How is this crazy? Server administrators could have done, and have done anything on their side of the code. Nothing changed on this front since the invention of the HTTP request.
They explicitly and aggressively facilitate practices that virtually every single person is against.
The outside world is more apathetic than hostile to it.
Just to enphasise: for GDPR it really doesn't matter where your data is shared with a third party, from the browser or server. It's your data so they have to ask your permission to share it and otherwise they can't.
To illustrate my point, here's a Stackoverflow question from nearly 10 years ago: https://stackoverflow.com/questions/11795477/using-google-an...
Whatever trust was ever there, it was false.