Data Integrity, Review and Record Retention
The controls that keep process and safety information attributable, readable, recorded at the time of work, accurate, protected from undisclosed change, reviewed for meaning and retrievable for the period in which it supports product decisions.
Definition
Data integrity means that a record remains a reliable representation of the activity or observation it claims to document. A reviewer should be able to determine who created it, when it was created, what was measured or observed, which method and unit were used, and whether the information was later changed. Integrity applies to paper, spreadsheets, controller files, cloud dashboards, laboratory reports and exported summaries. A technically precise measurement loses value when its identity or history is uncertain.
Original data and controlled copies
Original data may be a handwritten entry, the file held in a logger, an instrument result or a system database. A printout, screenshot, transcription or exported spreadsheet can be useful, but it should remain linked to the source and preserve the information needed to interpret it. A summary that omits alarms, excluded points, units or configuration changes is not equivalent to the original data. If the original cannot be retained, the organisation should define what constitutes a controlled true copy.
Attributable and contemporaneous records
Users should have individual identities where the system supports them; shared logins prevent reliable attribution. Observations should be recorded when performed, with date and time appropriate to the process. Backdating, pre-signing and completing repeated values by copying earlier records create false evidence. Clock synchronisation matters when separate instruments, controllers and operator logs must be aligned to investigate a process excursion.
Corrections and audit information
A paper correction should leave the original legible and identify the person and date. Electronic systems should preserve significant changes, deletions, approvals, recipe revisions and configuration changes in audit information appropriate to the risk. The reason for a change should be recorded when it is not obvious. An audit trail is useful only when it is retained and reviewed; collecting change events that nobody can retrieve or interpret does not protect the release decision.
Access and system control
Give users only the access needed for their role. Separate routine operation from permission to alter recipes, alarm limits, clocks, calibration factors or historical records. Control software versions, templates and calculation sheets so that users know which version is authorised. Changes should be tested and approved before use when they can affect food safety or record meaning. Cybersecurity, password recovery and account removal matter because unauthorised access can change both the process and its evidence.
Review for meaning
Record review is not a check that every box contains text. It should identify missing data, impossible sequences, repeated identical values, unexplained edits, sensor substitution, configuration changes, abnormal trends, unresolved alarms and results obtained with an out-of-status instrument. Automated exception reports can focus attention, but their rules must be known and verified. The reviewer should examine original or sufficiently detailed data when a summary hides the information needed for a decision.
Data gaps and integrity events
A blank interval may result from battery failure, full memory, network loss, sensor disconnection, incorrect clock, software error or deliberate deletion. Determine the cause, affected period, batches and decisions. Independent evidence may narrow the uncertainty, but absence of an alarm is not proof of normal conditions if the alarm channel also failed. Preserve the investigation and do not fill a gap with interpolated or assumed values presented as observations.
Backup, archive and recovery
A backup is a copy used to recover from loss; an archive preserves records for controlled retention and retrieval. The system should define backup frequency, protected storage, restoration testing and responsibility. Cloud synchronisation alone may replicate an accidental deletion or corrupt file. Long-term records need readable formats, indexes and migration controls when software or hardware is replaced. Recovery should be tested before an emergency, not assumed from the presence of a backup icon.
Retention and disposal
Retain each record for the period required by the applicable law, product, shelf life, customer or certification system and investigation need. United States HACCP rules and European requirements illustrate that record obligations are jurisdiction-specific. At the end of the approved period, dispose of records in a controlled way that protects confidential information and does not destroy material subject to an investigation, recall, legal hold or unresolved complaint.
Proportionate application
A small producer may use bound pages, protected files and periodic exports rather than a validated enterprise database. The practical controls are still clear: date entries, identify the batch and observer, preserve corrections, restrict recipe edits, back up records, retain source files and review before release. The system should become more formal as automation, production volume, product risk and the number of users increase. Complexity is not the goal; reliable evidence is.
Related in the Codex
References
- United States Food and Drug Administration / eCFR — 21 CFR Part 117 Subpart F — Requirements Applying to Records
- United States Food and Drug Administration — Computerized Systems in the Food Processing Industry
- United States Electronic Code of Federal Regulations / USDA Food Safety and Inspection Service — 9 CFR 417.5: HACCP Records
- USDA Food Safety and Inspection Service — FSIS Directive 5000.2: Review of Establishment Data by Inspection Personnel
- National Institute of Standards and Technology — NIST SP 800-92: Guide to Computer Security Log Management
- European Parliament and Council — Regulation (EC) No 852/2004 on the Hygiene of Foodstuffs
- European Parliament and Council — Regulation (EC) No 178/2002, Article 18: Traceability
- Codex Alimentarius Commission — General Principles of Food Hygiene, CXC 1-1969 (2022 revision)