Privacy & Product Counsel

Hilbert's AISan Francisco, CA
Hybrid

About The Position

Hilbert is seeking a Privacy & Product Counsel to build and lead the company's privacy program from within the product. This role requires fluency in US, UK, and European privacy laws and the ability to operate with the speed and ownership of a startup culture. The successful candidate will be the first dedicated privacy hire, embedded with product and engineering teams to design agentic systems that handle consumer data. This role also serves as a generalist backstop for various legal questions. The position involves designing and running the privacy program end-to-end, including policies, data mapping, retention, and vendor management, while also handling product and commercial legal work for an AI platform sold into enterprise accounts. The environment is characterized by high autonomy and ambiguity, with rapidly evolving data types, customer environments, and AI capabilities outpacing settled law.

Requirements

  • 6–7 years of PQE in privacy and product/commercial counsel, ideally split between in-house work at a data-intensive or AI company and enterprise contract negotiation.
  • Genuine fluency across US, UK, and EU privacy law — CCPA/CPRA and the state patchwork, UK GDPR/DPA 2018, and EU GDPR.
  • Experience negotiating enterprise DPAs, security addenda, and cross-border transfer mechanisms directly.
  • Ability to communicate with clarity and conviction, explaining complex legal concepts to diverse audiences.
  • Takes ownership and closes gaps in the privacy program or finds paths through stuck deals.
  • Ability to move at startup speed, being available and responsive without extensive legal-ops processes.

Nice To Haves

  • Thinks like a product person, not just a lawyer; prefers shaping data flows before they are built.
  • Genuine generalist, not just a specialist willing to help out.

Responsibilities

  • Design, build, and run Hilbert's privacy program - policies, data mapping, retention, and vendor/subprocessor management - from the ground up, covering both US and UK/EU entities and data flows.
  • Advise product and engineering on privacy-by-design for agentic workflows: what data an agent can access, retain, infer, or act on, and how that's documented and defensible under whichever regime applies.
  • Own compliance posture across CCPA/CPRA and the US state privacy patchwork, UK GDPR/DPA 2018, and EU GDPR, and track how state, federal, UK, and EU AI-specific rules are developing.
  • Build and maintain data processing agreements, international data transfer mechanisms (SCCs, UK IDTA/Addendum), and subprocessor frameworks that scale across enterprise customers without a bespoke redline every time.
  • Review and negotiate enterprise customer contracts, DPAs, and security addenda across US and UK/EU counterparties, working closely with sales to keep deals moving without compromising the company's data commitments.
  • Advise product on how new agentic features get built, marketed, and disclosed — including where an AI decision needs a human-in-the-loop checkpoint for legal or trust reasons.
  • Partner with security on incident response, breach notification obligations, and customer-facing security representations across jurisdictions.
  • Be the primary point of contact for enterprise customers' legal, security, and procurement teams when they ask how Hilbert's AI handles their data.

Benefits

  • Competitive salary + equity package
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service