Policy Pros
Written by Joanne Hughes, Policy & Compliance SpecialistLast reviewed

Policies and Procedures for the Public Sector

This page is for councils, government agencies and other public bodies that need their policy frameworks in order. Policy Pros writes bespoke policies and procedures for local authorities, arm's-length bodies, town and parish councils and public sector organisations across the UK, covering HR, data protection, IT security and health and safety.

Public bodies carry obligations that private companies do not: freedom of information, the public sector equality duty, and scrutiny from auditors, inspectors and elected members. The documents behind those obligations need to stand up to that scrutiny, which means accountability and audit readiness are built into everything we write.

Bespoke, audit-ready policies from £65 + VAT per document. Get a quote or call 020 3951 2875 for a free scoping conversation.

Policies Public Sector Organisations Need

  • Health and Safety Policy Statement - required in writing once you have 5 or more employees (Health and Safety at Work etc. Act 1974)
  • Data Protection Policy and privacy notices - UK GDPR and the Data Protection Act 2018 require you to demonstrate compliance, and public authorities must appoint a Data Protection Officer
  • Data Protection Complaints Procedure - a new duty under the Data (Use and Access) Act 2025, in force for controllers from 19 June 2026
  • Freedom of Information Policy and publication scheme - the Freedom of Information Act 2000 sets a 20 working day response deadline and requires a publication scheme approved by the Information Commissioner
  • Subject Access Request Procedure - public bodies handle high volumes of requests and need a documented process to meet the statutory deadlines
  • Equality Policy and published equality objectives - the public sector equality duty (Equality Act 2010, section 149) comes with specific publishing duties for listed authorities
  • Records Management and Information Security Policies - expected by internal audit and external assessors, and the backbone of FOI and data protection compliance
  • Whistleblowing Policy - standard governance for public bodies, giving staff a safe route to raise concerns before they become failures
  • Complaints Policy - a published, staged procedure is expected by ombudsman schemes and elected members alike
  • Anti-Bribery and Gifts and Hospitality Policy - the Bribery Act 2010 makes adequate procedures the defence, and registers of gifts and interests are standard public sector practice
  • Procurement Policy and contract standing orders - your internal rules for spending public money under the Procurement Act 2023

Freedom of Information and Transparency

Every public authority must answer FOI requests promptly and within 20 working days, and must adopt and maintain a publication scheme approved by the Information Commissioner. Both duties come from the Freedom of Information Act 2000, and both fail in practice without a written procedure that names who logs requests, who applies exemptions and who signs off responses.

An FOI policy also protects your team. When a refusal reaches the ICO, the first thing reviewed is whether you followed a defensible process.

Data Protection Duties Are Heavier for Public Bodies

Public authorities must appoint a Data Protection Officer under Article 37 UK GDPR, publish their contact details and notify them to the ICO. The ICO's DPO guidance sets out the role, and our data protection policy service writes the framework the DPO oversees, including a subject access request procedure built for high request volumes.

The Data (Use and Access) Act 2025 layers new duties on top. From 19 June 2026 every controller must operate a formal data protection complaints procedure, and our DUAA complaints procedure guide explains what it must contain. Our employer guide to the DUAA changes and privacy notice update guide cover the rest of the Act's staged commencement.

Procurement, Tenders and Supplier Requirements

Public bodies sit on both sides of procurement. As contracting authorities they run competitions under the Procurement Act 2023, in force since 24 February 2025, and our Procurement Act supplier guide and public sector tender documents guide explain the regime and the documents buyers ask suppliers to evidence.

Central government procurement also applies the social value model under PPN 002 and requires Carbon Reduction Plans for major contracts under PPN 006, and buyers routinely ask for modern slavery statements. Our guides to social value tender answers, Carbon Reduction Plans under PPN 006 and modern slavery statements for tenders cover each requirement. Arm's-length bodies and council trading companies that bid for work themselves can use our tender and RFP support service.

Equality, Accountability and Conduct

The public sector equality duty requires listed authorities in England to publish equality information annually and equality objectives at least every four years, and public bodies with 250 or more employees also publish gender pay gap figures each year. Our equality and diversity policy service writes the policy layer that sits behind those publications.

Governance documents carry the same weight in the public sector as statutory ones. Our whistleblowing, complaints and anti-bribery policy services cover the conduct framework auditors and ombudsman schemes expect to see.

Health and Safety and IT Security

The Health and Safety at Work etc. Act 1974 requires a written health and safety policy once you have 5 or more employees, and public bodies also owe duties to service users, contractors and visitors across offices, depots, schools and public spaces. Our health and safety policy service writes statements, arrangements and risk assessment frameworks around your actual sites and services.

Public bodies hold data that makes them a standing target for cyber attack, and many now require Cyber Essentials of their own suppliers. Our IT security policies service and Cyber Essentials policies service cover the documentation, from information security policy to incident response.

Public Sector Policy and Procedure Writers

Policy Pros writes bespoke documents around your organisation, services and governance structure, not a generic template with your logo on it. You get a fixed-price quote before any work starts, review rounds are included, and finished documents arrive on professionally branded templates ready for committee, cabinet or audit.

Tell us whether you need a single policy updated or a full framework built, and we will scope exactly what you need with no obligation. Get a quote or call 020 3951 2875.

Frequently Asked Questions

What policies does a public sector organisation legally need?

The statutory core is a written health and safety policy once you have 5 or more employees, data protection documentation under UK GDPR and the Data Protection Act 2018 including an appointed Data Protection Officer, a freedom of information procedure and publication scheme under the Freedom of Information Act 2000, and published equality information and objectives under the public sector equality duty.

From 19 June 2026 the Data (Use and Access) Act 2025 also requires a formal data protection complaints procedure. Beyond statute, auditors and ombudsman schemes expect whistleblowing, complaints, anti-bribery and records management policies as standard governance.

Do public bodies have to appoint a Data Protection Officer?

Yes. Article 37 UK GDPR requires every public authority or body to appoint a Data Protection Officer, with the only exception being courts acting in their judicial capacity. You must publish the DPO's contact details and notify them to the ICO.

The DPO oversees compliance, but the policies, procedures and records they rely on still have to be written. That framework is what we build.

What is changing for public bodies under the Data (Use and Access) Act 2025?

The Act received Royal Assent on 19 June 2025 and is being brought into force in stages. The change with the hardest deadline is the complaints duty: from 19 June 2026 every controller must operate a formal procedure for handling data protection complaints from individuals.

Privacy notices, subject access processes and records may also need updating as the staged commencement continues. Our DUAA guides cover each change in detail.

Do you work with smaller public bodies such as town and parish councils?

Yes. Many of our public sector clients are smaller bodies without in-house policy teams, where the clerk or a small officer team carries the whole compliance load. The legal duties, from freedom of information to data protection, apply regardless of size.

We scope what you actually need, quote a fixed price per document before starting, and include review rounds so the final versions fit how your organisation really works.

Trustpilot Reviews - 5 Stars