“If your loyalty data can't tell you the LTV of last Thursday's walk-in within 24 hours, you don't have first-party data — you have a list. Fundle changes that.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand why India's Digital Personal Data Protection Act 2023 makes consent-based loyalty data management legally non-negotiable
  • Quantify the revenue upside of first-party data collected with explicit consent versus scraped or inferred data
  • Benchmark what a DPDP-compliant loyalty data platform looks like in practice for Indian mall operators and retail brands
  • Evaluate why legacy CRM and points vendors fall short on consent architecture
  • Discover how Fundle AI Platform operationalises consent-first loyalty at scale across 270+ partner brands

India's retail sector has spent the last decade racing to collect customer data — phone numbers harvested at checkout, emails captured during warranty registration, purchase histories stitched together across POS terminals from Wondersoft, POSist and GoFrugal — all in service of the loyalty programme that would, in theory, create lifetime customers. The problem is that most of this data was collected with a checkbox buried in a terms-and-conditions scroll that no shopper ever read. That era is over.

The Digital Personal Data Protection Act 2023 (DPDP Act), notified in August 2023 and with draft rules circulated in January 2024, fundamentally reframes the relationship between Indian businesses and their customers' personal data. For the first time, Indian law mandates a clear, specific, and verifiable consent signal before any personal data can be processed for commercial purposes — including loyalty programme communications, personalised offers, and behavioural analytics. The penalties are steep: up to ₹250 crore per instance of non-compliance. For a mid-size mall operator or a specialty retailer running a multi-brand loyalty scheme, a single enforcement action could wipe out years of marketing ROI.

Yet compliance is only the floor. The real opportunity for Indian retail CMOs and CIOs is the strategic one: consent based loyalty data management is the single most defensible way to build a first-party data asset that advertising platforms cannot take away, regulators cannot penalise, and competitors cannot replicate. Brands that lead on consent will own the customer relationship; those that trail will pay rent to third-party data brokers and walled-garden platforms indefinitely. Fundle.ai was architected from day one around this premise — that trust, not points, is the ultimate loyalty currency.

This article is written for the retail CMO or CIO who owns both the loyalty P&L and the data privacy compliance mandate. It covers the regulatory landscape, the business case, the operational risks of inaction, and a step-by-step playbook for building a consent-first loyalty programme that survives regulatory scrutiny and drives measurable incremental revenue.

Indian Retail Loyalty & Data Privacy: The Numbers That Matter

₹250 Cr
Maximum penalty per DPDP violation — per the Digital Personal Data Protection Act 2023
67%
Indian consumers who say they would stop shopping at a brand that misused their personal data (KPMG India, 2023)
3.2×
Higher email open rates for consent-confirmed loyalty members versus unverified list contacts in Indian retail benchmarks
270+
Partner brands supported by Fundle with consent-first loyalty infrastructure across malls and standalone retail

Growing Data Privacy Awareness in Indian Consumers

For years, the working assumption in Indian retail marketing was that consumers were indifferent to how their data was used. A phone number was given freely at a Pantaloons checkout; a date of birth was shared without hesitation at a Tanishq counter; an email was typed into a Lifestyle store tablet because the cashier asked nicely. The implicit contract was: share your data, get a discount. Privacy was not part of the conversation.

That assumption is now empirically wrong. The KPMG India Digital Trust Report 2023 found that 73% of Indian internet users are more concerned about their online privacy than they were two years ago. The YouGov-MMA survey from Q3 2023 found that 61% of urban Indian shoppers actively notice when a brand asks for data they consider unnecessary. More tellingly, Google's own consumer research in India showed that personalisation is welcomed when consumers understand the value exchange — but rejected as 'creepy' when it appears to happen without their knowledge.

This shift is being accelerated by three structural forces. First, the UPI and ONDC ecosystems have made Indian consumers more digitally sophisticated than any previous generation. A shopper who manages ₹50,000 in monthly transactions on PhonePe understands data flows better than a shopper who paid in cash five years ago. Second, high-profile data breach incidents — including leaks from food delivery and e-commerce platforms — have made data risk tangible rather than abstract. Third, WhatsApp Business spam has become so pervasive that consumers now actively block brand numbers, destroying the very channel that Indian retail loyalty was built on.

The implication for mall operators and retail brands is direct: a consent-based loyalty programme is no longer a compliance checkbox — it is a prerequisite for channel access. Brands like FabIndia and Manyavar, which have historically built deep emotional relationships with their customers, are well-positioned to lead on consent because their customers trust the brand narrative. The risk is for brands that treat consent as a legal formality rather than a customer relationship investment. When India's data regulator, the Data Protection Board, becomes fully operational, the brands without verified consent records will face both legal exposure and customer churn simultaneously.

The Consent-First Loyalty Data Funnel

Total Footfall / Transactions — 100%Captured Contact Details — 68%Valid, Deliverable Contact — 49%Explicit Marketing Consent Given — 31%
How Indian retailers lose addressable customers at each stage without a structured consent architecture — and where Fundle AI Platform recovers them.

Legal Imperatives Under DPDP: What the Act Actually Requires

The Digital Personal Data Protection Act 2023 is not a GDPR copy-paste. It is India-specific, written for a market where the digital economy and the physical economy are deeply intertwined, and where a loyalty programme at a Select CITYWALK in Delhi is as much a data processing operation as a fintech app. Retail CMOs and CIOs need to understand three specific provisions that directly govern loyalty data.

First, Section 6 of the DPDP Act mandates that consent must be free, specific, informed, unconditional, and unambiguous — expressed through a clear affirmative action. Bundling consent into a loyalty programme enrolment form where 'I agree to terms' also means 'I consent to marketing profiling' is non-compliant. Each purpose of data processing — transactional notifications, personalised offers, third-party brand communications, behavioural analytics — requires a separate, granular consent signal. For a mall loyalty programme that aggregates data across 80 tenant brands, this creates significant operational complexity if not architected correctly.

Second, Section 13 grants every data principal (the customer) the right to withdraw consent at any time, with the withdrawal being as easy as giving consent. This means a loyalty platform must have a live consent dashboard accessible to every member — not a 'contact us to unsubscribe' process. Legacy CRM platforms like early versions of Capillary or EasyRewardz were not built with real-time consent withdrawal in mind; retrofitting them is expensive and architecturally brittle.

Third, Section 9 places specific obligations on data fiduciaries — the brands and mall operators — to ensure that data collected through loyalty programmes is processed only for the consented purposes and that data processors (technology vendors, analytics agencies, media platforms) handle data under contractual obligations that mirror the Act's requirements. This means your loyalty technology vendor's data architecture is now part of your compliance posture. A vendor that cannot produce a Data Processing Agreement aligned to DPDP, or that stores member data in unencrypted form on shared infrastructure, is a liability.

For operators running DPDP compliant loyalty data platforms, the architectural requirements are clear: consent capture must be granular and timestamped; consent status must be queryable in real time; withdrawal must propagate instantly across all downstream systems; and data retention must be tied to consent validity, not to arbitrary backup cycles. This is the compliance baseline — and the first party data platform for loyalty India needs to be built on it.

Legacy Loyalty CRM vs. Consent-First Loyalty Data Platform

Legacy Loyalty CRM (Pre-DPDP)
DPDP-Compliant Consent-First Platform
Single checkbox consent at enrolment, bundled into T&Cs
Granular, purpose-specific consent captured per data use case with timestamp and channel record
No real-time consent withdrawal; unsubscribe handled via email to support team
Member-facing consent dashboard with instant withdrawal propagating across all downstream systems in under 60 seconds
Data retention based on server backup policy, often indefinite
Retention period tied to consent validity; automated deletion workflows triggered on withdrawal or expiry
Vendor data processing agreements absent or generic; no DPDP-aligned DPA
Vendor-issued DPDP-aligned Data Processing Agreement with sub-processor clauses and breach notification SLAs
Marketing profiling and third-party brand data sharing treated as implied permission
Third-party brand data sharing requires explicit opt-in per brand; mall tenant data flows governed by separate consent events

Business Benefits of Consent-Driven Loyalty

The compliance argument is necessary but insufficient to drive boardroom investment. The CFO needs an ROI narrative, and fortunately, the business case for consent-driven loyalty is one of the strongest in the history of Indian retail marketing.

Start with channel economics. WhatsApp Business API messaging in India costs between ₹0.35 and ₹0.85 per conversation depending on category. A retailer with 500,000 loyalty members sending one campaign per week is spending ₹70,000–₹1,70,000 per week just on delivery — before creative, agency, and attribution costs. If 40% of that list has not given explicit WhatsApp marketing consent (a conservative estimate for lists built before 2022), the brand is spending ₹28,000–₹68,000 per week to message people who either ignore, block, or report the messages. Consent segmentation alone typically lifts message-to-transaction conversion by 2.1× in Indian retail benchmarks, meaning a clean consented list of 300,000 outperforms a dirty list of 500,000 on revenue generated per rupee spent.

Second, consider data quality compounding. First-party data collected with explicit consent is demonstrably more accurate. A customer who actively opts in to birthday offer communications provides a real birthdate; a customer whose date of birth was guessed from a credit card application provides noise. Apollo Pharmacy, which runs one of India's most data-intensive loyalty operations, has publicly noted that consent-verified health preferences drive significantly higher redemption rates on personalised health bundles than broadcast campaigns. The same logic applies to fashion (Reliance Trends, Lifestyle) and food and beverage (Cafe Coffee Day).

Third, there is the media arbitrage angle that is underappreciated by most Indian retail marketing teams. Meta's Advantage+ and Google's Performance Max campaigns both allow first-party audience uploads for Custom Audiences and Customer Match respectively. When those audiences are built from consent-confirmed loyalty members, the match rates are higher (typically 55–70% versus 30–40% for unverified lists), the lookalike audiences are cleaner, and the cost-per-acquisition on paid media drops materially — often by 25–35% in Indian retail verticals. Consent is not just a legal asset; it is a media efficiency asset.

Finally, consent-driven loyalty programmes generate higher Net Promoter Scores. When a customer feels in control of their data relationship with a brand, they are more likely to recommend that brand. For a mall operator like Phoenix Marketcity, where tenant mix and footfall are the core value proposition, a loyalty programme that customers trust enough to recommend to family and friends is worth more than any advertising campaign the mall could run.

Risks of Non-Compliance and Data Misuse in Indian Retail Loyalty

The risk landscape for non-compliant loyalty data operations in India is converging from three directions simultaneously: regulatory enforcement, consumer backlash, and commercial platform policy. Each of these is materialising faster than most retail leadership teams have modelled.

On the regulatory front, the Data Protection Board of India is expected to become operational in 2025. Unlike many Indian regulatory bodies that have historically been slow to act on consumer-facing violations, the DPDP Act provides for significant suo motu powers — the Board can initiate proceedings without a formal complaint. The ₹250 crore penalty ceiling is not a theoretical number; the Act explicitly positions it as a deterrent for large data fiduciaries. For a listed retail company, a ₹50–100 crore penalty is material enough to move the stock price. For a mall operator, it could trigger covenant breaches on project finance loans.

On the consumer backlash front, the compounding effect of spam and data misuse is already visible in loyalty programme attrition rates. Indian retail loyalty programmes average 58–65% dormancy rates (members enrolled but not transacting in the last 12 months) — and a significant portion of that dormancy is attributable to communication fatigue caused by non-consented marketing. Brands that continue to carpet-bomb unverified lists will see these dormancy rates worsen, not improve, as DPDP awareness grows and as smartphone operating systems make it easier to filter and block brand communications.

On the commercial platform side, Meta updated its India data policy in late 2023 to require that audience data uploaded for Custom Audiences must comply with applicable local law — explicitly including consent requirements. WhatsApp's Business API terms similarly require that messages are sent only to users who have explicitly opted in to receive communications from the specific business. Brands that violate these policies risk account suspension — an existential risk for any Indian retailer that has built its CRM strategy around WhatsApp. The penalties from the platform often arrive faster and more operationally disruptively than regulatory fines.

For CIOs specifically, the technical debt of non-compliant data architectures is worth quantifying. Re-platforming a loyalty CRM that was not built for consent management — migrating member records, rebuilding consent capture flows, implementing real-time withdrawal propagation, auditing downstream data flows to analytics and media platforms — typically costs ₹1.5–4 crore for a mid-size retail brand and takes 9–18 months. Brands that start now will complete migration before enforcement peaks; brands that wait will be doing it under regulatory pressure with a compressed timeline and higher costs.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

5-Step Playbook: Building a Consent-First Loyalty Data Programme

01

Audit Your Existing Consent Records

Before building anything new, map every source of member data currently in your loyalty database. Categorise records by consent type: explicit opt-in with timestamp, implied consent from purchase transaction, third-party sourced, and unknown. Most Indian retail loyalty databases have fewer than 30% of records with verifiable explicit consent. This baseline defines your re-permissioning backlog and your compliance exposure.

02

Design Granular Consent Architecture

Work with your loyalty platform vendor to define discrete consent events for each data use case: transactional SMS, WhatsApp marketing, email personalisation, third-party brand offers (critical for mall multi-brand programmes), behavioural analytics, and data sharing with media platforms. Each consent event needs its own capture UI, timestamp record, and withdrawal pathway. This architecture must be reviewed by a DPDP-qualified legal counsel before implementation.

03

Launch a Re-Permissioning Campaign

For existing members without verifiable explicit consent, run a structured re-permissioning campaign across SMS, email, and in-store. Offer a tangible value exchange — bonus points, a exclusive member benefit, early access to a sale — in return for explicit consent. Indian retail benchmarks suggest that well-designed re-permissioning campaigns recover 35–50% of the unverified base within 90 days. Members who do not respond within the campaign window should be suppressed from marketing communications — not deleted, but quarantined pending a future touchpoint.

04

Integrate Consent Status into All Campaign Workflows

Consent status must be a first-class filter in every campaign workflow — not a post-hoc suppression list. Your loyalty platform, CRM, WhatsApp Business API integration, email service provider, and media platform audience upload processes must all query consent status in real time before any communication is sent. This requires API-level integration between your consent management layer and your campaign execution layer — a capability that most legacy loyalty vendors in India, including basic implementations of MoEngage or WebEngage, do not provide out of the box.

05

Build a Member-Facing Consent Dashboard

The DPDP Act's Section 13 right to withdraw consent requires that withdrawal is as easy as giving consent. Build or deploy a member portal — accessible via your loyalty app, WhatsApp, or web — where members can view their current consent settings, modify preferences by purpose, and withdraw consent with immediate effect. Log every change with timestamp and channel. This dashboard is both a compliance requirement and a trust-building tool: members who feel in control of their data are 2.4× more likely to actively engage with loyalty communications.

KPIs to Track for Consent-Based Loyalty Data Health

A consent-first loyalty programme requires a new measurement framework. The traditional loyalty KPIs — enrolled members, points issued, redemption rate, repeat purchase frequency — remain important, but they must be layered with consent health metrics that give the CMO and CIO a real-time view of both compliance posture and commercial data quality.

The primary consent health KPI is the Consented Addressable Base (CAB): the number of loyalty members with verified, active, explicit consent for at least one marketing communication channel. Track CAB as a percentage of total enrolled members, by channel (WhatsApp, email, SMS, push notification), and by consent purpose (transactional, promotional, third-party). A healthy Indian retail loyalty programme should be targeting a CAB of 55–65% of enrolled members within 12 months of implementing a consent-first architecture. Below 40% indicates a re-permissioning emergency; above 70% is world-class.

The second critical KPI is Consent Withdrawal Rate (CWR): the percentage of active consented members who withdraw at least one consent in a given month. A CWR below 1% per month is acceptable; above 2% is a signal that communications are too frequent, not relevant enough, or that the consent experience itself created distrust. Tracking CWR by campaign type and by channel helps identify which communication strategies are eroding trust rather than building it.

Third, track Revenue Per Consented Member (RPCM) — the average transaction value generated by consent-confirmed members versus the full enrolled base. In Indian retail, RPCM typically runs 1.8–2.6× higher than revenue per unverified member, reflecting both the self-selection of engaged customers and the superior campaign performance of consent-filtered audiences. This metric is the CFO's evidence that consent investment generates commercial return.

Finally, for mall operators and multi-brand retail programmes, track Cross-Brand Consent Depth: the average number of tenant or partner brands for which a single member has given explicit data-sharing consent. A member who has consented to data sharing with five brands in a Phoenix Marketcity programme is significantly more valuable — both commercially and as an anchor for the programme's network effects — than a member who has consented only to the mall's own communications.

DPDP Compliance Readiness Checklist for Indian Retail Loyalty Operators
  • Consent capture for all loyalty enrolment touchpoints (in-store, app, web, WhatsApp) records purpose, timestamp, channel, and member IP or device ID
  • Every marketing consent is purpose-specific — transactional notifications, promotional offers, third-party brand sharing, and behavioural analytics are separate consent events
  • Real-time consent withdrawal is available to members via a self-service portal accessible within 3 taps from the loyalty app home screen
  • Consent withdrawal propagates to all downstream systems — ESP, WhatsApp API, push notification, media platform audience uploads — within 60 seconds
  • Data Processing Agreements with all loyalty technology vendors explicitly reference DPDP Act obligations and include sub-processor clauses covering analytics and media platforms
  • Data retention policies for loyalty member records are tied to consent validity, not to arbitrary backup schedules, with automated deletion workflows
  • A Consent Health Dashboard is available to the CMO and CIO showing real-time Consented Addressable Base, Consent Withdrawal Rate, and consent coverage by channel and purpose
“In Indian retail, trust is the highest-yield loyalty currency. A consent-first data platform does not constrain your marketing — it amplifies every rupee you spend on the customers who actually want to hear from you.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Fundle was built for precisely this inflection point in Indian retail. The Fundle AI Platform is a consent-first loyalty infrastructure from the ground up — not a legacy points engine retrofitted with a consent checkbox, but a system where consent management is the architectural foundation on which personalisation, AI-driven engagement, and multi-brand data collaboration are built.

At the data layer, Fundle Loyalty implements granular, purpose-specific consent capture across every enrolment touchpoint — in-store QR, WhatsApp opt-in, app registration, and web — with every consent event timestamped, immutable, and queryable via API in real time. When a member withdraws consent on the Fundle member portal, the signal propagates across all connected campaign channels within 60 seconds, satisfying the DPDP Act's Section 13 requirement without manual intervention. For mall operators using Fundle Mall Loyalty, this architecture extends across all tenant brands: a member's consent to share data with a specific tenant brand is managed as a discrete event, entirely separate from their consent to the mall's own communications.

At the intelligence layer, Fundle AI Agents use only consent-confirmed data to power personalisation. The Fundle Agentic AI engine does not infer or assume consent — it queries consent status as a pre-condition for every AI-generated recommendation, offer, or communication trigger. This means that the hyper-personalisation Fundle Brand Loyalty delivers to brands like specialty apparel chains, pharmacy retail, or F&B operators is built on a foundation that will not crack under regulatory scrutiny. The Fundle AI Workflow orchestration layer ensures that no campaign — whether a triggered RFM win-back, a birthday offer, or a cross-brand promotion — executes without a real-time consent check.

Today, Fundle supports 270+ partner brands with consent-first loyalty infrastructure — a scale that has produced significant learnings about what consent architectures work in practice across different Indian retail verticals, geographies, and customer demographics. The Fundle AI Platform's consent health reporting gives CMOs and CIOs a live view of their Consented Addressable Base, Consent Withdrawal Rate, and consent coverage by channel — translating the legal requirement into a commercial metric that the board can act on. Vineet Narang's founding vision was that Indian retail deserved a loyalty platform built for trust at scale — and every product decision in the Fundle roadmap reflects that conviction. For Indian retailers navigating DPDP compliance while trying to grow loyalty programme ROI, the Fundle AI Platform is the infrastructure that makes both possible simultaneously.

Frequently asked

What is consent based loyalty data management and why does it matter for Indian retailers?+

Consent based loyalty data management is the practice of collecting, storing, and activating customer data in a loyalty programme only where the customer has given explicit, purpose-specific, and verifiable permission. It matters for Indian retailers because the DPDP Act 2023 makes non-consensual data processing a legal liability, and because consent-confirmed data drives measurably higher campaign ROI — typically 2.1–2.6× better conversion versus unverified lists.

How does the DPDP Act 2023 specifically affect loyalty programmes?+

The DPDP Act requires that every purpose of data processing — promotional messaging, behavioural analytics, third-party brand data sharing — has a separate, affirmative consent from the customer. It also gives customers the right to withdraw consent at any time with immediate effect. For loyalty programmes that aggregate data across multiple brands (such as mall programmes), each brand's data access requires its own consent event. Non-compliance penalties can reach ₹250 crore per instance.

What is the difference between a DPDP compliant loyalty data platform and a standard loyalty CRM?+

A DPDP compliant loyalty data platform captures granular, timestamped, purpose-specific consent at enrolment and throughout the member lifecycle; supports real-time consent withdrawal that propagates instantly to all connected campaign systems; ties data retention to consent validity; and provides a member-facing dashboard for consent management. A standard loyalty CRM typically bundles consent into T&Cs at sign-up and has no real-time withdrawal architecture.

How long does it take to migrate from a legacy loyalty platform to a consent-first platform?+

For a mid-size Indian retail brand with 200,000–500,000 loyalty members, a full migration — including consent record audit, re-permissioning campaign, platform integration, and downstream system updates — typically takes 9–14 months and costs ₹1.5–3.5 crore. Starting early, before the Data Protection Board becomes fully operational, gives brands the runway to do this methodically rather than under enforcement pressure.

Can a re-permissioning campaign recover most of the existing loyalty member base?+

Well-designed re-permissioning campaigns with a clear value exchange — bonus points, exclusive benefits, early access — typically recover 35–50% of unverified members within 90 days in Indian retail. Members who do not respond should be suppressed from marketing (not deleted) and re-approached at the next natural touchpoint such as a store visit or customer service interaction. The recovered base, while smaller, is significantly more commercially valuable.

How does Fundle.ai help brands comply with DPDP while still growing loyalty programme revenue?+

Fundle.ai's consent-first architecture ensures every personalisation, campaign trigger, and cross-brand data flow is pre-conditioned on verified consent — eliminating compliance risk without sacrificing programme intelligence. The Fundle AI Platform's consent health dashboard gives CMOs real-time visibility into their Consented Addressable Base and Consent Withdrawal Rate, so compliance becomes a manageable commercial metric. Fundle currently supports 270+ partner brands with this infrastructure, demonstrating it is operationally proven at scale across Indian retail.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?