Legal Counsel - Datenschutz und Informationssicherheit (w/d/m)
Posted on September 24, 2025 (about 2 hours ago)
General Information
Reports to: Philip Ihde, Chief Operating Officer
Talent Partner: Celia Nielsen, People & Talent Partner
Salary Band:
IC L1 Junior: 49-57k € + VSOP (5% of annual gross salary)
IC L2 Mid-Level: 64-76k € + VSOP (10% of annual gross salary)
Remote Policy: Remote-first culture with offices in Berlin and Hamburg
Talent Partner: Celia Nielsen, People & Talent Partner
Salary Band:
IC L1 Junior: 49-57k € + VSOP (5% of annual gross salary)
IC L2 Mid-Level: 64-76k € + VSOP (10% of annual gross salary)
Remote Policy: Remote-first culture with offices in Berlin and Hamburg
Your Mission
HelloBetter is a pioneer in digital healthcare, developing evidence-based digital health applications for mental health conditions including stress management, depression, problematic alcohol use, panic disorder, anxiety, vaginismus, and sleep disorders. Six applications are approved as digital health applications and available free by prescription for insured adults in Germany. The Legal Counsel plays a key role in data protection and information security, providing expert legal guidance and operational management of data protection and information security systems ensuring compliance with GDPR, DiGAV, and other relevant regulations. The role requires a fully qualified lawyer with a strong background in data privacy law, proactive and organized approach, and a commitment to fostering a culture of security and compliance within the organization.
Your Objectives
Data Protection Management:
- Legal guidance and oversight of the data protection management system including retention policies, Data Protection Impact Assessments,Technical and Organisational Measures, and processing activities records.
- Driving data protection certification process per Article 42 GDPR (when available).
- Responding to data subject requests timely and accurately from various channels.
- Main contact for external Data Protection Officer.
- Legal support for ISMS management and monitoring (ISO 27001), including supplier management, incident management, and risk management.
- Advice on implementing information security norms and standards organization-wide to ensure legal and regulatory compliance.
- Organizing, conducting, and following up on internal and external audits including implementing improvements.
- Main contact for external Data Protection Officer.
- Monitoring legal and regulatory developments in data privacy and information security and providing updates and recommendations to management.
- Developing, implementing, improving, and monitoring training programs on data privacy and information security for employees.
- Contributing to a quarterly leadership newsletter focusing on GDPR and relevant topics.
- Drafting, reviewing, and negotiating various commercial contracts with a focus on data processing, supplier, and technology license agreements.
- Providing pragmatic legal advice on contract law, corporate governance, and other legal issues to various teams.
- Providing legal expertise on internal projects related to data protection and information security.
- Collaborating with cross-functional teams to embed "privacy and security by design" principles in new projects and initiatives.
- Participating in industry groups and forums to stay updated on best practices and emerging legal trends.
Your Profile
Must-Haves:
- Law degree (at least 1st state exam) or equivalent European qualification.
- 3+ years post-qualification experience in data protection or technology-focused legal roles, in-house or at law firms.
- Experience managing and maintaining data protection management systems and/or providing legal counsel on information security management systems including audits.
- Extensive experience handling data subject requests and managing security/privacy incidents legally.
- Excellent organizational and project management skills to manage multiple tasks and deadlines.
- Strong communication and negotiation skills for technical and non-technical collaboration.
- Proactive, solution-oriented mindset with attention to detail.
- Fluent in English and German (written and spoken, legal and business proficiency).
- Recognized certification in data protection or information security.
- Experience in healthcare or technology sectors.
- Experience with legal ticket management and supplier relationship management.
- Keen interest in legal and ethical AI implications.
Why Us?
Meaningfulness
Privacy Policy for Applicants
- Mental health is a human right: helping thousands with depression, stress, insomnia, burnout, and other issues monthly.
- Unique product, leading in digital health application research.
- Effectiveness continuously evaluated and published in top journals since 2014.
- Data is crucial and transparent about strategy, goals, and outcomes.
- Pioneers in applications for mental health, leading innovation.
- Exciting, emerging market.
- Annual training budget of 1,000 euros supporting employee personal growth.
- Remote-first culture, global hiring with +/- 4.5 hours CET window.
- Offices in Berlin and Hamburg available for on-site preference.
- Relocation support available.
- Equal treatment under Anti-Harassment Policy.
- Flexible work hours.
- English company language emphasizing inclusive language.
- Transparent salary bands.
- Additional 10 paid leave days for non-birth parents after child birth or adoption.
- 28 vacation days plus weekend holiday compensation.
- Tenure-based additional paid leave up to three days.
- Permanent employment contract.
- Attractive VSOP equity plan for employees.
- Above-average employer pension plan contribution.
- Free or subsidized fitness memberships.
- Regular team events.
Privacy Policy for Applicants
Interview Process
1. Screening Interview with People team (30 min)
2. Take-home Case Study (2 hours)
3. Case Study & Technical Interview with Legal team (60 min)
4. Hiring Manager Interview with Philip, Chief Operating Officer (60 min)
5. Offer Talk (15 min)
2. Take-home Case Study (2 hours)
3. Case Study & Technical Interview with Legal team (60 min)
4. Hiring Manager Interview with Philip, Chief Operating Officer (60 min)
5. Offer Talk (15 min)
About Us
HelloBetter, founded in 2015 as GET.ON Institut für Online Gesundheitstrainings GmbH by internationally recognized researchers and psychologists, develops and evaluates online programs for mental health prevention and treatment in cooperation with various universities including Harvard. Six therapy programs are approved as digital health applications by the German Federal Institute for Drugs and Medical Devices and are available on prescription free for insured adults in Germany. The expert team's work is published in international journals including The Journal of the American Medical Association and recognized with various awards. The company is based in Berlin and Hamburg with over 130 employees.
How to Apply
Thank you for your interest in HelloBetter and our commitment to advancing digital mental health. To proceed with your application, please complete the short form.
Submit your CV in English or German. You may include a cover letter, certificates, letters of recommendation, or other significant documents.
Your total file size should not exceed 20 MB. Files must be in PDF or JPG format; Word documents are not accepted.
For any difficulties, contact [email protected].
Submit your CV in English or German. You may include a cover letter, certificates, letters of recommendation, or other significant documents.
Your total file size should not exceed 20 MB. Files must be in PDF or JPG format; Word documents are not accepted.
For any difficulties, contact [email protected].