Zammad's means run higher on ticketing core (6.0 to 1.0), omnichannel (6.8 to 0.3), knowledge and self-service (4.2 to 0.2), integrations (4.0 to 0.0), sovereignty (6.3 to 3.5) and pricing transparency (6.8 to 0.0); OTRS publishes no prices, and pricing was not weighted against it. The split: customer data protection (3.8 to 2.8), one judge leaning OTRS, five lean Zammad. OTRS's case there is legal posture — German contracting entity, named external data protection officer, stated retention periods — scored 2–4 on the credit those practices earn; Zammad's captures show no tenant DPA, retention period or audit log evidenced. OTRS's other scores rest on legal pages where we found no public information on queues, routing, SLAs, APIs or connectors. Weighted totals per judge run Zammad 5.3–5.6 against OTRS 0.5–2.2. Zammad's gaps: only GitHub/GitLab and Grafana/Elasticsearch named as integrations; telephony appears in no tier's channel list and carries no price.
Choose OTRS if
Your contract must sit with a German-registered vendor — OTRS's legal entity jurisdiction is DE, and the imprint names OTRS GmbH, Oberursel (Amtsgericht Frankfurt am Main HRB 143059, VAT DE453344897).
You need a named external data protection officer documented before signature — OTRS's privacy-policy captures show one.
Your compliance gate is stated retention periods in a published privacy policy — OTRS's captures state them.
Your reviewers credit data-protection practices evidenced on the vendor's own site — on customer data protection, where OTRS scores spread 2–4, one judge leaned OTRS.
Choose Zammad if
You need core ticketing evidenced — states, assignment, escalations, SLAs, macros, templates and automation rules are named in Zammad's captures; ticketing core means 6.0 to 1.0, with 6 judges leaning Zammad.
Your customers reach you on many channels — email, web form, SMS, chat, Telegram, Facebook and WhatsApp are priced per tier into a unified ticket view (omnichannel 6.8 to 0.3).
You must budget before pilot — Zammad publishes €7/€16/€25 per agent per month plus a metered €0.03 per AI call, with VAT treatment stated (pricing transparency 6.8).
Your residency requirement is EU-only — Zammad's data residency attribute reads EU only and its subprocessor exposure reads none.
You want the self-hosted option — Zammad is offered cloud or self-hosted, and its sovereignty scores of 6–7 credit that option (sovereignty means 6.3 to 3.5).
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Integrator
Has to wire the helpdesk into a CRM, a shop and an identity provider that all predate it. Wants a documented API with rate limits, webhooks that retry, SCIM, and a sandbox. Reads a partner-contact form on an integrations page as a missing API.
OTRS
Zammad
This judge's pick
Criterion by criterion
Ticketing, queues & SLA
OTRS
The category label says Customer Service & Helpdesk, so a ticket engine presumably exists, but three homepage captures never mention a queue, a routing rule, an SLA timer or search — not one engine feature is evidenced, so I can't go past 'the engine exists'.
Zammad
States, assignment, escalations, macros, automation rules and SLAs are all named, which is the substance of rubric level 5 — but nothing evidences search across ticket bodies, priorities, business-hours SLA policies, merge/split, or what the 'Reporting' actually measures. In a ten-thousand-ticket queue I need to know an agent can find the ticket, and the evidence is silent on that.
Channels in one queue
OTRS
Not one channel fact in the evidence — even email-to-ticket is unconfirmed, and the only channel-adjacent quotes (web forms, video conferencing via a US provider) describe OTRS's own website, not the product's queue.
Zammad
Email, web form, chat, Telegram, Facebook, WhatsApp and telephony are all named, and 'all communication... in one structured ticket view' supports one history — but messenger consent handling is never stated, and there is no evidence of a portal where a requester sees their own tickets, only a help centre. That keeps it under the anchor-8 bar.
Knowledge base & deflection
OTRS
The single KB-shaped fact is that OTRS's own website has FAQs you can view after registering; nothing on article workflow, agent suggestions, review dates or deflection reporting for the product, so knowledge as a managed asset is entirely unevidenced.
Zammad
A public help centre with an explicit deflection claim and a multilingual knowledge base (Plus tier) clears rubric level 5. Nothing evidences editorial workflow, versioning, inserting articles into replies, suggestions to agents or customers, review dates, or deflection reporting — so I cannot credit the 8-anchor features beyond multilinguality.
Customer data protection
OTRS
There is a published privacy statement, a named external DPO and stated retention periods — but every one of them governs OTRS's own marketing and website data, not the ticket archive; the product gets no evidenced retention rules, agent roles, audit log or executable deletion path for a requester.
Zammad
The privacy policy lists full GDPR rights including deletion and granular roles are a feature, but that policy governs Zammad's own website — the evidence evidences no tenant DPA, no stated retention period for ticket archives, no audit log of ticket access, and no attachment handling. Roles plus documented rights sit just above the anchor-3 floor; nothing here executes.
Integrations & API
OTRS
No API, no webhooks, no SCIM, no sandbox, no rate limits, and not one named CRM, shop or identity connector on any captured page — there isn't even an integrations page to read a partner form off. In the world this sheet gives me, context is copied in by hand and I can wire nothing.
Zammad
'Open APIs and ready-to-use integrations' is a homepage bullet with no docs, and the named integrations are GitHub/GitLab and Grafana/Elasticsearch — developer tools, not one CRM, shop or identity system. My whole checklist — documented rate limits, webhooks that retry, SCIM, a sandbox, SSO — appears nowhere, which is the read-mostly rubric level 3 plus a sync claim I can't verify.
European sovereignty
OTRS
The contracting entity is solidly German — OTRS GmbH, Oberursel, HRB 143059 at Amtsgericht Frankfurt — which is real, but product hosting is unstated and the archive's own subprocessor chain is absent; the privacy policy itself concedes processors outside the EU and forum hosting partly outside the EU, and the named web-stack subprocessors include Google Inc., LinkedIn Corp and Vimeo in the US.
Zammad
Zammad GmbH in Berlin is the contracting entity, hosting is 'Made & hosted in Germany' in an ISO27001-certified German data centre, and a self-hosted option exists — rubric level 5 met, with self-hosting pulling above it. But the data-centre provider is unnamed, the pipeline itself marks residency and subprocessor exposure unknown, and the only listed subprocessors (Matomo, Moosend) are website tools, not the product chain.
Pricing transparency
OTRS
Three homepage captures plus the legal and privacy pages contain no price, no tier, no per-agent number, no billing period — the annual invoice is uncomputable from public pages alone.
Zammad
Three tiers with per-agent prices, explicit channel lists, agent caps, storage limits, VAT treatment and even a metered AI price of €0.03/call are public — most of an annual invoice is computable. But telephony is a channel on the product page that appears in no tier's channel list and carries no number, and no minimum term is stated.
Sovereignty, side by side
Dimension
OTRS
Zammad
Legal entity
Incorporated in DE
Incorporated in DE
Ownership
Not determined
Not determined
Data residency
Not determined
EU only
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.