will not wait for your audit cycle

India's Digital Personal Data Protection Act, 2023 — the DPDP Act — is not a distant regulatory event. The rules are being notified in phases, enforcement timelines are tightening, and every Indian retail CMO or CIO who runs a loyalty program is now sitting on a compliance liability that can reach ₹250 crore per violation. That is not a hypothetical number; it is the statutory maximum penalty written into the Act itself. For a sector that has spent the last decade hoarding customer data in siloed CRMs, point-of-sale systems, and third-party campaign tools, the reckoning is overdue.

The challenge is structural. Most Indian mall operators and retail brands — from Phoenix Marketcity and Select CITYWALK to standalone chains like Manyavar, FabIndia, and Reliance Trends — built their loyalty programs when data collection was frictionless and consent was a checkbox buried in a terms-of-service document nobody read. Loyalty databases grew fat with mobile numbers, email IDs, transaction histories, and behavioural signals collected without granular, purpose-specific consent. The DPDP Act changes the legal basis for all of that. You now need informed, free, specific, and unambiguous consent for each processing purpose. A single consent tick-box for 'marketing communications' will not survive regulatory scrutiny.

The operational implication is significant. A mid-size mall loyalty program typically holds 8-15 lakh registered members. Retroactively re-consenting even 30% of that base while simultaneously redesigning the data collection architecture for new enrolments is a multi-quarter programme. Done badly, it collapses your addressable audience and kills campaign ROI. Done well, it produces a cleaner, higher-intent first-party data asset that outperforms your old spray-and-pray list by a wide margin. The brands that move first will own a compliance moat that slower competitors cannot easily replicate.

This is precisely the problem that a purpose-built DPDP compliant loyalty data platform is designed to solve. Platforms like Fundle have been architecting consent-first loyalty infrastructure for Indian retail since before the Act received Presidential assent — because the direction of travel was always clear. This guide walks you through the implementation journey in the sequence that actually works in practice: from understanding the legal requirements, through a data audit, platform selection, security hardening, team training, and ongoing monitoring. Every step is grounded in Indian retail operational reality, not imported Western compliance playbooks.

The DPDP Compliance Gap in Indian Retail Loyalty — By the Numbers

₹250 Cr
Maximum penalty per DPDP violation — the regulatory ceiling that makes board-level attention non-negotiable
40-60%
Estimated share of Indian retail loyalty members lacking a lawful, purpose-specific consent record under DPDP standards
123+
Malls where Fundle powers automated daily sales reporting, ensuring data compliance at enterprise scale across India
72 hours
Maximum window to notify the Data Protection Board of a personal data breach — far shorter than most Indian retail IT teams' incident response SLAs

Understanding DPDP Requirements for a Loyalty Data Platform

The DPDP Act establishes seven rights for data principals — your loyalty members — that have direct operational consequences for how you collect, store, process, and delete customer data. These rights are: the right to access information, the right to correction and erasure, the right to grievance redressal, the right to nominate a nominee, and critically, the right to withdraw consent at any time with the same ease with which it was given. That last right is the one that breaks most existing loyalty architectures.

Consider how Pantaloons or Lifestyle manages a loyalty member today. The customer enrolled at the POS on the shop floor, handed over a mobile number, and perhaps ticked a box on a paper form or a tablet screen. That consent record — if it exists at all — lives somewhere in a third-party POS system like POSist, GoFrugal, Petpooja, or Wondersoft, possibly in a format that cannot be queried programmatically. When that customer sends a WhatsApp message asking to be removed from all marketing, how long does it take your team to suppress that record across your CRM, your email tool, your SMS gateway, and your push notification platform? For most retailers, the honest answer is days — or it simply does not happen consistently.

The DPDP Act also introduces the concept of a Consent Manager — a registered entity through which data principals can manage their consents across multiple data fiduciaries. For mall operators running multi-brand loyalty programs, this creates both a complexity and an opportunity. You can potentially become a trusted consent anchor for your tenant brands, but only if your platform architecture is designed to handle purpose-specific consent at the individual brand level, not just at the mall level.

The Act's data minimisation principle is equally disruptive. Loyalty programs have historically collected every data point that a customer would surrender — date of birth, anniversary, children's names, income bracket — on the theory that richer data enables better personalisation. Under DPDP, you can only collect data that is necessary for the specific, stated purpose. This means your enrolment forms, mobile app sign-up flows, and POS integration scripts all need a legal review and a data architecture redesign. A DPDP compliant loyalty data platform must enforce these constraints at the collection layer, not as a post-processing cleanup.

The DPDP Compliance Journey for a Retail Loyalty Program

1Stage 1: Legal Mapping2Stage 2: Data Audit3Stage 3: Platform Migration4Stage 4: Re-Consent Campaign5Stage 5: Continuous Monitoring
Five sequential stages from legal mapping to continuous monitoring — each stage has a defined owner, toolset, and success metric.

Conducting a Data Audit and Consent Review Before Migration

A data audit is not an IT task. It is a cross-functional programme that requires your CMO, CIO, legal counsel, and your data protection officer in the same room with a shared understanding of what you are trying to achieve. The output is a data inventory — sometimes called a Record of Processing Activities or ROPA — that documents every category of personal data collected, the system where it sits, the lawful basis for processing, the retention period, and the third parties who receive it. For a mid-size retail chain or mall operator, this inventory will typically run to 60-120 line items once you include POS data, loyalty app data, third-party analytics integrations, and campaign tool data shares.

Start with your POS integrations. Systems like GoFrugal, Wondersoft, and POSist are common across Indian retail, and they often hold transactional data linked to mobile numbers without a corresponding consent record in the loyalty CRM. Pull a data sample — with appropriate access controls — and classify every field: is it personal data under DPDP? Does it fall into any of the special categories? What was the stated purpose at collection? This exercise alone typically reveals that 20-30% of data fields have no documented collection purpose.

Next, audit your consent records. For every member in your loyalty database, you need a timestamped, immutable consent record that specifies the purpose for which consent was given, the channel through which it was obtained, and the version of the privacy notice that was presented. If you are running on a legacy platform like EasyRewardz, Capillary, or a homegrown CRM, the probability that you have this level of consent granularity is low. This is not a criticism of those platforms — they were built in a pre-DPDP world. But it is the gap you need to close before you can claim compliance.

The consent review should produce a clean segmentation of your loyalty base into three buckets: members with a lawful consent record for each marketing purpose, members with partial or ambiguous consent, and members with no usable consent record. The third bucket must be suppressed from all outbound marketing immediately — not after the re-consent campaign, not after the platform migration. Immediately. The legal risk of continuing to market to unconsented members while you are mid-migration is not a risk any Indian retail board should be willing to carry.

Legacy Loyalty Platform vs. DPDP Compliant Loyalty Data Platform

Legacy Platform (Pre-DPDP Architecture)
DPDP Compliant Platform (Privacy-First Design)
Single opt-in checkbox at POS enrolment — no purpose specificity
Granular, purpose-specific consent captured and stored with timestamp, channel, and privacy notice version
Consent withdrawal requires manual CRM update — average 3-7 days to propagate across channels
Real-time consent withdrawal auto-suppresses across email, SMS, WhatsApp, and push within seconds via API
Data residency undefined — customer records may sit on overseas cloud infrastructure
Guaranteed Indian data residency with data localisation certificates available for regulatory audit
No automated breach detection — incidents discovered through manual monitoring or customer complaints
Automated anomaly detection with 72-hour breach notification workflow pre-built and tested
Data access unrestricted across marketing, IT, and agency teams — no role-based controls
Role-based access controls with field-level masking, full audit logs, and least-privilege access enforcement

Selecting a DPDP Compliant Platform: What Indian Retailers Must Demand

Platform selection is where Indian retail organisations make the most consequential mistakes. The tendency is to evaluate loyalty platforms on campaign features — segmentation depth, journey builder UX, offer management flexibility — while treating compliance architecture as a checkbox that every vendor can apparently tick. It cannot all be ticked equally. The difference between a platform that has bolted on a consent banner and one that has built consent management into its data model at the schema level is the difference between cosmetic compliance and structural compliance.

When evaluating vendors — whether that is Capillary, Antavo, EasyRewardz, MoEngage, WebEngage, Xeno, Almonds.ai, or Customer Capital — ask five non-negotiable technical questions. First: where is personal data physically stored, and can you provide a data residency certificate confirming Indian soil? Second: does the consent management module sit inside the loyalty data model, or is it a separate third-party integration? Third: how is consent withdrawal propagated to downstream systems, and what is the measured latency? Fourth: does the platform maintain an immutable audit log of every consent event, accessible to your DPO without raising a support ticket? Fifth: what is the platform's own DPDP compliance posture — is it itself a registered data processor with documented data processing agreements?

Beyond these technical gates, evaluate the platform's ability to handle the Indian loyalty context specifically. India's loyalty landscape is characterised by a high share of mobile-first enrolments, significant regional language diversity, a mix of organised and semi-organised retail, and a customer base that is increasingly WhatsApp-native rather than email-native. A platform designed for European GDPR compliance will handle consent well but may struggle with the operational realities of a 400-store Indian retail chain running on five different POS systems across four regional languages.

Fundle powers automated daily sales reporting across 123+ malls ensuring compliance — this is not a marketing claim but an operational reality that reflects the depth of integration required to make compliance work at Indian mall scale. The platform must connect to your existing POS infrastructure without requiring a full rip-and-replace, ingest consent signals from multiple enrolment channels simultaneously, and present a single unified consent state to every downstream campaign tool. That is a hard integration problem, and the vendor's answer to how they solve it at scale is more revealing than any feature demo.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

5-Step Playbook: Implementing a DPDP Compliant Loyalty Data Platform

01

Step 1 — Legal Architecture and DPO Appointment

Appoint or designate a Data Protection Officer with a direct reporting line to the board. Engage legal counsel to produce a DPDP-compliant privacy notice, consent language in all relevant regional languages (Hindi, Tamil, Telugu, Marathi at minimum), and a data processing agreement template for all loyalty technology vendors. This legal groundwork must precede any platform work — retrofitting legal requirements into a live migration is exponentially more expensive.

02

Step 2 — Data Audit and ROPA Creation

Execute the full data audit described earlier. Produce a ROPA covering all loyalty data flows — POS to loyalty CRM, loyalty CRM to campaign tools, campaign tools to telcos and email ESPs, and any data shares with mall tenant brands. Classify every member record by consent status. Suppress all unconsented records from active marketing. This suppression should be implemented as a hard technical control in the platform, not a manual process or a segment exclusion in your campaign tool.

03

Step 3 — Platform Migration with Consent Architecture

Migrate to a DPDP compliant loyalty data platform with a consent management layer built into the core data model. Migrate only consented member records in the first instance. Configure role-based access controls, data masking for PII fields, and Indian data residency settings before going live. Run a parallel period where both old and new platforms operate simultaneously — this is essential for validating consent record integrity and campaign suppression accuracy before you decommission the legacy system.

04

Step 4 — Re-Consent Campaign for Existing Members

Design a structured re-consent campaign for the partial-consent and no-consent segments. Use non-marketing channels where possible — transactional SMS, in-store POS prompts, and app push notifications tied to a transaction event — to present a clean consent request. Offer a genuine value exchange: members who re-consent receive a bonus points event or an exclusive offer. Set a sunset date — typically 90 days — after which non-responding members are permanently suppressed. Expect to retain 35-55% of this segment; model your campaign ROI accordingly.

05

Step 5 — Training, Monitoring, and Continuous Compliance

Train every team that touches customer data — POS staff, CRM executives, digital marketing managers, and third-party agency teams — on the new consent protocols and their personal obligations under DPDP. Implement automated compliance dashboards that your DPO can review daily: consent capture rates by channel, withdrawal volumes, breach alerts, and data subject request response times. Schedule a quarterly compliance review with legal, IT, and marketing in the same room. Compliance is not a project with an end date; it is an operational discipline.

Data Security, Access Controls, and Breach Readiness

Data security under DPDP is not merely an IT concern — it is a board-level governance obligation. The Act requires data fiduciaries to implement 'reasonable security safeguards' to prevent personal data breaches. While the Act deliberately avoids prescribing specific technical standards, the Data Protection Board will almost certainly assess reasonableness against ISO 27001, the MeitY security guidelines, and sector-specific standards like RBI's guidelines for payment data. For retail loyalty programs that collect transactional data and link it to mobile numbers, the bar is meaningfully higher than for a simple newsletter subscriber list.

Role-based access control is the foundational security control that most Indian retail organisations have not implemented rigorously. In practice, this means that a campaign manager at a Phoenix Marketcity tenant brand should be able to see aggregated segment sizes and campaign performance metrics — but should never be able to export a raw list of mobile numbers or email addresses. A POS technician troubleshooting a transaction error should be able to see transaction metadata — but should not be able to access the full loyalty profile of the customer. Field-level masking, with full PII visible only to a designated set of named users with a logged business justification, is the implementation standard you should be targeting.

Breac readiness is where most Indian retail operators are genuinely underprepared. The DPDP Act's 72-hour breach notification requirement means you need a tested incident response playbook, not a draft document on a SharePoint folder that nobody has read. Your playbook should define: what constitutes a notifiable breach, who in the organisation is authorised to make the notification decision, how you assemble the required information (categories of data affected, estimated number of data principals affected, likely consequences of the breach, and remedial measures taken) within the 72-hour window, and who actually submits the notification to the Data Protection Board. Run a tabletop exercise with your leadership team before you need to use this playbook in a real incident.

For mall operators specifically, the multi-tenancy of loyalty data creates additional access control complexity. Tenant brands like Tanishq, Lenskart, Apollo Pharmacy, and Cafe Coffee Day may have contractual rights to access loyalty data about their own customers — but not about customers of other tenants in the same mall. Your platform's data architecture must enforce this boundary technically, not just contractually. A privacy-first loyalty platform India operators should demand is one where tenant-level data isolation is a schema-level constraint, not a configuration setting that an administrator could accidentally disable.

DPDP Compliance Readiness Checklist for Indian Retail Loyalty Programs
  • DPO appointed with board-level reporting line and documented authority to halt non-compliant processing
  • ROPA completed covering all loyalty data flows — POS, CRM, campaign tools, tenant data shares, and third-party analytics integrations
  • All unconsented loyalty member records suppressed from outbound marketing via a hard technical control in the platform
  • Platform data residency confirmed on Indian soil with a written certificate from the vendor, referenced in the data processing agreement
  • Role-based access controls and field-level PII masking configured and tested across all user roles — including third-party agency access
  • 72-hour breach notification playbook documented, distributed to all relevant stakeholders, and validated via a tabletop exercise in the last 12 months
  • Quarterly compliance review cadence established with fixed attendance from legal, IT, marketing, and the DPO — with documented minutes and action tracking
“In Indian retail, first-party data was always the prize. DPDP just made the rules explicit — the brands that earn consent earn the customer. Everything else is noise.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

The Fundle AI Platform was designed from the ground up for the operational reality of Indian retail and mall loyalty — which means consent-first data architecture was a design requirement, not a compliance retrofit. Where legacy platforms treat consent as a marketing preference flag, the Fundle Loyalty platform treats it as a first-class data object: every consent event is timestamped, immutable, purpose-tagged, and directly linked to every downstream processing action. When a member withdraws consent for promotional communications, that withdrawal propagates across every channel integration — SMS, email, WhatsApp, push — in real time via the Fundle AI Workflow engine, with a full audit trail accessible to your DPO without a support ticket.

For mall operators, Fundle Mall Loyalty provides the multi-tenant data isolation architecture that DPDP compliance demands. Tanishq's customer data stays within Tanishq's data boundary inside the platform. Lenskart's transaction history is invisible to every other tenant. The mall operator sees aggregated programme metrics and can run mall-wide campaigns to consented members — but the platform architecture enforces data separation at the schema level, not through configuration. This is the difference between structural compliance and cosmetic compliance.

Fundle Brand Loyalty extends the same architecture to standalone retail chains, while Fundle AI Agents handle the operational complexity of consent management at scale — including automated re-consent campaign journeys, data subject access request fulfilment workflows, and erasure request processing that cascades across all connected systems. These are not features you configure once and forget; the Fundle Agentic AI layer monitors consent state continuously and flags anomalies — a spike in withdrawals from a specific cohort, an enrolment channel showing abnormally low consent capture rates — so your compliance team can investigate before a pattern becomes a regulatory problem.

Vineet Narang's founding vision for Fundle was that loyalty in Indian retail could not be separated from trust — and that trust, in a post-DPDP world, is operationalised through consent architecture, data transparency, and the genuine ability for a customer to control their data. Fundle powers automated daily sales reporting across 123+ malls ensuring compliance — but the deeper value is that every one of those reporting streams is built on a data foundation that your legal team can defend in front of the Data Protection Board. The question for Indian retail CMOs and CIOs is not whether to build a DPDP compliant loyalty data platform. It is how fast you can do it, and whether you are building it on infrastructure that will hold up under regulatory scrutiny two years from now.

Frequently asked

What is a DPDP compliant loyalty data platform, and how is it different from a regular loyalty CRM?+

A DPDP compliant loyalty data platform treats consent as a first-class data object embedded in the core data model — not as a marketing preference flag. It enforces purpose-specific consent at collection, propagates consent withdrawals in real time across all channels, maintains immutable audit logs of every consent event, guarantees Indian data residency, and supports data subject rights like access, correction, and erasure via automated workflows. A standard loyalty CRM was not designed with these constraints and typically requires significant architectural modification or replacement to meet DPDP requirements.

Do existing loyalty members need to re-consent under DPDP if they signed up before the Act came into force?+

Yes, in most cases. If your existing consent records lack purpose specificity, channel attribution, or a reference to a DPDP-compliant privacy notice, they are unlikely to satisfy the Act's consent standard. You should conduct a consent audit and segment your loyalty base by consent quality. Members without a lawful consent record should be suppressed from marketing immediately and targeted with a structured re-consent campaign. Expect to retain 35-55% of this segment — model your addressable audience and campaign budgets accordingly.

What is the penalty for a data breach involving loyalty member data under DPDP?+

The DPDP Act provides for penalties of up to ₹250 crore per breach of the security safeguards obligation. Additional penalties apply for failure to notify the Data Protection Board within 72 hours of becoming aware of a breach, and for non-compliance with data principal rights requests. These penalties are per-incident, not aggregate — a single breach affecting a large loyalty database could trigger multiple penalty heads simultaneously. Boards and audit committees should be modelling this as a material financial risk.

How should a mall operator handle DPDP compliance for a multi-brand loyalty program where tenant brands also access member data?+

Mall operators running multi-brand loyalty programs are data fiduciaries under DPDP. When tenant brands access member data, they become either joint data fiduciaries or data processors, depending on the nature of the access and the contractual arrangement. You need a data processing agreement with every tenant brand that accesses loyalty data, specifying the permitted processing purposes, data security obligations, and audit rights. Your loyalty platform must enforce data isolation at the schema level so that tenant brands can only access data about their own customers. Purpose-specific consent obtained at enrolment must cover the specific tenant brand's processing purposes.

What does 'consent withdrawal in real time' actually mean in technical terms for a loyalty platform?+

Real-time consent withdrawal means that when a member withdraws consent — via an app preference centre, a WhatsApp message, a web portal, or a customer service interaction — the platform updates the member's consent state immediately and triggers an automated suppression event via API to every connected downstream system: email ESP, SMS gateway, WhatsApp Business API, push notification service, and any third-party analytics integrations. The entire propagation should complete in under 60 seconds. The platform should log every step of this propagation with timestamps, so you can demonstrate to the Data Protection Board that a withdrawal was acted upon promptly.

How long does it typically take an Indian retail chain or mall operator to implement a DPDP compliant loyalty data platform?+

A realistic timeline for a mid-size Indian retail operator with 5-20 lakh loyalty members runs 6-9 months end-to-end. Legal architecture and DPO appointment: 4-6 weeks. Data audit and ROPA: 6-10 weeks. Platform selection, contracting, and configuration: 8-12 weeks, running partially in parallel with the audit. Migration and parallel running: 6-8 weeks. Re-consent campaign: 12 weeks. Training and monitoring cadence: ongoing from week one. Organisations that attempt to compress this timeline by skipping the audit phase or running the re-consent campaign concurrently with the platform migration typically encounter data integrity problems that extend the overall programme by 3-4 months.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?