You can use cookies for necessary operations of the website, which this almost certainly is. Also, country level location data isn't PII, and also doing a geoip lookup that you don't store anywhere also isn't in violation.
However, you have a clear and stated use case for processing that PII so consent is not required, but you are required to mention this processing in your privacy policy. Not publishing this processing is (strictly speaking) a violation of the GDPR, but the processing itself isn't.
From Recital 26 (https://gdpr-info.eu/recitals/no-26/):
> The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable.