“Brand loyalty rewards what you bought. Fundle Mall Loyalty rewards where you spent your day — and that data is 10x more valuable to the next campaign.”
- •Understand why DPDP 2023 fundamentally changes how Indian retailers must collect and process loyalty data
- •Evaluate six non-negotiable privacy features before signing any loyalty platform contract
- •Map your existing POS and CRM stack to platform integration requirements before shortlisting
- •Benchmark Fundle's AI-native consent architecture against Capillary, EasyRewardz, and MoEngage
- •Track five KPIs that prove your privacy-first loyalty programme is working commercially, not just legally
India's Digital Personal Data Protection Act 2023 — universally shortened to DPDP — is not a compliance checkbox. It is a structural shift in how every Indian retailer, mall operator, and consumer brand must think about customer data. For a CMO at a Lifestyle or Pantaloons, or a CIO managing the tech stack of a Phoenix Marketcity, the question is no longer whether to build a privacy-first loyalty programme. The question is which platform can actually deliver one at the scale, speed, and regional complexity that Indian retail demands.
The stakes are real. Under DPDP, brands that collect, store, or process personal data without explicit, granular, and revocable consent face penalties of up to ₹250 crore per instance of non-compliance. For a mid-size retail chain running 200 stores across eight states, with loyalty data sitting across a Petpooja POS, a GoFrugal ERP, and a legacy SMS gateway, that exposure is not theoretical. It is a quarterly audit finding waiting to happen. And yet most loyalty platforms sold in India today were architected before DPDP existed — they bolt on consent banners as an afterthought rather than designing consent as a first-class data object.
The selection of a privacy first loyalty platform India retailers can genuinely trust requires evaluating five overlapping dimensions: consent architecture, data residency, purpose limitation, integration depth with existing retail systems, and the ability to deliver compliant experiences in multiple Indian languages. These dimensions are not independent. A platform that handles consent beautifully but cannot push consent flags downstream to your POSist terminal or Wondersoft store system is operationally worthless. A platform that claims DPDP readiness but stores member data on AWS servers outside India fails the data localisation test that the MeitY rules are expected to tighten further in 2025.
Fundle was purpose-built for this moment. Unlike platforms that grew up in loyalty points mechanics and are now retro-fitting privacy, Fundle AI Platform treats consent, purpose, and data minimisation as schema-level primitives — not UI overlays. This article gives retail CMOs and CIOs a structured, operator-level framework to evaluate any loyalty platform against DPDP requirements, and explains why the architectural choices made at platform selection time will determine your compliance posture for the next decade.
Indian Retail Loyalty & DPDP: The Numbers That Matter
Key Privacy Features to Evaluate in a Privacy First Loyalty Platform India
The first filter any CMO or CIO should apply is architectural: does consent live at the database layer or at the UI layer? In platforms like EasyRewardz or older Capillary deployments, consent is typically captured as a boolean flag in a member profile table — a true/false field that records whether the member clicked 'I agree' during enrolment. This is legally insufficient under DPDP. The Act requires purpose-specific consent, meaning your Tanishq customer must separately consent to (a) earning points on purchases, (b) receiving promotional SMS, (c) profiling for personalised offers, and (d) data sharing with Tanishq's insurance or gifting partners. A platform that stores all of this as a single flag will fail a DPDP audit.
The second feature is a fully functional consent withdrawal mechanism with real-time downstream propagation. DPDP grants every data principal the right to withdraw consent at any time, and the data fiduciary — your brand — must honour that withdrawal without delay. In practice, this means when a Manyavar loyalty member withdraws marketing consent on your app at 11 PM, that preference must propagate to your SMS gateway, your WhatsApp Business API, your email ESP, and your in-store POS display system before the store opens the next morning. Platforms that rely on nightly batch sync cannot meet this standard.
Third, evaluate data minimisation controls. DPDP's purpose limitation principle means you should not collect a loyalty member's date of birth if your programme has no birthday-reward mechanic. Platforms that mandate full demographic capture during enrolment because their analytics module needs it are creating unnecessary compliance exposure. Look for platforms that allow field-level purpose tagging — every data field linked to a declared processing purpose — so your DPO can audit data collection against declared purposes at any time.
Fourth, assess the platform's Data Principal Rights module. DPDP gives Indian consumers the right to access their data, correct inaccuracies, and request erasure. Your loyalty platform must provide a self-service portal — accessible in the languages your customers actually use — where these requests can be filed and fulfilled within the statutory timeline. Fifth, check for audit trail completeness: every consent grant, withdrawal, data access event, and purpose change must be logged with timestamp, channel, and actor identity. This is your primary defence in any regulatory investigation.
DPDP Consent Compliance Funnel for Indian Loyalty Programmes
Assessing DPDP Compliance Readiness of Any Loyalty Platform
Compliance readiness is not a vendor's marketing claim — it is a technical and legal due diligence exercise. Start with the vendor's Data Processing Agreement. Under DPDP, when your loyalty platform processes member data on your behalf, it is a Data Processor and you are the Data Fiduciary. The DPA must explicitly enumerate the purposes for which the processor handles data, the sub-processors it engages (your SMS gateway, your analytics engine, your cloud provider), and the mechanisms for data deletion upon contract termination. If a vendor cannot produce a DPDP-aligned DPA within 48 hours of request, that is a disqualifying signal.
Next, validate data residency. DPDP 2023 as enacted does not mandate blanket data localisation, but it empowers the Central Government to notify categories of personal data that must be stored within India. Given the trajectory of MeitY's rulemaking and the political economy of digital sovereignty, any loyalty platform that stores Indian consumer data exclusively on overseas infrastructure is a liability you will be managing in 18 months. Ask vendors for their cloud region configuration and whether Indian data stays in Indian AWS, Azure, or GCP regions as a default — not as a premium add-on.
Third, evaluate the platform's Consent Management Platform (CMP) architecture. A DPDP-ready CMP must support: (a) multi-language consent notices — at minimum English and Hindi, and ideally Tamil, Telugu, Marathi, Bengali, and Gujarati for pan-India deployments; (b) versioned consent records so that when your privacy policy changes, the system knows which version each member consented to; (c) consent expiry and re-consent workflows so that dormant members are not messaged on stale consent; and (d) minor-protection controls, since DPDP has specific and strict provisions around data of children under 18.
Finally, ask for a DPDP readiness scorecard or third-party audit report. Platforms like Fundle AI Platform have invested in purpose-built compliance architecture; others are patching existing systems. The difference shows up in the audit documentation. Require vendors to walk you through a simulated Data Principal Rights request — from the member filing an erasure request on the app, to the system propagating that deletion across all integrated touchpoints, to the confirmation record in the audit log. Time that workflow. If it takes more than 72 hours end-to-end in a demo environment, it will take weeks in production.
Privacy First Loyalty Platform India: Fundle vs. Competing Platforms
Integration Capabilities with Existing Indian Retail Systems
A loyalty platform's privacy architecture is only as strong as its integration with the systems that actually touch customer data. In Indian retail, that ecosystem is fragmented and deeply local. A Phoenix Marketcity or Select CITYWALK operator may have anchor tenants running POSist, specialty stores on Wondersoft, F&B outlets on Petpooja, and a central property management system that none of these vendors natively talk to. A Reliance Trends or FabIndia deployment will have its own in-house POS with legacy integration layers. The loyalty platform sits in the middle of this complexity and must propagate consent flags, member profiles, and transaction data across all of it — reliably, in real time, and without creating new data leakage points.
Evaluate the platform's pre-built connector library first. Does it have certified, maintained integrations with POSist, Petpooja, GoFrugal, Wondersoft, and Unicommerce? Pre-built connectors mean consent propagation is tested and documented — not a custom API project that your IT team must maintain. Second, examine the platform's event streaming architecture. Real-time consent propagation requires an event-driven design, not REST API polling. When a member withdraws SMS consent, that event must publish to a message broker (Kafka, Pub/Sub) that all integrated systems subscribe to. Polling-based integrations introduce lag; under DPDP, that lag is compliance exposure.
Third, assess webhook and API security. Every integration point is a potential data exfiltration vector. DPDP's security safeguards obligation (Section 8) requires data fiduciaries to implement reasonable security practices. Your loyalty platform's API layer must support mTLS, OAuth 2.0, field-level encryption for PII in transit, and IP allowlisting for B2B integrations. Ask vendors for their API security documentation and check whether their developer portal exposes any PII in sample payloads — a surprisingly common failure mode. Fourth, verify that the platform's integration layer supports transactional rollback: if a points-earn event is posted but the corresponding consent check fails, the transaction must roll back cleanly without orphaning data in either system. This is a nuanced requirement that many platforms handle poorly in edge cases.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
5-Step Playbook: Selecting a DPDP-Compliant Privacy First Loyalty Platform
Step 1 — Audit Your Current Data Inventory
Before evaluating any platform, map every touchpoint where your programme currently collects member data: POS enrolment, app registration, web sign-up, call centre, in-store kiosk. For each touchpoint, document what data is collected, the consent mechanism used, where the data is stored, and which downstream systems receive it. This data map is your DPDP Article 7 compliance baseline and your RFP foundation.
Step 2 — Define Your Consent Architecture Requirements
Translate your data map into a consent matrix: for each data category and processing purpose, define the required consent type (explicit opt-in, soft opt-in, legitimate interest), the withdrawal mechanism, and the downstream propagation requirement. Share this matrix with shortlisted vendors and require a technical response demonstrating how their CMP handles each scenario. Reject any vendor that cannot map your matrix to their system architecture within two weeks.
Step 3 — Issue a Privacy-First RFP with DPDP-Specific Requirements
Include in your RFP: (a) a mandatory DPDP DPA template for vendors to mark up; (b) a data residency declaration; (c) a Data Principal Rights workflow demonstration requirement; (d) a consent propagation latency SLA — we recommend a maximum of 60 seconds for real-time channels; (e) evidence of third-party security audit (ISO 27001, SOC 2 Type II, or equivalent). Weight privacy and compliance criteria at 40% of total RFP score.
Step 4 — Conduct a Live Compliance Proof-of-Concept
Require shortlisted vendors to run a 30-day POC in a sandbox environment mirroring your integration landscape. During the POC, execute: a simulated erasure request and measure end-to-end deletion time; a consent withdrawal event and verify propagation to all integrated channels within your SLA; a campaign dispatch that includes a mix of consented and non-consented members, and verify that the platform blocks the non-consented sends automatically. Document all findings with timestamps for your DPO.
Step 5 — Negotiate Privacy SLAs into the Commercial Contract
DPDP compliance obligations do not evaporate after go-live. Your contract must include: a Data Processing Agreement aligned to DPDP; a breach notification SLA (DPDP requires notification to DPBI within a timeframe to be prescribed — build a 6-hour vendor notification SLA into your contract as a buffer); a consent propagation uptime SLA of 99.9%; and a right-to-audit clause allowing your DPO to inspect the platform's compliance posture annually. Vendors unwilling to accept these terms have told you everything you need to know.
Scalability, Multi-Lingual Support, and India-Specific Design
India is not one market. A pan-India loyalty programme serving customers in Chennai, Kolkata, Ahmedabad, Lucknow, and Pune is serving five distinct linguistic, cultural, and commercial contexts. A platform that delivers consent notices, reward communications, and Data Principal Rights portals only in English is excluding the majority of India's 750-million-strong internet user base — and potentially creating DPDP compliance risk, since consent obtained in a language the data principal does not understand is arguably not informed consent.
Fundle offers native English and Hindi support with DPDP compliance baked-in. This is not a translation overlay — it is a natively bilingual consent and communications architecture where consent notices, purpose descriptions, rights request flows, and campaign messages are maintained in both languages as first-class content objects. For regional deployments — a Manyavar franchise network in Uttar Pradesh and Bihar, or an Apollo Pharmacy cluster in Tamil Nadu — the platform's multi-language engine extends to Tamil, Telugu, Marathi, Bengali, and Gujarati without requiring custom development from the retailer's IT team.
Scalability in the Indian context also means handling the transaction volume spikes that Indian retail generates. A Phoenix Marketcity property running a Diwali campaign across 200 tenants will process several hundred thousand loyalty transactions in a single day. The consent validation layer must perform at sub-100ms latency under that load — a failure here means either consent checks are bypassed (compliance risk) or the checkout queue slows down (commercial risk). Evaluate vendors on their published throughput benchmarks and ask for references from Indian deployments that have handled peak-day loads comparable to your own.
Finally, consider the platform's roadmap for India-specific regulatory evolution. DPDP's implementing rules are still being finalised by MeitY. The rules around consent managers, data protection officers, children's data, and cross-border transfers will all be clarified in secondary legislation expected through 2025-26. Your loyalty platform vendor must have a dedicated regulatory compliance function that monitors MeitY rulemaking and updates the platform proactively. A vendor without a named India compliance lead is a vendor that will ask you to fund emergency engineering sprints every time a new rule drops.
- Confirm consent is stored as a purpose-specific, versioned schema object — not a single boolean flag
- Verify real-time consent propagation to all integrated channels with a documented latency SLA of 60 seconds or less
- Require a live demonstration of the Data Principal Rights workflow: access, correction, and erasure end-to-end
- Validate data residency: member PII stored in India-region cloud by default, not as a premium add-on
- Test multi-language consent notices in at least English and Hindi; check for regional language availability
- Review the vendor's DPA for DPDP alignment: purpose enumeration, sub-processor disclosure, deletion obligations
- Confirm pre-built, certified integrations with your POS vendor (POSist, Wondersoft, GoFrugal, or Petpooja)
“In India, consent is not a legal formality — it is the foundation of customer trust. Build your loyalty programme on consent architecture first, and the commercial returns will follow. That is the only sequence that works.”
How Fundle solves this
Fundle AI Platform was architected from inception around a consent-first data model. Every member record in Fundle Loyalty carries a consent object that is purpose-specific, versioned, timestamped, channel-tagged, and propagated in real time via an event-streaming layer to every integrated touchpoint — POS, SMS, WhatsApp, email, push notification, and in-store display. When a member withdraws consent on the Fundle-powered mall app, Fundle Agentic AI publishes a consent-withdrawal event to all subscribed downstream systems within 30 seconds, with a delivery confirmation audit log that your DPO can access at any time. This is not a feature — it is the schema.
Fundle Mall Loyalty is purpose-built for the multi-tenant complexity of Indian mall operators. A single Fundle deployment at a Select CITYWALK or a Phoenix Marketcity instance can manage consent separately for the mall entity and for each participating brand tenant — so a Cafe Coffee Day running a double-points promotion can only message members who have consented to receive communications from Cafe Coffee Day, not just from the mall. Fundle Brand Loyalty extends this architecture to mono-brand retail chains like Tanishq or Lenskart, where the consent surface spans a branded app, a web portal, WhatsApp Business, and the in-store POS simultaneously.
Fundle AI Agents handle the operational complexity of DPDP compliance that no human team can manage at scale. When Fundle AI Workflow prepares a campaign for dispatch, a pre-send compliance agent automatically validates every member in the target segment against the current consent state, removes non-consented members, logs the suppression with reason codes, and generates a pre-send compliance certificate that your legal team can archive. If the campaign touches a data category that requires a specific consent purpose not captured for a subset of members, the agent flags this to the campaign manager before the send — not after. This moves compliance from a post-hoc audit function to a real-time operational control.
Vineet Narang's founding vision for Fundle was that AI and privacy are not in tension — they are mutually reinforcing. An AI system trained on clean, consented, purpose-limited first-party data outperforms one trained on scraped, inferred, or coerced data, every time. The Fundle AI Platform's personalisation engine — which drives offer recommendations for brands like FabIndia-tier specialty retailers and Reliance Trends-scale mass market chains alike — is more accurate precisely because it operates on high-quality consented data. When members trust the programme enough to share genuine preferences, the data gets better, the recommendations improve, and the commercial outcomes follow. That is the compounding return on privacy-first architecture that no compliance-as-afterthought platform can replicate.
Frequently asked
What does DPDP 2023 require from a loyalty programme's consent mechanism?+
DPDP requires that consent be free, specific, informed, unconditional, and unambiguous. For loyalty programmes, this means capturing separate consent for each processing purpose — points accrual, marketing communications, profiling, and third-party sharing — with a clear and equally prominent mechanism to withdraw each consent independently. A single 'I agree to terms' checkbox at enrolment does not meet this standard.
How is a privacy first loyalty platform India deployment different from a standard loyalty platform?+
A privacy-first platform treats consent as a schema-level data object with its own lifecycle management — versioning, expiry, withdrawal, and audit trail. A standard platform typically captures consent as a UI event and stores it as a profile flag, with no real-time propagation or purpose-level granularity. The difference becomes critical during a DPDP audit or a Data Principal Rights request.
Can existing loyalty platforms like Capillary or EasyRewardz be made DPDP compliant?+
These platforms are investing in DPDP readiness, but their base architectures were designed for pre-DPDP consent models. Retrofitting purpose-specific, real-time consent propagation onto a system that was not built for it requires significant custom engineering. The risk is that compliance gaps remain in edge cases — data category changes, multi-channel propagation failures, or minor-protection flows — that surface only during audits. Greenfield or re-platforming decisions should favour natively DPDP-architected platforms.
What integration does Fundle have with Indian POS systems for consent propagation?+
Fundle AI Platform has pre-built, certified integrations with POSist, Petpooja, GoFrugal, and Wondersoft. Consent flags propagate to these systems via an event-streaming layer with a documented 30-second SLA. This means in-store staff cannot inadvertently market to a member who has withdrawn consent, and the POS system reflects the current consent state at the time of each transaction.
Does the DPDP Act apply to loyalty programmes run exclusively in physical stores with no app or website?+
Yes. DPDP applies to the processing of digital personal data — and any data that is digitised from a physical source. If your store associate enters a member's mobile number into a POS terminal during enrolment, that data is digital personal data from the moment it is captured. All DPDP obligations — including consent, purpose limitation, and Data Principal Rights — apply from that point.
How does Fundle handle multi-language consent for regional Indian markets?+
Fundle offers native English and Hindi support with DPDP compliance baked-in, along with support for Tamil, Telugu, Marathi, Bengali, and Gujarati. Consent notices, purpose descriptions, and Data Principal Rights portal interfaces are maintained in each language as first-class content objects — not machine-translated overlays. This ensures that consent obtained from a Tamil Nadu or West Bengal customer is genuinely informed, which is a substantive DPDP requirement, not just a UX nicety.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
