Manage digital public records during system migration and when decommissioning
When managing digital public records over time, you may need to consider migrating them, particularly when refreshing storage media or when a business system reaches end of life or is replaced.
During any system migration process there is an increased risk of digital records and metadata being lost or corrupted and their integrity and authenticity being compromised. Careful planning, testing and quality assurance checks will help reduce risks and ensure that digital public records remain authentic and accessible in the new system.
Assess the risks based on the:
- value of the digital public records (e.g. retention status in a current disposal authorisation)
- new system's ability to capture all required information (e.g. the migrated records, metadata and other contextual information)
- ability to ensure the integrity and authenticity of digital public records (e.g. no data loss as a result of migration activities)
- file formats and the impact on usability and longevity of the digital public records
- potential risks to the accessibility and usability of digital public records.
Make sure decisions about acceptable levels of risks and risk mitigation are clearly documented.
The decommissioning business systems workflow and methodology 446.7 KB) will help you when migrating records or decommissioning business systems. It provides a transparent and defensible process for assessing the value of public records in business systems and determining the best strategy for managing them. Use this guidance alongside your ICT governance and change processes.
When to use this guidance
Use this process when digital public records need to be migrated or a business system containing public records is being retired, replaced or decommissioned.
Common situations include when records in the system:
- have already been migrated to another system
- are no longer accessible
- are accessible but not covered by a retention and disposal authorisation
- are accessible and covered by a retention and disposal authorisation.
More than one situation may apply within a single system.
Steps to migrate public records when decommissioning a business system
Confirm which public authority is responsible for the records contained in the system.
Responsibility usually sits with the authority that:
- created the records
- inherited the records through a machinery-of-government change
- is responsible for the function or business activity the records document
- otherwise controls the records.
Responsibility for records may be separate from ownership of the system itself. A public authority may still control records even where another entity operates or hosts the system. Control may exist where the authority has possession or custody of the records, or has the legal right or responsibility to access, manage or preserve them.
For example, a shared service provider may operate a system that contains records belonging to multiple public authorities.
If the system contains records belonging to other public authorities, involve them in the decommissioning process and obtain agreement before any disposal decisions are made.
If the responsible public authority cannot be identified, contact Queensland State Archives before disposing of any records.
Conduct an initial assessment to understand what the system contains and what can be retrieved.
Identify whether records:
- remain in the system
- can be accessed and used
- have already been migrated to another system.
This initial scan will help you determine which pathways to follow for managing the records.
A system being obsolete, unsupported or difficult to access does not, by itself, authorise disposal. If the records are no longer accessible, this may mean records are lost or damaged and will require further discussion with QSA
Assess whether the records in the system are covered by a current and approved disposal authorisation issued by the Queensland State Archivist.
You can do this by identifying:
- the business function the system supports
- the activities and transactions captured by the system
- the types of records produced or stored.
Records that cannot be matched to an approved disposal authorisation are not eligible for disposal until an appropriate disposal authorisation is established. In some cases, a special appraisal decision may need to be sought.
Consider disposing of any digital public records that are eligible for disposal beforehand. This can reduce the risks and complexity of migration or decommissioning processes. Permanent value records can be transferred to the QSA Digital Archive to ensure they are preserved long-term and protected from any future system migration.
Where records need to be migrated, the migration should be planned and tested before it occurs. This will help minimise the time and intervention required during migration, maintain an unbroken chain of custody and protect the authenticity and reliability of the records.
Where possible, involve or seek guidance from your IT support area.
The migration should be reversible. Establish and test a roll-back strategy in case problems arise. This allows digital public records to remain protected and business processes to resume in the old system until another migration is attempted.
Before migration, confirm that the new system or storage environment can manage the records appropriately. Consider what technology requirements and recordkeeping functionality are needed to support the records for as long as they need to be retained.
Also consider the potential impact on staff and the business, including access to records, records management activities and business continuity.
When migrating digital public records, make sure you migrate the metadata and contextual information needed to keep the records accessible, meaningful and reliable.
This may include:
- recordkeeping metadata for all digital public records being migrated
- metadata and control records for related physical public records
- metadata about records that are not being migrated, including inactive or legacy records
- disposal information for records that have already been destroyed or transferred
- any other information essential to the meaning, management or use of the records.
Where metadata or contextual information is stored outside the system, make sure those connections are retained after migration.
After migration, check that recordkeeping information remains accurate and unchanged, including dates used for recordkeeping actions, disposal triggers and disposal information.
If records have been migrated to another system, confirm that the migration was successful before disposing of source records or decommissioning the source system.
As a condition for disposal of migrated source records , your public authority must have developed and documented a defensible process for migration, including appropriate quality assurance checks.
At a minimum, quality assurance checks should confirm that:
- all intended records are present in the target system
- record content is complete and unaltered
- metadata, attachments and contextual relationships remain accurate
- records remain accessible and usable
- integrity checks have been carried out where appropriate.
Evidence of migration checks, results and approvals must be retained for the life of the records under Disposal Authorisation 1137 Data quality and integrity validation in the General Retention and Disposal Schedule (GRDS).
Use the quality assurance checklist for decommissioning business systems 147.3 KB) to help document these outcomes as well as the disposal decisions for any source records.
Under Disposal Authorisation 2942 Digital source records post migration in the Source Records Retention and Disposal Schedule all migration outcomes must be verified, documented, and then approved by your public authority’s Chief Executive, or their authorised delegate with disposal responsibilities, before any disposal of source records can take place.
Document all disposal decisions, including:
- the records that were disposed of
- the disposal authorisation relied upon
- the date disposal occurred
- who approved the disposal
- the quality assurance checks completed beforehand.
Records of disposal decisions need to be retained for a minimum period of 50 years after the disposal of the related record, as per Disposal Authorisation 1131 Record destruction documentation in the General Retention and Disposal Schedule (GRDS).
Follow your ICT governance processes to retire the system once records have been appropriately managed.
This guidance focuses on managing the records during system decommissioning. Technical, security and operational activities should be managed through your internal ICT processes.
Do not decommission a system containing public records until records have been migrated, retained, transferred or disposed of in accordance with an approved disposal authorisation.
Records that have not been migrated must continue to be managed for as long as they are required.
Ensure storage arrangements support:
- ongoing access
- security requirements
- integrity monitoring.
Plan for technology change by scheduling periodic migration activities to ensure records remain complete, accessible and usable.