It's not exactly complicated. Either get rid of their tracking cookies (why does a news website need tracking cookies to view an article?), or get consent before they use them.
People don't want to stop tracking their users and so they feign like it's some insanely complex law. It's not complex at all, it's just one that made the thing you used to do illegal, and you need to stop doing it, or get consent before you do it.
If maintaining a persistent session is somehow in the user's interest (say, maintaining an account at a store or online forum or something) then that's a legitimate-business-use exception. If it's for tracking/advertising/etc, then ask for consent, or presumptively don't do it. It's really not complex at all, unless you're being aggressively ignorant about it.
> In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. 3Whereas the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.
If this local newspaper isn't offering translations in French or German, and isn't offering subscriptions in Euro or GBP, then they're not ofering services to Europe.
With ad networks and IP logging does this requirement of erasing and copies become more onerous?
The only effect the gdpr have is creating endless popups on all sites to accept cookies.
This does not make any sense, because browsers already have setting to block cookies, and users that had even a slightest in cookies had opportunity to use one of many browser extensions to further control the way cookies were stored.
I see gdpr as an effect of beurocrats not understanding the field they are trying to regulate, and trying to implement the wish of a vocal minority.
To address comments of the type "It is difficult to get a man to understand something, when his salary depends upon his not understanding it." I have never worked for a company that uses adds or tracking cookies in any way.
(you can, of course, serve generic ads instead, if they opt out, or serve generic ads by default and not show a popup at all)