
Retail & Loyalty Programmes
DPDPA Impact on Retail & Loyalty Programmes
Retail and loyalty programmes build detailed member profiles from enrolment and purchase history — used for marketing and personalisation, all of which turn on notice, consent and purpose limitation.
In short
Retail and loyalty programmes fall under the DPDP Act, 2023 because member enrolment data and purchase-history profiles are digital personal data. Marketing consent under Section 6 cannot be bundled into programme enrolment, and profiling purposes must be notified under Section 5 read with Rule 3.
- Marketing consent must be separate from programme enrolment and cannot be a condition of joining.
- Purchase-history profiling must be limited to notified purposes under Section 5 read with Rule 3.
- Co-brand and analytics partners must be engaged under a valid Section 8(2) contract.
When the Act applies
The Act applies to member and customer personal data processed in India, and to retailers outside India offering goods or services to Data Principals in India.
Personal data typically in play
- Loyalty enrolment and contact data
- Purchase and transaction history
- Preference and personalisation profiles
- Marketing consent and channel choices
- Partner and co-brand data sharing
Mapped obligations
Itemised notice
Give each Data Principal a clear, itemised notice — in English or any language in the Eighth Schedule to the Constitution — describing the personal data collected and the specified purpose, before or at the time of seeking consent.
Consent that is free & withdrawable
Where processing rests on consent, it must be free, specific, informed, unconditional and unambiguous, limited to the specified purpose, and as easy to withdraw as it was to give.
Retention limits & erasure
Erase personal data on withdrawal of consent or once the specified purpose is no longer being served, unless retention is required by law.
Processor under valid contract
Engage every Data Processor — vendors, sub-contractors and technology partners — only under a valid contract, and remain accountable for the personal data throughout.
Reasonable security safeguards
Implement reasonable security safeguards — including measures such as encryption, access control, logging and monitoring — to prevent a personal data breach.
Data Principal rights
Enable the rights to access a summary of personal data and processing, to correction and erasure, to grievance redressal and to nominate — and publish the manner in which these are exercised.
Breach intimation
On becoming aware of a personal data breach, intimate each affected Data Principal without delay and give the Data Protection Board an initial description without delay, followed by detailed information within 72 hours (or such longer period as the Board may allow).
Recurring compliance risks
- Bundling marketing consent into programme enrolment
- Profiling purchase history for undisclosed purposes
- Sharing member data with co-brand partners without a contract
- No easy withdrawal or erasure for members who leave the programme
Actions that follow
- 1Separate programme enrolment from marketing consent
- 2Notify profiling purposes and confine use to them
- 3Contract co-brand and analytics partners under Section 8(2)
- 4Provide simple withdrawal, erasure and grievance routes
