Maybe it's time that frameworks like Django and Rails make it easier to be GDPR compliant from day 1. ASP.NET Core has APIs and templates for this:
https://docs.microsoft.com/en-us/aspnet/core/security/gdpr?v...
https://docs.microsoft.com/en-us/aspnet/core/security/gdpr?v...
The first step in being GDPR compliant is not installing a tracking library in your project. Web frameworks have no control over that.
These built-in templates for cookie popups are a joke, IMO.