“We will not build a loyalty platform for the AI era. We are building the loyalty platform of the AI era. That's the only standard worth shipping against.”
- •Understand why DPDP's consent framework directly impacts how loyalty programs collect, store, and activate customer data
- •Identify the five biggest operational gaps mall operators face when retrofitting consent into existing loyalty stacks
- •Benchmark your consent UX against what good looks like — granular, revocable, timestamped, and auditable
- •Follow a five-step playbook to wire consent management into your loyalty workflow automation without breaking campaign velocity
- •Deploy Fundle ConsentFirst CMP to manage consent at scale — already live for over 1.33 crore users across India
On August 11, 2023, India's Digital Personal Data Protection Act received Presidential assent. For most industries, it was a compliance headline. For loyalty program managers at Indian shopping malls and large retail chains, it was a structural disruption. Loyalty programs are, by design, data-harvesting machines — they capture phone numbers at checkout, track purchase frequency across brands, infer household income from basket size, and fire automated WhatsApp messages at 8 PM on a Tuesday. Every single one of those actions now sits inside the DPDP's regulatory perimeter.
The DPDP Act establishes that a 'Data Principal' — your loyalty member — must give free, specific, informed, and unambiguous consent before their personal data is processed. That sentence alone invalidates an estimated 60-70% of the consent flows currently embedded in Indian loyalty programs. Pre-ticked checkboxes on enrollment forms at Lifestyle's billing counter, blanket SMS opt-ins at Pantaloons' loyalty desk, and opaque 'by joining you agree to all marketing' clauses at Phoenix Marketcity are all non-compliant by the Act's standard. The Data Protection Board of India, once fully constituted, can levy penalties of up to ₹250 crore per breach instance.
What makes this particularly acute for mall operators is the multi-brand, multi-touchpoint nature of the loyalty environment. A shopper at Select CITYWALK might enroll via the mall's own app, make a purchase at a Tanishq outlet inside the mall, grab a coffee at Cafe Coffee Day, and redeem points at FabIndia — all in one visit. Each of those interactions potentially involves a separate data processor, a separate consent moment, and a separate purpose for data use. Stitching consent across that journey, in real time, without creating friction that kills enrollment conversion, is the central technical and operational challenge of 2024-2025 Indian retail loyalty.
This is precisely the problem Fundle was built to solve. DPDP compliant loyalty automation is not a feature add-on — it is the foundational architecture on which every downstream campaign, personalization engine, and AI workflow must sit. This article lays out the regulatory specifics, the implementation challenges, the benchmarks for what good consent UX looks like, and a concrete playbook for loyalty program managers who need to get this right before the enforcement clock runs out.
The DPDP Consent Crisis in Indian Loyalty: By the Numbers
Defining Consent Management Per DPDP Regulations
The DPDP Act defines 'consent' with surgical precision. It must be free — not bundled with a discount or made a precondition of program enrollment. It must be specific — not a single checkbox covering personalization, transaction confirmations, third-party sharing, and marketing in one stroke. It must be informed — the data principal must understand what they are consenting to, in language they can comprehend, ideally in their preferred Indian language. And it must be unambiguous — silence, pre-ticked boxes, or inaction do not constitute consent.
For a loyalty program manager at a large mall or retail chain, this translates into several concrete obligations. First, you need purpose-specific consent notices: a member must separately agree to (a) transaction-based point crediting, (b) personalized marketing communications, (c) sharing anonymized data with brand partners inside the mall, and (d) AI-based profiling for personalized offers. Bundling all four under one checkbox is a violation. Second, you must offer an equally easy mechanism to withdraw consent as to give it — a 'manage my preferences' link in every WhatsApp message or email that actually works, not one that leads to a dead-end landing page.
Third, and this is where most enterprise loyalty stacks completely fail, you need a timestamped, auditable consent ledger. If the Data Protection Board asks you to demonstrate that a specific member — say, a Manyavar customer who received a birthday offer SMS — had given explicit consent for that communication on a specific date, you must produce that record within a defined timeframe. Platforms like Capillary, EasyRewardz, or legacy POS-bundled loyalty modules from GoFrugal or Wondersoft were not architected with this requirement in mind. Their consent capture is typically a single flag in a customer master record, not an immutable log of consent events.
The DPDP also introduces the concept of a 'Consent Manager' — a DPDP-registered intermediary that acts as a single consent dashboard for data principals across multiple data fiduciaries. For mall operators, this is a significant structural opportunity: a mall's loyalty platform could potentially serve as the consent manager for all brand partners inside the mall ecosystem, giving shoppers one unified place to grant and revoke permissions. This is an architectural vision that DPDP compliant loyalty automation platforms must be designed around from day one, not retrofitted later.
The DPDP-Compliant Loyalty Consent Journey
Challenges in Implementing Consent Management
The gap between what DPDP requires and what most Indian loyalty stacks can deliver today is wide — and closing it under live operating conditions, without dropping enrollment rates or campaign volumes, is the core challenge facing mall CMOs heading into 2025.
The first and most pervasive challenge is legacy architecture. Most large mall operators and retail chains built their loyalty programs between 2015 and 2020, on platforms that treated consent as a binary field. A GoFrugal or POSist POS integration might capture a mobile number and a single marketing opt-in flag at the billing counter. That is the entirety of the consent infrastructure for millions of members at hundreds of Reliance Trends and Apollo Pharmacy outlets. Retrofitting a multi-purpose, multi-channel, timestamped consent layer on top of these systems without a complete re-enrollment campaign is technically complex and commercially risky — re-enrollment campaigns in Indian retail typically see 25-40% drop-off in active member base.
The second challenge is multilingual consent notice delivery. India's DPDP Act mandates that consent notices be provided in a language the data principal understands. A mall in Chennai serves Tamil-speaking shoppers; one in Ahmedabad serves Gujarati-speaking ones. A single English-language consent screen fails both. Most loyalty platforms — including MoEngage, WebEngage, and Xeno, which are excellent campaign orchestration tools — do not have native consent notice localization built into their enrollment flows. This is a gap that requires dedicated consent management infrastructure, not just a campaign tool.
The third challenge is consent drift in automated workflows. Loyalty workflow automation India is increasingly AI-driven: birthday campaigns fire automatically, lapsed-member re-engagement sequences run on triggers, and cross-brand offer dispatches happen without human review. Each automated step in these workflows must verify, at the moment of execution, that the target member's consent is still active for that specific communication purpose and channel. A member who withdrew marketing consent last Tuesday cannot receive a Diwali offer campaign that was scheduled three weeks ago. Most workflow automation engines — including those from Antavo and Almonds.ai — do not natively perform real-time consent validation at the workflow node level. They rely on a static suppression list that is updated periodically, which creates a compliance window.
Fourth, malls with multi-brand ecosystems face a consent graph problem: if a shopper gave consent to the mall's loyalty platform to share anonymized purchase data with brand partners, and subsequently withdrew that consent, every downstream data flow to every brand partner must be immediately interrupted. Operationalizing this in a live mall with 150+ brand stores, multiple POS systems, and asynchronous data pipelines is a genuine systems engineering challenge that most operators have not yet solved.
Generic Loyalty Platform vs. DPDP-Native Consent Architecture
Ensuring Transparency and Customer Trust in Loyalty Programs
Compliance with DPDP is the floor, not the ceiling. The mall operators and retail brands that will win the next decade of Indian customer loyalty are those who treat consent not as a legal checkbox but as a trust signal — a visible, ongoing demonstration that the brand respects the customer's data on the customer's terms.
The behavioral data is clear: Indian consumers, particularly in the 25-40 age bracket that drives discretionary retail spend at malls like Phoenix Marketcity and Select CITYWALK, are increasingly data-aware. A 2024 LocalCircles survey found that 71% of urban Indian consumers have at some point refused to share their mobile number at a retail checkout because they did not trust how it would be used. That is a loyalty enrollment opportunity lost at the very first touchpoint. Brands that lead with a transparent consent proposition — 'here is exactly what we will do with your data, here is how to change your mind at any time' — convert enrollment hesitation into active trust.
Transparency in loyalty programs has three operational expressions. The first is a readable privacy notice: not a 3,000-word legal document, but a four-sentence plain-language summary of what data is collected, why, who sees it, and how long it is kept. FabIndia's brand positioning around authenticity and trust makes this kind of transparent communication on-brand, not just legally required. The second is a live consent dashboard accessible to every member, showing in real time which permissions they have granted and providing one-tap controls to modify each. The third is proactive consent renewal: when a new use case is introduced — say, a mall wants to start sharing purchase data with a new fintech partner for EMI offers — members must be notified and asked to opt in, not silently enrolled.
The commercial upside of this approach is not theoretical. Research from the Baymard Institute and replicated in Indian e-commerce contexts shows that transparent data practices increase repeat purchase rates by 18-22% among high-value loyalty members. At an average Indian mall loyalty program with 5-8 lakh active members and an average annual spend of ₹45,000 per active member, a 20% increase in repeat visit frequency from the top 10% of members translates to incremental revenue of ₹45-90 crore annually — numbers that make the technology investment in a proper consent management system look trivial by comparison.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
5-Step Playbook: Integrating Consent Management With Loyalty Workflow Automation
Audit Your Current Consent State
Pull every consent record from your existing loyalty CRM — whether that is on Capillary, EasyRewardz, or a custom stack. Classify each record by consent type (transactional, marketing, profiling, partner-sharing), capture date, channel, and language. Identify the gap between your current consent data and DPDP's requirements. For most operators, 50-70% of records will need re-consent before they can be used in automated campaigns.
Architect a Consent Ledger Separate From Your CRM
Your CRM is optimized for campaign execution; your consent ledger must be optimized for legal defensibility. Build or deploy a dedicated consent record system that stores every consent event — grant, modification, withdrawal — as an immutable, timestamped log. This ledger must be queryable by member ID and exportable within 72 hours for regulatory response. Fundle ConsentFirst CMP provides this as a native module integrated with the loyalty platform.
Rebuild Enrollment Flows With Granular, Multilingual Consent Screens
Redesign your enrollment UX — whether at a mall kiosk, a brand store POS, or a mobile app — to present separate, opt-in-specific consent screens for each data use purpose. Detect the device language or ask the member's preferred language at the start. A/B test consent screen designs for enrollment conversion; well-designed granular consent flows in Indian retail typically see only a 3-5% reduction in enrollment completion versus blanket opt-ins, not the 20-30% that operators fear.
Wire Consent Validation Into Every Workflow Node
For each automated campaign or workflow in your loyalty system — birthday triggers, win-back sequences, cross-brand offer dispatches — insert a consent validation API call at the point of audience selection and again at the point of message dispatch. If a member's consent for a given channel or purpose is not active at execution time, the workflow must route them to a suppression bucket, not silently skip and log an error. This real-time validation is what separates DPDP compliant loyalty automation from a suppression-list workaround.
Launch a Re-Consent Campaign for Legacy Members
For the portion of your member base whose existing consent records do not meet DPDP standards, run a structured re-consent campaign before the enforcement deadline. Use your highest-trust channels first — in-store at billing counter, then app push notification, then SMS. Offer a tangible incentive for completing the re-consent flow: bonus points, an exclusive offer, or early access to a sale event. Segment the non-responders after 90 days and sunset their marketing eligibility until re-consent is obtained. Document the entire campaign as evidence of good-faith compliance effort.
KPIs to Track in a DPDP-Compliant Loyalty Automation Program
A consent management infrastructure investment is only defensible if you can measure its impact on both compliance posture and commercial outcomes. Mall CMOs and loyalty program managers need a dual-track KPI framework: one track for regulatory health, one for business performance.
On the regulatory health track, the primary metrics are: consent coverage rate (percentage of active members with DPDP-compliant consent records across all active data use purposes — target above 95%); consent audit readiness score (time in hours to produce a complete consent history for any named data principal — target under 4 hours); withdrawal response latency (time from member consent withdrawal to full suppression across all channels — target under 60 seconds for digital channels, under 24 hours for offline touchpoints); and consent drift incidents (automated workflows that fired despite missing or withdrawn consent — target zero, tracked monthly).
On the business performance track, the metrics that consent-first loyalty programs should monitor are: consent-gated enrollment conversion rate (percentage of new enrollments that complete granular consent flows without abandonment — benchmark 72-78% in well-designed flows); opted-in member engagement rate (click-through and redemption rates segmented by consent tier — members who have opted into profiling and personalized marketing should show 2-3× higher engagement than those with minimal consent); and revenue per consented member (average spend per year from members with full consent versus those with partial consent — the gap quantifies the commercial value of each consent tier).
The connection between these two tracks is the insight that drives strategic investment: when consent coverage rate drops, revenue per consented member becomes the only revenue you can legally pursue through automated channels. A mall with 8 lakh active members and a 60% consent coverage rate has effectively reduced its addressable loyalty automation audience to 4.8 lakh members. At ₹45,000 average annual spend and even a 5% campaign-driven incremental spend uplift, the lost revenue from the 3.2 lakh non-consented members is ₹72 crore per year. That is the cost of poor consent management, expressed in rupees.
- Consent records for all active loyalty members are purpose-specific, timestamped, and stored in an immutable audit ledger — not just a binary flag in the CRM
- Enrollment flows at every touchpoint (app, kiosk, POS, WhatsApp bot) present separate opt-in screens for transactional data, marketing communications, AI-based profiling, and third-party partner data sharing
- Consent notices are available in at least four regional languages relevant to your mall's primary catchment area
- Every automated loyalty workflow node performs a real-time consent validation API call before dispatching any communication — no reliance on periodic suppression list updates
- A member-facing consent management portal or USSD shortcode is live and tested, allowing any loyalty member to view, modify, or withdraw consent within 60 seconds without calling a helpline
- A re-consent campaign plan is documented and ready to execute for legacy members whose existing consent records do not meet DPDP standards
- Your legal and compliance team has reviewed the consent notice language and confirmed it meets DPDP's 'clear and plain language' requirement, including readability for low-literacy users
“In Indian retail, consent is not a legal disclaimer — it is the opening move in a trust relationship. Get it wrong at enrollment and no amount of AI personalization will recover the customer's confidence.”
How Fundle solves this
Fundle was architected from its first line of code with India's regulatory and data-privacy reality in mind. The Fundle AI Platform is not a Western loyalty tool retrofitted for Indian compliance — it is a ground-up, India-first loyalty and customer engagement platform where DPDP compliant loyalty automation is a foundational design principle, not an afterthought.
At the center of Fundle's compliance architecture is the Fundle ConsentFirst CMP — India's purpose-built consent management platform for loyalty programs. Fundle ConsentFirst manages consent for over 1.33 crore users, ensuring loyalty programs remain DPDP-compliant at every point in the member lifecycle. It maintains an immutable, timestamped consent ledger for every data principal, with purpose-specific records covering transactional processing, marketing communications, AI-based profiling, and inter-brand data sharing within mall ecosystems. The ledger is queryable within minutes, audit-report-ready in under four hours, and integrated natively with the Fundle Loyalty and Fundle Mall Loyalty modules so that consent status flows automatically into campaign audience selection without manual suppression list management.
Fundle Brand Loyalty extends this infrastructure to enterprise retail brands operating across multiple formats — Manyavar running standalone stores and shop-in-shop counters inside malls, Apollo Pharmacy across pharmacy and health-focused mall anchors, or Lenskart across its franchised retail footprint. Each brand gets its own consent namespace within the Fundle AI Platform, with the option to federate consent data upward to a mall-level consent manager role for shoppers who interact with multiple brands in the same mall ecosystem. This federated consent graph is precisely the architecture that the DPDP's Consent Manager framework envisions, and Fundle is positioned to operate as a registered Consent Manager once the MeitY certification framework is finalized.
Fundle AI Agents and Fundle Agentic AI bring real-time consent validation into the automation layer. Every Fundle AI Workflow — whether a birthday campaign, a lapsed-member reactivation sequence, or a cross-brand Diwali offer dispatch — includes a consent validation node that fires an API call to the ConsentFirst ledger before any message is dispatched. If consent has been withdrawn, modified, or is absent for the relevant purpose or channel, the workflow routes the member to a suppression bucket and logs the event. This closes the compliance window that plagues every loyalty operator currently running automated campaigns on static suppression lists. Vineet Narang's founding vision for Fundle was that AI-powered loyalty must be consent-powered loyalty — and the Fundle AI Platform is the fullest expression of that conviction available in the Indian market today.
Frequently asked
Does the DPDP Act apply to loyalty programs at small malls and regional retail chains, or only to large enterprises?+
The DPDP Act applies to any entity that processes digital personal data of Indian citizens, regardless of company size. However, the Government of India may notify certain categories of 'Significant Data Fiduciaries' subject to enhanced obligations. Even without that designation, any mall or retail chain running an automated loyalty program that sends marketing communications must have DPDP-compliant consent in place. The penalty exposure scales with the nature and volume of the violation, not just company size.
Can a loyalty program still use existing member data collected before DPDP enforcement begins?+
This is the most commercially sensitive question for operators with large legacy member bases. The prevailing legal interpretation is that data collected before DPDP enforcement is not grandfathered — if you continue to process that data for marketing purposes after enforcement begins, you need compliant consent. The practical answer for most operators is a structured re-consent campaign before the enforcement deadline, combined with a clear sunset policy for members who do not re-consent.
How does Fundle ConsentFirst handle consent for shoppers who interact with multiple brands inside the same mall?+
Fundle ConsentFirst supports a federated consent model where a shopper's consent preferences are captured once at the mall level and inherited by brand-level programs, subject to the shopper's explicit agreement to the federated arrangement. Each brand still maintains its own purpose-specific consent records, but the shopper sees a unified consent dashboard covering all their mall interactions. This significantly reduces consent fatigue while maintaining DPDP compliance at every level.
What happens to automated loyalty campaigns already scheduled when a member withdraws consent?+
Under DPDP, withdrawal of consent must result in immediate cessation of the processing for which consent was withdrawn. In practical terms for loyalty automation, this means that any campaign already in dispatch queue for a member who has withdrawn marketing consent must be suppressed before delivery. Fundle AI Workflow performs a real-time consent check at the point of dispatch — not just at campaign scheduling — so that scheduled campaigns are automatically suppressed for withdrawing members without manual intervention.
Is offering loyalty points as an incentive to obtain consent legal under DPDP?+
DPDP requires that consent be 'free' — meaning it cannot be coerced. There is an important distinction, however, between coercion and incentivization. Offering bonus points for completing a re-consent flow is likely permissible if the baseline program benefits are not withheld from members who decline to give expanded consent. The risk zone is conditioning core program enrollment or point-crediting on consent to marketing or profiling — that would likely be treated as coercive and non-compliant.
How long does it take to implement Fundle ConsentFirst on top of an existing loyalty program?+
Implementation timelines depend on the complexity of the existing loyalty stack. For malls or retail chains running on Capillary, EasyRewardz, or common POS platforms like Petpooja, GoFrugal, or POSist, Fundle ConsentFirst integrations are available via pre-built connectors, typically enabling a go-live in 8-12 weeks for mid-size deployments. Enterprise implementations with custom CRMs, multi-brand ecosystems, and multilingual consent flows across dozens of mall properties are typically completed in 16-20 weeks, including the re-consent campaign rollout.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
