Security & Privacy

Odoo GDPR Hosting: The Complete Vetting Guide

J
James Eriksson
··13 min read
How to audit an Odoo hosting provider for GDPR compliance. 7-point checklist for DPA, data residency, certifications, and breach SLA. German companies: Schrems II explained.
TL;DR
  • Your hosting provider is liable for GDPR failures, not Odoo. Vet them before signing a contract.
  • Minimum requirements: signed DPA, ISO 27001 + SOC 2 Type II certifications, EU data center, subprocessor list, backup location proof, 24-hour breach notification SLA.
  • German companies must ensure no US data transfer without Standard Contractual Clauses (Schrems II). Managed hosting eliminates this complexity.

When you host Odoo in the cloud, GDPR compliance becomes a shared responsibility. You control what data Odoo collects. Your hosting provider controls where it lives, who can access it, and how long it stays there. Get this wrong and you face EUR 20 million in fines or 4% of global revenue--whichever is higher. This guide shows you how to audit a provider's compliance claims and verify they meet your requirements.

Why GDPR Compliance Starts with Your Host

GDPR fines for hosting failures come from three sources: data breach notification delays, missing data processing agreements, and subprocessors outside the EEA without proper safeguards. Your hosting provider's infrastructure determines whether you meet each requirement. Hosting infrastructure--data center location, backup systems, audit rights--is outside Odoo's control.

The EU fined Meta EUR 1.2 billion in 2022 for transferring EU user data to the US without adequate safeguards. Meta used the same tools as your Odoo instance: cloud storage, subprocessors for email and analytics, data transfers across borders. The only difference is the level of scrutiny--not the underlying legal requirement.

Your hosting provider is a "data processor" under GDPR Article 28. You are the "controller." That means you remain liable for the processor's failures. If your host loses customer data, you notify regulators. If your host denies a subject access request, you face the penalty. The German DPA (BfDI) has issued guidance stating controllers cannot escape liability by pointing to processor failures.

Most Odoo buyers skip host vetting because they assume Odoo handles it. It does not. Odoo itself is ISO 27001 certified and SOC 2 Type II audited. But Odoo's SaaS offering and its managed partners run on different infrastructure. Some companies self-host on their own servers, meaning GDPR compliance is 100% their responsibility. So the question is not "Is Odoo compliant?" but "Is your specific hosting setup compliant?"

Host vetting is the first step in any GDPR compliance plan for Odoo.

Odoo's Role vs. Your Host's Role in GDPR

Odoo handles user consent, data retention policies, and access controls within the application. Your host handles data center location, encryption at rest, backup retention, and breach response. Both are critical. A gap in either one means non-compliance.

Odoo is responsible for: consent workflows (e.g., checkbox for newsletter signup), data retention rules (e.g., delete customer records after 3 years), access controls (e.g., who can view customer email addresses), encryption in transit (HTTPS from browser to Odoo server), user rights (data export, deletion request processing), and audit logs (who accessed what, when).

Your hosting provider is responsible for: data center location and jurisdiction, encryption at rest (disk-level encryption), backup and disaster recovery, physical access controls, network segmentation and DDoS protection, breach detection and notification SLA, and subprocessor management (e.g., if they use AWS or Google Cloud underneath).

A common mistake is thinking "Odoo is compliant, so I'm fine." Wrong. Imagine Odoo's consent is perfect, but your host stores backups in the US without Standard Contractual Clauses. You are not compliant. Imagine your host is SOC 2 audited, but Odoo has no data retention policy. You are not compliant.

The data processing agreement (DPA) you sign with your host defines this split. A good DPA will: name the data categories (names, emails, phone numbers, transaction history, etc.), specify the host's sub-processors and their locations, commit to specific response times for data subject requests, detail backup retention periods and deletion procedures, grant you audit rights (annual or on-demand), and outline breach notification (how quickly, to whom). If your host's DPA is vague--"we comply with GDPR" without specifics--it is a red flag.

The 7-Point Host Vetting Checklist

Before signing a contract, verify data center location, request the DPA and security audit reports, check the subprocessor list, and confirm backup locations, breach SLA, and uptime guarantees.

1. Data Center Location and Residency Proof

Ask: Where is your primary data center? Are backups in the same location? The Schrems II ruling invalidated Privacy Shield, meaning US data transfer is no longer adequate by default. Many hosts claim "EU data residency" but store backups on AWS US-East-1. Data center location is the foundation of compliance.

Verification method: Request a screenshot or certificate showing the data center's IP geolocation and certifications. OVH (a major Odoo host) publishes data center maps; you can verify OVH Frankfurt is actually in Germany. If the host cannot produce proof, do not sign.

2. Data Processing Agreement (DPA) and Standard Contractual Clauses

Ask: Do you provide a signed DPA? Does it reference Standard Contractual Clauses (SCCs) for cross-border transfers? A DPA is required by GDPR Article 28. Without it, hosting is non-compliant by definition.

Verification method: Request the DPA draft before signing anything. Have a lawyer review it (1-2 hours). Check for: scope (which data categories), subprocessors (listed? can you object to new ones?), duration (what happens if contract ends?), liability, and audit rights. Odoo's standard DPA names 15+ subprocessors and grants audit rights to customers. It references Standard Contractual Clauses and Binding Corporate Rules for international transfers.

3. Subprocessor Disclosure and Audit Rights

Ask: Who are your subprocessors? Where are they located? Can we audit your subprocessor chain? Subprocessors are third parties your host relies on. If your host uses Stripe and Stripe stores data on AWS US, you have a compliance risk. GDPR Article 28 requires you to approve all subprocessors.

Verification method: Request a complete subprocessor list. Look for: cloud infrastructure providers (AWS, Google Cloud, Azure), email providers (SendGrid, AWS SES), backup/CDN providers, payment processors, and monitoring tools. Check each subprocessor's location and SLA. If a subprocessor is in the US, ask whether the host enforces SCCs or Binding Corporate Rules.

4. Security Certifications

Ask: Are you ISO 27001 certified? SOC 2 Type II? PCI-DSS if you handle payments? Certifications indicate third-party audit and compliance with specific standards. ISO 27001 covers information security management. SOC 2 Type II covers controls over 18-24 months (more credible than one-time attestations).

Verification method: Request the certificate or audit report. Verify expiration date (certs are valid 3 years; anything before 2023 is expired). Check the scope--does it cover "data center operations," "cloud hosting," and "GDPR data processing"? Odoo's Privacy Policy states Odoo is ISO 27001 certified (April 2026, full scope). OVH holds SOC 1 Type II and SOC 2 Type II. Outscale holds SecNumCloud 3.2 certification.

5. Backup Location and Redundancy

Ask: Where are backups stored? How long are they retained? Encrypted? How quickly can you restore? Backups are still personal data--they need the same protection as production. If backups are in the US, the same Schrems II risk applies. If backups exceed your data retention policy, you are breaking GDPR.

Verification method: Request the backup policy in writing. Ensure: location within your jurisdiction, retention matches your data retention policy, encryption is AES-256 or equivalent, restore time under 24 hours. Example: If your host keeps 30-day backups in the EU and a 1-year archive in the US, that violates data residency. Ask them to delete or move the US archive.

6. Breach Notification SLA

Ask: If there is a data breach, how quickly will you notify us? GDPR Article 33 requires you to notify regulators within 72 hours of discovering a breach. You cannot meet this if your host takes 2 weeks to tell you. An SLA of 24 hours or less is reasonable.

Verification method: Confirm the SLA in the DPA or service agreement. Also ask: how do you detect breaches? Who do you notify? What information will you provide (affected records, compromise level, remediation steps)?

7. Service Level Agreement (SLA) and Uptime Guarantees

Ask: What uptime SLA do you guarantee? What credits for downtime? If Odoo goes down for a day and you cannot meet customer deadlines, you may face compliance claims. Standard SLAs: 99.5% (4.4 hours downtime/month), 99.9% (43 minutes), 99.95% (21 minutes). For a 100-person company, 99.9% is reasonable. For a 10-person company, 99.5% is acceptable with a documented disaster recovery plan.

Red Flags When Evaluating a Provider

Walk away if a host refuses to sign a DPA, has no third-party audit reports, cannot name subprocessors, or claims GDPR compliance without specifics. Vague compliance language is a liability.

"We are GDPR compliant" (without specifics). Compliance is context-dependent. What matters: DPA? Audit reports? Data location? Push back on vague claims.

"We will comply after you ask." Some hosts say they will draw up a DPA later. Agree only with a firm 30-day deadline. Do not proceed before it is finalized.

"You have access to raw logs, go audit yourself." GDPR Article 28 obligates the host to provide audit reports, not raw data. If the host denies third-party audits, they are not taking their obligations seriously.

"Subprocessors? We do not really use any." Everyone uses cloud infrastructure, email providers, or monitoring tools. If a host claims zero, they are lying or too small to be reliable.

"Backups are encrypted, trust us." Encryption means nothing without key management. Who controls the keys? If the host does, they can decrypt backups without permission. Ask about key management explicitly.

"Our data center is in Germany, no proof." Data center claims are easy to make. Schrems II violations often start here. Require proof--a certificate, a website, an IP geolocation tool.

"Gold tier gets audit reports, basic tier does not." GDPR is not optional for premium customers. If a host refuses audit reports without upselling, that is a red flag.

"We cannot disclose subprocessors due to commercial confidentiality." Subprocessors are not a trade secret. If a host hides them, they are hiding a risk. This is a dealbreaker.

How to Audit a Host's Compliance Claims

Verification is a three-step process: request documentation, hire a lawyer to review it, and request a site visit or attestation if the host is new to you.

Step 1: Gather Documentation

Create a due-diligence checklist and request in writing: current DPA (signed version specific to your contract), ISO 27001 certificate (full text, not just logo), SOC 2 Type II audit report (most recent), PCI-DSS compliance if applicable, complete subprocessor list with locations, data center location proof, backup policy (location, retention, encryption, restore SLA), breach notification SLA, and service level agreement.

Ask for a 30-day response window. If they miss it, that is a compliance risk--they are not organized enough to manage GDPR.

Step 2: Legal Review

Have a German lawyer or data protection officer review the DPA. This costs EUR 500-2,000. In this review, check: Does the DPA cover all your data categories? Are subprocessors listed and detailed? What is the data deletion policy if the contract ends? What are your audit rights (annual? on-demand? with notice?)? What is the liability cap (capped at annual fees, or no cap for data breaches)? Are Standard Contractual Clauses included? Is there a breach indemnity clause?

Step 3: On-Demand Audits and Attestation

For a new host or large contract (EUR 50K+/year), request a recent on-site audit or third-party attestation. If the host refuses to share audit reports under NDA, do not sign. For managed Odoo hosting, ask whether the host offers an annual audit as part of the contract. Good hosts do this proactively.

German Data Residency and Schrems II

German GDPR enforcement (BfDI) requires data to remain in Germany or the EU with Standard Contractual Clauses. Schrems II ruling (2020) added scrutiny: US hosting requires supplementary safeguards beyond SCCs alone, which most providers cannot meet. German companies should default to EU-only data centers.

The Schrems II ruling invalidated Privacy Shield and raised the bar for SCCs. The CJEU ruled that SCCs alone are not sufficient for US transfers. The US government has broad surveillance powers under Section 702 of FISA, which can compel US companies to disclose EU personal data without your knowledge.

In 2021, Facebook and its Irish subsidiary were fined EUR 405 million for "essentially no protection" in US data transfers. For Odoo hosting, this means: if you store customer data in the US, US law enforcement can compel disclosure. If you store in Germany, German law is more restrictive--your host must resist improper demands.

For your Odoo instance, ask: Are production data centers in Germany or the EU? Do you use US subprocessors? If yes, under what framework (EU-US Data Privacy Framework)? Are backups also in the EU, or do you replicate to the US? Do you use US-based cloud infrastructure (AWS, Google Cloud) for German production data?

If a host cannot answer these clearly, they are not thinking about Schrems II compliance. Walk away. Managed Odoo hosting providers (like Opsily or OBS Solutions) solve this by running dedicated German data centers and keeping the entire stack within the EU.

Frequently Asked Questions

What is the GDPR compliance checklist?

The core GDPR checklist: (1) Legal basis for processing (consent, contract, or legitimate interest); (2) Data inventory (what data, where); (3) Privacy policy (visible to data subjects); (4) Consent mechanism (e.g., checkbox for marketing); (5) Data subject rights fulfillment (access, deletion, portability); (6) Breach notification procedure (within 72 hours); (7) Vendor contracts (DPAs with all subprocessors); (8) Retention policy (how long you keep data); (9) Cross-border transfer safeguards (SCCs if non-EU); (10) Data protection impact assessment (for high-risk processing). For Odoo hosting specifically, add: host vetting (follow the 7-point checklist above), backup verification (location, retention, encryption), audit rights documentation, and subprocessor monitoring.

What are the 7 GDPR principles?

GDPR principles are: (1) Lawfulness, fairness, transparency; (2) Purpose limitation (data used only for stated purpose); (3) Data minimization (collect only what you need); (4) Accuracy (keep it current); (5) Storage limitation (delete it when done); (6) Integrity and confidentiality (encrypt and protect); (7) Accountability (document everything). For Odoo: lawfulness means you have a legal reason to process customer emails. Purpose limitation means you cannot sell customer data to marketers. Data minimization means you do not store phone numbers if you only need emails. Storage limitation means you delete records after a contract ends. Integrity means you encrypt customer data. Accountability means you have a DPA with your host and audit logs.

What is Odoo's privacy policy?

Odoo's privacy policy covers: data Odoo collects (account info, usage data, support requests), purpose (service delivery, security, analytics), retention (varies by data type; account data deleted when requested), subprocessors (15+ listed, including cloud providers), certifications (ISO 27001, SOC 1 Type II, SOC 2 Type II, PCI-DSS), data centers (OVH France/Germany, Google Cloud EMEA, Outscale France), DPA availability (yes, available on request), and breach notification (within 72 hours per GDPR Article 33). However, Odoo's privacy policy covers Odoo's own systems, not your hosting environment. That is your hosting provider's responsibility. Read both policies carefully.

Does the USA have an equivalent to GDPR?

No. The US has sector-specific privacy laws (HIPAA for health, CCPA for California, GLBA for finance) but no comprehensive privacy law. This is why Schrems II matters: US data transfers are riskier because US companies have fewer legal constraints on sharing with law enforcement. For Odoo hosting: if you store data in the US, US law enforcement can compel disclosure. If you store in Germany, German law is more restrictive--your host must resist improper demands.

What certifications should an Odoo host have?

Minimum: ISO 27001 (information security management), SOC 2 Type II (controls over 18+ months). For German companies, SecNumCloud or BSI C5 is a plus (more stringent than ISO 27001). Nice-to-have: PCI-DSS if the host handles payments, ISO 27017 and ISO 27018 (cloud-specific). Red flag: a host with no certifications or only one old cert from 2020. Certifications are 3-year cycles; if older, the host has not been re-audited.

The Bottom Line

GDPR compliance for Odoo is not about Odoo--it is about where your data lives and who can access it. Your hosting provider is the critical decision. Invest time in vetting: request the DPA, verify certifications, check data center location, confirm subprocessors, review backup retention. A 4-hour legal review costs EUR 500-2,000 and saves you EUR 20 million in fines.

For a small German company, managed hosting pre-solves this entire problem. Opsily's managed Odoo hosting includes a signed DPA, verified certifications, German data centers, and EU-only subprocessors. Start here: explore /hosting/odoo/odoo-hosting-germany.

Cut GDPR Vetting Time in Half
Opsily's managed Odoo hosting comes pre-certified with signed DPA, German data centers, and audit reports included.
Get Started Free

Ready to self-host your own apps?

One server. Multiple apps. No per-app fees.

Get started →