What is data integrity in GMP?
Short answer
Data integrity in GMP means that data are complete, consistent, accurate, trustworthy and reliable throughout their lifecycle. Decisions about manufacture, testing, validation, release and patient safety depend on records that accurately show what happened.
Data integrity applies to paper, electronic and hybrid records. It includes the visible result and the supporting context, such as dates and times, user identities, audit trails, metadata, calculations, instrument records and review evidence.
What this means in practice
A compliant system should make it possible to reconstruct the activity and understand who performed it, what was recorded, when it occurred, how a result was produced and what was reviewed. Controls should be proportionate to the risk and should cover the full data lifecycle from creation or acquisition through processing, review, reporting, retention and disposal.
Regulatory guidance and ALCOA+
MHRA GxP data integrity guidance sets out regulatory expectations for data governance across the pharmaceutical lifecycle. EU GMP Chapter 4 and Annex 11 provide relevant expectations for documentation and computerised systems.
ALCOA+ is a widely used good-practice framework: data should be attributable, legible, contemporaneous, original and accurate, as well as complete, consistent, enduring and available. The mnemonic is not a substitute for a risk-based data-governance system or the applicable GMP requirements.
Evidence of effective data governance normally includes
Defined ownership and accountability for data throughout its lifecycle.
Appropriate access controls and unique user identities.
Contemporaneous recording and controlled correction of errors.
Review of audit trails and metadata where relevant to the risk.
Validated systems, controlled spreadsheets and protected master data.
Secure retention, backup, retrieval and disaster-recovery arrangements.
Quality oversight, periodic review and investigation of data-integrity events.
Common weaknesses
Shared accounts or uncontrolled administrator access.
Transcribing results without retaining or reviewing the original data.
Backdating, pre-dating or completing records after the activity without justification.
Disabled audit trails or audit-trail data that are available but not reviewed.
Uncontrolled spreadsheets, calculations or electronic templates.
Focusing on individual behaviour while overlooking poor system design, workload or governance.
Questions to ask internally
Can the full activity and decision be reconstructed from the retained records?
Are original data, metadata and relevant audit trails protected and reviewable?
Are access rights appropriate and periodically reviewed?
Are manual and electronic data flows included in risk assessments?
Would the records support the same conclusion during an inspection?
How W2 can help
W2 Cleanroom Consulting can review data flows, documentation practices, Annex 11 controls and investigation evidence where data integrity intersects with cleanroom operations, validation and Pharmaceutical Quality Systems. The client remains responsible for system ownership, Quality approval, validation decisions and regulatory obligations.
Need help assessing a data-integrity risk?
Contact W2 Cleanroom Consulting at info@w2cleanrooms.com to discuss an independent review, inspection-readiness assessment or remediation support.
Prepared and reviewed by: W2 Cleanroom Consulting GMP team. Last reviewed: 24 July 2026.
