Zammad's means run higher on ticketing core (6.0 to 1.0), omnichannel (6.8 to 0.3), knowledge and self-service (4.2 to 0.2), integrations (4.0 to 0.0), sovereignty (6.3 to 3.5) and pricing transparency (6.8 to 0.0); OTRS publishes no prices, and pricing was not weighted against it. The split: customer data protection (3.8 to 2.8), one judge leaning OTRS, five lean Zammad. OTRS's case there is legal posture — German contracting entity, named external data protection officer, stated retention periods — scored 2–4 on the credit those practices earn; Zammad's captures show no tenant DPA, retention period or audit log evidenced. OTRS's other scores rest on legal pages where we found no public information on queues, routing, SLAs, APIs or connectors. Weighted totals per judge run Zammad 5.3–5.6 against OTRS 0.5–2.2. Zammad's gaps: only GitHub/GitLab and Grafana/Elasticsearch named as integrations; telephony appears in no tier's channel list and carries no price.
Choose OTRS if
Your contract must sit with a German-registered vendor — OTRS's legal entity jurisdiction is DE, and the imprint names OTRS GmbH, Oberursel (Amtsgericht Frankfurt am Main HRB 143059, VAT DE453344897).
You need a named external data protection officer documented before signature — OTRS's privacy-policy captures show one.
Your compliance gate is stated retention periods in a published privacy policy — OTRS's captures state them.
Your reviewers credit data-protection practices evidenced on the vendor's own site — on customer data protection, where OTRS scores spread 2–4, one judge leaned OTRS.
Choose Zammad if
You need core ticketing evidenced — states, assignment, escalations, SLAs, macros, templates and automation rules are named in Zammad's captures; ticketing core means 6.0 to 1.0, with 6 judges leaning Zammad.
Your customers reach you on many channels — email, web form, SMS, chat, Telegram, Facebook and WhatsApp are priced per tier into a unified ticket view (omnichannel 6.8 to 0.3).
You must budget before pilot — Zammad publishes €7/€16/€25 per agent per month plus a metered €0.03 per AI call, with VAT treatment stated (pricing transparency 6.8).
Your residency requirement is EU-only — Zammad's data residency attribute reads EU only and its subprocessor exposure reads none.
You want the self-hosted option — Zammad is offered cloud or self-hosted, and its sovereignty scores of 6–7 credit that option (sovereignty means 6.3 to 3.5).
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Shop Operator
Handles "where is my parcel" at volume and needs the order in front of the agent without a second login. Judges omnichannel by whether WhatsApp and the shop actually land in one queue, and deflection by whether the ticket count falls in December.
OTRS
Zammad
This judge's pick
Criterion by criterion
Ticketing, queues & SLA
OTRS
Nothing in the captured pages evidences a queue, a status model, an SLA timer, routing rules or ticket search — I cannot even confirm a ticket exists in this product from this sheet. For a shop at ten-thousand-ticket volume, an engine the evidence is silent on is an engine I must treat as absent.
Zammad
States, assignment, escalations, SLAs, macros, automation rules and reporting are all named, which is a genuine engine above the routing-and-status floor. But the evidence is silent on search entirely — I need to find one parcel ticket in ten thousand — and business-hours SLA policies, escalation chains, merge/split and per-agent response reporting are nowhere evidenced.
Channels in one queue
OTRS
No email, chat, phone, portal, WhatsApp or social channel lands anywhere in this evidence; the only channel-adjacent fact is a video-conference tool OTRS itself uses, hosted with a US processor. One queue with one history, an order surface inside the ticket, a customer moving mid-issue — none of it is evidenced.
Zammad
Chat, Telegram, Facebook and WhatsApp land as channels alongside email and web form, with a unified ticket view claimed — WhatsApp and the shop form in one queue is evidenced, not marketing. Docked below 8 because telephony is only a bare 'integration' with no call logging, messenger consent handling is unstated, and no requester-facing portal with own tickets appears anywhere.
Knowledge base & deflection
OTRS
The lone FAQ mention is about viewing FAQs on OTRS's own website during free-trial registration, not a public help centre with workflow or deflection reporting in the product. No article states, no suggestions, no deflection number my December ticket count would respond to — silence is the information here.
Zammad
A help centre explicitly positioned at 'without opening a ticket' plus a multilingual KB in the Plus tier shows deflection intent, above a bare article list. But no editorial workflow, no article suggestions to agent or customer, no review dates, and no deflection reporting — I couldn't tell you whether December's ticket count fell.
Customer data protection
OTRS
Retention is stated per category (6 months application data, 5 years business cards, 10 years email archive), a DPO is named and a Trust Center exists, which already beats the anchor-3 state of 'no stated retention period'. But this is the vendor's handling of its own website visitors, not the product's ticket archive: no agent roles, no queue visibility, no audit of who opened which ticket, no executable requester deletion is evidenced — so it cannot reach 5.
Zammad
Individual roles and permissions, 2FA and an ISO27001 data centre give real access control, but no published DPA, no ticket retention period, no audit log and no product-level deletion path are evidenced — the GDPR-rights facts describe Zammad's own website inquiries, not the customer archive. Deletion is left entirely to the customer to arrange.
Integrations & API
OTRS
No API, no webhooks, no rate limits, no named CRM, shop or identity integration appears anywhere in the three homepage captures or the legal pages. The order in front of the agent without a second login has zero support in this registry — hand-copied context is the anchor-0 state.
Zammad
'Open APIs and ready-to-use integrations' plus GitHub/GitLab and Grafana/Elasticsearch is a handful of named hooks, but nothing a shop runs on. No CRM, shop or order-management connector, no webhooks, no SSO, and nothing evidenced that puts the customer's order in front of the agent without a second login — my core requirement.
European sovereignty
OTRS
But where the ticket archive is hosted is unstated, the product's subprocessor list is absent, and the vendor's own web chain runs Google, LinkedIn, Vimeo and 6sense with US transfers papered over by SCCs — that is the anchor-3 'subprocessor list absent' arm, not 5.
Zammad
German GmbH with a commercial register number, made and hosted in Germany, ISO27001-certified data centre, and open source with a self-host option — I can keep the archive on my own infrastructure. It stops short of the higher anchor because the data-centre provider is unnamed and no subprocessor list for the hosted product is published (the named Matomo/Moosend are the vendor's website tools).
Pricing transparency
OTRS
Three homepage captures plus the legal and privacy pages and there is no per-agent price, no tier, no billing period, no VAT treatment — every tier is a sales conversation, which is rubric level 0 verbatim. A support lead could not compute one line of the annual invoice from these pages.
Zammad
Per-agent prices for all three tiers with agent caps, storage limits, VAT treatment and even usage-metered AI at €0.03 per call are public, and WhatsApp clearly starts at Plus — I can nearly compute my invoice. Docked for no stated minimum term and for telephony, which is advertised as a channel but appears in no plan's channel list and carries no price.
Sovereignty, side by side
Dimension
OTRS
Zammad
Legal entity
Incorporated in DE
Incorporated in DE
Ownership
Not determined
Not determined
Data residency
Not determined
EU only
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.