Data governance in clinical trials refers to the framework by which the sponsor and investigator manage the integrity, traceability, confidentiality, and security of trial data throughout its entire lifecycle. ICH E6(R3) addresses data governance as a standalone topic and assigns it specific responsibilities for data and computerised systems. It is not a single control activity; rather, it links roles, procedures, and technical safeguards.
Shared responsibility of sponsor and investigator
The ICH guideline assigns different but interrelated tasks to the sponsor and the investigator. The investigator must ensure the integrity of the data within their area of responsibility, regardless of whether it is generated on paper or electronically. The sponsor is responsible for ensuring that data that is generated and managed is handled with integrity and confidentiality. If tasks are transferred to service providers, overall responsibility remains with the delegating party.
Data governance therefore requires clearly documented agreements on roles, activities, and oversight. A sponsor may outsource data management, EDC operations, or statistical programming, but must continue to oversee the data quality and integrity requirements. The same applies to trial sites that delegate activities to qualified members of their team. The level of oversight should be proportionate to the importance of the data and the risks to participant protection and the reliability of results.
Four core areas of data governance
ICH E6(R3) identifies the protection of participants’ privacy and confidentiality as a core area. Personal information may only be accessible to the extent required by law and for the study. In the EU, the General Data Protection Regulation complements this protection; the Clinical Trials Regulation refers to the applicable data protection law for research outside the trial protocol.
Other areas relate to the governance of computerised systems, safeguarding randomisation, dose adjustments, and blinding, and supporting key decisions such as data finalisation and unblinding. What matters is not only a system’s technical function, but also clear assignment of who administers it, which data flows it affects, and how changes, access, and the maintenance of blinding are controlled.
For computerised systems, governance requires a risk-based perspective on their use throughout the study. This includes not only validation of an EDC system, but also the management of user rights, interfaces, data transfers, and changes during operation. The EMA guideline on computerised systems and electronic data in clinical trials provides an important European reference in this regard.
Systems that influence randomisation, dose adjustment, or blinding are particularly sensitive. Their governance must prevent unauthorised persons from gaining access to treatment-related information or a system change from altering assignments without being detected. In addition, for data finalisation it must be clear which outstanding reviews have been completed, which data are frozen, and who authorises the release.
Distinction from data integrity and the Data Management Plan
Data integrity is a quality attribute of individual data and records: they must be accurate, complete, and traceable. Data governance is the overarching framework that defines how this quality attribute is protected through responsibilities, system governance, access controls, and oversight. Data integrity is therefore an objective within governance, not a complete description of it.
A Data Management Plan is also not data governance. The plan documents study-specific processes such as data capture, queries, coding, data transfer, and database lock. Governance defines the broader principles and responsibilities under which this plan is created, implemented, and controlled. Both instruments must work together, particularly when multiple systems or service providers work with the same participant and study data.
Relevance for clinical trials
In practice, data governance becomes visible when a randomisation system change could affect blinding, a laboratory introduces new data transfers, or a critical reconciliation is still pending before database lock. The project then requires not only a technical solution, but also clear decision rights, documented risk assessments, and controlled access to the relevant information. Inspection-relevant evidence includes, among other things, documentation of system governance, the assignment of responsibilities, and the ability to trace the origin and modification of data.
Full-service CROs such as Mediconomics support data governance by preparing data management and system overviews, defining data handovers and roles, conducting risk-based data review, coordinating validation documentation, and preparing for database lock and unblinding. With external EDC, IRT, or laboratory partners, they can integrate the agreed controls, access rules, and escalation pathways into project-specific quality governance.
Frequently Asked Questions (FAQ)
Is data governance only an IT task?
No. IT systems are an important component, but governance also covers clinical responsibilities, data protection, randomisation, data review, and decisions on data status.
Does the sponsor remain responsible if a service provider operates the EDC?
Yes. ICH E6(R3) allows tasks to be transferred, but overall responsibility for the quality and integrity of trial data remains with the sponsor.
What does database lock have to do with data governance?
Database lock is a key decision. Governance should ensure that the data status, outstanding issues, and the authority to finalise are managed in a traceable manner.
Regulatory References
- ICH E6(R3) Good Clinical Practice, Section 4 – describes data governance as a responsibility of the investigator and sponsor.
- EMA Guideline on computerised systems and electronic data in clinical trials – specifies requirements for systems and electronic data.
- Regulation (EU) No 536/2014 on clinical trials – sets out key requirements for trials, documentation, and data in the EU context.
- Regulation (EU) 2016/679 General Data Protection Regulation – protects the personal data of study participants.