Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The data lifecycle is the set of decisions and activities involved in planning, creating or collecting, processing, using and sharing data, then preserving it or disposing of it responsibly. There is no single stage list for every context: NIST’s general information lifecycle is a broad model, while its Research Data Framework (RDaF) describes research data management in greater detail.

What does “data lifecycle” mean?

The phrase can refer to related but distinct models. NIST’s general information lifecycle covers information from creation or collection through processing, dissemination, use, storage and disposition. Its glossary defines it as “The stages through which information passes, typically characterized as creation or collection, processing, dissemination, use, storage, and disposition, to include destruction and deletion.” The glossary attributes the definition to NIST SP 800-37 Rev. 2 and OMB Circular A-130 (2016). NIST CSRC: Information life cycle.

For research data, NIST’s Research Data Framework (RDaF), Version 2.0, published in February 2024, sets out six more detailed stages. It is a customizable management framework, not a rule that every organization must follow identically.

NIST also has a narrower glossary definition of “data life cycle”: “The set of processes in an application that transform raw data into actionable knowledge.” That application-oriented definition, sourced to NIST SP 800-188, is not the same as either the broad information lifecycle or the RDaF. NIST CSRC: Data life cycle.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The UK Government’s Data Quality Framework describes the lifecycle as the stages data passes through “from collection to dissemination and archival/destruction,” and emphasizes planning storage and processes before data is collected or used. UK Government Data Quality Framework.

The six stages in NIST’s research data framework

The RDaF stages are interconnected and cyclical, not a one-way production line. A project can revisit earlier decisions, enter the framework at different points, or work across multiple stages at once.

1. Envision

Set out why the data program exists, what it needs to achieve and how it fits organizational goals, strategy and governance. Decisions about privacy and security begin here, rather than being postponed until data is ready to share.

2. Plan

Decide how data will be acquired, what formats and storage approaches will be suitable, who is responsible for managing it, and what documentation and quality checks are needed. Plan for policies, possible sharing or dissemination, and eventual retention or disposal before collection begins.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Generate or acquire

Create raw data through experiments or computational work, or obtain data created elsewhere. Record where it came from and the conditions or methods relevant to interpreting it.

4. Process or analyze

Transform generated or acquired data, often with software, into forms that can support observations and conclusions. Keep track of important changes so users can understand how processed data relates to its source.

5. Share, use or reuse

Use or disseminate raw and processed data inside or outside the organization, subject to relevant constraints and incentives. Sharing is not automatically public release: decide who may access the data, on what terms, and with what explanatory documentation.

6. Preserve or discard

Determine what should be retained for future use or as a record, what belongs in an archive or repository, and what should be safely disposed of when no longer needed. Preservation and deletion are both parts of responsible data management.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to manage data throughout its lifecycle

Plan before collecting

  • Define the purpose of the data and confirm the authority or permission to collect or use it.
  • Assign responsibilities for collection, documentation, storage, quality checks, access and end-of-life decisions.
  • Choose usable formats and storage approaches, and decide what documentation will let others interpret the data.
  • Identify intended users and any privacy, security, policy or contractual constraints on access and sharing.
  • Set out what may need to be retained, where it may be preserved, and how data will be disposed of if retention ends.

Track origin, handling and changes

Provenance is the documented history of a data asset’s origin and alterations. A chain of custody records who possessed an asset, when and why. These records help users assess how data was produced, transferred and changed; they are especially important where trust, accountability or reproducibility depends on the handling history. NIST discusses provenance and chain of custody in its RDaF 2.0.

Manage quality at every stage

Quality is not a final inspection performed only after collection. Documentation, storage, ownership and quality assurance matter throughout the lifecycle. The U.S. Geological Survey describes quality management as protocols and methods that ensure data is properly collected, handled, processed, used and maintained, with lifecycle-stage questions to address at each step. USGS: Data Lifecycle.

Make storage and backups fit the purpose

Storage is a distinct stage in NIST’s broad information lifecycle, but the RDaF treats storage choices as a planning concern that continues to matter during ongoing management. Consider access, protection, documentation, availability and retention needs when selecting a location. A separate backup copy can help protect against loss, but a backup by itself does not establish an archive, satisfy retention obligations or provide a complete security strategy.

Decide deliberately what to share

Before sharing, check whether the data can be understood and reused: provide useful documentation, explain provenance and transformations, and state access terms. Some data may need restricted access or may not be suitable for release. The RDaF recognizes both internal and external use and the constraints or incentives that affect dissemination.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set an end-of-life decision

Preserve data when it has ongoing value or must be kept as a record; discard it safely when it no longer has a justified retention need. The appropriate retention period depends on the dataset, applicable jurisdiction and organizational policy. The lifecycle models do not establish one universal retention period or require every dataset to be kept indefinitely.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why lifecycle models differ

Lifecycle models serve different purposes, so their stages should not be treated as competing universal checklists.

Model Scope Stage design Storage and sharing End of life
NIST information life cycle General information management Broad activities: creation or collection, processing, dissemination, use, storage and disposition Storage is a named stage; dissemination and use are named activities Disposition includes destruction and deletion
NIST Research Data Framework (RDaF) 2.0 Research data management Six detailed stages: Envision; Plan; Generate/Acquire; Process/Analyze; Share/Use/Reuse; Preserve/Discard Storage choices are addressed in planning and management; sharing, use and reuse have a dedicated stage Preservation and discarding are paired in the final stage
UK Government Data Quality Framework Data quality across the lifecycle Describes the span from collection to dissemination and archival or destruction Emphasizes planning processes and storage before collection and use Includes archival and destruction

Sources: NIST CSRC information life cycle glossary, NIST RDaF 2.0, and the UK Government Data Quality Framework.

What a lifecycle framework does—and does not—decide

A lifecycle model helps people assign responsibility and make connected decisions about quality, documentation, storage, access and end of life. It does not decide by itself whether a dataset should be public, how long it must be retained, or which controls apply. Those choices depend on the data, its purpose, applicable obligations and organizational policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.