The article shows the use of third-party solutions none of which are GDPR compliant: not the cookie banners, not the data storage, not CDNs. And every step of the way the authorities explained all the issues and waited for solutions (quote, google translate, "There was neither a court judgment nor a fine actually imposed.")
As a business you are responsible for user data. You can't use some third-party business, point at them and say "it's them who are responsible, not me". The responsibility of properly handling user data is yours.
GDPR was adopted in 2016, 6 years ago. You'd think this was enough time to learn it by heart by now, or at least not make mistakes about the simple core things of the law. It's not as big, or as hard, or as ambiguous as people who have never even read it make it out to be.