Zammad's means run higher on ticketing core (6.0 to 1.0), omnichannel (6.8 to 0.3), knowledge and self-service (4.2 to 0.2), integrations (4.0 to 0.0), sovereignty (6.3 to 3.5) and pricing transparency (6.8 to 0.0); OTRS publishes no prices, and pricing was not weighted against it. The split: customer data protection (3.8 to 2.8), one judge leaning OTRS, five lean Zammad. OTRS's case there is legal posture — German contracting entity, named external data protection officer, stated retention periods — scored 2–4 on the credit those practices earn; Zammad's captures show no tenant DPA, retention period or audit log evidenced. OTRS's other scores rest on legal pages where we found no public information on queues, routing, SLAs, APIs or connectors. Weighted totals per judge run Zammad 5.3–5.6 against OTRS 0.5–2.2. Zammad's gaps: only GitHub/GitLab and Grafana/Elasticsearch named as integrations; telephony appears in no tier's channel list and carries no price.
Choose OTRS if
Your contract must sit with a German-registered vendor — OTRS's legal entity jurisdiction is DE, and the imprint names OTRS GmbH, Oberursel (Amtsgericht Frankfurt am Main HRB 143059, VAT DE453344897).
You need a named external data protection officer documented before signature — OTRS's privacy-policy captures show one.
Your compliance gate is stated retention periods in a published privacy policy — OTRS's captures state them.
Your reviewers credit data-protection practices evidenced on the vendor's own site — on customer data protection, where OTRS scores spread 2–4, one judge leaned OTRS.
Choose Zammad if
You need core ticketing evidenced — states, assignment, escalations, SLAs, macros, templates and automation rules are named in Zammad's captures; ticketing core means 6.0 to 1.0, with 6 judges leaning Zammad.
Your customers reach you on many channels — email, web form, SMS, chat, Telegram, Facebook and WhatsApp are priced per tier into a unified ticket view (omnichannel 6.8 to 0.3).
You must budget before pilot — Zammad publishes €7/€16/€25 per agent per month plus a metered €0.03 per AI call, with VAT treatment stated (pricing transparency 6.8).
Your residency requirement is EU-only — Zammad's data residency attribute reads EU only and its subprocessor exposure reads none.
You want the self-hosted option — Zammad is offered cloud or self-hosted, and its sovereignty scores of 6–7 credit that option (sovereignty means 6.3 to 3.5).
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Skeptic
Counts the channel logos on the marketing page, then asks which of them share one queue and one history. Reads for the tier where SLA policies begin, what a "light agent" may actually do, and whether the AI summariser is included or metered.
OTRS
Zammad
This judge's pick
Criterion by criterion
Ticketing, queues & SLA
OTRS
Three captures of the homepage produced no queues, no SLA timers, no routing, no search — the entire registry is legal notices and the vendor's own privacy policy, so the engine is unevidenced end to end. rubric level 0 is where absence of any ownership/status/history model sits, and I can't even confirm a shared mailbox.
Zammad
States, assignment, escalations, SLAs, macros, templates and automation rules are all named, and I can read exactly which tier SLAs start at — Professional v2. But nothing evidences business-hours-aware SLA policies, merge/split, first-response reporting by agent and queue, or full-text search across ticket bodies — the bullets are marketing nouns, so I stop just past the anchor-5 line.
Channels in one queue
OTRS
No channel facts at all — the only 'channels' in the evidence are the vendor's own ad pixels and embeds (Google, LinkedIn, X, YouTube), which are marketing plumbing, not support channels landing in one queue. There isn't even a logo count to be skeptical about.
Zammad
Seven channels are named per tier — Email, Web Form, SMS, Chat, Telegram, Facebook, WhatsApp — plus 'Telephony integration', and the 'unified structured ticket view with history' claims one history. My follow-ups go unanswered: no evidence of call logging behind the telephony bullet, no consent handling stated for WhatsApp, and no requester portal where a customer sees their own tickets — the help centre is a knowledge base, not a ticket portal.
Knowledge base & deflection
OTRS
The single FAQ mention is OTRS's own website FAQ named in the privacy policy as a reason for collecting trial registrations — that is the vendor's help centre, not a product capability. No article workflow, no deflection, no suggestions: rubric level 0.
Zammad
A help centre and knowledge base exist, multilingual from the Plus tier. Deflection is asserted — 'without opening a ticket' — but never instrumented: no draft/publish workflow, no article-insert into a reply, no suggestions before submission, and no reporting on which articles deflect. That's a basic article list with a language setting, a step above rubric level 3 and clearly short of rubric level 5.
Customer data protection
OTRS
The vendor's own GDPR hygiene is real: a named external DPO (IITR GmbH), a published privacy statement with stated retention periods, SCCs documented for the US video-conference processor, and recording gated on documented consent. But every one of those facts governs OTRS GmbH's website — nothing evidences a signable DPA, agent roles, retention configuration or an executable deletion path for a customer's ticket archive, which pins this just above zero.
Zammad
The GDPR rights list and auto-deletion in cover Zammad's own website inquiries, not the customer's ticket archive — that policy was last changed in 2020. Product-side I have 'Permissions' and individual roles at Professional, 2FA and an ISO27001 data centre, but no published DPA, no stated retention period for tickets, no audit log of who opened which ticket, and nothing on attachment handling or redaction.
Integrations & API
OTRS
The only named 'integrations' are the vendor's marketing stack — Google Ads, Hotjar, 6sense, HubSpot — which are pixels on their site, not CRM or shop connectors for a helpdesk. No REST API, no webhooks, no rate limits, no SSO: rubric level 0.
Zammad
'Open APIs and ready-to-use integrations' plus exactly two named non-channel integrations — GitHub/GitLab and Grafana/Elasticsearch. That's a handful of natives and an API asserted in marketing language: no webhooks, no documented rate limits, no SSO, and no CRM or shop system named anywhere on the evidence.
European sovereignty
OTRS
The contracting entity is firmly German and register-listed (OTRS GmbH, HRB 143059, Amtsgericht Frankfurt, DE VAT number), which is a genuine plus the pipeline's 0 doesn't credit. But where the ticket archive is hosted and which subprocessors touch it is entirely unstated, and the policy concedes processors 'could also be used outside the European Union' — so rubric level 3's absent-subprocessor-list scenario is where this lands.
Zammad
The contracting entity is nailed down — Zammad GmbH, Marienstraße 18 Berlin, HRB 163946 B — with 'Made & hosted in Germany' and an ISO27001-certified German data centre, plus a genuine self-hosted option. But the data-centre provider is unnamed, the only published subprocessors are the website's Matomo and Moosend Ltd rather than the product chain's, and the metered AI feature never states who processes it or where — so rubric level 8's named-provider and full-subprocessor-list bar isn't met.
Pricing transparency
OTRS
Three homepage captures on three dates surfaced no per-agent price, no tiers, no billing period, no light-agent terms — a support lead cannot compute even the headline from these pages. No public prices at all is exactly rubric level 0.
Zammad
Three tiers priced per agent with agent limits, VAT treatment, storage caps and even the AI meter at €0.03 per call are all public — unusually honest on the AI. But there's no billing period or annual option, no minimum term, no light-agent pricing, and the usage-metered channels (SMS from Starter upward, telephony) carry no price at all, so I can't compute the invoice for a chat-plus-SMS team.
Sovereignty, side by side
Dimension
OTRS
Zammad
Legal entity
Incorporated in DE
Incorporated in DE
Ownership
Not determined
Not determined
Data residency
Not determined
EU only
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.