One way to think of it is that “a business” is not “a user tracking, ad targeting website.” Whatever the business is, it’s not equal to the website, which is just one means of distribution of information or content.
If the business was so predicated on user tracking and selling that data or using it to target ads, I think GDPR (in spirit) is saying “that’s not a business” and requiring a greater form of transparency and informed consent before a website can inflict that on a (possibly unwitting) user.
I’m not trying to say this point of view is right or wrong, just that I think there is a spirit here in the intention of GDPR to say “that’s not something we’ll allow to be called a business model.” (Obviously it doesn’t fully go that far, but it’s the idea.)
It’s not that different in spirit than regulating usury or payday loan businesses. If your business model profitably works only because it preys on people, the spirit of the regulation is to say, “that’s not a business model,” and regulate or disallow it. Usury laws in the case of excessive short-term interest rates; GDPR in the case of excessive user tracking and data privacy concerns.
So when you ask, “how can be a business sustainable in this way?” it sort of has the wrong premise.
Instead, if the business could not be profitable without this then it wasn’t actually ever a business— rather it was some other data exploitation entity, and the lack of an alternate way to be profitable in compliance with GDPR is a signal that the entity was unable to determine a way to exist without causing the kinds of harm that GDPR aims to prevent.
Again, I’m just trying to represent what I think the spirit is behind the GDPR choices— not saying they were right or wrong.