You need consent for every kind of storage usage on client side if you create profiles to analyze the them for marketing goals. If not, and no PII is being processed, no consent is required. Eg you could easily aggregate your server logs without a consent.
But if you use the data for analytics purposes, you do need the users' consent for that, even if it's the same data that you use for operational purposes.
That's not correct; if you collect PII, even if you don't use it, you need consent. Actually, if you don't have a legitimate use for the data, you are prohibited from collecting it at all.
GDPR isn't an assault on online marketing; it's about privacy.
We're not. And that's exactly the point, because we don't want to track. I make a distinction between tracking, analyzing and stats. What we do is guess who are the unique visitors (and who are not), and I say guess because it's guesswork since the browser can spew out any kind of info.
Cookies you require for functionality (ie. login cookies, language settings) require no consent, but do require to be laid out in a cookie policy.
Printed newspapers are disappearing. Ad supported news sites need tracking for ad targeting otherwise there isn't enough ad revenue to support their business.
Supermarkets are a bad example here because they are a critical link in the distribution economy.
Google? Not so much