Overview
Contacts Privacy and Export Control limits contact phone and email visibility and export access in Odoo 19 for users without Contact Admin rights.
Supports v 19.0 — available directly on the Odoo Apps Store.
Description
Contacts Privacy and Export Control addresses a common data-security gap in Odoo 19: by default, every user can view the phone numbers and email addresses stored on any contact record, regardless of who created that contact. This module changes that behavior by introducing a Contact Admin role that governs who can see contact details, open contact records created by others, and export contact data. It is intended for businesses that want to prevent sales representatives, support staff, or other employees from freely viewing or exporting contact information that was not created by them.
Key Features
- Access to phone and email fields is restricted to users with Contact Admin permission across list, kanban, and form views in Odoo 19.
- Users without Contact Admin access cannot see the phone or email of contacts that were created by other users.
- Users can always view the phone and email of contacts they created themselves, regardless of their permission level.
- When a user without Contact Admin access clicks on a contact created by someone else, the contact form does not open.
- Export of contact data is limited to users who hold Contact Admin permission; other users cannot export the contacts list.
How It Works
Contacts Privacy and Export Control works through a dedicated Contact Admin security group that is assigned directly on the Odoo 19 user form. Once a user is added to this group, they gain full visibility into the phone and email fields of all contacts in the system, along with the ability to open contact records created by other users and export contact data. Users who are not part of the Contact Admin group retain visibility only over contacts they personally created. For every other contact record, their phone number and email fields are hidden, and attempting to open the record from a list or kanban view is blocked. This access logic applies consistently across list, kanban, and form views, and the module is described as working on both Odoo.sh and On-Premise deployments.
Business Use Cases
This module is relevant for Odoo 19 environments where multiple sales representatives, account managers, or employees manage their own set of contacts but should not be able to browse or export the contact details entered by their colleagues. In such setups, granting Contact Admin permission only to administrators or designated managers ensures that sensitive customer information — phone numbers, email addresses, and the underlying business relationships — is not casually exposed to the entire user base.
A typical scenario involves a sales team where each representative manages their own leads and customers. With Contacts Privacy and Export Control in place, each rep can continue to see and work with the phone numbers and emails of the contacts they personally created, but they cannot open or export contact records that belong to other reps unless they are explicitly given Contact Admin access. This reduces the risk of a departing employee or an unauthorized user extracting the full customer and prospect database before the access restriction is applied.
Another use case applies to companies that need to comply with internal data-handling policies or client confidentiality agreements. By limiting export rights to Contact Admin users only, the module helps ensure that bulk extraction of contact phone numbers and emails is controlled and limited to a smaller group of trusted users, rather than being available to every Odoo 19 user by default.
Frequently Asked Questions
Does this module restrict all contact fields, or only phone and email?
Based on the supplied module information, the restriction applies specifically to phone numbers and email addresses, along with the ability to open certain contact records and export contact data.
Can a regular user still see contacts they created themselves?
Yes. Users can always view the phone and email details of contacts they personally created, even without Contact Admin permission.
How is Contact Admin access granted?
Contact Admin access is assigned by adding the Contact Admin group to a user's profile from the Odoo 19 user form.
What happens when a restricted user clicks on someone else's contact?
The contact form will not open for that user unless they have been granted Contact Admin access.
Does this module affect contact data export permissions?
Yes. Only users with Contact Admin permission can export contacts data in Odoo 19; other users are prevented from exporting the contacts list.