> A brick and mortar doesn't need your consent to track you on cctv
GDPR is superseded by more specific laws, of course. For example, you can use CCTVs for security, but you also have to prominently display a notice that the store uses CCTV cameras. Also, you cannot store that data indefinitely long, you can't sell it to other parties etc.
So, can websites track and log their users? Yes. Can they sell that data to a million ad agencies? No. Can they use that data to track the user to their home? No.
> The law is just a bad idea poorly executed
The law is an amazing idea. The poor execution is purely on the part of companies (and also developers like you) who have become so used to collecting all the data they can wholesale that they can't even imagine not doing it.
> like what if I use cookies to store the fact that people don't want to be tracked so I don't pester them with the notice?
So, save that cookie, there's literally nothing stopping you from doing that.
> If the EU wanted to ban tracking users they could easily have just wrote that into law
That's basically what they did: you can't collect personal user information that's not required for the functioning of your business without consent. This literally prevents tracking.