There’s a lot of conflation between the 2003 EU Cookie Directive, and the GDPR. The cookie directives specified a technical means (“cookies”) and actions that needed to be taken in order to use them. The GDPR specifies the ends (collecting and/or processing personal information) and the conditions (explicit and freely given consent), stating that anything achieving those ends must meet the conditions. It’s a much better written law than the 2003 Cookie Directive, because it avoids the need to irritate users for legitimate use cases, while also preventing legal loopholes (e.g. “We didn’t use a cookie, just the browser’s localStorage feature.”)