GDPR and Odoo — privacy basics for European companies
GDPR is not an add-on you sprinkle on top of Odoo before an audit. It is a set of habits, configurations and documented decisions that should sit inside your Odoo from day one. This post covers the privacy basics every European company running Odoo should have in place.
We are not lawyers, and this post is not legal advice. We are Odoo consultants who help European companies put a GDPR-acceptable Odoo into production. This is the playbook we apply across our clients in Belgium, the Netherlands, Luxembourg and France.
GDPR scares teams more than it should. Most of the work is configuration, documentation and a few small modules. Done up front it costs days; done in panic before a supervisory authority visit it costs weeks and credibility.
We will walk through the data map, lawful bases, retention, subject rights, sub-processors, and the operational habits that keep an Odoo deployment defensible.
Map the data first — you cannot protect what you do not know
The first step is always a data map: which personal data lives in which Odoo module, who has access, where it is hosted and where it goes next. Most clients are surprised by what shows up — old marketing lists, employee data still in CRM after departure, helpdesk threads with personal context.
Half a day with the right people in a room produces a first-pass data map. Refine it over the following weeks and you have the document that any GDPR conversation needs to start with.
- List every Odoo module that holds personal data
- Per module, list categories of data subjects (employees, customers, prospects, suppliers)
- Per module, list categories of data (identification, contact, financial, behavioural)
- Per module, list lawful basis (consent, contract, legitimate interest)
- Per module, list retention rules and review dates
Lawful basis — pick one per processing
GDPR allows several lawful bases for processing personal data. In Odoo the most common are 'contract', 'legitimate interest' and 'consent'. The point is not to invoke all three — it is to pick one explicit basis per processing and document it.
Marketing usually rests on consent or legitimate interest depending on jurisdiction. Customer and supplier records rest on contract performance. Employee records rest on employment law and contract. Each of these has different consequences for retention and for subject rights.
- Contract performance for customer and supplier records
- Legitimate interest for fraud prevention and security
- Consent for marketing where required
- Legal obligation for tax and accounting records
- Vital interest only in narrow operational cases
Retention — delete on time, not when convenient
Personal data should not live forever in your Odoo. GDPR asks you to define retention periods aligned with the purpose, and to actually delete or anonymise when the period expires. This is the part most companies skip — and the part supervisory authorities ask about first.
We help clients set retention rules per module: prospects untouched for 24 months are anonymised, employee files are kept per labour law minimums, accounting records per fiscal law minimums. We then schedule the cleanup as a real automated process, not a yearly intention.
- Define retention per data category and document it
- Automate anonymisation or deletion where possible
- Keep accounting and tax records per legal minimums
- Anonymise CRM prospects with no contact for 24 months by default
- Review retention rules annually with legal
Subject rights — be ready to answer in 30 days
Anyone whose personal data you hold can ask you for a copy, ask you to correct it, ask you to delete it, or object to your processing. GDPR gives you 30 days to respond. Without a process, that 30-day clock becomes very stressful.
We set up a documented intake (mailbox, form or helpdesk category), assign an owner, and run two dry-runs before any real request arrives. The first request is not the moment to discover that your CRM and HR cannot be queried consistently.
- Documented intake channel for subject requests
- Named owner and back-up for handling requests
- Two dry-run requests run end-to-end before go-live
- Standard templates for response within 30 days
- Audit trail of every request and response
Sub-processors — your Odoo is not alone
Odoo is rarely your only data processor. Email providers, marketing tools, payment processors, LLM providers, monitoring vendors — any of them might process personal data on your behalf. Each needs to be on your sub-processor list with a DPA in place.
We maintain the list with the client and review it twice a year. Whenever a new integration is wired, the sub-processor question is part of the change request, not an afterthought.
- Maintain a sub-processor register
- Sign a DPA with each sub-processor before production use
- Verify EU hosting and cross-border transfer mechanisms
- Add the sub-processor question to every integration change request
- Review the register at least twice a year
GDPR mistakes we see in Odoo deployments
Five patterns we audit out before they become a problem.
- No data map — privacy decisions made on intuition.
- Indefinite retention because nobody scheduled the cleanup.
- Marketing tools added without a DPA and without a sub-processor entry.
- Subject requests handled ad hoc — no owner, no template, no log.
- Sending personal data to AI providers without checking the DPA terms.
How to measure that GDPR is alive in your Odoo
Operational signals reviewed quarterly.
- Data map completeness — every module covered.
- Retention automation — scheduled jobs running and logged.
- Subject request response time — under 30 days, every time.
- Sub-processor register up-to-date in the last 6 months.
- Privacy training completed by every Odoo admin user yearly.
How we run GDPR readiness at Flydoo
We run a half-day privacy workshop with the client's DPO or a designated owner. We produce a first-pass data map, a lawful-basis table, a retention plan and the sub-processor list. From that we plan the technical configuration in Odoo (anonymisation jobs, archive flags, helpdesk intake).
We always end with two dry-run subject requests so the owner has muscle memory. The day a real request arrives, the playbook is on paper and the templates are ready.
- Half-day privacy workshop with the DPO or named owner
- Produce data map, lawful basis table, retention plan, sub-processor list
- Configure anonymisation and archive jobs in Odoo
- Set up subject-request intake in helpdesk with templates
- Run two dry-run subject requests end-to-end before go-live
GDPR readiness checklist for Odoo
If you can tick most of these, your Odoo is in defensible shape.
- Data map produced and reviewed annually
- Lawful basis documented per processing
- Retention rules defined and automated where possible
- Subject request process documented with named owner
- Sub-processor register up-to-date with DPAs signed
- Privacy training completed by Odoo admins
- Annual review meeting with DPO on the calendar
GDPR is muscle, not paperwork
Treat GDPR as a set of operational habits inside your Odoo rather than a binder for the auditor. The companies that do this find the paperwork falls out naturally — the data map, the basis table, the retention plan are simply how they describe their own system.
The work is bounded and the payoff is real: less stress when a request arrives, less risk when an authority calls, and more trust from the customers and employees whose data you hold.
If you would like a sanity check on your GDPR posture in Odoo, we are happy to spend a half-day with your DPO and produce a one-page assessment.
Frequently asked questions
Do I really need a data map for my Odoo?
Yes. Without a data map, every other GDPR conversation is a guess. Start with a one-page version covering the modules you actually use — it is enough to begin and can be refined over time. Most companies that say 'we don't need one' discover later that they did.
Where should I host my Odoo to comply with GDPR?
Anywhere with appropriate transfer mechanisms in place. EU hosting on Odoo Online or Odoo.sh covers most needs. For strict residency rules — only this country, only this provider — self-hosted in your jurisdiction is usually the only option that satisfies the auditor.
Can I use AI providers like OpenAI or Anthropic with personal data?
Only after adding them to your sub-processor list, signing a DPA, and minimising the personal data you send. Many clients prefer to anonymise or redact before the model call. Treat them like any other SaaS sub-processor: deliberate, documented, monitored.
How long can I keep customer or employee data?
As long as you have a lawful purpose. Once the purpose ends, retention should follow the legal minimum (often 7–10 years for accounting and tax) and then anonymise or delete. CRM prospects with no contact for 24 months are a common default for anonymisation.
What happens if a customer asks for their data?
You must respond within 30 days. Provide a copy of the personal data you hold, in a portable format. If they ask for deletion or correction, do it where lawful — and explain when retention obligations prevent it. Run two dry-runs before the first real request.
Want to discuss what this means for your own Odoo project? We're happy to talk.
