Policy development · Public sector & education
Privacy & Security Policy Development for Public Agencies & Crown Corporations
Privacy Horizon drafts the internal privacy and security policy suite a public body needs to operationalize its statute and the central directives above it, from breach procedures that reflect the TBS Appendix B playbook to retention schedules that finally empty decades-old file shares. Policy work usually begins when a commissioner's guidance, a directive update or a new statutory duty exposes how far current documents lag reality.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What agency policies have to govern in practice
Policies in this niche are working instruments read by ATIP coordinators, claims staff and auditors, so each one must resolve the situations those people actually face.
Collection tied to legal authority
Public bodies collect under statutory mandates, not consent, so policies must anchor every program's collection to its authority and keep purposes from drifting as programs evolve.
Case files and adjudicative records
Handling rules for hearing materials, investigation files and claims records must balance openness principles, procedural fairness and the privacy of parties and complainants.
Employee data across generations of systems
HR archives holding SINs and banking detail need retention and disposition rules with teeth; the Toronto Zoo incident reached staff records from 1989 because nothing ever required their destruction.
Disclosures, sharing and consistency of use
Information-sharing with ministries, law enforcement and other institutions needs documented gates, so a well-meaning disclosure never becomes the subject of a commissioner's finding.
AI and automated decisions
Staff use of AI tools and any automated decision-making need policy coverage aligned to the OPS AI Directive, the IPC-OHRC principles, or the federal directive's Algorithmic Impact Assessment regime.
Regulatory map
The instruments your internal policies must mirror
An agency's policy suite is judged against the central-government framework that binds or steers it, which makes drafting a mapping exercise as much as a writing one.
TBS Policy on Privacy Protection
Federal institutions' internal documents must implement the policy's material-breach definition, 7-day reporting duty and PIA publication expectations, in force since October 9, 2024.
Directive on Privacy Practices
The directive's PIA triggers for new or modified administrative programs and its Appendix B breach procedures are the skeleton for a federal body's privacy operating procedures.
FIPPA and the IPC's expectations
Ontario agency policies must operationalize the s. 38(3) PIA-before-collection rule, the safeguards duty, RROSH notification and the access regime, all under IPC review powers gained in 2025.
The Agencies and Appointments Directive layer
Ontario provincial agencies' security policies should trace to GO-ITS 25.0 and related OPS standards, and procurement-adjacent policies to the OPS Procurement Directive.
Provincial AI instruments
The OPS Responsible Use of AI Directive from December 2024 and the IPC-OHRC principles released January 21, 2026 set the reference points an Ontario agency's AI policy must reflect.
BC and Alberta program requirements
FOIPPA s. 36.2 privacy management programs and Alberta's POPA program requirement both presuppose documented policies, procedures and review cycles as the program's visible core.
What goes wrong
Where weak policies become findings against agencies
Commissioners rarely fault public bodies for lacking documents; they fault them for documents that did not govern anything.
Practices a commissioner calls unreasonable
Nova Scotia's MOVEit investigation concluded the government lacked reasonable security and information practices, a finding built on the gap between written expectations and operational reality.
Retention rules that exist only on paper
When disposition never actually runs, every breach is amplified by years of data that should not exist; Toronto Public Library's incident touched 8,018 staff and dependants partly for this reason.
Vendor clauses regulators now dissect
The IPC's PowerSchool investigation scrutinized contract terms and oversight practices, signalling that policy-level vendor requirements are now tested against what agreements actually say.
Ungoverned AI experimentation
Staff adopting generative tools ahead of policy puts case files and personal information into services no directive has cleared, creating exposure that surfaces at the worst possible time.
Our policy development for public agencies & crown corporations
The policy suite we build for public bodies
Deliverables follow our policy development service, adapted to the instruments and audiences of a board-governed institution.

Custom privacy and security policies
Core documents reflecting how your body actually operates: collection and use, safeguards, access and correction, breach response, and acceptable use, each traceable to your statute and directives.
ATIP and FOI operating procedures
Request handling, exemption decision support, fee and timeline management including Ontario's 45-business-day clock, and coordination between access and privacy streams.
Retention and disposition schedules
Rules by record class with named owners and disposal mechanics, designed so old HR, claims and program data is destroyed on schedule instead of accumulating in shares.
Employee and vendor-facing standards
Guidelines that put data-handling duties into role language for staff, and baseline security and privacy expectations you can attach to vendor agreements.
AI use policy
Boundaries for staff AI use and automated decision-making mapped to the directive regime your government applies, including assessment gates before deployment.
Update and review cycle
A managed revision rhythm so policies track directive amendments, statutory milestones and machinery changes rather than fossilizing at version 1.0.
How the engagement runs
How agency policy engagements unfold
Step 1
Instrument mapping
We catalogue every statute, TBS or OPS instrument, MOU commitment and commissioner guidance your policies must satisfy, and audit existing documents against that inventory.
Step 2
Drafting with your operators
Policies are written with the ATIP coordinator, records staff, IT and counsel in the room, so procedures describe workflows people recognize and will follow.
Step 3
Governance approval
We prepare the package for executive sign-off and, where your framework requires it, board or committee endorsement, with a briefing note that explains what changed and why.
Step 4
Rollout and upkeep
Launch communications, quick-reference materials and a scheduled review cycle turn approved documents into operating practice.
What it costs
Cost drivers for agency policy suites
Scope sets the price: how many instruments your suite must mirror, whether you need the full stack or targeted gaps like retention and AI, the number of programs and record classes involved, and how heavy your approval process is. A federal Crown with subsidiaries and published PIA summaries needs more drafting and mapping than a single-program provincial tribunal.
After reviewing your current documents and obligations inventory we quote a fixed fee for the defined suite, with the option to fold ongoing revisions into a retainer so the documents stay current between engagements.
Public Agencies & Crown Corporations: Policy development questions, answered
Federally: the Policy on Privacy Protection, the Directive on Privacy Practices including its Appendix B breach procedures, the Directive on Automated Decision-Making if you automate decisions, and, for PGS-covered entities, the Policy on Government Security. In Ontario: FIPPA itself, GO-ITS 25.0 via the Agencies and Appointments Directive, the OPS Procurement Directive and the Responsible Use of AI Directive. We build a traceability matrix so every internal policy clause points at the instrument it satisfies.
It reads as one system rather than two silos: a shared intake and records-location procedure, access handling with exemption decision support and statutory timelines, privacy procedures covering collection authority, PIAs, safeguards and breach response, and one accountability map naming the head of the institution's delegates. Defensibility comes from three properties commissioners test: the documents match your statute's current text, they describe practices you can evidence, and someone demonstrably maintains them.
Yes, and in Ontario the framework already exists to write it against: the OPS Responsible Use of AI Directive and the IPC-OHRC principles define transparency, oversight and rights-protection expectations. Federal bodies must also respect the Directive on Automated Decision-Making, which required legacy automated systems to be compliant by June 24, 2026. A short, enforceable policy that names permitted tools, prohibited inputs like case files and personal information, and an approval gate beats an aspirational framework nobody applies.
Substantially. A commercial Crown corporation writes for customer accounts, marketing boundaries, OT operations and market-facing vendor chains, with board committees approving and ministry oversight reading. A tribunal writes for parties, hearings, decision publication and small-office realities where one person wears three hats. The statutes may even differ. We size the suite to the body: a tribunal gets fewer, tighter documents rather than a scaled-down copy of a utility's binder.
Expect it during any investigation. Ontario's IPC gained explicit review powers over agency practices with the 2025 FIPPA amendments, the OPC examines federal institutions' practices and receives their PIAs, and breach investigations in every jurisdiction begin with a request for your policies, procedures and evidence they operated. The PowerSchool investigation shows the depth now applied to contract and oversight documentation. Well-built suites shorten investigations; hollow ones become the finding.
More for public agencies & crown corporations
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.