Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Policy development · Public sector & education

Privacy & Security Policy Development for Public Agencies & Crown Corporations

Privacy Horizon drafts the internal privacy and security policy suite a public body needs to operationalize its statute and the central directives above it, from breach procedures that reflect the TBS Appendix B playbook to retention schedules that finally empty decades-old file shares. Policy work usually begins when a commissioner's guidance, a directive update or a new statutory duty exposes how far current documents lag reality.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What agency policies have to govern in practice

Policies in this niche are working instruments read by ATIP coordinators, claims staff and auditors, so each one must resolve the situations those people actually face.

Collection tied to legal authority

Public bodies collect under statutory mandates, not consent, so policies must anchor every program's collection to its authority and keep purposes from drifting as programs evolve.

Case files and adjudicative records

Handling rules for hearing materials, investigation files and claims records must balance openness principles, procedural fairness and the privacy of parties and complainants.

Employee data across generations of systems

HR archives holding SINs and banking detail need retention and disposition rules with teeth; the Toronto Zoo incident reached staff records from 1989 because nothing ever required their destruction.

Disclosures, sharing and consistency of use

Information-sharing with ministries, law enforcement and other institutions needs documented gates, so a well-meaning disclosure never becomes the subject of a commissioner's finding.

AI and automated decisions

Staff use of AI tools and any automated decision-making need policy coverage aligned to the OPS AI Directive, the IPC-OHRC principles, or the federal directive's Algorithmic Impact Assessment regime.

Regulatory map

The instruments your internal policies must mirror

An agency's policy suite is judged against the central-government framework that binds or steers it, which makes drafting a mapping exercise as much as a writing one.

TBS Policy on Privacy Protection

Federal institutions' internal documents must implement the policy's material-breach definition, 7-day reporting duty and PIA publication expectations, in force since October 9, 2024.

Primary source →

Directive on Privacy Practices

The directive's PIA triggers for new or modified administrative programs and its Appendix B breach procedures are the skeleton for a federal body's privacy operating procedures.

Primary source →

FIPPA and the IPC's expectations

Ontario agency policies must operationalize the s. 38(3) PIA-before-collection rule, the safeguards duty, RROSH notification and the access regime, all under IPC review powers gained in 2025.

Primary source →

The Agencies and Appointments Directive layer

Ontario provincial agencies' security policies should trace to GO-ITS 25.0 and related OPS standards, and procurement-adjacent policies to the OPS Procurement Directive.

Primary source →

Provincial AI instruments

The OPS Responsible Use of AI Directive from December 2024 and the IPC-OHRC principles released January 21, 2026 set the reference points an Ontario agency's AI policy must reflect.

Primary source →

BC and Alberta program requirements

FOIPPA s. 36.2 privacy management programs and Alberta's POPA program requirement both presuppose documented policies, procedures and review cycles as the program's visible core.

Primary source →

What goes wrong

Where weak policies become findings against agencies

Commissioners rarely fault public bodies for lacking documents; they fault them for documents that did not govern anything.

  • Practices a commissioner calls unreasonable

    Nova Scotia's MOVEit investigation concluded the government lacked reasonable security and information practices, a finding built on the gap between written expectations and operational reality.

    Source →

  • Retention rules that exist only on paper

    When disposition never actually runs, every breach is amplified by years of data that should not exist; Toronto Public Library's incident touched 8,018 staff and dependants partly for this reason.

    Source →

  • Vendor clauses regulators now dissect

    The IPC's PowerSchool investigation scrutinized contract terms and oversight practices, signalling that policy-level vendor requirements are now tested against what agreements actually say.

    Source →

  • Ungoverned AI experimentation

    Staff adopting generative tools ahead of policy puts case files and personal information into services no directive has cleared, creating exposure that surfaces at the worst possible time.

Our policy development for public agencies & crown corporations

The policy suite we build for public bodies

Deliverables follow our policy development service, adapted to the instruments and audiences of a board-governed institution.

Two data analysts Working on data analysis dashboard for business strategy
  1. Custom privacy and security policies

    Core documents reflecting how your body actually operates: collection and use, safeguards, access and correction, breach response, and acceptable use, each traceable to your statute and directives.

  2. ATIP and FOI operating procedures

    Request handling, exemption decision support, fee and timeline management including Ontario's 45-business-day clock, and coordination between access and privacy streams.

  3. Retention and disposition schedules

    Rules by record class with named owners and disposal mechanics, designed so old HR, claims and program data is destroyed on schedule instead of accumulating in shares.

  4. Employee and vendor-facing standards

    Guidelines that put data-handling duties into role language for staff, and baseline security and privacy expectations you can attach to vendor agreements.

  5. AI use policy

    Boundaries for staff AI use and automated decision-making mapped to the directive regime your government applies, including assessment gates before deployment.

  6. Update and review cycle

    A managed revision rhythm so policies track directive amendments, statutory milestones and machinery changes rather than fossilizing at version 1.0.

How the engagement runs

How agency policy engagements unfold

  1. Step 1

    Instrument mapping

    We catalogue every statute, TBS or OPS instrument, MOU commitment and commissioner guidance your policies must satisfy, and audit existing documents against that inventory.

  2. Step 2

    Drafting with your operators

    Policies are written with the ATIP coordinator, records staff, IT and counsel in the room, so procedures describe workflows people recognize and will follow.

  3. Step 3

    Governance approval

    We prepare the package for executive sign-off and, where your framework requires it, board or committee endorsement, with a briefing note that explains what changed and why.

  4. Step 4

    Rollout and upkeep

    Launch communications, quick-reference materials and a scheduled review cycle turn approved documents into operating practice.

What it costs

Cost drivers for agency policy suites

Scope sets the price: how many instruments your suite must mirror, whether you need the full stack or targeted gaps like retention and AI, the number of programs and record classes involved, and how heavy your approval process is. A federal Crown with subsidiaries and published PIA summaries needs more drafting and mapping than a single-program provincial tribunal.

After reviewing your current documents and obligations inventory we quote a fixed fee for the defined suite, with the option to fold ongoing revisions into a retainer so the documents stay current between engagements.

Public Agencies & Crown Corporations: Policy development questions, answered

Federally: the Policy on Privacy Protection, the Directive on Privacy Practices including its Appendix B breach procedures, the Directive on Automated Decision-Making if you automate decisions, and, for PGS-covered entities, the Policy on Government Security. In Ontario: FIPPA itself, GO-ITS 25.0 via the Agencies and Appointments Directive, the OPS Procurement Directive and the Responsible Use of AI Directive. We build a traceability matrix so every internal policy clause points at the instrument it satisfies.

It reads as one system rather than two silos: a shared intake and records-location procedure, access handling with exemption decision support and statutory timelines, privacy procedures covering collection authority, PIAs, safeguards and breach response, and one accountability map naming the head of the institution's delegates. Defensibility comes from three properties commissioners test: the documents match your statute's current text, they describe practices you can evidence, and someone demonstrably maintains them.

Start from what exists, not what should: a scan of shares, archives and legacy systems to find the oldest personal information you hold. Then set retention by record class with a legal basis for each period, name an owner for disposition, and build destruction into an actual calendar with sign-off. The proof of a working schedule is disposal certificates, not the schedule document. Given that a 2024 ransomware incident exposed one agency's staff records dating to 1989, this is the single highest-value policy most bodies can ship.

Yes, and in Ontario the framework already exists to write it against: the OPS Responsible Use of AI Directive and the IPC-OHRC principles define transparency, oversight and rights-protection expectations. Federal bodies must also respect the Directive on Automated Decision-Making, which required legacy automated systems to be compliant by June 24, 2026. A short, enforceable policy that names permitted tools, prohibited inputs like case files and personal information, and an approval gate beats an aspirational framework nobody applies.

Substantially. A commercial Crown corporation writes for customer accounts, marketing boundaries, OT operations and market-facing vendor chains, with board committees approving and ministry oversight reading. A tribunal writes for parties, hearings, decision publication and small-office realities where one person wears three hats. The statutes may even differ. We size the suite to the body: a tribunal gets fewer, tighter documents rather than a scaled-down copy of a utility's binder.

Expect it during any investigation. Ontario's IPC gained explicit review powers over agency practices with the 2025 FIPPA amendments, the OPC examines federal institutions' practices and receives their PIAs, and breach investigations in every jurisdiction begin with a request for your policies, procedures and evidence they operated. The PowerSchool investigation shows the depth now applied to contract and oversight documentation. Well-built suites shorten investigations; hollow ones become the finding.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.