A secondary, but similar, issue, is that now all embeds are opt-in: streams, videos, everything must first be clicked on to even load the thumbnail.
A third, and less-important, issue is that advertising providers are basically over: the website, on load, can't query the third-party ad service to figure out what ad to display. Which I'm fine with, abstractly, but it's also a very large revenue issue.
This is fairly fundamental under GDPR. It's the 'data controller'/'data processor' split.
I suspect (but IANAL of course) that most CDNs would fail here, because the blanket agreements they offer are basically worthless.
But it's easy to imagine a CDN that has a different business model (charges a tiny amount pr. resource stored, for example), and is completely fine under the GDPR.
But who knows what else google does? The "privacy info" for site owners using google fonts says nothing about what they use any collected data for.
When you share personal data about your visitors with a data processor, you need an agreement that specifies how that data is treated.
Any CDN that is owned/operated/subsidiary in full within countries that have legal GDPR protections in place, such as member states of the EU, would be fine to use — but that rules out Cloudflare, Akamai, etc.
(I am not your lawyer, this is not legal advice.)