How we picked
GDPR compliance is not a feature a helpdesk has or lacks — it's a division of responsibility between you as controller and the vendor as processor. So we ranked on how much of that burden each vendor genuinely absorbs and how easy they make it to discharge the rest. A vendor that hands you a solid Article 28 DPA, a current sub-processor list, EU hosting, and working erasure tooling has done its share. One that offers a compliance badge on a marketing page and nothing operational has not.
Data location drove the first cut. GDPR doesn't mandate EU residency, but it makes life materially easier: no transfer impact assessment, no SCC review, a shorter DPIA, and a procurement conversation that ends in weeks rather than months. That's why this list skews toward self-hosted and EU-headquartered options — Zammad out of Germany, Trengo out of the Netherlands, and the self-host trio where the data never leaves infrastructure you chose.
Then we tested the operational side, which is where compliance gets real. Data subject requests arrive with a one-month deadline. If fulfilling an erasure request means opening a support case with the vendor and waiting, you cannot meet that reliably at any volume. We favored platforms with self-service export and erasure, configurable retention that actually deletes rather than soft-hides, and audit logging good enough to demonstrate accountability under Article 5(2). And in 2026 the AI question is unavoidable: any feature that ships ticket content to a model provider adds a sub-processor, and you need that documented before it's switched on.
What to prioritize
- A current sub-processor list, read before signing. Every entry is a transfer you may have to justify. Confirm there's a notification mechanism and a right to object when the list changes.
- Erasure that reaches search indexes and attachments. Test it in a trial: submit a request, then search for the person's email. If results still surface, the erasure is cosmetic.
- Retention policies with real deletion. Configurable per-object retention that hard-deletes on schedule. Data minimisation under Article 5(1)(e) is an obligation, not a preference, and indefinite ticket retention is the most common breach of it.
- EU hosting if it shortens your legal review. Not required, but for EU-regulated buyers it converts a months-long transfer assessment into a checkbox. Verify it covers backups and support tooling, not just the primary database.
- AI data flows documented explicitly. Where is inference performed, is your data used for training, and can AI be disabled per-workspace? Unanswered means assume the worst.
- Audit logs you can export. Article 5(2) accountability means demonstrating compliance, not asserting it. Access logs showing who viewed which customer record are what you'll produce when a regulator asks.