
Nalini’s Retail Loyalty Programme and the Profile She Never Agreed To
The Scenario
Nalini is a 29-year-old working professional in Mumbai. She had enrolled in a large retail chain’s loyalty programme several years ago. At the time of enrolment, she provided her name, phone number, email address, and date of birth in exchange for discount points.
Over the following years, the retail chain built an increasingly sophisticated analytics capability. It combined Nalini’s purchase history — over 400 transactions across groceries, personal care, clothing, and home products — with her app browsing data, location signals from in-store beacons, and inferred demographic data purchased from a data enrichment vendor. The analytics platform then classified her into behavioural segments — “health-conscious millennial,” “premium spender,” “likely expecting” — and used these segments to target her with personalised advertising and to adjust the pricing of certain dynamic offers.
Nalini had not been informed that her purchase history would be used to infer personal attributes. She had not consented to location tracking via in-store beacons. She had no knowledge of the data enrichment vendor or the categories of inferred data it supplied. Furthermore, when she eventually tried to delete her account, the platform told her that her historical transaction data had to be retained for seven years under applicable tax and commercial regulations — and that her behavioural segments were derived data and therefore could not be erased.
The DPDP Act Position
Nalini’s situation is the most layered of the three stories, because it involves multiple compliance failures running simultaneously across the full analytics pipeline.
First — Consent obtained for enrolment is not consent for analytics profiling. Section 6(1) requires consent to be limited to personal data that is necessary for the specified purpose. The specified purpose at enrolment was participation in a loyalty programme for discount points. Predictive profiling, behavioural segmentation, demographic inference, and dynamic pricing optimisation are materially different purposes — each requiring its own consent basis.
Rule 3 of the DPDP Rules further tightens this standard. The notice must give an itemised description of personal data and a specific description of the goods, services, or uses that processing will enable. A loyalty programme enrolment form that says “your data will be used to improve your shopping experience” does not satisfy this requirement when the actual use involves inferring pregnancy likelihood or segmenting users by spending disposition.
Second — Inferred data is personal data under Section 2(t). The DPDP Act defines personal data as any data about an individual who is identifiable by or in relation to such data. Behavioural segments derived from Nalini’s purchasing patterns — “likely expecting,” “premium spender” — are data about an identifiable individual. They are personal data. Their creation and storage are processing activities subject to the Act’s full consent and purpose requirements. The retail chain’s argument that derived data cannot be erased does not hold under Section 12(3) — the erasure right applies to personal data in whatever form it exists, including derived outputs of analytics processing.
Third — Third-party data enrichment without disclosure under Section 5. The retail chain ingested demographic inference data from an external vendor to enrich Nalini’s profile. This enrichment vendor is a Data Processor under the Act. Its data categories were never disclosed to Nalini in the original notice. Section 5(1) and Rule 3 together require that the source and category of every piece of personal data used in processing be disclosed to the Data Principal at the time of notice. Using enrichment data that was never disclosed violates this requirement.
Fourth — In-store beacon tracking without consent under Section 6. Location signals collected from in-store beacons constitute processing of personal data. Nalini had enrolled in a loyalty programme — she had not consented to being tracked by physical location sensors during her store visits. This is a separate processing activity requiring a separate consent.
Fifth — The “seven-year retention” argument does not justify analytics profiling. The retail chain’s argument that transactional data must be retained for seven years under commercial law is legally accurate for transaction records — but retention for regulatory compliance does not authorise the retained data to be used for new purposes. Section 8(1) and the purpose limitation principle require that data retained for regulatory compliance be isolated from analytics processing pipelines. Retaining data is not the same as having a continuing licence to process it for all purposes.
The IS Audit and Puttaswamy Perspective
IS Audit 3.0 by ICAI describes data analytics as a series of processes designed to sanitise raw data and transform it into a form appropriate for analysis to facilitate decision-making. In Nalini’s case, the analytics pipeline transformed loyalty programme enrolment data into a comprehensive personal profile — a transformation that was never disclosed, never consented to, and that the DPDP Act does not permit on the basis of an original loyalty enrolment consent alone.
The Puttaswamy judgment (2018) is especially pertinent here. The court directly addressed the concept of the “quantified self” — individuals generating vast amounts of data through everyday activities, without conceiving of themselves as having volunteered it for profiling. Justice Kaul’s analysis of profiling under data protection law applies directly: using personal data to evaluate aspects of an individual’s life — her economic situation, personal preferences, behaviour, or movements — is a privacy-sensitive activity that requires explicit, specific authorisation. A discount programme sign-up is not that authorisation.
Furthermore, the court’s description of the “Big Data” era as one where data sets are linked, searchable, and permanently collected maps directly to Nalini’s situation: her 400 transactions, combined with location signals and enrichment data, created exactly the kind of linked, searchable, permanent dataset that the Puttaswamy judgment identified as requiring robust legal governance.
The Compliance Fix
Retail loyalty programmes and any organisation using analytics for customer profiling must:
→ Separate enrolment consent from analytics consent. Loyalty enrolment and behavioural profiling are different processing activities. They require separate, specific consent notices that clearly describe what profiling will occur, what data will be used, and what outputs will be generated.
→ Treat all derived data — segments, inferences, scores — as personal data under Section 2(t). Design erasure mechanisms that reach derived data, not just source data.
→ Disclose every external data enrichment vendor by name and category in the consent notice under Rule 3. “Third-party partners” is not adequate disclosure.
→ Obtain separate consent for in-store location tracking via beacons. Physical location processing is a distinct activity requiring a distinct lawful basis.
→ Apply a regulatory retention firewall: data retained for tax or commercial law compliance must be technically isolated from live analytics pipelines. Regulatory retention and analytics processing are separate activities requiring separate legal bases.
→ For organisations using analytics on large volumes of personal data for profiling, segmentation, or prediction, a DPIA under Rule 13 of the DPDP Rules is a mandatory exercise — not an optional governance measure.
Nalini’s retail chain ran excellent analytics. However, it ran them on a broken consent architecture. The quality of the insights does not determine the lawfulness of the processing.
The Central Compliance Question for Data Analytics Deployments
Data analytics is not inherently incompatible with the DPDP Act. Organisations can legitimately use data analytics for internal operations, fraud detection, product improvement, and customer service — provided the analytics is designed from the ground up around a compliant consent and purpose framework.
The compliance failure that runs through all three stories in this episode is the same: analytics capabilities grew beyond the consent architecture that was in place when data was originally collected. Devika’s lender ran predictive models on data never disclosed to her. Harini’s hospital activated a marketing module without patient consent. Nalini’s retail chain built a behavioural profile using data from sources never itemised in any notice.
Every organisation running data analytics on personal data must therefore answer six questions before each analytics deployment:
One. Does our Rule 3 notice itemise every data source feeding this analytics model — including external enrichment vendors, third-party data providers, and inferred or derived data categories?
Two. Is every analytical use case — profiling, segmentation, prediction, decision-making — identified as a specific stated purpose at the time of consent?
Three. Are all Data Processors in the analytics pipeline — vendors, cloud platforms, enrichment providers — covered by Section 8(2) contracts that limit them to the specified purpose?
Four. Does our analytics pipeline have a purpose limitation control that prevents data collected for one purpose from feeding into models built for a different purpose?
Five. Can we honour a Section 11 access request accurately enough to tell a Data Principal which data sources contributed to a decision about her?
Six. Can we honour a Section 12(3) erasure request that reaches derived data — segments, scores, and inferences — not just source records?
IS Audit 3.0 study material by ICAI identifies data privacy risk as the primary challenge for analytics deployments. Rule 13 of the DPDP Rules mandates annual DPIA and audit for Significant Data Fiduciaries using analytics at scale. Together, they establish that governance of data analytics is not optional — it is the compliance baseline.
What Responsible Data Analytics and DPDP Compliance Looks Like
The organisations that will manage this intersection well are not those with the most sophisticated models. They are the ones that invested in governance architecture before their analytics capabilities outgrew their consent frameworks.
Responsible data analytics and DPDP compliance means one thing above all else: every data point entering an analytics pipeline must be traceable to a consent record that specifically authorises its use for that specific analytical purpose. Where that traceability breaks down — at the point of data collection, at the point of third-party enrichment, at the point of model output — the compliance obligation is violated, regardless of how valuable or accurate the analytical output may be.
The value of an insight does not determine the lawfulness of how it was generated. The DPDP Act makes that unambiguous. The compliance deadline is 13 May 2027.
Disclaimer
The contents of this post are intended for general awareness and informational purposes only. They do not constitute legal opinion, professional advice, consultancy, statutory interpretation, or a recommendation to act in any particular manner.
The Digital Personal Data Protection Act, 2023, related rules, notifications, regulatory guidance and judicial interpretations may evolve from time to time. The applicability of the law may also vary depending on the facts, sector, nature of data processing, organisational role, contractual terms and compliance framework.
Readers should not rely solely on this post for making legal, business, HR, technology, data-processing or compliance decisions. Specific advice from a qualified legal, privacy, cybersecurity, governance or compliance professional should be obtained before acting on any matter discussed.
The author / publisher shall not be responsible for any loss, liability, claim, penalty or consequence arising from reliance on the contents of this post without independent professional advice.
Authors: This article has been co-authored by CA. Sunil Elayadath and CA. Karthik Narayanan S, Partners of Karthik & Sunil, together with Mr. Dhanesh P. K., Designated Partner, DSK Sustainability Tech.
