Cookies aren't really mentioned in GDPR or other privacy laws, folks just latched onto cookies as one area that can track users. But really, all personal data is subject to most of the privacy laws, including outbound requests as well as stored data.
IANAL. But for context from lawyers, see: https://ico.org.uk/for-organisations/direct-marketing-and-el...
A web server’s logs may include the IP and http request they’ve made, but once you start attaching that to an identity instead it might count as data processing.
> ‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
One can use the “legitimate interest” basis (recital 49 may be relevant here) or “compliance with a legal obligation” for logging.
Third parties may wish to store information on the equipment of a user, or gain access to information already stored, for a number of purposes, ranging from the legitimate (such as certain types of cookies) to those involving unwarranted intrusion into the private sphere (such as spyware or viruses). It is therefore of paramount importance that users be provided with clear and comprehensive information when engaging in any activity which could result in such storage or gaining of access. The methods of providing information and offering the right to refuse should be as user-friendly as possible. Exceptions to the obligation to provide information and offer the right to refuse should be limited to those situations where the technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user. Where it is technically possible and effective, in accordance with the relevant provisions of Directive 95/46/EC, the user’s consent to processing may be expressed by using the appropriate settings of a browser or other application. The enforcement of these requirements should be made more effective by way of enhanced powers granted to the relevant national authorities.
- ePrivacy Directive which is about local storage
- GDPR which is about information processing