“Indian retail is the most dynamic consumer market on the planet. The platforms it deserves should be the most dynamic too. That conviction is why Fundle exists.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand how India's DPDP Act 2023 reshapes loyalty data collection and consent obligations for retail brands
  • Audit your existing loyalty stack against seven non-negotiable compliance checkpoints before Q2 2025 enforcement kicks in
  • Design consent flows that are granular, revocable, and linked to actual loyalty programme mechanics
  • Evaluate every martech vendor — POS integrations, CRM, ESP — on data residency, breach notification SLAs, and audit readiness
  • Deploy a DPDP compliant loyalty data platform like Fundle that bakes compliance into the product, not the legal team's inbox

India's Digital Personal Data Protection Act 2023 — the DPDP Act — is not a framework you can retrofit into your loyalty programme six months after your legal team flags it. It is a structural shift in how every Indian retailer, mall operator, and enterprise brand must collect, store, process, and delete customer data. The fines are real: up to ₹250 crore per violation for significant data fiduciaries. And loyalty programmes — which sit at the richest intersection of identity, behavioural, transactional, and location data — are squarely in the regulator's crosshairs.

The Indian retail loyalty landscape has matured fast. Phoenix Marketcity's Phoenix First programme, Select CITYWALK's tiered rewards, Tanishq's Golden Harvest scheme, Lenskart's membership club, and Manyavar's occasion-based CRM collectively hold hundreds of millions of data points on Indian consumers. Platforms like Capillary, EasyRewardz, and Xeno have powered much of this growth. But growth-era data practices — bulk SMS blasts to unverified numbers, pre-ticked consent checkboxes, indefinite data retention, third-party data sharing without explicit disclosure — are now liability-grade risks. The DPDP Act does not grandfather legacy consent.

For CMOs and CIOs leading loyalty and data privacy compliance, the question is not whether to comply but how fast you can build a defensible, auditable, and customer-centric compliance posture without breaking your loyalty programme's commercial engine. That tension — between personalisation depth and consent granularity — is the central design challenge of the next 24 months in Indian retail. Every loyalty point redemption, every WhatsApp nudge, every RFM-triggered offer is a data processing event that now requires a lawful basis.

This is precisely the operating environment Fundle was built for. A DPDP compliant loyalty data platform is not a checkbox — it is a competitive moat. Brands that treat consent as a trust signal rather than a legal irritant will see higher opt-in rates, richer first-party data pools, and better long-term customer lifetime value. This checklist gives Indian retail CMOs and CIOs the exact compliance architecture, vendor evaluation criteria, and operational playbook to build that moat correctly.

Indian Retail Loyalty & DPDP: The Numbers That Matter

₹250 Cr
Maximum penalty per violation under India's DPDP Act 2023 for significant data fiduciaries
68%
Share of Indian loyalty programme members who say they would stop sharing data if consent controls were unclear (RedSeer 2023)
3.2×
Higher customer lifetime value for loyalty members enrolled via explicit, granular consent versus implicit opt-in (Fundle platform benchmark)
₹180 Cr+
Estimated combined annual loyalty points liability across top 10 Indian mall operators — all subject to DPDP data audit obligations

Understanding DPDP and Other Privacy Regulations Governing Loyalty Data

The Digital Personal Data Protection Act 2023 establishes a consent-first, purpose-limited framework for processing personal data of Indian citizens. For loyalty programmes, this translates into five immediate obligations: collect data only for a specified and lawful purpose, obtain free, specific, informed, and unambiguous consent before processing, provide every data principal the right to access, correct, and erase their data, notify the Data Protection Board and affected individuals within 72 hours of a data breach, and appoint a Data Protection Officer if you qualify as a significant data fiduciary.

Retail brands running loyalty programmes will almost certainly qualify as significant data fiduciaries given the volume and sensitivity of data they process. A single mid-sized mall operator running a programme across 200 stores, capturing purchase history, phone numbers, email IDs, demographic profiles, and app location signals for 1.5 million members, is processing sensitive personal data at scale. The MeitY rules expected in 2024-25 will specify exact thresholds, but operators should plan for significant data fiduciary obligations now.

Beyond the DPDP Act, Indian retailers must also align with the Information Technology Act 2000 and its 2011 Sensitive Personal Data Rules (still operative until DPDP rules fully supersede them), RBI's data localisation requirements if your loyalty programme integrates payment instruments or co-branded cards, and TRAI's commercial communications regulations governing SMS and WhatsApp marketing — the primary channels for loyalty communications. If your loyalty programme operates across MENA markets alongside India, you additionally need to map compliance against UAE's PDPL and Saudi Arabia's PDPPL, both of which share structural similarities with GDPR.

The critical insight for CMOs is this: loyalty data is not just CRM data. It is a longitudinal behavioural record that can reveal income levels, health conditions (Apollo Pharmacy loyalty data), religious practices (FabIndia purchase patterns during festivals), and family composition (Pantaloons children's category purchases). This depth is precisely what makes loyalty data valuable — and precisely what makes it high-risk under a purpose-limitation framework. Your compliance architecture must reflect this depth, not flatten it into a generic privacy policy checkbox.

DPDP Compliance Journey for a Loyalty Programme

1Stage 1: Data Inventory & Purpose Mapping2Stage 2: Consent Architecture Design3Stage 3: Data Residency & Security Hardening4Stage 4: Rights Management Infrastructure5Stage 5: Continuous Audit & Breach Readiness
From raw data collection at POS to a fully auditable, consent-driven loyalty data architecture — five stages every Indian retailer must navigate under the DPDP Act 2023.

Consent and User Rights Management: Building a Privacy-First Loyalty Programme India

Consent under the DPDP Act is not a one-time event — it is a living, revocable permission that must be as easy to withdraw as it was to give. For loyalty programmes, this creates a design challenge that most legacy platforms — including older versions of Capillary and EasyRewardz — were not architected to handle. Consent must be purpose-specific: a member who agrees to receive purchase history-based offers has not necessarily consented to their data being shared with the mall's anchor tenant brands for cross-brand targeting. These are separate processing purposes requiring separate consent signals.

Practically, this means your loyalty enrolment flow — whether at a Reliance Trends POS terminal, a Lifestyle app onboarding screen, or a Pantaloons in-store kiosk — must present consent in plain language, broken into distinct purposes: transaction processing, personalised offers, third-party brand communications, and analytics profiling. Each toggle must be independently configurable. Bundling all consent into a single 'I agree to T&Cs' checkbox is a DPDP violation waiting for an enforcement action.

User rights management is the operational challenge that most retail CIOs underestimate. Under DPDP, every loyalty member has the right to access a summary of their personal data within 30 days of a written request, correct inaccurate data (address, date of birth, phone number), erase their data upon withdrawal from the programme — which means deleting not just the CRM record but also downstream copies in your ESP, your analytics warehouse, your POS system, and every vendor integration — and nominate a representative to exercise these rights in case of incapacity or death. The erasure right, in particular, requires a data lineage map: you need to know every system that holds a copy of a member's data, or you cannot honour an erasure request fully.

For a consent based loyalty data management architecture, the best-practice model is a centralised consent ledger — a single source of truth for every consent signal, timestamped, with the version of the consent language the member agreed to and the channel on which they gave it. Every downstream system — ESP, WhatsApp BSP, analytics platform, POS — queries this ledger before processing. When consent is withdrawn, the ledger update propagates automatically. This is not a future-state aspiration; it is the baseline requirement for DPDP compliance in a multi-channel loyalty ecosystem.

Legacy Loyalty Platform vs. DPDP Compliant Loyalty Data Platform

Legacy Loyalty Stack (Pre-DPDP)
DPDP Compliant Loyalty Data Platform
Single bundled consent checkbox at enrolment — no purpose granularity
Granular, purpose-specific consent toggles with version-controlled consent ledger
Data retained indefinitely or until manual deletion request
Automated data retention policies with purpose-expiry triggers and erasure workflows
Member data shared with third-party brand partners by default
Explicit, opt-in consent required for each brand partner data share — auditable by regulator
Breach notification timeline undefined or dependent on vendor SLA
72-hour breach notification protocol with automated alerting and Data Protection Board reporting workflow
No self-service rights portal — erasure and access requests handled manually via email
Self-service member portal for data access, correction, and erasure with 30-day SLA tracking

Data Security Measures and Encryption Every Loyalty CMO Must Mandate

The DPDP Act does not prescribe specific technical standards — it requires 'reasonable security safeguards' — but MeitY guidance and India's IS/ISO 27001 framework provide the practical benchmarks. For a loyalty data platform processing millions of members' personal and transactional data, reasonable is a high bar. Here is what your security architecture must include, with no exceptions for cost or complexity.

Encryption is non-negotiable at every layer. Data at rest must be encrypted using AES-256 or equivalent. Data in transit — between POS systems (Petpooja, POSist, GoFrugal, Wondersoft integrations are common in Indian retail) and the loyalty platform, between the loyalty platform and your ESP, between the platform and your analytics warehouse — must use TLS 1.3. Database-level encryption alone is insufficient; column-level encryption for sensitive fields (Aadhaar-linked IDs, mobile numbers, date of birth) adds a critical second layer. Key management must be separated from data storage — storing encryption keys in the same environment as encrypted data is a single point of failure.

Access control architecture must follow the principle of least privilege. Your call-centre agents running loyalty redemptions at a Cafe Coffee Day franchise should not have access to members' full purchase history across all brands. Role-based access controls, enforced at the API layer, with multi-factor authentication for all admin roles, are the minimum standard. Every data access event — who accessed which record, when, from which IP, for what stated purpose — must be written to an immutable audit log. This log is your primary evidence artefact in any regulatory investigation or Data Protection Board proceeding.

Data residency is a specific DPDP compliance requirement for sensitive personal data — it must be stored on servers physically located in India. Many global martech platforms (certain ESPs, CRM tools, and analytics platforms popular in Indian retail) store data on AWS US-East or EU data centres by default. Your vendor contracts must include explicit data residency clauses with right-to-audit provisions. If your loyalty platform vendor cannot provide a signed data processing agreement confirming India residency, you are operating with unquantified regulatory risk. This is a common gap in older loyalty deployments at Indian mall operators and brand retailers alike.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

7-Step DPDP Compliance Playbook for Indian Retail Loyalty Programmes

01

Step 1: Full Data Inventory and Purpose Audit

Map every personal data field collected by your loyalty programme — at POS, app, web, and in-store kiosk — to a specific, stated processing purpose. Eliminate data collection for which you cannot articulate a clear, member-facing purpose. This is your compliance foundation.

02

Step 2: Rebuild Consent Flows with Purpose Granularity

Redesign enrolment consent to cover at minimum: transaction processing, personalised marketing, third-party brand sharing, and behavioural profiling. Each must be independently toggleable. Migrate legacy members by re-obtaining consent via a clearly communicated re-permission campaign — WhatsApp and app push are the most effective channels in Indian retail.

03

Step 3: Deploy a Centralised Consent Ledger

Implement a version-controlled consent ledger that timestamps every consent event, records the exact consent language version, the channel, and the member identifier. Integrate all downstream systems (ESP, WhatsApp BSP, POS, analytics) to query this ledger in real time before any data processing event.

04

Step 4: Build the Member Rights Self-Service Portal

Launch a self-service portal (web and in-app) where members can view their stored data, request corrections, and initiate erasure. Configure automated workflows to propagate erasure requests to all downstream systems within the 30-day DPDP response window, with a tracked SLA dashboard for your DPO.

05

Step 5: Harden Security Architecture and Run Penetration Testing

Implement AES-256 encryption at rest, TLS 1.3 in transit, column-level encryption for sensitive fields, role-based access controls with MFA, and immutable audit logs. Commission an annual penetration test from a CERT-In empanelled security auditor and remediate all critical findings before the next audit cycle.

Vendor and Platform Compliance Evaluation: What to Ask Before You Sign

The DPDP Act makes you — the data fiduciary — accountable for every data processor you engage. If your loyalty platform vendor, ESP, WhatsApp BSP, or POS integration partner processes your members' personal data without adequate safeguards, the regulatory and reputational liability flows back to you. Vendor compliance evaluation is not a procurement checkbox — it is a risk management function that must involve your legal, IT security, and loyalty operations teams in parallel.

When evaluating any loyalty platform — whether you are comparing Fundle AI Platform against Capillary, Antavo, MoEngage, WebEngage, Xeno, Customer Capital, or Almonds.ai — demand the following as non-negotiable contract terms: a signed Data Processing Agreement (DPA) that explicitly specifies processing purposes, data categories, retention periods, and sub-processor disclosures; written confirmation of India data residency for all personal data; IS/ISO 27001 certification or equivalent, with the most recent audit report available for review; a contractually committed 72-hour breach notification SLA; a right-to-audit clause allowing your team or a third-party auditor to verify compliance annually; and a clear data deletion protocol specifying how your members' data is wiped from the vendor's systems upon contract termination.

POS integration partners — Petpooja, POSist, GoFrugal, Wondersoft — deserve particular scrutiny because they sit at the data origination point. Every time a Lifestyle or Pantaloons POS terminal records a transaction against a loyalty member ID, that is a personal data processing event governed by DPDP. Your POS vendor must confirm that member data transmitted to the loyalty platform is encrypted in transit, that POS-level logs containing member data are stored with appropriate access controls, and that any POS-side data cache is cleared per your retention policy.

Finally, evaluate vendors on their compliance roadmap velocity. The DPDP rules are still being finalised by MeitY. A vendor whose compliance posture is static — 'we are DPDP ready as of today' with no stated update process — is a risk. You need a partner whose engineering and legal teams are actively tracking MeitY rule updates and building compliance changes into product sprints, not retrospective patches. Ask for the vendor's documented compliance update process and the last three instances where they proactively updated their platform in response to a regulatory change.

DPDP Loyalty Data Compliance Checklist: 7 Non-Negotiables for Indian Retailers
  • Consent architecture is granular and purpose-specific — no bundled T&C checkboxes — with a version-controlled, timestamped consent ledger integrated across all loyalty touchpoints including POS, app, and web
  • All loyalty member personal data is stored exclusively on India-resident servers with written data residency confirmation in the vendor DPA — verified, not assumed
  • AES-256 encryption at rest and TLS 1.3 in transit are implemented with column-level encryption for sensitive fields (mobile, DOB, Aadhaar-linked IDs) and separated key management
  • Self-service member rights portal is live with tracked SLA for access, correction, and erasure requests — maximum 30-day response time with audit trail for every request
  • 72-hour breach notification protocol is documented, rehearsed annually, and contractually committed in every vendor and sub-processor agreement
  • Data retention policies are automated with purpose-expiry triggers — no personal data is held beyond the stated loyalty programme processing purpose without fresh consent
  • Annual compliance audit by a CERT-In empanelled or ISO 27001 accredited auditor with findings tracked to remediation — Fundle's platform undergoes rigorous compliance audits to meet India's DPDP requirements
“In Indian retail, consent is not a legal footnote — it is the opening bid in a trust transaction. The brands that treat data privacy as product design will own the next decade of customer loyalty.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Fundle AI Platform was architected from the ground up with a privacy-first, consent-native data model — not because regulation demanded it, but because Vineet Narang's founding thesis was that sustainable loyalty can only be built on a foundation of earned trust and explicit permission. That architectural choice means every feature of the Fundle Loyalty Platform — from onboarding flows to RFM segmentation to AI-driven offer personalisation — operates within a consent boundary that is continuously enforced, not periodically audited.

Fundle Mall Loyalty gives mall operators — from Phoenix Marketcity-scale portfolios to regional malls — a centralised consent ledger that aggregates member permissions across every anchor tenant, F&B brand, and entertainment zone within the mall ecosystem. When a Tanishq or Cafe Coffee Day within the mall wants to trigger a personalised WhatsApp offer to a shared loyalty member, Fundle AI Agents query the consent ledger in real time and suppress the communication if the member has not opted in to third-party brand sharing. This is not a manual process — it is a Fundle AI Workflow running automatically at every campaign execution event, eliminating the compliance gap that legacy platforms leave open between consent management and actual message dispatch.

Fundle Brand Loyalty extends the same consent-native architecture to enterprise retail brands running standalone loyalty programmes — Reliance Trends, Lifestyle, or any brand retailer operating across hundreds of stores with POS integrations via Petpooja, GoFrugal, Wondersoft, or POSist. The Fundle Agentic AI layer continuously monitors consent status across the member base, flags members approaching consent expiry (for time-bound consent scenarios), and triggers re-permission campaigns automatically — ensuring that your active loyalty communications base is always a fully consented base, not a legacy list with undefined consent provenance.

On the security and audit side, Fundle's platform undergoes rigorous compliance audits to meet India's DPDP requirements — with IS/ISO 27001-aligned controls, AES-256 encryption, India data residency by default, and a right-to-audit provision in every enterprise contract. The Fundle AI Platform's immutable audit log captures every data access, consent change, and processing event — giving your DPO and legal team the evidentiary foundation to respond to any Data Protection Board inquiry with confidence. For Indian CMOs and CIOs who need a DPDP compliant loyalty data platform that is both commercially powerful and regulatorily defensible, Fundle is built for exactly this moment in Indian retail.

Frequently asked

What is a DPDP compliant loyalty data platform and why does it matter for Indian retailers?+

A DPDP compliant loyalty data platform is a loyalty technology stack that operationalises the requirements of India's Digital Personal Data Protection Act 2023 — including purpose-limited consent collection, member rights management, India data residency, and 72-hour breach notification. It matters because the DPDP Act imposes penalties up to ₹250 crore per violation on significant data fiduciaries, and most Indian retail loyalty programmes process data at a scale that qualifies them for this designation.

Does the DPDP Act apply to existing loyalty programme members enrolled before 2023?+

Yes. The DPDP Act does not grandfather legacy consent. If your existing loyalty members were enrolled under bundled T&C checkboxes or implicit consent mechanisms that do not meet the Act's free, specific, informed, and unambiguous consent standard, you must run a re-permission campaign to obtain valid consent before continuing to process their data for marketing purposes.

What is the difference between a consent ledger and a standard CRM opt-in flag?+

A CRM opt-in flag is a binary yes/no field that records a point-in-time preference. A consent ledger is a versioned, timestamped record of every consent event — including the exact language the member consented to, the channel, the date, and any subsequent changes. The consent ledger is the evidentiary standard required under DPDP for demonstrating lawful processing to the Data Protection Board.

How should Indian mall operators handle data sharing between the mall loyalty programme and individual tenant brands?+

Data sharing between the mall loyalty programme and tenant brands is a separate processing purpose that requires explicit, purpose-specific consent from the member — distinct from the consent given to join the mall loyalty programme itself. Each tenant brand sharing arrangement must be individually disclosed at consent, and members must be able to opt out of individual brand data shares without losing their core loyalty programme membership.

What should I look for in a loyalty platform vendor's data processing agreement for DPDP compliance?+

Your vendor DPA must include: explicit data processing purposes and categories, India data residency confirmation, IS/ISO 27001 certification evidence, a contractual 72-hour breach notification SLA, sub-processor disclosure with equivalent obligations, a right-to-audit clause, and a documented data deletion protocol effective upon contract termination. Absence of any of these terms is a compliance gap you own as the data fiduciary.

How does Fundle.ai help retailers manage ongoing DPDP compliance as regulations evolve?+

Fundle AI Platform maintains a living compliance framework that tracks MeitY rule updates and incorporates regulatory changes into product sprints. Fundle AI Agents automate consent monitoring, re-permission triggers, and rights-request workflows — so compliance is operationalised in the platform layer, not delegated entirely to your legal team. Fundle's platform undergoes rigorous compliance audits to meet India's DPDP requirements, giving enterprise retail clients an independently verified compliance foundation.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?