Your role
As a Corporate Counsel, Product & Privacy, you'll be a trusted, largely independent legal advisor on how Dialpad's AI-powered products intersect with privacy, security, customer protection, and related regulatory obligations. You'll work closely with Product, Engineering, Security, Marketing, Sales, and Customer Success to embed legal judgment directly into how our products are designed, launched, and scaled. You'll help build the frameworks, playbooks, and guardrails that keep Dialpad a trustworthy, enterprise-ready AI platform, and find creative, practical solutions for novel legal questions where no template exists.
This position reports to our Deputy General Counsel and may be based in our San Francisco, CA (preferred) office. You'll join a collaborative legal team alongside dedicated product, privacy, and telecom legal resources, supported by a strong network of outside counsel and cross-functional partners.
What you'll do
- AI governance & product counseling – Advise Product and Engineering on privacy-by-design and AI governance considerations across the product lifecycle. Help build and maintain legal frameworks covering AI training data, LLM data use, model governance, and compliance with the EU AI Act, US state AI laws, and FTC guidance.
- Global privacy & data protection – Support Dialpad's global privacy program (GDPR/UK GDPR, CCPA/CPRA, HIPAA, and biometric privacy laws including BIPA and relevant state voice/voiceprint statutes). Own day-to-day administration of the data subject access request program, maintain DPIAs and RoPAs, support cross-border transfer mechanisms (SCCs, UK IDTA, EU-US DPF), and serve as on-call counsel for data incidents, including breach response and required notifications.
- Telecom & regulatory coordination – Partner with Dialpad's Telecommunications & Regulatory Counsel on call-recording and consent issues that intersect with product features (transcription, AI notetaking, real-time coaching) and on CIPA/wiretap-adjacent product questions. Stay conversant in FCC/TCPA/911/USF fundamentals to spot issues early and route them to the right owner, without holding primary responsibility for telecom regulatory strategy.
- Security partnerships & certifications – Partner with Security and GRC on certifications (ISO 27001, SOC 2, PCI, HIPAA) and help design privacy-enhancing controls, including automated redaction, anonymization, and access governance.
- Commercial & marketing enablement – Support DPA and BAA negotiations, advise Sales on privacy- and product-related contract terms, and counsel Marketing on TCPA, CIPA, web tracking, consent signals, and digital advertising compliance.
- IP & legal operations – Participate in the Patent Review Board, support litigation holds and records-retention practices, contribute to internal policies, and help build resources that turn complex regulations into practical, usable guidance for the business.
Skills you'll bring
- J.D. from an ABA-accredited law school; license in good standing to practice law in at least one U.S. state.
- 5–8 years of substantive privacy, product-counseling, and regulatory experience, ideally including time at a law firm with a technology or privacy practice plus in-house experience at a SaaS or technology company.
- Working knowledge of GDPR, CCPA/CPRA, and HIPAA, including privacy-by-design principles and cross-border data transfer mechanisms.
- Familiarity with AI legal frameworks (EU AI Act, US state AI legislation, FTC priorities) and demonstrated interest in developing deeper expertise as the landscape evolves.
- Experience advising Product and Engineering teams directly, including translating complex legal requirements into clear, actionable guidance for non-legal audiences.
- Some exposure to FCC/TCPA/VoIP regulation, call recording, or telecom/voice-AI compliance is a plus, though this role is not expected to own telecom regulatory strategy.
- Experience supporting incident response and breach notification under U.S. state laws and/or GDPR.
- CIPP/US, CIPP/E, or equivalent privacy certification is a plus.