Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
OTRS is a service management and ticketing system available as open source (community edition via Znuny) or commercial cloud service by Rother OSS GmbH (Germany). It provides ticket management, ITIL processes, customer portals, and workflow automation. EU based and EU hosted, OTRS is a strong GDPR compliant helpdesk option.
OTRS is a service management and ticketing system from Germany. The open source community edition (Znuny) is self hosted. The commercial version by Rother OSS GmbH offers EU cloud hosting (Germany). OTRS provides ITIL processes, ticket management, customer portals, and workflow automation. EU based and EU hosted, it offers strong GDPR compliance foundations. Session cookies for authenticated users. Legal basis: contract or legitimate interest. Steps: DPA for cloud, RBAC, retention, DPIA if sensitive ITSM data. Alternatives: Zammad, osTicket, FreeScout, ServiceNow.
Websites using OTRS must obtain user consent under GDPR regulations.
DPIA considerations
DPIA recommended for large scale support operations. EU based (Germany) and EU hosted reduces risk. Assess: ticket content, customer portal data, email integration, ITIL process data, file attachments.
Sample consent text
This site uses OTRS for service management. Data is processed by Rother OSS GmbH (Germany, EU). Please refer to our privacy policy.
Third-party domains contacted
otrs.comportal.otrs.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| OTRSAgentInterface | authentication | Session | Agent session cookie for OTRS dashboard. |
| OTRSCustomerInterface | authentication | Session | Customer portal session cookie. |
OTRS uses cookies for user preferences — inform visitors with a consent banner.
Session cookie. CSRF token. No third party cookies.
Not for internal use. Customer portal session cookies may need notice.
Contract performance or legitimate interest.
No. German company, German hosting for cloud. Self hosted: full control.
If processing sensitive ITSM data at scale.
DPA for cloud, RBAC, retention, email integration security, DPIA.
Zammad, osTicket, FreeScout, ServiceNow, Jira Service Management.
Document session cookie if public. EU hosting simplifies everything.