GDPR-Compliant ITSM Software: European Vendors Compared (2026)

A GDPR-compliant ITSM platform processes an organisation’s service desk data — asset inventories, access rights, staff records and security incidents — under European data protection law, with a controller-processor relationship that a European supervisory authority can actually enforce.

How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect the order tools appear in. It never buys a listing: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

European Purpose may be paid for placements on this page and may earn a commission through links on it. Paid placement can affect the order in which tools appear; it never affects whether a tool is listed or what our review says. Editorial policy

Key takeaways

  • TOPdesk offers both SaaS and self-hosted deployment, which is why it appears across European public sector, healthcare and education.
  • The data that accumulates in a service desk is the reason jurisdiction matters here: the asset inventory and access rights together describe how to attack the organisation.
  • Matrix42 and OTRS both offer German hosting, and Matrix42 additionally runs fully on-premises for organisations that cannot use SaaS at all.
  • Efecte hosts in European data centres and is the only one holding identity data — access rights and recertification records — in the same platform, which raises the stakes on where it sits.
  • GDPR compliance is a property of the deployment as much as the vendor: a European platform configured with unlimited retention and no access controls is not compliant because the vendor is Dutch.

A mature service desk holds a map of the organisation: what it runs, how systems depend on each other, who can reach what, and frequently the security incidents themselves. This ranking judges six European platforms on where that map is processed, whether it can stay on your own infrastructure, and how the vendor handles the sensitive parts.

6 European IT service management tools compared

European IT service management tools compared on position, country, entry price and best use
PositionToolEstablishedEntry priceBest for
#1 TOPdesk Netherlands Per operator, per month Public bodies that may need self-hosting
#2 Matrix42 Germany Per device or per user licence Organisations that cannot use SaaS at all
#3 Efecte Finland Subscription per user Where identity data is in scope
#4 OTRS Germany Managed subscription Security incident data that cannot leave Germany
#5 USU Germany Enterprise licence Enterprises handing over their full software inventory
#6 Serviceware Germany Enterprise licence Cost and contract data across the estate

The 6 tools reviewed

#1 TOPdesk

Delft, Netherlands Per operator, per month Demo on request

Best for: Public bodies that may need self-hosting

TOPdesk is available as SaaS or self-hosted, which is the distinction that decides many public sector tenders. Universities, hospitals and municipalities across Europe run it, and the option to keep the whole desk on their own infrastructure is frequently why.

As a Dutch company it processes under the GDPR with a supervisory authority any European customer can reach.

What TOPdesk does well

  • SaaS or self-hosted deployment
  • Dutch company, EU jurisdiction
  • Long public sector and healthcare track record

Where TOPdesk falls short

  • Self-hosting shifts operations to you
  • Per-operator pricing on large desks

Standout feature. The deployment choice public procurement usually insists on.

#2 Matrix42

Frankfurt, Germany Per device or per user licence Demo on request

Best for: Organisations that cannot use SaaS at all

Matrix42 runs fully on-premises as well as SaaS, with German hosting for the managed option. For a service desk joined to endpoint management, that matters twice over: the platform holds not only tickets but installed software, device inventory and user activity across the estate.

That telemetry is among the most revealing data an organisation produces, which is why German buyers in particular want it under German law.

What Matrix42 does well

  • Full on-premises deployment
  • German hosting for SaaS
  • Endpoint telemetry stays in the same jurisdiction

Where Matrix42 falls short

  • On-premises means you operate it
  • Suite licensing is complex

Standout feature. Tickets and endpoint telemetry under one jurisdiction, on your own hardware if required.

#3 Efecte

Espoo, Finland Subscription per user Demo on request

Best for: Where identity data is in scope

Efecte holds access rights, approvals and recertification records alongside the service desk, which makes it the platform in this list with the most sensitive data footprint. It hosts in European data centres and sells largely into European enterprise and public bodies on exactly that basis.

For an organisation whose access governance evidence has to satisfy an auditor, EU processing of that evidence is part of the answer.

What Efecte does well

  • European data centres
  • Identity governance evidence under EU law
  • Sells into European public sector

Where Efecte falls short

  • Cloud-first — less on-premises flexibility
  • Identity scope widens the assessment

Standout feature. Access governance records processed under the same law that requires them.

#4 OTRS

Oberursel, Germany Managed subscription Demo on request

Best for: Security incident data that cannot leave Germany

OTRS AG hosts the managed service in Germany, and its security operations edition is designed to carry incident response cases. A desk holding security incidents is a particularly poor candidate for foreign jurisdiction, and OTRS is one of the few platforms addressing that combination directly.

The community edition was discontinued, so self-hosting for free is no longer an option — confirm the deployment model before planning around it.

What OTRS does well

  • German hosting for the managed service
  • Security incident response edition
  • Highly configurable retention and permissions

Where OTRS falls short

  • No free self-hosted edition
  • Interface dated next to newer platforms

Standout feature. Security incidents handled on a German-hosted platform built for them.

#5 USU

Möglingen, Germany Enterprise licence Demo on request

Best for: Enterprises handing over their full software inventory

USU’s asset management means the vendor receives a complete picture of what an enterprise runs and what it has contracted for. That is commercially sensitive quite apart from personal data, and a German vendor under German law is a materially different exposure from a US one.

USU is listed in Frankfurt, which brings its own disclosure and governance obligations.

What USU does well

  • German company, listed and audited
  • Software inventory stays in EU jurisdiction
  • Enterprise governance track record

Where USU falls short

  • Enterprise-scale deployment
  • Pricing quoted per deployment

Standout feature. A complete software and contract inventory held under German law.

#6 Serviceware

Bad Camberg, Germany Enterprise licence Demo on request

Best for: Cost and contract data across the estate

Serviceware’s financial management holds cost and contract data across an entire IT estate — commercially sensitive information that rarely gets the same attention as personal data but deserves it. It is a listed German company with European hosting.

For organisations already treating supplier contracts as confidential, keeping the system that models them inside the EU is consistent rather than exceptional.

What Serviceware does well

  • Listed German company
  • European hosting
  • Cost and contract data under EU jurisdiction

Where Serviceware falls short

  • Enterprise licensing
  • Smaller presence outside DACH

Standout feature. The financial model of the IT estate, held in the same jurisdiction as the estate.

What does a service desk actually accumulate?

More than tickets. A mature deployment holds the asset inventory, a configuration database describing how systems depend on each other, records of who has access to which application, staff records flowing through onboarding and offboarding, and frequently the security incidents themselves.

Taken together that is a map of the organisation — what it runs, where it is weak, and who can reach what. It is precisely what an attacker would want, and precisely what a regulator will ask about after a breach.

That combination is why this category concentrates in public sector, healthcare and education, where the answer to "who processes this" has to be defensible rather than convenient.

Is EU hosting enough?

Not by itself. Where the servers sit matters less than which entity you contract with and which law governs it: a US-established vendor with European datacentres remains subject to US legislation including the CLOUD Act.

The stronger positions are a European contracting entity, and better still a self-hosted deployment where the vendor is not a processor of live data at all. TOPdesk and Matrix42 both offer that route.

Then there is the configuration. Retention periods, access controls, what gets logged and for how long are decisions you make, and a European platform configured carelessly is not compliant because the vendor is European.

What does NIS2 change for the service desk?

For in-scope organisations, incident handling and reporting move from good practice to obligation, with defined timelines. The service desk is usually where an incident is first recorded and where the timeline starts.

That makes the desk part of the compliance evidence rather than an operational convenience — its records have to be complete enough and retained long enough to support a report, and available quickly enough to make a deadline.

Supply chain obligations also bring the vendor itself into scope of the assessment. This is a summary rather than legal advice; take proper counsel for your sector.

How we selected and ranked these 6 tools

Every tool on this page is in the European Purpose directory, which means the operating company is established in Europe and we have verified that from the company register or the vendor's own legal notice rather than from a marketing page. Tools headquartered outside Europe are not eligible, however good they are.

  1. Feature verification (weight: 40%). We check each capability against the vendor's own documentation and product pages, and record what the tool does rather than what the category is assumed to include.
  2. Ease of adoption (weight: 30%). Integrations, published API access, trial availability and how much configuration stands between signing and a usable result.
  3. Value and transparency (weight: 30%). Published pricing counts in a vendor's favour; quote-only pricing is recorded as quote-only rather than estimated. We weigh what a buyer gets for the entry price, not the headline feature count.
  4. Editorial review. Three people touch every page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's documentation. The three weights above decide the order; a position is a ranking against the other European tools in this category, not an absolute score.

Vendor-reported outcomes — ROI figures, margin uplift, time saved — are labelled as vendor claims wherever they appear on this page. We have not audited them, and neither has anyone else who quotes them. Read our full editorial process for how pages are re-verified.

Frequently asked questions

TOPdesk offers SaaS and self-hosted deployment, and Matrix42 runs fully on-premises as well as SaaS. OTRS is now a managed service after the community edition was discontinued. If self-hosting is a hard requirement, confirm it explicitly with the vendor rather than inferring it from open-source heritage.

No. The contracting entity and the governing law matter more than the datacentre location, because a US-established vendor remains subject to US legislation wherever its servers are. Beyond that, compliance depends on your configuration: retention periods, access controls and logging are decisions you make, not properties of the vendor.

Because of what the desk accumulates. The asset inventory, the configuration database and the access records together describe how the organisation works and where it is weak, and procurement rules in many member states require that map to be processed under enforceable European jurisdiction — frequently on infrastructure the body itself controls.

Efecte and Matrix42, for different reasons. Efecte holds identity and access governance records alongside the tickets. Matrix42 holds endpoint telemetry — installed software, device inventory, user activity — across the estate. Both are more revealing than a ticket queue, and both offer European or German hosting for that reason.

It affects what the platform has to do rather than which one you buy: incident handling and reporting within defined timelines, with records complete enough to support a report. Supply chain obligations also bring the vendor into the assessment for in-scope organisations. This is a summary, not legal advice.