Introduction
Customer data helps sales, marketing and service teams build useful relationships. It also creates obligations. A contact may want order updates by email, marketing messages by SMS or no promotional communication at all. A business needs a dependable way to respect those choices across Odoo CRM, Sales, Marketing, Helpdesk and connected tools.
Odoo customer consent management is not simply a checkbox on a web form. It is a controlled process for capturing a lawful basis, recording channel preferences, applying suppression when required and retaining evidence that explains what happened. The process must also account for imported lists, third-party integrations, changes to a customer’s preferences and applicable retention rules.
This guide explains a functional and business framework for designing that process in Odoo. It does not provide legal advice. Privacy and direct-marketing rules vary by country, industry, customer type and communication channel. Before configuring policies or campaigns, obtain local legal review and ensure the process is aligned with the jurisdictions where the organization operates.
For a connected CRM and communications workflow, see Odoo CRM, Odoo Sales, Odoo Marketing and Odoo Helpdesk.
Why Consent Needs More Than A Marketing Field
Customer contact data often enters Odoo through many paths: a website inquiry, sales meeting, event registration, quotation, support request, imported list, partner referral or eCommerce order. If every source uses a different field or uses no field at all, the team cannot confidently answer three basic questions: why may we contact this person, which channel may we use and what proof do we have?
Consent is only one possible lawful basis for processing personal data. Depending on the context and local law, a business may rely on a contract, legal obligation, legitimate interests or another lawful basis. These are not interchangeable labels. A sales order may justify operational messages needed to fulfill the order, while it may not automatically justify a promotional campaign. The Odoo record should show the purpose and basis selected under the organization’s approved policy.
Separating service communication from marketing communication reduces confusion. An account holder may need a password-reset email or delivery update even after opting out of newsletters. At the same time, an unsubscribe from a promotional email should not be quietly ignored because the contact has an active opportunity. Design clear categories of communication and use the correct one each time.
Define Lawful Basis, Purpose And Channel Rules
Start with a register of the communications the business sends. For each one, define the purpose, audience, channel, proposed lawful basis, evidence needed, owner and retention rule. This becomes the operating design that Odoo forms, contact fields, marketing lists and integrations must follow.
| Communication Type | Typical Purpose | Data Needed In Odoo | Control Owner |
|---|---|---|---|
| Transactional email | Confirm an order, delivery, payment or account action | Related order or account, recipient and send record | Operations or customer service |
| Sales follow-up | Respond to a request or manage a stated sales interest | Lead source, purpose, lawful-basis decision and contact channel | Sales leadership |
| Marketing email | Send campaigns, newsletters or event promotion | Marketing preference, timestamp, source and unsubscribe status | Marketing owner |
| SMS or messaging | Send approved alerts or promotions through a mobile channel | Verified number, channel preference and suppression check | Marketing and compliance owner |
| Service communication | Resolve support requests or notify customers about service activity | Ticket, contact preference and service record | Helpdesk owner |
Do not assume a channel preference applies to every purpose. A person who agrees to product newsletters by email may not agree to SMS promotions. A company contact may be able to receive account messages while declining product announcements. Store preferences at a level that lets the business apply this distinction consistently.
Define the organization’s source-of-truth rule. In many cases, the contact or partner record is the central customer profile while marketing applications consume approved preference fields. If a consent portal or external preference center is authoritative, its updates need a reliable path back to Odoo. A duplicate field on a campaign record is not a durable substitute for the master profile.
Capture Consent And Preference Evidence At The Source
Evidence should be captured at the moment a choice is made. At a minimum, keep the identity of the contact, the date and time, capture source, wording or policy version, channels selected, purpose and the event that recorded it. Where appropriate, retain form identifiers, IP-related information or a confirmation event according to approved policy and legal guidance. Collect only what is necessary and protect it appropriately.
A website form can pass consent selections into the Odoo CRM lead and linked contact. An event registration can record the event, form version and communications requested. A salesperson entering a trade-show lead should not mark a person as opted in merely because a business card was collected. Give the salesperson a way to record the source and follow the approved follow-up process instead.
When importing contacts, treat the list as evidence to be assessed rather than a marketing audience to be uploaded. Confirm the source, date, collection notice, permitted channels and proof of opt-in or other approved basis before activation. If the evidence is incomplete, quarantine the record from promotional workflows until the organization decides the correct treatment. A clean import is not one with the most records. It is one whose permitted use is understood.
| Capture Source | Required Evidence | Odoo Workflow | Common Risk |
|---|---|---|---|
| Website form | Choice, form version, timestamp, purpose and channel | Map form fields to the lead or contact record | Preselected boxes or unclear wording |
| Sales inquiry | Source, requested topic and permitted follow-up basis | Create lead with source and status for follow-up | Treating a badge scan as broad consent |
| Customer portal | Updated choice, account identity and effective date | Update master contact preferences and retain change history | Letting users change one channel but not others |
| Imported list | Supplier details, collection method, date and permitted use | Validate then import to controlled audience | Loading unknown lists into campaigns |
| Support interaction | Request, identity validation and scope of preference change | Update preference after documented request | Confusing service contact with marketing permission |
Apply Preferences And Suppression Across Odoo Workflows
Capture has little value if a campaign, automation or integration can ignore the result. Preference fields must be applied before recipients are selected. This requires clear audience logic: marketing workflows include only contacts that meet the permitted purpose and channel conditions while suppressions take priority over general audience rules.
Suppression is an instruction not to send a defined type of communication. It may result from an unsubscribe, objection, do-not-contact request, invalid address, complaint or internal risk decision. Keep the reason and effective date. Do not delete the contact automatically if there is an ongoing contract, accounting record or support history that must be retained. Instead, limit communication and processing in line with the approved policy.
An unsubscribe link should update the appropriate marketing preference promptly. A request received by phone, email or support ticket needs a controlled internal route so the preference is updated without relying on a staff member’s personal notes. Make it easy for frontline teams to recognize such requests, verify the contact identity where appropriate and record the change.
The end-to-end flow should be visible to every owner:
- A lead, customer or subscriber provides data through an approved source.
- Odoo records the purpose, lawful-basis outcome, channel preferences and evidence reference.
- Campaign or automation audience rules evaluate the contact before a message is queued.
- Suppression and unsubscribe records exclude restricted recipients before sending.
- Delivery, bounce, complaint and preference-change events update the profile or exception queue.
- Owners review exceptions, reconcile integrations and retain evidence for the approved period.
Govern Integrations, Duplicates And Data Changes
Consent data is especially vulnerable when external tools are involved. A marketing platform, web form, event tool, call system, customer portal or data-enrichment provider may each create or update contacts. Without mapping and ownership, one system may re-enable a preference that another system correctly suppressed.
For each integration, document which system creates the contact, which system owns each preference field, which values may flow in each direction and how conflicts are resolved. Use stable identifiers so that an unsubscribe applies to the same person across systems. Email address alone may not be enough when a customer changes addresses, shares an inbox or has duplicate records.
Deduplication is a consent control as well as a CRM hygiene task. If the same person appears twice, one record can be opted out while the other is still marketed to. Define matching rules, a merge process and a decision about which evidence survives the merge. Do not merge merely because names look similar. A mistaken merge can attach one person’s preferences to another person’s account.
| Integration Control | Design Decision | Evidence Or Monitoring |
|---|---|---|
| Field ownership | Name the authoritative system for each preference and suppression field | Integration specification and data-owner approval |
| Event handling | Define how unsubscribe, bounce, complaint and portal events reach Odoo | Event logs and failed-message queue |
| Conflict resolution | Decide what happens when systems hold different preference values | Conservative rule and exception record |
| Duplicate management | Match safely and preserve the strongest restriction when reviewing duplicates | Merge approval and retained history |
| Access control | Limit who can export, override or change preferences | Role review and audit log |
Use the most protective approved state when a conflict cannot be resolved automatically. For example, do not restore marketing eligibility merely because an imported file shows a blank preference while the master record is suppressed. Send uncertain cases to a review queue. The cost of delaying a campaign message is normally lower than the cost of ignoring a valid objection.
Set Retention, Access And Ownership Rules
An opt-out record may need to be retained in a restricted form so the business does not accidentally re-contact the person. The precise approach depends on local law and legal advice. Privacy teams should define whether identifiers are minimized, hashed or retained with limited access. Do not promise deletion in a customer notice if operational systems cannot perform it consistently.
Access should follow the principle of least privilege. Sales users may need to view current communication status but should not override a suppression without approved authority. Marketers may build audiences but should not export unrestricted customer data. Administrators and integration accounts need audited permissions because their actions can affect thousands of records at once.
Ownership closes the control loop. Assign a business owner for the consent policy, a data owner for the customer profile, an application owner for Odoo configuration and an integration owner for connected tools. Give them a review cadence and escalation path. The CFO, sales leader and customer-service leader should understand the impact of poor controls even when they do not administer the fields themselves.
Useful KPIs include the percentage of active marketing contacts with complete evidence, opt-out processing time, suppression failures, duplicate contacts with conflicting preferences, campaign exclusions by reason, integration exceptions and overdue retention actions. These measures reveal whether the design is working in daily operations rather than only on a policy document.
Conclusion
Customer consent and communication preferences work when they are treated as a cross-functional business process, not as a marketing setting. Start by distinguishing the purpose of each communication and recording the approved lawful-basis outcome. Capture clear evidence at the source, apply preferences before messages are sent and make suppression stronger than broad audience rules.
Then protect the process through integration ownership, duplicate controls, retention rules and restricted access. Odoo can connect CRM, sales, service and marketing records, but it cannot make legal judgements for the organization. Build the workflow with local legal review and revisit it whenever communication channels, regions or data sources change.
Frequently Asked Questions
1. Is Consent The Only Lawful Basis For Customer Communication?
No. The appropriate basis depends on the communication, relationship and applicable law. Operational messages connected to an order may be handled differently from promotional messages. Your privacy or legal adviser should approve the organization’s basis and documentation rules.
2. Should An Unsubscribe Stop All Emails From Odoo?
Usually, marketing opt-out and operational service messages need separate treatment. An unsubscribe should reliably stop the communication type it covers. Do not use that distinction to send disguised promotions as service notices.
3. What Evidence Should Odoo Keep For Marketing Consent?
Keep the contact identity, timestamp, source, purpose, channels selected and the wording or policy version that was presented. Add other evidence only when required by your approved process and local legal advice.
4. Can We Import A Purchased Or Event Contact List Into Odoo Marketing?
Only after the organization verifies the permitted use, channel rights, collection date and evidence under its policy. Unknown or incomplete lists should be restricted from promotional activity until reviewed.
5. How Do We Handle A Consent Request Received By Phone?
Use a documented workflow for verifying the requester when appropriate, recording the request and updating the correct preference or suppression field promptly. Retain the ticket, call note or other approved evidence of the change.
6. What Happens If Two Integrated Systems Have Different Preference Values?
Define one authoritative source for each field and use a conservative rule when a conflict remains. In practice, this often means retaining the stronger restriction until the issue has been reviewed rather than automatically restoring eligibility.
7. Does This Guide Replace Legal Advice?
No. It provides an operational framework for using Odoo customer data responsibly. Privacy, marketing and retention requirements vary by jurisdiction and situation, so obtain local legal review before finalizing policies, notices, workflows or configurations.