Data integrity is not a separate compliance topic bolted onto GMP; it is the property that makes every other record meaningful. A validation report, a batch record and a release decision are only worth what the underlying data is worth. That is why data integrity findings escalate quickly — they undermine the evidential basis of everything else on the site.
The distinction between static and dynamic records matters for what you must retain. A static record is a fixed image, such as a paper record or a PDF. A dynamic record allows interaction — a chromatogram that can be reprocessed with different integration parameters is dynamic, and printing it produces a static picture that loses the ability to reconstruct what was done. Retaining only the printout for a dynamic record is a well-established finding.
Most real-world gaps are unglamorous. Audit trails enabled but never reviewed. Shared logins that make records unattributable. Uncontrolled spreadsheets. Hybrid paper-and-electronic systems where neither record is definitive. Original observations recorded on a scrap of paper and transcribed later, which breaks contemporaneity and originality at once.
The governance point is the one that changes outcomes. Data integrity is largely a design and culture problem: systems that make the compliant route the easy route, and an environment where reporting a problem is safe. Where people are penalised for raising deviations, pressure to make data look acceptable is created by management, not by individuals — and inspectors are alert to that pattern.