Data integrity
Article 25
1. Suitable measures shall be implemented to ensure data integrity from the moment when data is generated and throughout the relevant retention period, including: (a) implementation of measures to protect data against accidental loss or damage by appropriate methods such as duplication or back-up and transfer to another storage system; (b) implementation of measures to protect data against tampering or unauthorised manipulation. In the case of computerised systems, suitable controls shall be put in place to limit access to authorised persons, such as the use of keys, pass cards, personal codes with passwords, biometrics or restricted access to computer equipment and data storage areas. The type of security controls shall be adapted to the criticality of the computerised system; (c) implementation of measures to ensure the accuracy, completeness, availability and legibility of documents throughout the retention period. Handwritten entries shall be made in a clear, legible and indelible way. The implemented measures shall be commensurate to the risks and the criticality of the data. 2. The issuance, revision, superseding and withdrawal of all documents shall be controlled by keeping a record of all revisions (revision histories). 3. Any alteration made to the entry on a document shall be signed and dated. The alteration shall permit the reading of the original information. Where appropriate, the reason for the alteration shall be recorded.