Why GDPR website questions are rarely just document questions
This page is designed to give high-level, practical guidance only. Exact obligations can depend on how your website operates, the technologies it uses, the audiences it serves and the way the underlying business model works in practice.
When businesses ask about GDPR for websites, the concern often starts with documentation but quickly turns into operations. What forms are present? What information is collected? What tools are installed? Which providers receive data? What is the purpose of each collection point? Do consent or choice mechanisms match the actual journey?
That means the stronger question is not simply whether a privacy notice exists. It is whether the live website, its tools and the public-facing explanations still match each other in a way that is coherent and evidence-led.
This is also why websites drift. Marketing tools get added. Forms change. Support systems evolve. Booking or checkout flows are rebuilt. A document is left behind. The result is often not obvious until someone reviews the whole picture.
If you want a quicker operational view, use the compliance estimator. If you want a broader entry page first, use check your website compliance.