“We will not build a loyalty platform for the AI era. We are building the loyalty platform of the AI era. That's the only standard worth shipping against.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand why India's DPDP 2023 Act fundamentally rewrites the rules for automated loyalty campaigns
  • Map the five consent failure points that expose retail CMOs to regulatory and reputational risk
  • Adopt a ConsentFirst workflow model that embeds consent capture into every automation trigger
  • Benchmark your loyalty stack against DPDP-ready platforms before the enforcement clock starts
  • Evaluate Fundle's ConsentFirst module as the compliance layer for AI-powered loyalty automation software

India's organised retail sector crossed ₹11 lakh crore in FY2024, and loyalty programs are now the single most important data-collection instrument that mall operators and retail chains own. From Tanishq's Golden Harvest scheme to Lifestyle's Inner Circle and Manyavar's in-store reward cadence, brands are building enormous first-party data estates — member purchase histories, visit frequencies, wish-list signals, and even try-on preferences. Every data point feeds an automated campaign engine: birthday offers, win-back flows, tier-upgrade nudges, and cross-sell journeys across WhatsApp, SMS, and email. The engine never sleeps. The compliance team, historically, barely woke up.

That equation changed on 11 August 2023, when India's Digital Personal Data Protection Act (DPDP 2023) received Presidential assent. Unlike the Information Technology Act's vague privacy addenda, DPDP 2023 is specific, enforceable, and consumer-empowering. It mandates that every automated touchpoint — every triggered SMS, every AI-generated personalisation, every retargeting event — must rest on a lawful basis of processing, with explicit, informed, purpose-limited consent sitting at the top of that hierarchy. For loyalty program operators, this is not a back-office legal problem. It is a front-line marketing architecture problem.

The irony is acute: the very loyalty program automation tools India's retail sector has spent the last five years deploying — RFM-based triggers, behavioural cohort campaigns, churn-prediction workflows — are now the systems most likely to create compliance exposure if consent is not captured, stored, version-controlled, and honoured in real time. Platforms like Capillary, EasyRewardz, and MoEngage offer powerful automation, but consent management as a first-class architectural layer remains largely an afterthought or a bolt-on checkbox. Fundle was designed differently from day one, with ConsentFirst as a foundational module, not a feature.

This article is written for retail CMOs and loyalty program managers at Indian multi-brand malls, large retail chains, and F&B/QSR brands who need to answer a board-level question with precision: are our automated loyalty workflows DPDP-compliant today, and what does remediation look like if they are not? The answer requires understanding consent architecture, automation workflow design, and the specific obligations DPDP 2023 places on data fiduciaries operating loyalty programs at scale.

India Loyalty Automation Compliance: The Numbers That Matter

₹11L Cr+
India organised retail market size FY2024, where loyalty data estates are concentrated
270+
Brands across which Fundle's ConsentFirst powers consent management ensuring India's DPDP compliance
₹250 Cr
Maximum penalty per data breach incident under DPDP 2023 for significant data fiduciaries
68%
Indian loyalty program members who say they would disengage from a brand that misuses their personal data (RedSeer 2023)

Overview of Consent Management in Loyalty Program Automation Tools India

Consent management in the context of loyalty program automation tools India is not a single event — it is a continuous, multi-layered process that spans the entire member lifecycle. When a customer enrolls in the Inner Circle program at a Lifestyle store in Phoenix Marketcity, they hand over their mobile number, email, date of birth, and purchase intent data. At that moment, four distinct consent decisions are being made simultaneously: consent to store personal data, consent to receive transactional communications, consent to receive marketing communications, and consent to allow behavioural profiling for personalisation. Most loyalty stacks treat this as one checkbox. DPDP 2023 treats it as four separate, revocable, purpose-specific permissions.

The automation challenge compounds this. A modern loyalty workflow automation platform India deployment might have 40 to 80 active campaign triggers running at any given time. A customer who visits a Reliance Trends outlet in Bengaluru at 7 PM on a Saturday could simultaneously be eligible for a tier-upgrade notification, a cross-sell offer for their recently browsed category, a birthday week campaign, and a win-back flow if they haven't transacted in 45 days. Each of those four automated messages must check against the individual's current consent state before firing. Not the consent state at enrollment. The current state — because DPDP 2023 gives data principals the right to withdraw consent at any time, and that withdrawal must be honoured within a reasonable timeframe across all downstream automation pipelines.

This is where most existing implementations fail. Consent is captured at a point of sale terminal via a paper form or a basic digital checkbox. It is stored in a CRM field. But the automation engine — whether it is running inside Capillary, WebEngage, or a homegrown system — reads from a campaign eligibility database that is often not synchronised in real time with the consent store. The result: a customer who opted out of marketing communications on Monday morning still receives a promotional WhatsApp blast on Monday afternoon because the opt-out signal took 48 to 72 hours to propagate through the stack.

ConsentFirst is the architectural pattern that solves this. It positions consent as a real-time gate that every automation trigger must pass through before execution, not as a historical attribute stored in a profile field. The practical implication for loyalty program managers is significant: building or selecting AI-powered loyalty automation software must now include consent-gate architecture as a non-negotiable evaluation criterion, not a compliance checkbox reviewed annually by the legal team.

The ConsentFirst Loyalty Automation Funnel

Member Enrollment — Purpose-specific consent captured per channel and use case — Gate 1Consent Store Sync — Real-time propagation to all automation engines within 60 seconds — Gate 2Trigger Evaluation — Automation checks live consent state before campaign eligibility — Gate 3Revocation Monitoring — Opt-out signals from any channel suppressed across all pipelines — Gate 4
Every automated loyalty touchpoint must pass through all five consent gates before execution. Failure at any gate halts the message and logs an audit event.

DPDP 2023 Requirements and Impact on Loyalty Programs

The Digital Personal Data Protection Act 2023 introduces obligations that are specifically disruptive for loyalty program operators, and understanding the precise provisions matters more than understanding the general principle. Section 6 of DPDP 2023 requires consent to be free, specific, informed, unconditional, and unambiguous. The word 'specific' is the one that most loyalty stacks violate today. A generic enrollment consent that says 'I agree to receive communications from the brand' is not specific enough. Purpose limitation — telling the customer that their purchase history will be used to generate personalised offers and that their visit frequency will be shared with the mall operator for aggregate footfall analytics — must be declared at enrollment and honoured throughout.

Section 11 grants data principals the right to withdraw consent at any time, and critically, the Act specifies that withdrawal must be as easy as giving consent. If your brand captures consent through a WhatsApp opt-in flow, the opt-out must be equally accessible via WhatsApp — not buried in a help-centre email thread. For F&B and QSR brands like Cafe Coffee Day, where the primary loyalty channel is a mobile app with SMS as the secondary touchpoint, this means maintaining consent revocation pathways across both channels simultaneously, with real-time synchronisation between them.

Section 16 addresses children's data, which is relevant for family-format malls like Select CITYWALK in Delhi or Phoenix Marketcity in Mumbai, where family loyalty memberships often include minor dependants. Any loyalty program that collects or processes data of individuals under 18 must obtain verifiable parental consent. Most mall loyalty programs today have no mechanism for this whatsoever. The enforcement date for DPDP rules has not been formally announced as of mid-2025, but the rules are being finalised, and the window for remediation is narrowing.

For loyalty program managers, the operational impact clusters into three areas. First, campaign eligibility logic must be rebuilt to include consent-state checks. Second, data retention policies — a cornerstone of most loyalty analytics programs — must be aligned with the purpose stated at consent capture: you cannot retain a customer's full purchase history indefinitely if the stated purpose was 'personalising offers during active membership.' Third, and most practically, the consent audit trail must be machine-readable and regulatorily producible, meaning that if the Data Protection Board of India requests evidence of consent for a specific member transaction, your stack must be able to produce a timestamped, version-controlled consent record within a defined SLA. Most loyalty platforms in India today cannot do this.

ConsentFirst Architecture vs. Legacy Consent Bolt-Ons

Legacy Loyalty Stack (Consent as Checkbox)
ConsentFirst Architecture (Fundle AI Platform)
Consent captured once at enrollment, stored as a static CRM flag
Consent captured per purpose per channel, stored in a dynamic, versioned consent ledger
Opt-out propagation takes 48–72 hours across campaign systems
Opt-out signal synchronised across all automation triggers within 60 seconds
No mechanism for granular purpose-specific consent withdrawal
Member can withdraw consent for marketing while retaining transactional communications
Audit trail is a manual CSV export, not regulatorily producible on demand
Machine-readable consent audit log with timestamp, version, channel, and purpose metadata
Children's data handled identically to adult data with no verifiable parental consent flow
Age-gate at enrollment with verifiable parental consent workflow for under-18 dependants

How ConsentFirst Integrates with Automated Campaigns

The technical integration of a ConsentFirst layer into a loyalty workflow automation platform India deployment is a design pattern, not a product feature. It can be implemented whether the automation engine is Fundle AI Workflow, a third-party ESP, or a custom-built campaign manager. The core principle is that the consent store becomes an authoritative, real-time API endpoint that every campaign trigger queries before execution. This is sometimes called a 'consent gateway' or a 'permission middleware,' and it is the architectural equivalent of adding authentication to every API call rather than authenticating only at login.

In practice, consider a Pantaloons loyalty program running a WhatsApp-first re-engagement campaign for members who have not transacted in 60 days. The campaign automation identifies 1.2 lakh eligible members on Sunday night. In a legacy stack, all 1.2 lakh receive the WhatsApp message on Monday morning. In a ConsentFirst architecture, the automation engine queries the consent gateway for each of the 1.2 lakh members immediately before message dispatch. Members who have withdrawn WhatsApp marketing consent since their last transaction — even if they remain active loyalty members — are automatically excluded. The exclusion event is logged. The remaining eligible members receive the message. The compliance posture is clean.

The integration extends to cross-brand data sharing, which is particularly relevant for mall loyalty programs. At a multi-brand mall like Select CITYWALK, the mall operator might share footfall and category affinity data with anchor tenants like FabIndia or Apollo Pharmacy to enable co-branded campaigns. Under DPDP 2023, this data sharing requires explicit consent from the member for the specific purpose of cross-brand sharing. ConsentFirst manages this through what Fundle's architecture team calls 'consent inheritance rules' — a member's mall-level consent does not automatically extend to brand-level data sharing unless a separate, purpose-specific consent event has been captured.

For F&B operators using POS systems like Petpooja, POSist, or GoFrugal, the ConsentFirst integration happens at the point of transaction capture. When a customer makes a payment and provides their loyalty ID, the POS system queries the consent gateway in real time before storing any behavioural data beyond the transaction itself. If the customer has not consented to behavioural profiling, the transaction is recorded for points calculation only, and no category, time-of-day, or item-level preference data is written to the analytics database. This granular enforcement at the data-capture layer — not just the campaign dispatch layer — is what separates a genuinely DPDP-compliant loyalty stack from one that is merely compliant on paper.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Five-Step ConsentFirst Implementation Playbook for Loyalty Teams

01

Consent Inventory Audit

Map every data collection point in your loyalty stack: enrollment forms, POS capture, app onboarding, WhatsApp opt-ins, survey responses. For each point, document what consent is currently captured, in what format, and where it is stored. Most retail chains discover 6–12 untracked collection points during this audit, particularly in offline channels at Tier-2 and Tier-3 outlets.

02

Purpose Taxonomy Definition

Define the finite list of purposes for which member data is processed: transactional communications, marketing offers, behavioural profiling, cross-brand sharing, analytics aggregation, and third-party enrichment. Each purpose becomes a discrete consent dimension. A member's consent state is a vector across all purposes, not a single binary flag. Work with your legal team to ensure purpose descriptions are written in plain, accessible language as required by DPDP 2023.

03

Consent Store Architecture

Build or procure a consent store that is independent of your CRM and accessible via a real-time API. The consent store must support versioning (consent can be given, withdrawn, and re-given with timestamps), purpose-level granularity, and channel-level granularity. It must produce an audit record for every consent state change. If you are on the Fundle AI Platform, ConsentFirst provides this as a native module with pre-built integrations to major Indian POS and CRM systems.

04

Campaign Trigger Refactoring

Update every automation trigger in your campaign stack to query the consent gateway before execution. This applies to scheduled batch campaigns, real-time event-triggered messages, and AI-generated personalisation recommendations. Triggers that cannot be refactored — typically legacy batch systems — must be deprecated or quarantined until refactoring is complete. Prioritise channels with highest breach risk: WhatsApp, SMS, and push notifications, where unsolicited messages have the highest regulatory visibility.

05

Member-Facing Consent Centre

Deploy a self-service consent management portal accessible via the loyalty app, website, and WhatsApp chatbot. Members must be able to view their current consent state across all purposes, withdraw any specific consent, and download a record of all consent events. The portal must be designed for low digital-literacy users: regional language support, voice-guided navigation for older demographics, and one-tap withdrawal for the highest-risk opt-out scenario. Test the withdrawal flow end-to-end across all campaign systems before go-live.

Ensuring Transparent Customer Consent in India: KPIs to Track

Compliance is not a binary state — it is a continuously measured operational capability. Loyalty program managers need a KPI framework that makes consent health as visible as campaign performance. The most important metric is Consent Coverage Rate: the percentage of active loyalty members for whom a valid, purpose-specific, channel-specific consent record exists for every automation type currently running. For most retail chains that audit honestly, this number starts between 40 and 60 percent. A DPDP-compliant program requires it to be above 95 percent for active campaign recipients.

The second critical metric is Opt-Out Propagation Latency — the time elapsed between a member submitting a consent withdrawal and that withdrawal being honoured across all active campaign pipelines. The regulatory standard is 'without undue delay,' which industry practitioners are interpreting as under four hours for digital channels. The Fundle AI Workflow architecture targets 60-second propagation, which provides significant headroom. Legacy stacks running batch opt-out processing at 24-hour cycles are clearly out of compliance.

Third, track Consent Audit Producibility — the percentage of consent events for which you can produce a complete, timestamped, regulatorily presentable audit record within one business day. This metric is particularly important for significant data fiduciaries (loyalty programs with more than 10 lakh members, which includes most national retail chains and major mall loyalty programs). The Data Protection Board of India can request consent evidence as part of its investigation process, and inability to produce records is itself a compliance failure independent of whether the underlying consent was valid.

Fourth, monitor Purpose Drift Incidents — cases where member data was processed for a purpose beyond the scope of their captured consent. These are typically discovered through campaign log analysis: a member who consented only to transactional communications receiving a promotional offer, or a member who opted out of cross-brand sharing having their purchase history included in an anchor-tenant co-marketing cohort. Purpose drift incidents are the leading indicator of regulatory exposure and should trigger an immediate root-cause analysis on the automation workflow that produced the incident.

DPDP 2023 Readiness Checklist for Loyalty Program Operators
  • Consent captured at enrollment is purpose-specific, channel-specific, and written in plain language (not legalese)
  • Consent store is a real-time, versioned, API-accessible system independent of the CRM or marketing database
  • Every automated campaign trigger queries the live consent gateway before message dispatch
  • Opt-out signals from any channel (WhatsApp, SMS, app, in-store) propagate to all pipelines within four hours
  • A self-service consent management portal is accessible to members via at least two channels, including one offline or low-tech pathway
  • Children's data handling has a verified parental consent workflow for all under-18 dependants in family loyalty memberships
  • A complete consent audit trail is producible for any member transaction within one business day upon regulatory request
“In India, consent isn't a legal footnote — it's the foundation of trust. The brands that build consent into the first line of their loyalty architecture will own the next decade of customer relationships.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Fundle was purpose-built for the Indian retail context, and nowhere is that more visible than in the ConsentFirst module embedded across the Fundle AI Platform. Vineet Narang's founding thesis was simple and sharp: the shift from third-party cookie-based marketing to first-party loyalty data only creates sustainable competitive advantage if the first-party data is collected with full consent, maintained with integrity, and activated with precision. That thesis is now validated by DPDP 2023, which effectively mandates what Fundle's architecture has always assumed.

Fundle's ConsentFirst powers consent management ensuring India's DPDP compliance across 270+ brands — spanning multi-brand malls, retail chains, and F&B operators. The module operates as a real-time consent gateway sitting between the member data store and every campaign automation engine in the Fundle AI Workflow stack. For Fundle Mall Loyalty deployments — where a single consent record must govern data sharing between the mall operator and multiple anchor tenants — ConsentFirst maintains a hierarchical consent model: mall-level consent, brand-level consent, and purpose-level consent are stored as separate, independently revocable dimensions. A member at a Phoenix Marketcity property can consent to the mall's aggregate analytics without consenting to individual brand marketing, and that boundary is enforced in real time across every Fundle AI Agents workflow running for any tenant brand.

For Fundle Brand Loyalty deployments at standalone retail chains — think a national pharmacy chain with the footprint of Apollo Pharmacy or an ethnic wear brand like Manyavar — ConsentFirst integrates directly with POS systems including Petpooja, POSist, and GoFrugal via pre-built API connectors. Consent is captured at the moment of first transaction, version-controlled across the member's lifecycle, and surfaced via a self-service portal available in eight Indian languages. The Fundle Agentic AI layer monitors consent drift in real time: if a member's consent state changes through any channel, the AI agent automatically suppresses affected campaign queues, logs the suppression event, and flags the campaign manager for review within minutes rather than hours.

The Fundle AI Platform's compliance reporting module generates DPDP-ready audit exports on demand — timestamped consent events, purpose attribution, channel attribution, and revocation history — in a format aligned with the Data Protection Board of India's anticipated evidence requirements. For loyalty program managers preparing for regulatory readiness assessments, this capability alone eliminates weeks of manual data compilation. The practical outcome is a loyalty program that is simultaneously more compliant and more effective: when members trust that their consent choices are honoured, opt-in rates for high-value personalisation purposes increase, and the quality of the first-party data estate improves. Compliance and customer experience are not in tension in a ConsentFirst architecture — they are the same outcome, measured differently.

Frequently asked

What does DPDP 2023 specifically require from loyalty program operators in India?+

DPDP 2023 requires loyalty program operators to capture free, specific, informed, unconditional, and unambiguous consent before collecting or processing personal data. Consent must be purpose-limited, revocable at any time through a mechanism as accessible as the original opt-in, and supported by a machine-readable audit trail. For programs with over 10 lakh members, the obligations of a 'significant data fiduciary' may apply, with stricter data localisation and audit requirements.

How quickly must a loyalty program honour a consent withdrawal under DPDP 2023?+

DPDP 2023 uses the phrase 'without undue delay,' which the industry is broadly interpreting as under four hours for digital marketing channels. Fundle's ConsentFirst architecture targets 60-second propagation across all connected campaign pipelines, providing significant regulatory headroom. Batch opt-out processing at 24-hour cycles is clearly insufficient under any reasonable interpretation of the Act.

Can a loyalty program continue to process a member's historical data after they withdraw consent?+

No. Once consent is withdrawn for a specific purpose, processing for that purpose must cease, and in most cases existing data collected solely for that purpose must be deleted or anonymised. The key exception is data required for a separate lawful basis — for example, transaction records required for statutory accounting purposes can be retained even if marketing consent is withdrawn, provided the member was informed of this at enrollment.

How does ConsentFirst handle cross-brand data sharing in a mall loyalty program?+

Fundle's ConsentFirst uses a hierarchical consent model where mall-level consent, individual brand-level consent, and purpose-level consent are stored as independent, separately revocable dimensions. A member can consent to mall-level aggregate analytics without consenting to their data being shared with specific anchor tenants for marketing purposes. The Fundle Mall Loyalty platform enforces these boundaries in real time across all Fundle AI Agents workflows running for any tenant brand.

What is the difference between ConsentFirst and a standard opt-in/opt-out checkbox in a loyalty app?+

A standard checkbox captures a binary, static consent event at one point in time. ConsentFirst is a dynamic, real-time consent gateway that captures purpose-specific and channel-specific consent, maintains a versioned audit trail of every consent state change, queries the current consent state before every automated campaign trigger, and synchronises opt-out signals across all connected campaign pipelines within 60 seconds. The checkbox is a user interface element. ConsentFirst is an architectural layer.

How long does it take to implement ConsentFirst compliance for an existing loyalty program?+

For brands already on the Fundle AI Platform, ConsentFirst activation typically takes four to eight weeks, covering consent inventory audit, purpose taxonomy definition, POS integration via pre-built connectors, campaign trigger refactoring, and member portal deployment. For brands migrating from a legacy stack, the timeline extends to twelve to sixteen weeks, with the longest phase being campaign trigger refactoring across existing automation workflows. Fundle's implementation team provides a DPDP readiness assessment at the start of each engagement.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?