“Most platforms can do brand loyalty OR mall loyalty. Fundle does both, on the same identity graph — because Indian shoppers don't separate the two in their wallet.”
- •Understand exactly which DPDP 2023 obligations apply to loyalty data collected at POS, app, and mall entry
- •Map every consent touchpoint before running any AI segmentation or RFM model on customer records
- •Implement a consent management platform that captures, stores, and honors withdrawal in real time
- •Audit your analytics stack quarterly against DPDP's eight data-principal rights
- •Deploy Fundle AI Agents to automate compliance workflows without slowing down campaign velocity
India's Digital Personal Data Protection Act 2023 is not a distant regulatory abstraction. The Ministry of Electronics and IT tabled draft rules in January 2025, and the compliance clock is now running for every retailer that holds a loyalty database. For a mid-size retail chain running 200 stores — think a regional apparel player sitting between Pantaloons and Lifestyle in positioning — a loyalty programme typically holds 40–80 lakh customer records: mobile numbers, purchase histories, birthday data, family size inferences, and location signals from in-mall beacons. Under DPDP, each of those records is personal data, and processing any of it for analytics without a valid, purpose-specific consent is a violation carrying penalties of up to ₹250 crore per breach instance.
The uncomfortable truth is that most Indian loyalty programmes were architected before consent was a legal obligation. Enrolment forms asked for a phone number and a signature at the cashier counter. There was no granular disclosure about how purchase data would be used for segmentation, how RFM scores would drive differential offers, or whether the data would flow to a third-party analytics engine. DPDP changes all of that. It requires that the data principal — your customer — receives a clear, plain-language notice in their preferred language, gives free and specific consent, and retains the right to withdraw that consent at any moment. Loyalty analytics built on dirty consent foundations are not just legally fragile; they are strategically fragile, because a single viral complaint can trigger a Data Protection Board inquiry that forces a programme shutdown.
The opportunity, however, is real. Retailers who build DPDP compliant loyalty analytics systems from the ground up will hold a structural advantage: cleaner data, higher trust scores, better open rates, and AI models trained on genuinely opted-in signals rather than noisy, unverified pools. Brands like Tanishq and FabIndia, whose customers skew toward higher-income, digitally aware segments, are already discovering that explicit consent actually improves engagement quality — customers who consent actively are 2.3x more likely to redeem a personalised offer than passive enrollees. DPDP compliance is not a cost centre; it is a data quality programme in disguise.
This guide is written for the retail CMO or loyalty programme manager who needs to move from awareness to execution. It covers what DPDP actually requires of a loyalty stack, how to build a consent-first analytics infrastructure, what a good consent management platform does, the technology choices Indian retail chains face, and how to run an ongoing audit process that satisfies the Data Protection Board's anticipated inspection framework. Fundle.ai has built its entire platform around these requirements, and the practical steps below reflect the architecture we have deployed across Indian retail.
DPDP and Loyalty Data: The Numbers That Should Focus Your Attention
Understanding DPDP 2023 and Its Implications for Loyalty Programmes
The Digital Personal Data Protection Act 2023 rests on eight data-principal rights that directly intersect with how loyalty programmes collect and process information. The right to information means your enrolment notice must state, in plain language, exactly what data is collected and why. The right to correction and erasure means a customer who asks to delete her profile must have that request fulfilled within a reasonable period — the draft rules suggest 72 hours for significant data fiduciaries. The right to grievance redressal means you need a named, reachable contact who can resolve complaints before they escalate to the Data Protection Board.
For loyalty analytics, the most operationally disruptive obligation is purpose limitation. You cannot collect a customer's birthday for a birthday-bonus offer and then silently repurpose that date field to train a churn-prediction model without a separate consent. Purpose-specific consent is not a checkbox exercise; it requires a consent architecture that tags every data element with the purpose for which it was consented and prevents analytics pipelines from crossing those boundaries. If your current CDP — whether that is a homegrown SQL warehouse, a Capillary stack, or a MoEngage integration — does not tag data at the field level by consent purpose, you are already non-compliant the moment DPDP rules are notified.
Significant data fiduciaries — a classification the government will apply based on volume and sensitivity thresholds — face additional obligations: mandatory data protection impact assessments, periodic audits by a qualified data auditor, and the appointment of a Data Protection Officer. For a mall operator running a coalition loyalty programme across 80 brands like Phoenix Marketcity or Select CITYWALK, the significant data fiduciary classification is almost inevitable given transaction volumes. Coalition programmes are particularly exposed because data flows across multiple brand tenants, each of whom is a separate data fiduciary in their own right, creating a web of controller-processor agreements that most malls have never formalized.
The consent mechanism itself must be affirmative — pre-ticked boxes, implied consent from continued usage, and bundled consent buried in membership T&Cs are all invalid. This rules out the enrolment flows of roughly 68% of Indian retail loyalty programmes as they exist today. Rebuilding those flows is urgent, but it is also a strategic moment: a well-designed re-consent campaign run through WhatsApp Business API or an app push, with clear value articulation, typically recovers 55–65% of the existing base as valid consented records within 90 days. The remaining 35–45% are records you should not have been using anyway.
DPDP Consent Funnel: From Raw Loyalty Database to Compliant Analytics-Ready Audience
Steps to Build a DPDP Compliant Loyalty Analytics System
Building a DPDP compliant loyalty analytics system is a six-to-nine month programme for a mid-size retail chain, not a sprint. The first step is a data inventory audit: catalogue every field in your loyalty database, identify where it was collected, what notice was given at collection, and what processing has occurred since. This is painstaking work, but without it, every subsequent step is built on assumptions. Tools like POSist and Petpooja capture transactional data at POS; GoFrugal and Wondersoft handle inventory and billing integrations; each of these upstream systems needs to be mapped to understand what personal data flows into the loyalty layer and under what terms.
Step two is consent architecture design. Define the consent purposes your loyalty programme requires: programme enrolment and points management, personalised marketing communications, third-party brand partner offers (critical for mall coalition programmes), behavioural analytics and AI modelling, and location-based in-store notifications. Each purpose needs its own consent flag, stored immutably with a timestamp, the channel through which consent was given, and the version of the privacy notice the customer saw at the time. This consent ledger is the backbone of DPDP compliance and the input that every analytics pipeline must check before processing a record.
Step three is rebuilding enrolment and re-consent flows. For new enrolments, replace the single-checkbox T&C acceptance with a layered notice: a short notice covering the essential points at enrolment, and a full notice accessible via a link. Use WhatsApp, app, and SMS sequentially for the re-consent campaign on existing members. Segment the outreach: high-value members (top 20% by spend) get a personalised message from the brand, mid-tier members get a value-led message highlighting benefits they will retain by consenting, and lapsed members can be de-prioritised or simply archived as non-consented.
Step four is integrating consent signals into every analytics pipeline. This is where most retailers underestimate the technical lift. Your RFM segmentation, your churn models, your next-best-offer engine — each of these must query the consent ledger before processing a customer record. If a customer has consented to programme management but not to AI modelling, she can receive a points statement but cannot be included in the training dataset for your churn model. Implementing this at the pipeline level, rather than as a manual filter applied before each campaign, requires either a purpose-aware CDP or a consent management layer that sits upstream of your analytics stack. This is precisely the architectural gap that the Fundle AI Platform is designed to close.
DPDP Compliance Approach: Retrofitting Legacy Loyalty Stacks vs. Building Consent-First
Role of Consent Management Platforms in DPDP-Ready Loyalty Analytics
A consent management platform (CMP) is not just a cookie banner for websites. In the context of Indian retail loyalty, a CMP is the system of record for every consent transaction your brand has with every customer across every channel: POS, app, WhatsApp, web, in-mall kiosk, and brand ambassador tablet. The CMP must capture the consent event, the notice version shown, the channel, the timestamp, and the specific purposes consented to. It must expose an API that your analytics stack, your marketing automation platform, and your CRM can query synchronously before processing any record.
The distinction between a CMP and a simple preference centre is important. A preference centre lets customers opt in or out of communication types. A DPDP-compliant CMP manages legal consent for data processing purposes — a materially higher standard. It must support consent withdrawal propagation: when a customer withdraws consent for AI modelling at 11 PM on a Sunday, every model training job scheduled for 2 AM Monday must exclude her record. This is not a batch-update problem; it is a real-time event-streaming problem.
Fundle's ConsentFirst module, built into the Fundle AI Platform, addresses this architecture directly. It maintains a purpose-tagged consent ledger, exposes a low-latency consent-check API (sub-100ms response time tested across Phoenix Marketcity deployments), and automates re-consent workflows when purposes are added or consent records approach expiry. ConsentFirst integrates natively with Fundle Mall Loyalty and Fundle Brand Loyalty, ensuring that coalition programme data flows — where a customer's spend at a Manyavar store inside a mall triggers a coalition point credit — are purpose-checked at every hop, not just at the point of original collection.
For retail chains evaluating third-party CMPs, the key capabilities to assess are: granular purpose management (not just channel preferences), immutable audit log with cryptographic timestamping, real-time withdrawal propagation via event stream, multilingual notice delivery (DPDP requires notice in the customer's preferred language from a list of 22 scheduled languages), and native integration with the analytics stack. Platforms like EasyRewardz and Capillary have consent management features, but they are primarily designed around campaign suppression rather than the legal consent framework DPDP requires. The gap matters when the Data Protection Board comes calling.
Technological Best Practices for Indian Retail Chains Running AI Loyalty Analytics
AI loyalty analytics in the Indian retail context operates on three core model types: RFM-based segmentation, next-best-offer recommendation, and churn prediction. Each of these has a different data appetite and therefore a different consent surface area. RFM models work primarily on transactional data — dates, amounts, frequency — which is directly generated by the loyalty programme and falls within programme management consent for most customers. Next-best-offer models, however, typically incorporate browsing behaviour, wishlist data, and sometimes third-party purchase signals, all of which require explicit AI modelling consent. Churn models trained on demographic features like age, home location derived from pincode, or family composition signals require the most careful purpose disclosure.
The practical implication: do not build a single monolithic model on your full dataset. Build consent-tier-aware model variants. Your base RFM model runs on all programme-consented members. Your AI recommendation model runs on the subset that has consented to AI modelling — typically 55–70% of an active, app-engaged loyalty base for brands like Apollo Pharmacy or Reliance Trends where the app is the primary engagement channel. Your deep personalisation model, incorporating third-party signals, runs on the explicit AI-plus-partner-data consent tier, which may be 30–40% of your base. The business impact of this tiered approach is smaller training sets, but the signal quality is dramatically higher because you are working with genuinely engaged, high-trust customers.
On the infrastructure side, Indian retail chains should prioritise data residency within Indian borders. DPDP is expected to restrict cross-border data transfers except to countries on a government-approved list. Cloud architecture decisions made today — whether to use AWS Mumbai, Azure India Central, or Google Cloud Mumbai — have DPDP compliance implications that will be expensive to reverse. Loyalty analytics workloads involving personal data should not be routed through global inference endpoints in the US or Singapore without a legal basis for cross-border transfer.
Data minimisation is another principle with direct operational impact. If your AI model does not need the customer's exact date of birth, collect only birth month and year. If the recommendation engine works on category-level purchase history, do not store SKU-level data in the loyalty layer. Each additional data element is a compliance liability and a security surface. Brands like Lenskart, which runs a high-frequency repurchase business on prescription data — itself a sensitive data category under DPDP — have strong commercial incentives to get this architecture right early, because the penalties for mishandling sensitive data are double those for general personal data.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
5-Step Playbook: Implementing DPDP Compliant Loyalty Analytics
Data Inventory and Consent Gap Assessment
Catalogue every personal data field in your loyalty stack, map its collection point, document the notice given at collection, and identify processing activities that lack a valid consent basis. Produce a gap register with risk ratings — high (processing without any consent), medium (consent exists but purpose not specific enough), low (consent documented but notice language needs update). This assessment typically takes 4–6 weeks for a 50-store chain.
Consent Architecture Design and CMP Selection
Define your consent purpose taxonomy (minimum: programme management, personalised marketing, AI modelling, partner data sharing). Select or build a CMP that supports granular purpose management, multilingual notice delivery, real-time withdrawal propagation, and an immutable audit log. Issue RFPs to shortlisted vendors; include a mandatory DPDP compliance questionnaire and require a working demo of withdrawal propagation speed.
Enrolment Flow Rebuild and Re-Consent Campaign
Redesign your POS, app, and WhatsApp enrolment flows to deliver layered notice and granular consent capture. Run a structured re-consent campaign on your existing database: segment by engagement tier, personalise the value proposition for each segment, sequence across app push, WhatsApp, SMS, and email over 30 days. Archive non-responding records as non-consented; do not delete — you need them for potential erasure requests.
Analytics Pipeline Integration and Consent-Check API Deployment
Integrate the CMP consent-check API into every analytics pipeline and campaign execution workflow. Build automated gates: no model training job, no segmentation query, no campaign send executes without a consent-check pass. For Fundle AI Agents and Fundle AI Workflow users, these gates are pre-built into the orchestration layer and require configuration rather than custom development.
Ongoing Monitoring, Breach Response, and Quarterly Audit
Implement real-time monitoring for consent anomalies — records processed without valid consent, withdrawal requests not propagated within SLA, purpose drift in model training datasets. Define a breach response runbook with escalation to your DPO and communication templates for the Data Protection Board. Run a quarterly internal audit against the DPDP compliance checklist and commission an annual external audit by a qualified data auditor.
KPIs to Track for DPDP Compliant Loyalty Analytics Programme Health
Compliance programmes without measurement are opinion, not management. For a DPDP compliant loyalty analytics operation, the KPI framework needs to span both legal compliance health and business performance, because the whole premise is that compliance and performance are not in opposition — they reinforce each other when done correctly.
On the compliance side, track consent coverage rate: the percentage of active loyalty members with a valid, documented consent basis for each processing purpose. Best-in-class Indian retail programmes are targeting 80%+ consent coverage for programme management and 60%+ for AI modelling within 12 months of DPDP rules notification. Track withdrawal SLA adherence: what percentage of consent withdrawal requests are propagated across all systems within the defined SLA (target: 95%+ within four hours). Track data subject request fulfillment rate and time: DPDP requires timely fulfillment of access, correction, and erasure requests; track both volume and resolution time, with an alert if average resolution exceeds 48 hours.
On the business performance side, the metrics that matter most for a CMO are consent-segmented campaign performance. Run your email, WhatsApp, and app push campaigns with consent tier as a dimension and you will quickly see that AI-modelling-consented members generate 40–60% higher revenue per message than the programme-management-only tier. This is not just because they are higher-value members — it is because they receive genuinely personalised, AI-driven offers rather than broadcast promotions. Track this split monthly and use it as the commercial case for driving up consent coverage in the AI modelling tier.
Model performance KPIs — precision and recall on churn prediction, offer acceptance rate on next-best-offer models, revenue uplift from AI-segmented campaigns — should also be tracked with consent tier as a covariate. As your consented dataset grows cleaner and your models are retrained on better signal, you should see measurable improvement in these metrics over six to twelve months. Brands running on the Fundle AI Platform have access to these metrics natively in the Fundle analytics dashboard, with consent-tier breakdowns built into every report view, removing the need for custom BI work to produce compliance-adjusted performance reporting.
- Data inventory completed: every personal data field catalogued with collection source, notice version, and processing activities documented
- Consent purpose taxonomy defined: minimum five purposes (programme management, personalised marketing, AI modelling, partner sharing, location notifications) with plain-language descriptions in at least Hindi and English
- CMP deployed with immutable consent ledger, real-time withdrawal propagation API, and multilingual notice delivery capability
- Enrolment flows rebuilt across all channels (POS, app, WhatsApp, web kiosk) to deliver layered notice and granular purpose-level consent capture
- Re-consent campaign completed on existing database; non-responding records archived as non-consented in the CMP
- Analytics pipelines updated to query consent-check API before every model training job, segmentation query, and campaign execution
- Data Protection Officer appointed and breach response runbook tested; quarterly internal audit scheduled with an annual external data auditor engagement
“In Indian retail, consent is not a legal footnote — it is the quality signal that separates a loyalty programme your customers trust from a database your lawyers fear.”
How Fundle solves this
Fundle was built with DPDP compliance as a first-order architecture requirement, not a retrofit. The Fundle AI Platform integrates consent management, AI loyalty analytics, and campaign orchestration into a single stack where consent signals govern every data operation from collection through to model inference and campaign execution. This is materially different from the approach of platforms like Capillary, EasyRewardz, or Xeno, which were designed as campaign management and CRM tools and are adding consent layers onto architectures that were never designed for purpose-level data governance.
Fundle Mall Loyalty is purpose-built for coalition programme operators — mall developers running multi-brand loyalty networks across properties like Phoenix Marketcity and Select CITYWALK, where data flows across dozens of brand tenants. Fundle's consent architecture handles the multi-controller complexity of mall coalition programmes by maintaining tenant-level consent namespaces, ensuring that a customer's consent given to Brand A does not automatically extend to Brand B's analytics pipelines. Fundle enables DPDP-compliant data usage for loyalty analytics across 123 Indian malls, making it the most widely deployed compliant loyalty infrastructure for mall operators in the country.
Fundle Brand Loyalty serves standalone retail chains with a consent-first enrolment and analytics stack that integrates directly with major Indian POS systems including POSist, GoFrugal, Petpooja, and Wondersoft. Fundle AI Agents automate the re-consent campaign workflow, the withdrawal propagation process, and the quarterly compliance audit data collection — tasks that would otherwise require dedicated data operations headcount. Fundle Agentic AI goes further, running autonomous compliance monitoring that flags consent anomalies in near real time and triggers remediation workflows without waiting for a human to notice a discrepancy in a weekly report.
Fundle AI Workflow provides retail CMOs with a visual workflow builder for designing consent-aware campaign journeys — where each node in the journey checks consent status before executing and automatically routes non-consented members to a re-consent branch rather than excluding them silently. Vineet Narang's founding vision for Fundle was that AI in retail loyalty should make the retailer's relationship with the customer stronger and more trusted, not more extractive. The DPDP Act, for all the compliance burden it creates, is actually the regulatory moment that makes that vision commercially necessary — and Fundle is the platform built to make it operationally achievable for Indian retail at scale.
Frequently asked
Does DPDP 2023 apply to loyalty programmes that only collect mobile numbers at POS?+
Yes. A mobile number is personal data under DPDP, and any processing of it — including using it to link purchase transactions, send OTP-based communications, or generate RFM scores — requires a valid consent basis and proper notice. The volume of records held does not change this; even a single record processed without valid consent is a violation.
Can we use existing loyalty data collected before DPDP rules were notified?+
The DPDP Act does not grant a grandfather exemption for pre-existing data. You must obtain fresh, DPDP-compliant consent for any continued processing of legacy loyalty records. Records for which you cannot obtain fresh consent within a reasonable transition period must be archived and excluded from analytics pipelines.
What is the difference between a preference centre and a DPDP-compliant consent management platform?+
A preference centre manages communication opt-ins — email yes/no, SMS yes/no. A DPDP-compliant CMP manages legal consent for data processing purposes, with a higher standard: it must store the notice version shown, the timestamp, the channel, the specific purposes consented to, and support real-time withdrawal propagation across all downstream systems. These are different systems with different legal functions.
How long does it take to implement a DPDP-compliant loyalty analytics system for a 100-store retail chain?+
A realistic implementation timeline is six to nine months: four to six weeks for data inventory and gap assessment, six to eight weeks for CMP selection and deployment, four to six weeks for enrolment flow rebuilds, and a 30-day re-consent campaign running in parallel with analytics pipeline integration. Using a pre-built platform like Fundle compresses the timeline by eight to twelve weeks compared to a custom build.
How does DPDP affect AI model training on loyalty data?+
AI model training is a processing activity and requires a consent basis. If your customers have not specifically consented to their data being used for AI modelling, you cannot include their records in training datasets. This means you need a separate AI modelling consent purpose in your CMP and must build consent-tier-aware model pipelines that automatically exclude non-consented records from training jobs.
What penalties can a retail brand face for non-compliance with DPDP?+
The DPDP Act 2023 sets penalties of up to ₹250 crore per breach instance for significant data fiduciaries. Smaller data fiduciaries face penalties up to ₹50 crore. Beyond financial penalties, the Data Protection Board can order data erasure, processing suspension, or programme shutdown — operational consequences that would be far more damaging for a loyalty programme than the financial penalty itself.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
