You need consent for every kind of storage usage on client side if you create profiles to analyze the them for marketing goals. If not, and no PII is being processed, no consent is required. Eg you could easily aggregate your server logs without a consent.
But if you use the data for analytics purposes, you do need the users' consent for that, even if it's the same data that you use for operational purposes.
That's not correct; if you collect PII, even if you don't use it, you need consent. Actually, if you don't have a legitimate use for the data, you are prohibited from collecting it at all.
GDPR isn't an assault on online marketing; it's about privacy.
We're not. And that's exactly the point, because we don't want to track. I make a distinction between tracking, analyzing and stats. What we do is guess who are the unique visitors (and who are not), and I say guess because it's guesswork since the browser can spew out any kind of info.
Cookies you require for functionality (ie. login cookies, language settings) require no consent, but do require to be laid out in a cookie policy.
Printed newspapers are disappearing. Ad supported news sites need tracking for ad targeting otherwise there isn't enough ad revenue to support their business.
Supermarkets are a bad example here because they are a critical link in the distribution economy.
Google? Not so much
A privacy-conscious serverside GTM/GA implementation won't leak any personal data like IP address to Google, but there's no way to avoid sending the GCLID if you advertise.
A lot of companies are dependent on Google Ads for demand generation, so it's the reason they are sticking with GA even as the writing's on the wall.
Processing of your users' personal data is legal only in the few exceptional scenarios outlined in Article 6.
So "exceptional" in the sense that they are exceptions to a more general rule, as of opposed to the sense of being extraordinary.
Send me a hello email at the address listed on my profile, would be happy to send out an invite when ready.