Start your 7-day free trial, card not charged until it ends

Compliance

Website Compliance for Legal Teams: Reviewing a Site That Changes Daily

· 9 min read

Legal approves the website once. Marketing edits it every week. How approved wording drifts, why the CMA has raised the stakes, and how to close the gap without becoming the website police.

By the TLDTrack team, part of FullyCoded, a working UK web agency.

Here is the uncomfortable truth about website sign-off: legal approves a snapshot, and then marketing keeps publishing. The wording you reviewed in March is not the wording that is live in July. Somebody strengthened a claim, deleted a "boring" disclaimer, launched a landing page that never crossed your desk, or let an old promotion keep running long after its terms changed.

This is not a people problem, it is a process problem: legal review is periodic, websites change continuously. This guide covers what actually drifts, why the regulatory stakes have gone up, and how legal and compliance teams are using automated monitoring to close the gap without becoming the website police.

The approval gap

Most organisations have decent controls at launch: legal reviews the site, the claims, the terms, the privacy policy. The gap opens afterwards, because the website is edited by people optimising for conversion, not compliance, and every edit is a chance for approved wording to quietly disappear:

  • Claims get stronger over time. "Helps improve" becomes "improves" becomes "guaranteed". Each edit looked harmless to the person making it.
  • Disclaimers and footnotes get deleted. They are the first casualty of every redesign, because to a designer they are clutter.
  • Pages nobody remembers stay live. Old campaign landing pages with expired offers, superseded terms, or pricing that no longer exists.
  • Legal pages get edited without legal. A well-meaning colleague "tidies up" the terms or pastes a template privacy policy over the bespoke one.
  • Sustainability claims creep in. "Eco-friendly", "carbon neutral", "100% recyclable", added by marketing in good faith, each one a green claim that needs substantiation.

Why the stakes have risen

Two shifts make website wording a live legal risk rather than a housekeeping issue. First, UK regulators have moved from guidance to enforcement on marketing claims: the CMA's Green Claims Code set clear expectations on environmental claims, and the Digital Markets, Competition and Consumers Act gave the CMA the power to fine businesses directly, up to 10 percent of global turnover, for unfair commercial practices, no court case required. Misleading claims on a website sit squarely in scope.

Second, the ASA has become systematic: it actively monitors online advertising at scale, and a website page is advertising. Add sector regimes on top, health claims, financial promotions (which we cover in a separate guide for finance teams), and the website is often the largest unreviewed surface the business publishes.

What "monitoring" means for a legal team

The fix is not more sign-off meetings. It is making the website report its own changes, so legal reviews what changed instead of re-reading everything, or worse, finding out from a regulator's letter. In practice that is four layers:

1. Change alerts on the pages that matter to you

Terms, privacy policy, cookie policy, pricing pages, key product claims pages. Any edit triggers a notification showing exactly what changed. Ten seconds to read, and nothing on those pages moves without you knowing. This is standard content monitoring.

2. Must-contain rules

The approved disclaimer, the mandatory wording, the required footnote: encode each as a rule that says "this page must always contain this text". The day a redesign drops it, you get an alert, not a complaint.

3. Policy-based checks on everything else

The newer layer, and the one that changes the game for legal teams: give the system your actual policies, the claims you never make, the wording standards, the tone rules, the sustainability position, and AI-powered checks read every page against them, flagging content that contradicts what you have stated. TLDTrack's compliance checks work exactly this way: upload the policy documents, and each scan judges the site's real content against your rules, so "marketing added a guarantee we do not offer" surfaces as a finding, not a surprise.

4. An evidence trail

Every check, change and resolution is logged. When a regulator, insurer or acquirer asks "what controls do you have over published claims?", you have a running record of oversight rather than a shrug. Demonstrable monitoring is itself a mitigating factor in most enforcement regimes.

A workflow that does not make legal the bottleneck

  1. Write down the rules you actually enforce. Most teams have them scattered across email threads and memory. A one-page claims policy is enough to start.
  2. Put the crown jewels on change alerts: legal pages, pricing, top product pages.
  3. Encode the must-never and must-always wording as rules.
  4. Run policy checks on a schedule and treat findings like a review queue: confirm, fix, or update the policy.
  5. Keep the log. It is your audit trail and your renewal-conversation evidence in one.

None of this replaces legal judgement, the point is that judgement gets applied to a short list of real changes instead of an unreadable whole. For the broader foundation, cookie consent, company information, accessibility, see our plain-English website compliance guide. And as ever: this is practical guidance, not legal advice.

01 · Questions

Frequently asked questions

Can automated checks replace legal review?

No, and they should not try. What they replace is re-reading: instead of periodically reviewing an entire website, legal reviews a short queue of actual changes and flagged contradictions. The judgement stays human; the detection becomes continuous. That combination is faster for marketing and safer for the business than either pure sign-off or pure trust.

Which pages should a legal team monitor for changes?

Start with the pages carrying legal weight: terms and conditions, privacy and cookie policies, pricing pages, product pages making claims, and campaign landing pages. Add must-contain rules for any mandated wording, disclaimers, footnotes, regulatory statements, so their removal triggers an alert rather than waiting for the next review cycle.

What counts as a misleading green claim?

Under the CMA's Green Claims Code, environmental claims must be truthful, clear, substantiated, and must not omit important information; vague terms like "eco-friendly" or "sustainable" without evidence are the classic failure. With the CMA now able to fine unfair commercial practices directly, unsubstantiated green wording added casually by marketing is a genuine financial risk, and worth a banned-phrases rule of its own.
Mark Grice, founder of TLDTrack

Mark Grice, founder of TLDTrack. Runs FullyCoded, a Cornwall web agency, and built this to keep 500+ client sites in front of him every day.

What happens next

Put this on autopilot

Do it yourself

Start your free trial

TLDTrack runs every check in this guide automatically across all your client sites and alerts you the moment something changes. Your card is not charged for 7 days.

Start your free trial

Talk it through

Arrange a call with Mark

If you would rather talk through how this works across every site you look after, we can go through it together.

Book a call

See every check TLDTrack runs