Perhaps. Though with GDPR the framework is intentionally vague on a lot of things. You often hear about limits and design requirements and such, well those don't exist. They are just legal "best guesses" with the frameworks inherent goal as a guide. Nobody knows whether default configs are disallowed as long as opt-in is positive action. The current best guesses for that vary and all that's known in GDPR in that regard is that there must be positive user opt-in with a good faith effort of informing the user. In this sense google likely thought they were satisfying this requirement.
It can be argued and should because the arguments laid out in this discussion set precedence that acts as a more concrete requirement that sits on top of GDPR. Basically imo this could be a very interesting set of arguments that mean changes to a huge amount of websites.