PIC/S PI 041-1 and the EMA data integrity Q&A both frame data integrity around the data lifecycle: creation, processing, review, reporting, retention, retrieval and destruction. The reason is that most failures occur at the boundaries, where data move from one stage or one system to another and the controls of the previous stage are assumed to still apply. This guide follows a record through the later stages, where the findings are about retention, archiving and the tools used to process data on the way.
How long records are kept
EU GMP 4.11 requires batch documentation to be retained for at least one year after expiry of the batch or at least five years after certification of the batch by the Qualified Person, whichever is longer. 4.12 extends this to other documentation according to the activity it supports, and to critical documentation, including raw data, for as long as the marketing authorisation remains valid where the data support it. Annex 19 adds its own periods for reference and retention samples, and Annex 13 and the Clinical Trials Regulation set longer periods still for investigational products.
The complication is that the retention period applies to the record, not to a copy or a summary. For an electronic record, PIC/S PI 041-1 section 8.9 allows a verified true copy, and Annex 11 section 17 requires archived data to be checked for accessibility, readability and integrity throughout the retention period, with the ability to retrieve and restore verified. So the question is not 'do we keep the file' but 'in five years, can we open it, read it, and see its audit trail'.
Backup is not archive
Sites confuse these constantly. A backup is a copy of current data kept so that the system can be restored after a failure. It protects availability, it is usually rolling, and it is expected by Annex 11 section 7.2. An archive is the controlled long-term storage of records that are no longer in active use, in a form that stays readable, with metadata and audit trail, for the retention period. A backup that overwrites itself every thirty days archives nothing. A backup that is never restored proves nothing.
- Test the backup by restoring it, on a schedule, and record the test.
- Define what is archived, when, where, in what format, and who can retrieve it.
- Archive electronic records with their metadata and audit trail. A PDF of the result is not the record.
- Plan for the software. If the data system will be replaced, the migration or the retained ability to read old data is a validation activity.
Where the record is kept
EU GMP 4.10 requires that it is clearly defined where each record is located and that it stays intact for the retention period, and the manufacturing authorisation requires records to be kept available to the national competent authority, at the site or from another location from which they can be produced within a reasonable time. Off-site archives are fine. Records on a contractor's system without an agreement on access and retention are not. Records on a departed employee's laptop are the worst case, and it happens more often than anyone admits.
The spreadsheet
Somewhere between the instrument and the certificate of analysis, a calculation happens. Often it happens in Excel. The workbook was built by an analyst years ago, sits on a shared drive, has no version number, and has formula cells that anyone can edit. It is used because it works, and it is a finding waiting to be written, because it is a computerised system under Annex 11, section 4 expects it to be validated, and it never has been.
PIC/S PI 041-1 section 9 and the EMA data integrity Q&A both name spreadsheets specifically. The expectation is proportionate: a template that performs a GMP calculation needs to be validated against known inputs, protected so that formulas cannot be changed without control, version controlled so that the version used for any result is known, and access controlled. The spreadsheet inventory is how sites find out how many of these they have, and the number is always a surprise.
- List every spreadsheet that generates or reports GMP data. Ask the laboratory, production, engineering and warehouse. Include the ones people 'just use to check'.
- For each one, name an owner and decide: validate it, replace it with a LIMS or data system function, or retire it.
- For those kept, lock formula cells, add a version number that prints, put the template under change control, and validate against a documented set of inputs and expected outputs.
- Until validation is complete, verify every result by an independent calculation and record the verification.
Destruction
The end of the lifecycle is also controlled. Records are destroyed only after the retention period, under a documented procedure, with a record of what was destroyed and when. Destruction before the period, whether by a disk filling, a well-meaning clear-out, or a system decommissioned without migration, is a loss of GMP records and is reported and investigated as a deviation. Inspectors ask for the destruction log; sites without one have usually never thought about it.
Module 5 of the course follows one HPLC result from injection to archive, naming the record and the control at each stage, and then runs a spreadsheet through a validation with a worked test case set you can reuse.