About cookies, the relevant law is ePrivacy 2002/58/CE, article 5(3), which says you don't need to ask for consent for “strictly necessary” cookies. In practice, this means session ID cookies, user preferences, etc. This also applies to local storage or any other way to store and retrieve data on a user's device.
The issue is not that the law is unclear, it's people that can't help but speculate on its content even though they never read it. Google is full of links to this, and HN is bad in this regard. And to be honest, this is not exclusive to GDPR.
I've found Stackexchange law and /r/gdpr to be okay-ish. Otherwise, there is a guide on the commission's website, there is gdpr.eu, there is the commented version of GDPR on gdprhub.eu:
https://commission.europa.eu/law/law-topic/data-protection/r... https://gdpr.eu/ https://gdprhub.eu/index.php?title=Article_1_GDPR
You can find a lot of advice on various DPAs website (ICO, and even the CNIL publishes stuff in english sometimes).
https://ico.org.uk/for-organisations/direct-marketing-and-pr...