Passive taps, not SPAN ports: monitoring that holds up under GDPR.

Lawful interception and data-retention rules require full-fidelity capture, not sampling. That pushes network monitoring from SPAN ports toward passive TAPs.

Network traffic monitoring has to answer to more than performance dashboards. GDPR and data-retention obligations mean that what gets captured, and how faithfully, is a compliance question, not just an operational one — and most operators only discover the distinction once a conventional SPAN port has quietly dropped the packets an audit needed.

Bandwidth requirements compound the problem: link speeds that ran at 10 Mbps a decade ago now run at up to 800 Gbps, and legal compliance increasingly means monitoring everything, not sampling, with narrow exceptions. SPAN (Switch Port for Analysis) still has its place for limited, low-stakes situations, but it was never built to be an evidentiary source.

Why a TAP behaves differently

A TAP (Test Access Point) is a passive, purpose-built copy of the physical link. It does not renegotiate timing the way a switch's analysis port can, which matters for VoIP and full-duplex traffic analysis where distance and response time are part of the signal. It does not introduce extra jitter or distortion into a video or voice capture, and it passes VLAN tags through untouched — a SPAN port dropping tags is a classic source of phantom problems that take hours to diagnose.

The rest of the list reads like an audit checklist because that is what it is: no filtering of undersized, oversized, or bad-CRC frames; no dropped packets regardless of bandwidth; no addressable network presence, so nothing to compromise; no configuration to get wrong. It is protocol-agnostic — IPv4, IPv6, whatever runs over the link passes through unmodified.

The upgrade trigger

The practical trigger tends to be a network refresh: moving to multi-gigabit, 10 Gigabit, or higher forces the question, because the legal requirements — full visibility for security compliance, lawful interception, deep packet inspection — do not scale down gracefully on a SPAN port under that kind of load.

A SPAN port is a convenience feature borrowed for a compliance job it was never designed for.

None of this is exotic engineering. It is choosing the tool that matches what the regulation actually asks for, before an audit points it out.