← GXP GLOSSARY
Data Integrity

Data Integrity

Data Integrity (DI)

The degree to which data is complete, consistent, and accurate throughout its lifecycle. DI failures — backdating, shared logins, deleted results, disabled audit trails — are among the most serious findings a regulator can issue.

Data integrity is the assurance that a record is complete, consistent, and accurate across its entire lifecycle — generation, processing, review, reporting, retention, and disposal. It matters because every quality decision downstream rests on it: if the data cannot be trusted, neither can the batch release, the stability conclusion, or the submission built on it.

The weakest link sets the ceiling. Pristine acquisition means nothing if the review step never examines the audit trail, or if a record can be deleted without trace before archiving. The highest-risk stage is almost always review: second-person review that checks only the printed result — not the metadata, integration, and reprocessing history behind it — is the single most commonly cited gap.

Failures fall into two categories, and regulators treat them very differently. Lapses are control weaknesses without intent — poor procedures, unconfigured systems, inadequate training. Falsification is deliberate. Both produce findings, but suspected falsification escalates quickly to warning letters, import alerts, and application integrity actions, because it calls the honesty of every other record into question.

KEY POINTS
  • Covers the full lifecycle: generation → processing → review → reporting → retention → disposal.
  • Review is the highest-risk step — metadata and audit trails must be examined, not just results.
  • Hybrid paper/electronic systems carry the most risk; define which record is the original.
  • Lapses (control weakness) and falsification (intent) are treated very differently by regulators.
  • Common findings: shared logins, disabled audit trails, back-dating, deleted or reprocessed data.
  • It is a quality-culture problem as much as a technical one — people falsify under pressure.
REGULATORY BASIS

MHRA GXP Data Integrity Guidance (2018); PIC/S PI 041-1 (Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments); FDA Data Integrity and Compliance With Drug CGMP (2018); WHO TRS 1033 Annex 4; EU GMP Chapter 4 and Annex 11.

Frequently asked questions

What does Data Integrity stand for?

Data Integrity stands for Data Integrity (DI).

What is Data Integrity?

The degree to which data is complete, consistent, and accurate throughout its lifecycle. DI failures — backdating, shared logins, deleted results, disabled audit trails — are among the most serious findings a regulator can issue.

Which regulations cover Data Integrity?

MHRA GXP Data Integrity Guidance (2018); PIC/S PI 041-1 (Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments); FDA Data Integrity and Compliance With Drug CGMP (2018); WHO TRS 1033 Annex 4; EU GMP Chapter 4 and Annex 11.

SEE ALSO
ALCOA+Attributable, Legible, Contemporaneous, Original, Accurate — plus Complete, Consistent, Enduring, AvailableAudit TrailGDocPGood Documentation Practice
Browse the standards library →Explore GxP disciplines →

SPEQ decodes published regulatory concepts in plain language. Definitions are a practitioner reference, not legal or regulatory advice.

Weekly Briefing

Get the Weekly GxP Briefing

Curated regulatory intelligence — enforcement, recalls, guidance, and quality signals — in one practitioner-grade email each week. Free.

Read a past issue →