When a server goes down at three in the morning, the first company to find out isn't the on-call team — it's the incident management platform deciding which phone, in which country, gets the call. That routing — who receives the alert, at what priority, and what personal contact data is stored to make it possible — passes through a specific vendor's servers. PagerDuty, the world's most widely used incident management platform, processes those alerts from US infrastructure operated by a company that has traded on the NYSE since 2019. Grafana OnCall, its open-source alternative, lets that same flow of on-call personal data never leave a European server the organisation itself chooses.
PagerDuty (United States, EIU 7.85) centralises and charges per user for an expensive but robust service. Grafana OnCall (Sweden / open source, EIU 9.39) is free in its self-hosted version and fully decentralises data control. The difference between the two isn't whether they work — both wake up an on-call engineer with equal effectiveness — it's which law protects your technical team's personal phone numbers, on-call schedules and incident histories.
Why democratic origin matters in incident management
An incident management platform stores, by design, one of the most sensitive sets of personal data in any technical organisation: each on-call engineer's personal mobile number, their availability schedules, their approximate location when receiving alerts, and in many cases, behavioural patterns like how long each person takes to respond to an incident at 4am. That information, cross-referenced with the organisation's incident logs, allows a precise reconstruction of dozens of employees' personal lives and sleep habits.
The incident data itself — which system failed, when, at what severity, which vulnerability was exploited in specific cases — is also competitively sensitive information. A leak of a company's incident history would reveal to competitors, or to an attacker, exactly what infrastructure weaknesses it has and when they occur most often. Democratic Market treats this category as high-risk software precisely because of the combination of sensitive personal data and confidential corporate data it processes simultaneously.
Grafana OnCall: Swedish open source integrated into the observability stack
Grafana OnCall is an open-source project maintained by Grafana Labs, the same company — majority Swedish in governance, dual-headquartered in Stockholm and New York — responsible for the popular Grafana, Loki and Tempo observability stack. Sweden scored 9.39 on the 2025 EIU Democracy Index, one of the four highest scores in the world, with fully independent judicial institutions and a personal data protection framework that goes beyond the minimums required by GDPR.
Grafana OnCall's structural advantage is that, being self-hostable under an open-source licence, the entire database of personal phone numbers, on-call schedules and incident histories can live on a server directly controlled by the organisation, on European territory if so decided. This entirely removes the need to trust a third party's standard contractual clauses: there is no third party, because there's no data transfer outside the perimeter the company itself controls. It's also natively integrated with Grafana and Prometheus, so alerts are generated directly from infrastructure metrics without passing through any additional intermediary.
Grafana OnCall isn't perfect: its escalation-configuration interface is less polished than PagerDuty's, and its catalogue of third-party integrations — Slack, Teams, Jira — while solid, is smaller. For teams already using the rest of the Grafana stack, native integration more than makes up for that gap; for teams starting from scratch with a heterogeneous tool ecosystem, the initial learning curve is somewhat steeper than with PagerDuty.
Other democratic alternatives in incident management
Beyond Grafana OnCall, Democratic Market identifies two additional alternatives with fully democratic origin. Zenduty, though of Indian origin (EIU 7.18, flawed democracy but above our threshold), offers EU data residency options under specific contract. iLert, developed in Cologne, Germany (EIU 8.53), is a commercial incident management platform hosted exclusively in Europe since its founding, built specifically for companies that need strict regulatory compliance without taking on the burden of self-hosting their own infrastructure. Both are worth evaluating alongside Grafana OnCall for teams that want a managed European service rather than operating their own on-call infrastructure end to end.
PagerDuty: US headquarters, AWS infrastructure, closed source
The United States scored 7.85 on the 2025 EIU Democracy Index, classified as a flawed democracy — above the 6.0 threshold Democratic Market applies, but penalised on the political participation and government functioning dimensions due to the country's persistent institutional polarisation. PagerDuty, headquartered in San Francisco and listed on the NYSE since April 2019, hosts its infrastructure on Amazon Web Services and offers no self-hosting option whatsoever: it is a fully closed platform managed exclusively by the company.
PagerDuty offers European Union data residency (Ireland-based data centres) as a contractual option on its Business and Enterprise plans, but that option isn't available on its entry-level plan, the one most common among startups and budget-constrained SMEs. As a US company subject to the CLOUD Act, even data physically hosted in Ireland remains legally accessible to US authorities under certain circumstances — a nuance PagerDuty acknowledges in its legal documentation but rarely surfaces prominently to customers at the point of sale.
Technical comparison: reliability, integrations and cost
PagerDuty has a historical advantage in reliability proven at scale: it processes alerts for thousands of Fortune 500 companies with an independently audited public uptime track record, and its machine-learning-based alert routing engine (Event Intelligence) reduces duplicate-alert noise more sophisticatedly than most open-source alternatives. Its integration catalogue exceeds 700 third-party tools. Pricing, however, is notably higher: starting at $21 per user per month on the Professional plan, and considerably more on Enterprise with EU data residency.
Grafana OnCall, in its self-hosted version, is free aside from the infrastructure cost of the server it runs on; its Grafana Cloud version starts from a limited free tier and scales at pricing significantly below PagerDuty for equivalent alert volumes. The reliability gap proven at Fortune 500 scale is closing quickly as more European telecom operators and critical-infrastructure organisations adopt the full Grafana stack, but PagerDuty still retains an edge in verifiable track record for the largest organisations with the most demanding SLAs.
EU legislation in 2026 applicable to incident management
The NIS2 Directive explicitly requires operators of essential services to have incident-response capabilities with very tight notification deadlines — 24 hours for early notification, 72 hours for full notification to the competent authority — turning the incident management platform into a piece of critical infrastructure subject to regulatory audit. GDPR, for its part, classifies employees' personal phone numbers and availability-hour patterns as personal data subject to the same safeguards as any other sensitive data, with the added obligation that any international transfer of that data — as happens by default with PagerDuty outside its Enterprise plan — must be legally justified before the relevant supervisory authority.
How Democratic Market evaluates incident management software
For this category, Democratic Market weighs the exposure of employees' personal data — phone numbers, availability patterns — especially heavily against the other usual dimensions. A provider headquartered in a full democracy, with auditable code and a self-hosting option on European territory, earns the highest possible score; a provider headquartered in a flawed democracy, with closed code and EU data residency available only on premium plans, earns an intermediate score, never the maximum, regardless of its technical quality.
Who each one is for
PagerDuty makes sense for large organisations with extremely demanding uptime requirements, ample budget for the Enterprise plan with EU data residency, and a need for a mature alert-routing engine fine-tuned over years at very high scale. It's also reasonable for companies already heavily dependent on its 700-plus integration marketplace that don't want to bear the cost of migrating their entire alerting ecosystem.
Grafana OnCall is the natural choice for any team already using the Grafana stack for observability, for startups and SMEs on tight budgets who can't afford PagerDuty's Enterprise plan, and for any organisation — especially in regulated sectors like banking, healthcare or critical infrastructure — that needs to be able to show an auditor exactly which server, under which jurisdiction, holds its technical staff's personal phone numbers.
International transfers: the GDPR angle on on-call data
Personal phone numbers and on-call rosters are personal data under GDPR Article 4, and when PagerDuty processes them outside its Enterprise EU-residency tier, that data is transferred internationally under Articles 44 to 49, relying on Standard Contractual Clauses plus supplementary technical measures required since Schrems II. The compliance burden of verifying those measures are adequate falls on the customer organisation, not on PagerDuty itself. With Grafana OnCall self-hosted on a European server, there's no international transfer to document in the first place — a meaningful simplification for any data protection officer building a record of processing activities under Article 30.
Practical buying guide: how to choose your on-call platform
For teams already using the Grafana observability stack, Democratic Market's recommendation is clear: adopt self-hosted Grafana OnCall from day one, leveraging native integration and eliminating any transfer of personal data outside the Union. For large organisations with extremely strict reliability requirements and budget for the Enterprise plan with EU data residency, PagerDuty remains a technically solid option, though structurally less favourable from a data-sovereignty standpoint than its European alternatives.
Conclusion: who wakes up your team, and under what law
The platform that decides which personal phone to call at three in the morning handles, without most organisations perceiving it as such, one of the most sensitive sets of personal data in their technical infrastructure. Grafana OnCall isn't the option with the longest track record on the market, but it's the one that lets you answer with certainty the question that actually matters: under what law is your on-call team's personal data protected. For most European teams already building on open, self-hostable tooling, that certainty is worth more than PagerDuty's extra decade of polish.
This article was originally published at Democratic Market. Read the full version with additional analysis on our site.
Top comments (0)