AMLEGALS — Strategic Lawyering
Retail & Loyalty Programmes — DPDPA sector brief

Retail & Loyalty Programmes

DPDPA Impact on Retail & Loyalty Programmes

Retail and loyalty programmes build detailed member profiles from enrolment and purchase history — used for marketing and personalisation, all of which turn on notice, consent and purpose limitation.

In short

Retail and loyalty programmes fall under the DPDP Act, 2023 because member enrolment data and purchase-history profiles are digital personal data. Marketing consent under Section 6 cannot be bundled into programme enrolment, and profiling purposes must be notified under Section 5 read with Rule 3.

  • Marketing consent must be separate from programme enrolment and cannot be a condition of joining.
  • Purchase-history profiling must be limited to notified purposes under Section 5 read with Rule 3.
  • Co-brand and analytics partners must be engaged under a valid Section 8(2) contract.

When the Act applies

The Act applies to member and customer personal data processed in India, and to retailers outside India offering goods or services to Data Principals in India.

Personal data typically in play

  • Loyalty enrolment and contact data
  • Purchase and transaction history
  • Preference and personalisation profiles
  • Marketing consent and channel choices
  • Partner and co-brand data sharing

Mapped obligations

Section 5 · Rule 3

Itemised notice

Give each Data Principal a clear, itemised notice — in English or any language in the Eighth Schedule to the Constitution — describing the personal data collected and the specified purpose, before or at the time of seeking consent.

Section 6

Consent that is free & withdrawable

Where processing rests on consent, it must be free, specific, informed, unconditional and unambiguous, limited to the specified purpose, and as easy to withdraw as it was to give.

Section 8(7) · Rule 8

Retention limits & erasure

Erase personal data on withdrawal of consent or once the specified purpose is no longer being served, unless retention is required by law.

Section 8(2)

Processor under valid contract

Engage every Data Processor — vendors, sub-contractors and technology partners — only under a valid contract, and remain accountable for the personal data throughout.

Section 8(5) · Rule 6

Reasonable security safeguards

Implement reasonable security safeguards — including measures such as encryption, access control, logging and monitoring — to prevent a personal data breach.

Sections 11–14 · Rule 14

Data Principal rights

Enable the rights to access a summary of personal data and processing, to correction and erasure, to grievance redressal and to nominate — and publish the manner in which these are exercised.

Section 8(6) · Rule 7

Breach intimation

On becoming aware of a personal data breach, intimate each affected Data Principal without delay and give the Data Protection Board an initial description without delay, followed by detailed information within 72 hours (or such longer period as the Board may allow).

Recurring compliance risks

  • Bundling marketing consent into programme enrolment
  • Profiling purchase history for undisclosed purposes
  • Sharing member data with co-brand partners without a contract
  • No easy withdrawal or erasure for members who leave the programme

Actions that follow

  1. 1Separate programme enrolment from marketing consent
  2. 2Notify profiling purposes and confine use to them
  3. 3Contract co-brand and analytics partners under Section 8(2)
  4. 4Provide simple withdrawal, erasure and grievance routes

Frequently asked questions

Can a retailer bundle marketing consent into loyalty programme sign-up?
No. Consent under Section 6 must be free, specific and unconditional. Marketing consent must be separated from programme enrolment so that joining the programme is not conditioned on agreeing to marketing.
Is profiling of purchase history allowed under the DPDP Act?
Profiling is permitted only for purposes that have been notified to the member under Section 5 read with Rule 3 and to which any required consent relates. Using purchase history for undisclosed purposes is a compliance risk.
What happens when a member leaves the loyalty programme?
The member can withdraw consent and seek erasure. Under Section 8(7) read with Rule 8, personal data must be erased once the purpose is no longer served, unless retention is required by law.