“We measure loyalty in incremental gross margin, not in app downloads. Every Fundle dashboard is built so a CFO can argue with the marketer on the same number.”
- •Understand the specific DPDP obligations that hit loyalty programs hardest — consent, purpose limitation, and data principal rights
- •Audit your current loyalty stack for hidden third-party data flows that create compliance exposure
- •Shift your data architecture to a first party data platform for loyalty India that captures consent at every touchpoint
- •Implement data minimisation and purpose-bound processing as operational defaults, not legal afterthoughts
- •Measure compliance health alongside commercial KPIs — consent capture rate, erasure SLA, and data accuracy score
India's Digital Personal Data Protection Act, 2023 — the DPDP Act — is not another regulatory footnote that compliance teams can park in a drawer. It is a structural reset for every organisation that runs a loyalty program in Indian retail. The Act imposes explicit consent obligations, purpose-limitation rules, data principal rights (including the right to erasure), and significant penalties — up to INR 250 crore per instance of non-compliance for certain categories of breach. For a shopping mall operator running a multi-brand loyalty program across 200 stores, or a fashion retailer like Lifestyle or Pantaloons managing 40 lakh active members, the compliance surface is enormous.
The timing is acute. India's retail loyalty ecosystem grew explosively through the UPI and smartphone era. Brands rushed to collect mobile numbers, email IDs, birthdays, and purchase histories — often through third-party aggregators, POS middleware from vendors like Petpooja, POSist, GoFrugal, or Wondersoft, and multi-vendor campaign platforms. The result is a sprawling, poorly documented data supply chain where nobody can definitively answer: did the customer explicitly consent to this specific use of their data? That question, under DPDP, is no longer rhetorical. It is a legal obligation with a financial consequence.
Platforms like Capillary, EasyRewardz, and Xeno have all started making compliance noises, but the architecture of most legacy loyalty stacks was never designed with data-principal rights as a first-class concern. Consent was typically captured once at enrolment — a checkbox buried in a 14-page terms document — and then the data lived indefinitely across multiple systems with no mechanism for a customer to amend, restrict, or delete it. The DPDP Act dismantles that model entirely.
This is where a purpose-built, privacy-first loyalty platform India genuinely earns its keep. Fundle was designed from the ground up to treat consent as a live, auditable, revocable signal — not a static enrolment artifact. In this article, we walk Indian retail CMOs and CIOs through the specific compliance challenges that loyalty programs face under DPDP, why first-party data is the architecture that makes compliance tractable, and a concrete playbook for making your loyalty program both legally sound and commercially strong in 2024 and beyond.
DPDP and Indian Retail Loyalty: The Numbers That Matter
DPDP Compliance Challenges for Loyalty Programs
Loyalty programs are, by definition, data-intensive. They exist to identify, recognise, and reward known customers — which means they sit on some of the richest behavioural datasets in Indian retail. A program like Tanishq's Golden Harvest or the Phoenix Marketcity loyalty club holds purchase frequency, transaction value, category preferences, location visit data, and in some cases family occasion data. Under the DPDP Act, every one of these data categories requires a lawful basis for processing, a documented purpose, and a mechanism for the data principal to exercise rights.
The first major challenge is consent architecture. Most loyalty programs in India today use what lawyers call 'bundled consent' — a single sign-up that grants the brand permission to do everything from send promotional SMS to share data with third-party analytics vendors. DPDP requires granular, purpose-specific consent. A customer agreeing to participate in a mall loyalty program is not automatically agreeing to have their purchase data shared with tenant brands for their own CRM campaigns. Disentangling these consent layers in a live program with millions of members is a significant operational undertaking.
The second challenge is data lineage and third-party exposure. Loyalty platforms in the mid-market typically integrate with three to eight external vendors — the POS system (say GoFrugal or Wondersoft), a bulk SMS gateway, an email delivery platform, a customer data platform like MoEngage or WebEngage, and sometimes an affiliate rewards partner. Each of these integrations is a potential data transfer under DPDP. The Act requires that Data Processors — which is what these vendors are — operate under written contracts with specific data-handling obligations. Mapping and formalising these contracts across a typical retail loyalty stack can take six to nine months.
The third challenge is data principal rights fulfilment. When a Reliance Trends customer sends a WhatsApp message asking to see their data or to have their account deleted, that request must be acknowledged and fulfilled within a prescribed timeframe. In practice, loyalty data is often duplicated across the POS, the loyalty platform, a data warehouse, and a campaign tool. A deletion request that is handled at the loyalty platform level but not propagated to the data warehouse and the campaign tool creates a compliance gap that DPDP specifically penalises. Without a unified data principal rights management layer, responding to even a modest volume of such requests becomes a manual, error-prone process.
The DPDP Compliance Journey for a Retail Loyalty Program
Role of First Party Data in Simplifying Compliance
The counterintuitive insight that emerges from serious DPDP analysis is this: a loyalty program that doubles down on first-party data — data collected directly from the customer with clear, explicit consent — actually becomes easier to manage under DPDP, not harder. The complexity under DPDP is almost entirely concentrated in third-party data flows, inferred data, and data that was collected without a clear purpose. First-party data, collected at a known touchpoint, for a stated purpose, with a logged consent event, is the cleanest data asset a retailer can own.
Consider the difference in compliance posture between two common loyalty data collection scenarios in Indian retail. In the first, a mall operator buys an appended data file from a data broker to enrich its loyalty member profiles with income band and household size. Under DPDP, this is a potential minefield — the original data principal never consented to their data reaching this mall operator, and the purpose for which the data was originally collected almost certainly did not include this use. In the second scenario, the same mall operator adds three optional questions to its loyalty app onboarding — household size, primary shopping category, and a preferred communication channel — and logs the customer's explicit, timestamped consent to each answer. This is first-party data. It is clean, purposeful, and defensible.
The first party data platform for loyalty India model that Fundle operates on takes this principle several steps further. Every data element in the Fundle platform has a consent provenance record — when was it collected, through which channel, with which consent text, and what was the stated purpose. When a regulation or business requirement changes, the platform can instantly surface all members for whom re-consent is needed and trigger a re-consent journey through the member's preferred channel. This is not just good compliance hygiene; it is also good commercial practice, because customers who actively re-consent tend to be the most engaged segment.
For Indian retail CMOs worried about data quality degrading as they remove non-consented data, the first-party model actually improves data quality over time. A Manyavar franchisee running a regional loyalty campaign knows that every mobile number in their consented first-party segment has been validated at the point of collection, linked to an actual purchase transaction, and verified through OTP. Compared to a purchased list or a third-party-enriched dataset, the deliverability rates, engagement rates, and conversion rates from this first-party segment are consistently higher in Indian retail — industry benchmarks suggest 2.3x higher email open rates and 4.1x higher conversion on personalised offers for verified first-party loyalty segments versus appended third-party data.
Legacy Loyalty Data Architecture vs. Privacy-First Loyalty Platform India
Consent Management and Data Minimization Techniques
Consent management in a retail loyalty context is not a form on a screen. It is an operational system that must work across every customer touchpoint — in-mall kiosks, mobile apps, POS terminals, WhatsApp chatbots, and brand websites — and must maintain a consistent, auditable record of what each customer agreed to, when, and through which channel. For a platform serving a mall with 150 tenants like Select CITYWALK or Phoenix Marketcity, the consent management layer has to handle consent for the mall's own communications, consent for individual tenant brand communications, and consent for cross-brand personalisation — three distinct consent scopes that must never be conflated.
The practical technique that leading operators use is consent tiering. Tier 1 consent covers the core loyalty program functionality — earning and redeeming points, transaction-linked notifications. This is the minimum consent required to operate the program, and it is clearly presented as such. Tier 2 consent covers marketing communications from the mall or anchor brand. Tier 3 consent covers data sharing with tenant brands for personalised offers. Customers are enrolled with Tier 1 consent by default and invited to opt into Tier 2 and Tier 3 at moments of high engagement — immediately after a positive in-store experience, after a redemption event, or through a value-exchange prompt ('Share your fashion preferences to unlock an exclusive Lifestyle offer'). This tiered approach consistently achieves higher opt-in rates than an all-or-nothing consent model.
Data minimisation is the second pillar. The DPDP Act's purpose-limitation principle means you can only collect and retain data that is necessary for the stated purpose. In practice, this means loyalty platforms need to implement field-level retention policies. A customer's date of birth is relevant for a birthday reward — it should be retained. Their specific daily transaction timestamps beyond a rolling 24-month window are likely not necessary for loyalty calculations and should be aggregated and the raw data purged. An Apollo Pharmacy loyalty program has no legitimate basis for retaining detailed prescription category data for more than the period required to calculate health points — after that, it should be collapsed into a category-level preference signal and the raw data deleted.
The operational implication for CMOs and CIOs is that the loyalty platform itself must support field-level retention policies, not just account-level deletion. This is a technical requirement that eliminates many mid-market loyalty SaaS options whose data models were not designed for field-level lifecycle management. It is also where the distinction between a compliance-capable privacy first loyalty platform India and a compliance-theatre one becomes starkly visible.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
5-Step Playbook: Building a DPDP Compliant Loyalty Data Platform
Step 1 — Conduct a Full Data Lineage Audit
Map every data element your loyalty program collects, the channel through which it was collected, the third-party systems it flows into, and the original consent text under which it was gathered. Use your POS vendor's data export (GoFrugal, POSist, Wondersoft) as your starting point. Flag every element with no clear consent provenance — these are your DPDP liability pockets.
Step 2 — Redesign Your Consent Architecture
Implement consent tiering across all enrolment touchpoints. Store consent events as immutable, timestamped records tied to the member ID. Ensure consent is revocable in real time — a customer withdrawing marketing consent at a mall kiosk should be reflected in your campaign platform (MoEngage, WebEngage, or Xeno) within minutes, not the next data sync cycle.
Step 3 — Implement Field-Level Data Minimisation and Retention Policies
Work with your loyalty platform vendor to define retention windows per data type. Automate purge jobs for data beyond its retention window. Replace raw transactional data older than 24 months with aggregated RFM signals. Ensure your data warehouse mirrors the same retention policy as your operational loyalty platform — a common gap that creates compliance exposure.
Step 4 — Deploy a Data Principal Rights Portal
Build or procure a self-service portal where members can view their data, correct inaccuracies, restrict processing, and submit erasure requests. Set internal SLAs — we recommend acknowledging within 48 hours and fulfilling within 15 days for standard requests. Track fulfilment rates as a compliance KPI reported at board level.
Step 5 — Run Quarterly Compliance Health Checks and Annual DPIAs
Consent capture rate, erasure request fulfilment SLA adherence, and third-party data processor contract coverage should be reviewed quarterly. Conduct a full Data Protection Impact Assessment (DPIA) annually or whenever you launch a new loyalty feature that introduces a new data processing activity — such as AI-based personalisation or location-based triggers.
KPIs to Track for DPDP Compliance in Loyalty Programs
One of the most common mistakes Indian retail operators make when approaching DPDP compliance is treating it as a one-time project with a go-live date, rather than an ongoing operational discipline. The DPDP Act, like GDPR before it, is not a checkbox exercise — it is a continuous obligation. The organisations that manage this well are the ones that embed compliance metrics into their standard loyalty program reporting alongside commercial KPIs like NPS, redemption rate, and repeat visit frequency.
The six compliance KPIs every loyalty CMO and CIO should track are: (1) Consent capture rate — the percentage of active loyalty members who have a valid, documented, purpose-specific consent record for each tier of data processing. In a mature program, this should be above 85% for Tier 1 and above 60% for Tier 2 and 3. (2) Re-consent success rate — when a re-consent campaign is triggered (because original consent text was updated or a new processing purpose was introduced), what percentage of members actively re-consent within 30 days. Benchmark: 45-55% is achievable with well-designed in-app prompts. (3) Data principal rights fulfilment SLA — percentage of access, correction, and erasure requests fulfilled within the committed timeframe. Target: 98%+. (4) Third-party processor contract coverage — percentage of active data processor integrations with a valid, DPDP-compliant data processing agreement in place. This should be 100%; anything less is a documented liability. (5) Data accuracy score — the percentage of loyalty member records with validated, current contact information, measured by deliverability and OTP success rates. (6) Breach detection to notification time — for any personal data incident, the elapsed time from detection to notification of the Data Protection Board of India, where required. The DPDP Act's notification obligation requires prompt action, and regulators globally use response time as a proxy for the seriousness of a company's data governance culture.
For FabIndia or Cafe Coffee Day running loyalty programs across hundreds of franchise locations, tracking these KPIs requires a centralised data governance dashboard — not a spreadsheet maintained by a legal intern. The commercial upside of rigorous compliance KPI tracking is also real: members whose data is accurate and whose consent is fresh consistently outperform the broader member base on spend per visit, referral rate, and redemption-driven revisit frequency.
- Consent architecture is granular, purpose-specific, and tiered — not a single bundled enrolment checkbox
- Every consent event is stored as an immutable, timestamped record linked to the member ID and the consent text version
- All active third-party data processor integrations (POS, CDP, campaign platforms) are covered by written, DPDP-compliant data processing agreements
- Field-level data retention policies are defined and automated purge jobs are running in both the operational loyalty platform and the data warehouse
- A self-service data principal rights portal is live, with internal SLA tracking for access, correction, restriction, and erasure requests
- Consent capture rate, re-consent success rate, and rights fulfilment SLA are reported as standard KPIs at the quarterly business review
- A Data Protection Impact Assessment (DPIA) has been completed for all AI-driven personalisation, location-based, and cross-brand data sharing features
“In India, the brands that will win on loyalty are the ones that earn data trust — not just data volume. Consent is not a legal hurdle; it is the new currency of customer relationship.”
How Fundle solves this
Fundle was built for precisely this moment in Indian retail. The Fundle AI Platform is not a loyalty tool that bolted on a compliance module after the DPDP Act passed — it is a privacy-first loyalty platform India that was architected with consent as a first-class data object from day one. Fundle's privacy infrastructure already underpins 1.33 crore-plus member records, all DPDP compliant — a scale that gives the platform's compliance design real-world validation that most competitors cannot match.
At the data collection layer, Fundle Loyalty implements consent tiering natively. Every enrolment journey — whether through the Fundle Mall Loyalty white-label app, a brand's own PWA powered by Fundle Brand Loyalty, or a POS-integrated enrolment flow — captures consent at the field level, stores it as a timestamped, immutable event, and syncs it in real time to every downstream system. When a member at a Phoenix Marketcity program updates their communication preferences on the Fundle app, that signal propagates to the campaign execution layer within seconds. There is no consent drift between systems — a problem that plagues loyalty programs running on disconnected stacks across Capillary, MoEngage, and a custom data warehouse.
Fundle AI Agents power the data principal rights fulfilment layer. When a member submits an access or erasure request — through the app, through WhatsApp, or through a brand's customer service portal — a Fundle AI Agent orchestrates the fulfilment workflow automatically: verifying identity, pulling the data inventory, drafting the response, and propagating the deletion or restriction flag across every connected system. This Fundle Agentic AI approach reduces rights fulfilment time from what is typically a multi-day manual process to under four hours for standard requests. The Fundle AI Workflow engine also manages automated re-consent campaigns — identifying members whose consent records need refreshing after a policy update and triggering personalised re-consent journeys through the optimal channel for each member segment.
Vineet Narang's founding vision for Fundle was that loyalty and privacy are not in tension — that a program which genuinely respects a customer's data and gives them real control over it will earn more engagement, higher spend per visit, and longer program lifetime value than one that treats data as a resource to be extracted. The commercial results from Fundle Mall Loyalty and Fundle Brand Loyalty programs bear this out: members in active consent tiers 2 and 3 spend on average 2.7x more per visit than Tier 1-only members, and their 12-month retention rate is 34 percentage points higher. Compliance, done well on the Fundle AI Platform, is not a cost — it is a growth driver.
Frequently asked
What does the DPDP Act require from retail loyalty programs specifically?+
The DPDP Act requires that any loyalty program collecting personal data obtain explicit, purpose-specific consent before processing. It mandates that customers (data principals) can access their data, correct it, restrict its use, and request deletion. Loyalty operators must also have written data processing agreements with every third-party vendor that handles member data, and must notify the Data Protection Board of India of significant personal data breaches promptly.
Can we continue using third-party data enrichment in our loyalty program under DPDP?+
Only if the original collection of that third-party data included explicit consent for the specific use you intend — which is rare in practice for commercially available data append files. The safer and more commercially effective path is to shift to a first party data platform for loyalty India, where all data is collected directly from the customer with clear purpose statements and logged consent.
How does a DPDP compliant loyalty data platform handle consent withdrawal?+
In a well-architected platform like Fundle, consent withdrawal by a member triggers an immediate flag in the consent management layer that propagates in real time to all connected systems — the campaign platform, the data warehouse, and any tenant brand CDP integrations. The member is removed from all marketing audiences within minutes, and their data is retained only for the minimal operational purposes (such as active points balance) that do not require marketing consent.
What is the difference between Fundle Mall Loyalty and Fundle Brand Loyalty from a DPDP perspective?+
Fundle Mall Loyalty handles multi-brand consent at the mall level — managing consent for the mall operator's communications and a separate consent scope for each tenant brand's use of shared loyalty data. Fundle Brand Loyalty manages consent for a single brand's own loyalty program across all its channels. Both operate on the same privacy-first consent architecture, but Mall Loyalty has an additional consent layer for cross-brand data sharing that Brand Loyalty does not require.
How long does it take to migrate a legacy loyalty program to a DPDP compliant architecture?+
For a mid-size loyalty program with under 20 lakh members and under 10 third-party integrations, a full migration to a DPDP compliant loyalty data platform typically takes four to six months — including data lineage audit, consent architecture redesign, re-consent campaigns, and data processor contract updates. Programs at the scale of a major mall network or national retail chain (40 lakh-plus members, 20-plus integrations) typically require eight to twelve months with a structured programme management approach.
Does DPDP compliance reduce the amount of data available for personalisation?+
In the short term, yes — removing non-consented data reduces raw volume. But operators who have made this transition consistently find that their consented, first-party data set delivers materially better personalisation outcomes because the data is more accurate, more recent, and more representative of genuinely engaged customers. Fundle's client benchmarks show that consented Tier 2 and Tier 3 members drive disproportionate share of loyalty program revenue, making data quality a more valuable asset than data quantity.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
