SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Nelly is building an AI-driven financial operating system for European healthcare, automating administrative processes from patient care through billing and payments. The company has raised over €50M in Series B funding and is solving critical challenges in healthcare delivery and practice management.
As Legal Counsel for Data Privacy & Compliance, you will own how Nelly approaches data protection—not as a gatekeeper, but as an integrated part of product development. You'll work at the intersection of highly sensitive patient data and rapid product innovation.
Key responsibilities include:
- Independently review, develop, and establish internal data protection processes and documentation
- Guide new products from a data privacy perspective and establish necessary legal frameworks
- Advise all teams across the company on data protection and compliance questions
- Identify and resolve data protection risks and legal issues
- Serve as the central point of contact for customers and internal teams on all privacy matters
You'll need a law degree (Staatsexamen or Master's in business law) and 1–3 years of in-house data privacy experience. Strong knowledge of GDPR, German data protection laws (BDSG), European Health Data Space (EHDS), and healthcare-specific regulations (DiGAV, SGB V) is essential. You must have strong product and technology understanding—able to quickly grasp APIs, cloud infrastructure, and data flows to shape privacy-compliant architecture decisions. Fluent German and English (written and spoken) required.
The company offers flexible working hours, hybrid setup, up to 4 weeks workation, 28 days vacation (increasing to 30), €500 annual L&D budget, Urban Sports Club membership, Deutschland-Ticket or Swapfiets, and a dog-friendly office with strong team culture.