Agreed. It isn't the third party that is the issue - it is the separate purpose.
For example, if I access a web page, I'm giving my IP address to the server, so that it knows how to sent the data I just asked for back. That IP address is personal information, but it is necessary for the server to fulfil the purpose of the task I just asked for. That server also gives the IP address to a third party - the router in between it and me. That's also necessary, because otherwise the packets can't be routed, and it's fine legally.
However, if the company running the web page were to take that IP address and store it and use it for deep analytics, matching my request up to other requests from the same IP address, then the personal data has not been handed over to a third party, but it is being used for a purpose which requires consent, and would be illegal unless that consent had been obtained. That data use isn't necessary for the original purpose of the task I asked for, which is to serve me a web page - it is a separate purpose.