If you have a project that doesn't allow users to enter any kind of information but simply displays ads (via Adsense), is that in scope for GDPR or is a proper Privacy Policy enough?
Do you set cookies that are required? Need to identify them and inform the user.
Server logs? You probably have ip addresses. Despite what us nerds think the EU considers them personal data.
I run the site behind cloudflare and don't store X-Forwarded-For IP, the analytics software I use immediately anonymizes them before storing them. So I should be fine I hope.
Isn’t GDPR fun?