Data integrity refers to the state in which data are complete, accurate, traceable and reliable for their intended purpose throughout their entire lifecycle. In clinical trials, it concerns not only individual eCRF values, but also their collection, checking, transfer, analysis, retention and, if applicable, destruction. It is a prerequisite for ensuring that results can be correctly reported, reviewed and interpreted.
Protection goal over the entire data lifecycle
Data integrity is a quality objective for all media and data sources, i.e. for paper records as well as for electronic health records, laboratory transfers, ePRO systems or central databases. ICH E6(R3) requires investigators and sponsors to have procedures that ensure the integrity and confidentiality of the generated and managed data. For this purpose, the EMA assigns ownership, responsibilities, processes and systems to an end-to-end data governance.
In practice, this objective already begins with the protocol and the design of data collection: only required, clearly defined data should be collected. Subsequently, permissions, training, validation, interface controls, backups, archiving and access must be designed in such a way that critical information is neither lost unnoticed nor falsified. In case of migrations, it must be verified that neither the value nor the meaning of the data changes. Reliability therefore arises from the interplay of people, processes and technology, not from a single IT tool.
Controls, metadata and demonstrability
Essential controls include risk-based system validation, role-based user management, documented standard operating procedures and appropriate checks of data and metadata. Metadata give the data value its context, such as who entered or changed it, when this happened and for what reason. An audit trail makes changes traceable, must not obscure the original entry and must be evaluable.
Data integrity does not demand that every discrepancy is automatically an error. Corrections can be permissible and required if they are authorized, justified and transparently documented. It is crucial that the original observation, the change and the responsible person remain reconstructible. Automated data flows therefore also require specifications, testing and controls. During inspections, the responsible party must be able to demonstrate the integrity of the relevant data and the effectiveness of these controls.
Differentiation from ALCOA+ principles
Data integrity is the goal to be achieved, not the name for a fixed mnemonic. The ALCOA+ principles, on the other hand, are a set of criteria that can be used to assess the quality of individual records and the associated processes. ALCOA stands for attributable, legible, contemporaneous, original and accurate. The extension typically includes complete, consistent, enduring and available when needed; the current EMA guideline explicitly adds traceability and speaks of ALCOA++.
If all these criteria are met, this is strong evidence for data integrity, but does not replace a governance system. For example, a correctly time-stamped value can still be inadequately protected, not meaningfully transferable or incomplete for an analysis. Conversely, validation, audit trail review and access controls are measures for achieving the goal, but not synonyms for data integrity. The conceptual separation prevents the comprehensive requirement from being reduced to a mere input checking scheme.
Relevance for clinical trials
Regulation (EU) No 536/2014 requires that clinical trials generate reliable and robust data; information must be recorded, processed and stored in a way that allows accurate reporting, interpretation, monitoring and inspection. In everyday trial practice, data integrity therefore determines the credibility of safety evaluations, efficacy analyses and the clinical study report. A clear description of the data flow, risk-oriented controls of critical data as well as a traceable handling of deviations and corrections are essential.
Full-service CROs such as Mediconomics support data governance by designing data flows, selecting and assessing the validation of electronic systems, data management, monitoring and preparing for audits or inspections. This includes, for example, authorization concepts, specifications for interfaces and edit checks, review plans for data and metadata as well as the documentation of data transfers and archiving processes.
Frequently Asked Questions (FAQ)
Does data integrity only apply to electronic data?
No. The goal applies regardless of the medium. Electronic systems bring additional requirements for validation, access protection, metadata and technical safeguards, but paper source data must also be kept and stored in a legible, complete and traceable manner.
Is an audit trail already proof of complete data integrity?
No. An audit trail documents events and changes. It is an important control tool, but must be supplemented by appropriate processes, risk-based review and further measures such as validation and access control.
Who bears the responsibility for data integrity?
Investigators and sponsors each have responsibilities for the data under their control. Tasks can be delegated to service providers, but the regulatory responsibility and the necessary oversight remain with the responsible parties.
Regulatory references
- ICH E6(R3), Good Clinical Practice — describes data governance, integrity, metadata and traceability in clinical trials.
- EMA/INS/GCP/112288/2023, Guideline on computerised systems and electronic data in clinical trials — specifies data integrity and ALCOA++ for electronic trial data.
- Regulation (EU) No 536/2014 on clinical trials — requires reliable, robust data and adequate recording and storage.
- EudraLex Volume 4, Annex 11, Computerised Systems — contains risk-based requirements for data integrity, validation and data storage.