The ePrivacy Directive (aka the cookie directive) also required you to be able to opt out. It was pretty explicit, too:
"Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 95/46/EC, inter alia about the purposes of the processing, and is offered the right to refuse such processing by the data controller."
The problem was that some member states cooked up an "implied consent" interpretation, according to which visitors can be assumed to have consented.
The difference between the GDPR (and the new ePrivacy Regulation, which most likely is going to address the issue directly) is that they're regulations; they're directly applicable EU law, not law that has to be transposed into local law by the member states. The EU Commission is also given enforcement powers; and, if I read the upcoming ePrivacy Regulation correctly, can also go after the adtech companies directly rather than the site owners (because ignoring lack of consent is done at the adtech level rather than by site owners, as opposed to a failure of providing a consent mechanism).
I also wouldn't put too much emphasis on the GDPR; while it's likely to cause compliance trouble for adtech companies, the ePrivacy Regulation is more directly applicable.
The first question could be: are you in the EU?
yes -> no access
no -> access, but with tracking
So, basically training users to lie about their location.
Just to be clear - it's about EU citizens, not EU located-people, and your location can change. You have to ask if they're EU citizens.
This feels to me as not a lawyer as something that will only be clear after precedent is set.
I for one don’t want to be a test case.
Most companies just moved the site to their non-eu parts and handled it with internal cost centers. The ones that couldn't do that or that had to show EU sold ads are the ones stuck with the cookie "OK-only" popups.
And dont forget that the next regulation is ePrivacy regulative which might fix workarounds like you are proposing.
The idea of GDPR is about human rights and if you are having a problem with protecting them, than I think GDPR is not a problem, you are.
Showing targeted ads to EU people is only valuable because someone somewhere expects to sell stuff to EU people based on those ads; behavior data about EU people is only valuable because someone somewhere expects to use that data to get money from those people.
The end users (potential buyers) of that data will need to be GDPR compliant, because they'll be trading with EU and thus have a presence in EU - and they will have to show that they got all that data in a compliant manner and had consent for that. All the major advertisers with all their money won't be able to legally buy or use "tainted" data for which they have no GDPR-style consent, so they won't.
So if USAdCo has no presence in EU, and has been "paid with data", then it's been paid in a worthless currency - EU companies won't/can't buy that data, worldwide companies like CocaCola or Netflix or Amazon or other USA companies who have EU customers won't/can't buy that data since they have EU presence and will need to be compliant, and USA companies who don't have EU customers won't buy that data since it's not valuable to them.
What good is all that data if you can't really use or sell it? It's not enough for you to be out of GDPR reach, you also need your main partners to be out of GDPR reach; since if you're trading information that might contain private data, and they want to be compliant, guess what - they'll require you to be compliant as well, since they can't simply say "oh, they sold us that data, it's their problem", they're fully responsible.
When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
So GDPR does not say its illegal, just that it will be determined on case by case basis.
For legal experts, is this facebook consent obtaining GDPR compliant ?
https://www.facebook.com/legal/terms/update
By using or accessing Facebook Services, you agree that we can collect and use such content and information in accordance with the Data Policy as amended from time to time.
Simply having a term in the general conditions fails the "a clear affirmative act" part.
Saying "use such content" fails the "informed and specific" part - it needs to detail exactly what uses (explicitly listing each) you're consenting to; and it doesn't list the purpose of the use, which is a key part ("When the processing has multiple purposes, consent should be given for all of them")
If facebook has obtained your consent for one (or hundred and one) use-case, it does not mean that it can use it for something else simply by amending ("from time to time") the Data Policy, it would need to get additional explicit, affirmative (opt-in), informed consent to the new processing need of your information.