Unfortunately, the tech industry as a whole decided instead of finding a way to work in a more privacy conscious way it was far easier just to exhaust users so that they didn't have to change anything.
We ended up with cookie rules because regulators were concerned about the use of cookies to create user profiles based on activity across multiple websites, especially for "evercookies"/"zombie cookies" where a user's cookieID would be resurrected even after a user deleted them. Instead of banning zombie cookies or cross-site tracking, the EU instead decided it was a violation of user privacy to place any cookies or other data files on the user's machine without their consent.
The actual language is "Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information."
Cookie consent boxes are implemented at the website level because the law applies to website publishers, not browser makers. Website publishers were explicitly told that they cannot rely on a user's browser settings. This put the browsers in the back seat and ended up with today's world where you have to opt out of a service provider like Google Analytics on a site-by-site basis.
The vast, vast majority of users do not touch cookie settings. There are probably more users running scripts to disable cookie popups than there are users opting in or out of specific cookies.
It is an odd world where websites bend over backward to make cookie popups that actually work knowing full well users do not care. The average user doesn't really know much about cookies, much less the wide variety of activities powered by cookies. Cookie consent popups are publicly available, making them easy targets for regulatory audits. Ireland ran a huge sweep and sent out letters to a number of large companies telling them to clean up their act by October or else. We are a few weeks away from seeing what the "or else" will be.
I'm happy to answer any other questions you have on this.
If the cookies do not involve personal data, then GDPR does not apply, and a popup/pushdown/modal with text, a link, an accept button, and a reject button is all you need.
If the cookies do involve personal data (e.g., IP address), then GDPR applies. For cookies where GDPR applies, the legal requirements depend on the purpose for using the cookie. Wach purpose for using cookies requires its own consent. For example, cookies used for analytics require separate consent from cookies used for third party advertising. If a website only used cookies for a single purpose, the consent window could be pretty small. If there are multiple purposes, it's basically going to be a privacy policy just for cookies.
There are several billion dollar lawsuits against online adtech because it's not clear under GDPR whether anonymous but unique cookieIDs are personal data. If they are, the entire industry violates GDPR.
Here are the rules from the ICO's website, UK's privacy regulator: https://ico.org.uk/for-organisations/guide-to-data-protectio...
The problem is there is no enforcement of these rules despite the potential for huge fines.
Not because they use cookies, but because they show a full-screen pop-up that I have to read through or simply accept what it is saying without reading. Whenever I get a cookie pop-up I just close the site.
I hate a lot more the time and brain power wasted on dealing with cookie pop-ups than the cookies themselves.
But aside from that, they are completely useless and just making the web less enjoyable