Skip to Content

Customer Consent And Communication Preferences In Odoo

Learn how to manage customer consent and communication preferences in Odoo with lawful basis, suppression, evidence, retention and ownership controls.
10 min read
September 24, 2026
Odoo CRM & Sales

Introduction

Customer data helps sales, marketing and service teams build useful relationships. It also creates obligations. A contact may want order updates by email, marketing messages by SMS or no promotional communication at all. A business needs a dependable way to respect those choices across Odoo CRM, Sales, Marketing, Helpdesk and connected tools.

Odoo customer consent management is not simply a checkbox on a web form. It is a controlled process for capturing a lawful basis, recording channel preferences, applying suppression when required and retaining evidence that explains what happened. The process must also account for imported lists, third-party integrations, changes to a customer’s preferences and applicable retention rules.

This guide explains a functional and business framework for designing that process in Odoo. It does not provide legal advice. Privacy and direct-marketing rules vary by country, industry, customer type and communication channel. Before configuring policies or campaigns, obtain local legal review and ensure the process is aligned with the jurisdictions where the organization operates.

For a connected CRM and communications workflow, see Odoo CRM, Odoo Sales, Odoo Marketing and Odoo Helpdesk.

Why Consent Needs More Than A Marketing Field

Customer contact data often enters Odoo through many paths: a website inquiry, sales meeting, event registration, quotation, support request, imported list, partner referral or eCommerce order. If every source uses a different field or uses no field at all, the team cannot confidently answer three basic questions: why may we contact this person, which channel may we use and what proof do we have?

Consent is only one possible lawful basis for processing personal data. Depending on the context and local law, a business may rely on a contract, legal obligation, legitimate interests or another lawful basis. These are not interchangeable labels. A sales order may justify operational messages needed to fulfill the order, while it may not automatically justify a promotional campaign. The Odoo record should show the purpose and basis selected under the organization’s approved policy.

Separating service communication from marketing communication reduces confusion. An account holder may need a password-reset email or delivery update even after opting out of newsletters. At the same time, an unsubscribe from a promotional email should not be quietly ignored because the contact has an active opportunity. Design clear categories of communication and use the correct one each time.

Define Lawful Basis, Purpose And Channel Rules

Start with a register of the communications the business sends. For each one, define the purpose, audience, channel, proposed lawful basis, evidence needed, owner and retention rule. This becomes the operating design that Odoo forms, contact fields, marketing lists and integrations must follow.

Communication TypeTypical PurposeData Needed In OdooControl Owner
Transactional emailConfirm an order, delivery, payment or account actionRelated order or account, recipient and send recordOperations or customer service
Sales follow-upRespond to a request or manage a stated sales interestLead source, purpose, lawful-basis decision and contact channelSales leadership
Marketing emailSend campaigns, newsletters or event promotionMarketing preference, timestamp, source and unsubscribe statusMarketing owner
SMS or messagingSend approved alerts or promotions through a mobile channelVerified number, channel preference and suppression checkMarketing and compliance owner
Service communicationResolve support requests or notify customers about service activityTicket, contact preference and service recordHelpdesk owner

Do not assume a channel preference applies to every purpose. A person who agrees to product newsletters by email may not agree to SMS promotions. A company contact may be able to receive account messages while declining product announcements. Store preferences at a level that lets the business apply this distinction consistently.

Define the organization’s source-of-truth rule. In many cases, the contact or partner record is the central customer profile while marketing applications consume approved preference fields. If a consent portal or external preference center is authoritative, its updates need a reliable path back to Odoo. A duplicate field on a campaign record is not a durable substitute for the master profile.

Capture Consent And Preference Evidence At The Source

Evidence should be captured at the moment a choice is made. At a minimum, keep the identity of the contact, the date and time, capture source, wording or policy version, channels selected, purpose and the event that recorded it. Where appropriate, retain form identifiers, IP-related information or a confirmation event according to approved policy and legal guidance. Collect only what is necessary and protect it appropriately.

A website form can pass consent selections into the Odoo CRM lead and linked contact. An event registration can record the event, form version and communications requested. A salesperson entering a trade-show lead should not mark a person as opted in merely because a business card was collected. Give the salesperson a way to record the source and follow the approved follow-up process instead.

When importing contacts, treat the list as evidence to be assessed rather than a marketing audience to be uploaded. Confirm the source, date, collection notice, permitted channels and proof of opt-in or other approved basis before activation. If the evidence is incomplete, quarantine the record from promotional workflows until the organization decides the correct treatment. A clean import is not one with the most records. It is one whose permitted use is understood.

Capture SourceRequired EvidenceOdoo WorkflowCommon Risk
Website formChoice, form version, timestamp, purpose and channelMap form fields to the lead or contact recordPreselected boxes or unclear wording
Sales inquirySource, requested topic and permitted follow-up basisCreate lead with source and status for follow-upTreating a badge scan as broad consent
Customer portalUpdated choice, account identity and effective dateUpdate master contact preferences and retain change historyLetting users change one channel but not others
Imported listSupplier details, collection method, date and permitted useValidate then import to controlled audienceLoading unknown lists into campaigns
Support interactionRequest, identity validation and scope of preference changeUpdate preference after documented requestConfusing service contact with marketing permission

Apply Preferences And Suppression Across Odoo Workflows

Capture has little value if a campaign, automation or integration can ignore the result. Preference fields must be applied before recipients are selected. This requires clear audience logic: marketing workflows include only contacts that meet the permitted purpose and channel conditions while suppressions take priority over general audience rules.

Suppression is an instruction not to send a defined type of communication. It may result from an unsubscribe, objection, do-not-contact request, invalid address, complaint or internal risk decision. Keep the reason and effective date. Do not delete the contact automatically if there is an ongoing contract, accounting record or support history that must be retained. Instead, limit communication and processing in line with the approved policy.

An unsubscribe link should update the appropriate marketing preference promptly. A request received by phone, email or support ticket needs a controlled internal route so the preference is updated without relying on a staff member’s personal notes. Make it easy for frontline teams to recognize such requests, verify the contact identity where appropriate and record the change.

The end-to-end flow should be visible to every owner:

  1. A lead, customer or subscriber provides data through an approved source.
  2. Odoo records the purpose, lawful-basis outcome, channel preferences and evidence reference.
  3. Campaign or automation audience rules evaluate the contact before a message is queued.
  4. Suppression and unsubscribe records exclude restricted recipients before sending.
  5. Delivery, bounce, complaint and preference-change events update the profile or exception queue.
  6. Owners review exceptions, reconcile integrations and retain evidence for the approved period.

Govern Integrations, Duplicates And Data Changes

Consent data is especially vulnerable when external tools are involved. A marketing platform, web form, event tool, call system, customer portal or data-enrichment provider may each create or update contacts. Without mapping and ownership, one system may re-enable a preference that another system correctly suppressed.

For each integration, document which system creates the contact, which system owns each preference field, which values may flow in each direction and how conflicts are resolved. Use stable identifiers so that an unsubscribe applies to the same person across systems. Email address alone may not be enough when a customer changes addresses, shares an inbox or has duplicate records.

Deduplication is a consent control as well as a CRM hygiene task. If the same person appears twice, one record can be opted out while the other is still marketed to. Define matching rules, a merge process and a decision about which evidence survives the merge. Do not merge merely because names look similar. A mistaken merge can attach one person’s preferences to another person’s account.

Integration ControlDesign DecisionEvidence Or Monitoring
Field ownershipName the authoritative system for each preference and suppression fieldIntegration specification and data-owner approval
Event handlingDefine how unsubscribe, bounce, complaint and portal events reach OdooEvent logs and failed-message queue
Conflict resolutionDecide what happens when systems hold different preference valuesConservative rule and exception record
Duplicate managementMatch safely and preserve the strongest restriction when reviewing duplicatesMerge approval and retained history
Access controlLimit who can export, override or change preferencesRole review and audit log

Use the most protective approved state when a conflict cannot be resolved automatically. For example, do not restore marketing eligibility merely because an imported file shows a blank preference while the master record is suppressed. Send uncertain cases to a review queue. The cost of delaying a campaign message is normally lower than the cost of ignoring a valid objection.

Set Retention, Access And Ownership Rules

An opt-out record may need to be retained in a restricted form so the business does not accidentally re-contact the person. The precise approach depends on local law and legal advice. Privacy teams should define whether identifiers are minimized, hashed or retained with limited access. Do not promise deletion in a customer notice if operational systems cannot perform it consistently.

Access should follow the principle of least privilege. Sales users may need to view current communication status but should not override a suppression without approved authority. Marketers may build audiences but should not export unrestricted customer data. Administrators and integration accounts need audited permissions because their actions can affect thousands of records at once.

Ownership closes the control loop. Assign a business owner for the consent policy, a data owner for the customer profile, an application owner for Odoo configuration and an integration owner for connected tools. Give them a review cadence and escalation path. The CFO, sales leader and customer-service leader should understand the impact of poor controls even when they do not administer the fields themselves.

Useful KPIs include the percentage of active marketing contacts with complete evidence, opt-out processing time, suppression failures, duplicate contacts with conflicting preferences, campaign exclusions by reason, integration exceptions and overdue retention actions. These measures reveal whether the design is working in daily operations rather than only on a policy document.

Conclusion

Customer consent and communication preferences work when they are treated as a cross-functional business process, not as a marketing setting. Start by distinguishing the purpose of each communication and recording the approved lawful-basis outcome. Capture clear evidence at the source, apply preferences before messages are sent and make suppression stronger than broad audience rules.

Then protect the process through integration ownership, duplicate controls, retention rules and restricted access. Odoo can connect CRM, sales, service and marketing records, but it cannot make legal judgements for the organization. Build the workflow with local legal review and revisit it whenever communication channels, regions or data sources change.

Frequently Asked Questions

1. Is Consent The Only Lawful Basis For Customer Communication?

No. The appropriate basis depends on the communication, relationship and applicable law. Operational messages connected to an order may be handled differently from promotional messages. Your privacy or legal adviser should approve the organization’s basis and documentation rules.

2. Should An Unsubscribe Stop All Emails From Odoo?

Usually, marketing opt-out and operational service messages need separate treatment. An unsubscribe should reliably stop the communication type it covers. Do not use that distinction to send disguised promotions as service notices.

3. What Evidence Should Odoo Keep For Marketing Consent?

Keep the contact identity, timestamp, source, purpose, channels selected and the wording or policy version that was presented. Add other evidence only when required by your approved process and local legal advice.

4. Can We Import A Purchased Or Event Contact List Into Odoo Marketing?

Only after the organization verifies the permitted use, channel rights, collection date and evidence under its policy. Unknown or incomplete lists should be restricted from promotional activity until reviewed.

5. How Do We Handle A Consent Request Received By Phone?

Use a documented workflow for verifying the requester when appropriate, recording the request and updating the correct preference or suppression field promptly. Retain the ticket, call note or other approved evidence of the change.

6. What Happens If Two Integrated Systems Have Different Preference Values?

Define one authoritative source for each field and use a conservative rule when a conflict remains. In practice, this often means retaining the stronger restriction until the issue has been reviewed rather than automatically restoring eligibility.

7. Does This Guide Replace Legal Advice?

No. It provides an operational framework for using Odoo customer data responsibly. Privacy, marketing and retention requirements vary by jurisdiction and situation, so obtain local legal review before finalizing policies, notices, workflows or configurations.

Customer Consent And Communication Preferences In Odoo
Vishesh Joshi Business Systems Strategist

About the Author

Helps organizations scale operations, improve visibility, and drive growth through process transformation, ERP strategy, and digital execution. Writes about business systems, operational excellence, and technology-led growth.
Book a Consultation

Share this post