Data privacy compliance, audit-ready inside Odoo
Handle subject access and erasure requests on deadline, prove consent, maintain your Article 30 register, run DPIAs, and manage breaches — all from one unified GDPR suite built for Odoo 19.
The problem
Personal data is scattered across contacts, orders, invoices and messages with no way to find it, no deadline tracking for the one-month statutory response window, and no defensible proof of consent or erasure. Compliance teams fall back on spreadsheets, ad-hoc SQL exports and expensive consultants — and still cannot show a regulator what was done, by whom, and when.
The solution
A single, audit-ready suite inside Odoo: cross-model discovery finds every record for a subject, a deadline engine tracks every statutory clock, consent is captured with immutable proof, and an Article 30 register, DPIA screening, breach management and retention automation round out the full compliance lifecycle — all logged to a tamper-proof audit trail.
Everything a DPO needs, in one suite
Every capability below is implemented in the module.
Cross-Model Data Discovery
Scan across models for a single data subject and get a per-category record count before drafting any response, instead of hunting through Odoo by hand.
Statutory Deadline Engine
Every subject request tracks its one-month statutory deadline with overdue and at-risk list decorations, a kanban countdown progress bar, and a formal extension wizard.
Safe Erasure with Preview
The erasure wizard previews exactly which records and fields will be anonymized or deleted per data source before you confirm — no silent, partial deletions.
Consent Registry & Proof
Capture versioned consent text, channel, IP address, user agent and timestamp for every grant, with a full withdrawal history and reusable consent templates.
Article 30 Processing Register
Maintain a Register of Processing Activities with a DPIA activation gate, so high-risk processing cannot go live without an assessment on file.
Data Protection Impact Assessments
Run WP248-style DPIA screening with a risk heatmap, decorated by risk level, directly linked to the processing activity it assesses.
Breach Register & 72-Hour Clock
Log breaches and track the Article 33 72-hour notification deadline with a kanban countdown and overdue/closed list decorations.
Retention Automation
Configure archive, anonymize or delete retention rules per data source with safe-by-default guards, and review every automated action in the retention log.
Immutable Audit Trail
Every privacy action — requests, consent changes, erasures, retention runs — is written to an audit log that cannot be edited or deleted, ready for a regulator.
How it works
Intake
A subject request arrives via the website intake form, the customer portal, or is logged manually by staff.
Discovery
A cross-model scan locates every record tied to the subject and returns per-category counts before any action is taken.
Review & Respond
Staff review the discovery results, extend the deadline if needed, and progress the request through its guided stages.
Erasure & Audit
Approved erasure runs through the preview wizard, and every step — from intake to closure — is written to the immutable audit trail.
Frequently asked
No sales fog. If your question isn't here, email us and we'll answer it the same way.
Access, rectification, erasure, restriction, portability and objection — the full set of rights under GDPR Articles 15-21, each tracked through the DSAR request workflow with its statutory deadline.
Buy it on the Odoo App Store
Purchase, download and install directly from the official Odoo Apps Store — you'll always get the latest supported build.
Data Privacy & GDPR Compliance Suite
Cross-model data discovery, statutory deadline tracking, previewed erasure, consent proof, the Article 30 register, DPIAs and a 72-hour breach clock — all backed by an immutable audit trail.
Buy on Odoo App Store