Data Integrity

Data Lifecycle

What a definition is not

A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.

The data lifecycle is all phases a record passes through from initial generation and capture, through processing, review, reporting and use, to retention, retrieval, and eventual destruction. Data integrity controls must apply at every phase, not only at the point the data is created.

Regulators frame data integrity around the lifecycle precisely because vulnerabilities appear late: original data can be deleted after reporting, backups can be unrecoverable, and archived records can become unreadable as systems change. ALCOA+ attributes must hold from creation to destruction.

A mapped data lifecycle identifies, for each record type, where data is created, what is the raw/original record, who reviews it and how, where and how long it is retained, and how it is disposed — enabling risk to be assessed at the true point of vulnerability rather than assumed at capture.

KEY POINTS
  • Spans creation → processing → review → retention → destruction.
  • ALCOA+ must hold across every phase.
  • Late-phase risks (deletion, unreadable archives) are often overlooked.
  • Mapping the lifecycle locates the true points of vulnerability.
REGULATORY BASIS

MHRA GXP Data Integrity Guidance (2018); PIC/S PI 041-1 (2021); FDA Data Integrity and Compliance With Drug CGMP (2018).

Frequently asked questions

What is Data Lifecycle?

The data lifecycle is all phases a record passes through from initial generation and capture, through processing, review, reporting and use, to retention, retrieval, and eventual destruction. Data integrity controls must apply at every phase, not only at the point the data is created.

Which regulations cover Data Lifecycle?

MHRA GXP Data Integrity Guidance (2018); PIC/S PI 041-1 (2021); FDA Data Integrity and Compliance With Drug CGMP (2018).