Every pharmaceutical logistics provider knows temperature must be monitored. Far fewer have a data trail that survives an inspection. The gap is almost never the sensor — it is the record: what was captured, in what form, and whether it can be produced intact two, five or ten years later.

This article covers the practical requirements that apply to temperature-controlled pharma shipments under Good Distribution Practice (GDP), and how to build a monitoring setup that holds up under audit.

What GDP actually requires

GDP — implemented in the EU through the 2013/C 343/01 guidelines and mirrored in most national regimes — requires that temperature-sensitive medicinal products are transported within a validated temperature range, and that evidence of compliance is retained. It also requires that deviations are detectable, investigated and documented.

Three obligations follow from that:

  1. Continuous monitoring — not spot checks. The record must cover the whole journey, including handovers and storage in transit.
  2. Traceable records — each record must be linked to a specific shipment, batch, date and device.
  3. Retention and retrievability — records must remain accessible and legible for the required period.

Data integrity: the ALCOA+ standard

Most regulators assess records against the ALCOA+ principles. This is the lens an inspector uses when they open your data:

PrincipleWhat it means for temperature data
AttributableYou can identify who or what produced each record, and on which device/shipment
LegibleThe record is readable and exportable in a durable format — not locked in a proprietary viewer
ContemporaneousData is timestamped at the moment of capture, not entered later from memory
OriginalThe first capture is preserved; any derived report is clearly marked as a copy
AccurateThe measurement is within the device's stated accuracy and the device is calibrated
CompleteNo gaps. Missing intervals must be explainable, not silently absent
ConsistentTimestamps, units and sequence are internally coherent across the whole record
EnduringThe record survives device decommissioning and platform migration
AvailableIt can be produced on request, promptly, for the full retention period

The two principles most often failed in practice are complete and enduring. Gaps appear when a device loses signal mid-transit; records become unavailable when they live only in a vendor's cloud account that gets cancelled.

What to capture in every record

  • Temperature at a defined interval (commonly 5–15 minutes for high-value pharma; 1 hour acceptable for less critical lanes if justified in the validation)
  • Timestamp with timezone, generated by the device — never back-filled manually
  • Device identity — serial number and calibration status
  • Shipment linkage — batch/lot, consignment ID, origin and destination
  • Position — so excursions can be tied to a leg of the journey and a responsible party
  • Excursion flags — automatic marking of out-of-range events, with duration and magnitude
  • Door or handover events — where the device supports it, to explain legitimate temperature changes

How long must records be retained?

There is no single global number, but the requirement is consistent in shape: retention must cover the product's shelf life plus a margin, and typically at least five years. In practice this means:

  • EU GDP: sufficient to cover the shelf life of the product, and in any case no shorter than the period required by national law — commonly 5 years
  • US cGMP-linked expectations: at least 1 year past expiry, which for long-dated products can exceed 5 years
  • Clinical trial materials: retention often extends to the end of the trial plus several years

The safe design rule is to retain everything for five years minimum, and longer wherever shelf life dictates — and to make sure retention is a contractual guarantee, not a vendor's default setting.

21 CFR Part 11 and electronic records

If your temperature data is stored electronically — which it will be — Part 11 (and EU Annex 11) requirements come into play. The practical implications for a monitoring system:

  • Audit trails for any change to a record: what changed, who changed it, when, and why
  • Access control so records cannot be edited without trace
  • No silent deletion — records must not be removable by ordinary users
  • Validated systems with documented evidence that the system does what it claims

An inspector's first question is rarely "was the temperature in range?" It is "show me the raw data for this shipment." Everything else follows from whether you can answer that in minutes.

What auditors ask for, in order

  1. The temperature range specified for the product and the justification for it
  2. The raw data file for a named shipment — not a summary PDF
  3. Evidence the device was calibrated and in date
  4. An explanation for any gap or excursion, with the investigation record
  5. Proof the record has been retained unchanged since capture

If any of those takes more than a few minutes to produce, the underlying system has a gap worth fixing before an inspection finds it.

Hardware implications

Most compliance failures trace back to hardware choices made months earlier. Three that matter most:

Buffer memory. If the device cannot store data while out of network coverage and upload it later, you will have gaps — and gaps are the hardest thing to defend. Insist on on-device logging independent of connectivity.

Accuracy class. A ±0.5°C device is often fine for ambient food lanes but marginal for a 2–8°C pharma product where the tolerance band itself is only 6°C wide. Specify the accuracy the product demands.

Export format. The record must be producible in a durable, human-readable format. If the only way to see data is a vendor's dashboard, your retention is only as good as that vendor's continuity.

The L Series and G Series logger platforms from AOVX log independently of network coverage, expose raw records for export, and are specified with the accuracy class pharma lanes require.

Building a GDP-ready monitoring programme?

Tell us your product lanes and retention requirements — we'll recommend the right logger accuracy class and data export setup.

Talk to Our Engineers →
Previous: Cold Chain Hardware Buyer's Guide Next: Choosing Connectivity →