
Privacy Counsel
400M+ downloads. 75M+ monthly users. A decade of building – and we’re still accelerating.
Flo is the world’s #1 health app on a mission to build a better future for female health. Backed by a $200M investment led by General Atlantic, we became the first product of our kind to reach a $1B valuation in 2024 – and we’re not slowing down.
With 6M paid subscribers and the highest-rated experience in the App Store’s health category, we’ve spent 10 years earning trust at scale. Now, we’re building the next generation of digital health – AI-powered, privacy-first, clinically backed – to help our users know their body better.
The job
Legal and Compliance are partners across the whole business here at Flo. They watch over everything: Flo’s privacy programme, compliance with regulatory obligations, contract management, IP enforcement… you name it.
The team’s divided into three groups - Privacy & Data Protection, Regulatory & Compliance, and Legal Services, each managing its own area.
This role’s all about delivering Flo’s continued commitment to privacy by design and default.
Reporting to our VP of Privacy, it sits as part of a team of 5 doing some really exciting work.
Having achieved our ISO 27701 Privacy certification (the first business of our kind with it!), and having launched Anonymous Mode (also making it open source), we’re continuing to embed privacy into our product and internal processes, and focus on protecting the rights and freedoms of our customers.
We’re looking for a Privacy Counsel who’s eager to roll up their sleeves and act as a trusted advisor on all things data protection. You’ll need to bring curiosity, tenacity, and a strong sense of ownership to the table—plus a willingness to learn how privacy really works in a product-led business. This is a hands-on role with exposure to real product, commercial, and operational work. You’ll work closely with team members while also building relationships with engineering, product, and commercial stakeholders.
Your Experience
Must have:
- Qualified solicitor in the UK with experience (usually 1-3 years’ PQE) in a privacy and data protection position.
- Proven track of work in a tech company, software focussed product company or reputable law firm.
- Knowledge of data protection laws globally (including the US).
- Practical experience in privacy by design.
- Experience of privacy risk management.
- Ability to explain legal topics in plan, simple and actionable language.
- Knowledge of OneTrust, miro, JIRA, Confluence.
Nice to have:
- CIPP certifications (CIPP/E, CIPM, CIPT, CIPP/US or others).
- Knowledge of agile methodologies.
- Proven track of work in a health tech, digital health or digital wellness company.
- Experience working with software Engineers, Marketing teams and Product Managers directly.
- Experience implementing AI tooling to enhance legal team efficiencies.
What you'll be doing
You'll be responsible for:
- Providing privacy and data protection advice to the business.
- Providing guidance on new product features.
- Supporting team members on advice relating to online advertising practices and AI technologies.
- Giving guidance to ensure data protection is baked into the design, build, test and deployment stages across activities and departments.
- Carrying out Data Protection Impact Assessments , and providing solutions to mitigate privacy risks.
- Contributing to our core integrated Information Security and Privacy Management System (ISPMS) processes, including maintaining framework documents and other ISPMS documented information.
- Assisting with the creation and delivery of staff training and Privacy Champion Network communications on privacy best practice.
- Undertaking legal research on emerging privacy and data protection laws and guidance, and horizon scanning for regulatory updates.
- Working to ensure that data protection and best practices are fully integrated into Flo’s compliance framework.
- Adopting a curious approach to privacy-enhancing technologies and helping to set up new tooling from a privacy perspective.
You'll be targeted on:
- Successfully providing pragmatic business-oriented and compliant privacy solutions to the company on various topics such as: consent management, privacy assessments, digital marketing and user rights.
- Being a proactive team player that delivers on assigned targets, with a positive and collaborative approach.
- Successful rollout of educational and partnering sessions for various stakeholders (including product and marketing).
#LI-JC1 #LI-Hybrid
Annual Salary Range (ranges may vary based on skills and experience)
£60,000 - £90,000 GBP
How we work
We’re a mission-led, product-driven team. We move fast, stay focused and take ownership – from brief to build to impact. Debate is encouraged. Decisions are shared. We care about craft, ship with purpose, and always raise the bar.
You’ll be working with people who take their work seriously, not themselves. It takes commitment, resilience, and the drive to keep going when things get tough. Because better health outcomes are worth it.
What you'll get
We support impact with meaningful reward. Here’s what that looks like:
- Competitive salary and annual reviews
- Opportunity to participate in Flo’s performance incentive scheme
- Paid holiday, sick leave, and female health leave
- Enhanced parental leave and pay for maternity, paternity, same-sex and adoptive parents
- Accelerated professional growth through world-changing work and learning support
- Flexible office + home working, up to 2 months a year working abroad
- 5-week fully paid sabbatical at 5-year Floversary
- Flo Premium for friends & family, plus more health, pension and wellbeing perks
Diversity, equity and inclusion
Our strength is in our differences. At Flo, hiring is based on merit, skill and what you bring to the role – nothing else. We’re proud to be an equal opportunity employer, and we welcome applicants from all backgrounds, communities and identities. Read our privacy notice for job applicants.
Apply for this job
*
indicates a required field