The web has become a sad place where most of the content is made for showing you ads and tracking you around, therefore tracking cookies are needed, therefore tracking cookie permission banners are displayed.
I mean, in theory they could do that retroactively, but that would be waaay to complex.
Popular cookie banners enable services by executing their javascript. There's no event tracking mechanism whatsoever. Cringe fact about cookie banners.
It's probably because every engineer spends as little time as possible on it, since it's boring af. It's annoying & boring to implement, and once it's done, annoying to everyone that sees it.
Correct (speaking as someone who worked in an adjacent area).
On Android, it uses blink (Chromium)
This extends to many areas, including e-mail, if they are required to deliver your services you may just save them. However, you may not use the e-mail to send newsletters. Of course, you want to double opt-in e-mails in any case unless you don't mind false or malicious entries and being labeled as a spammer. But that has nothing to do with the GDPR.
* the type of data is of importance when we are talking about data breaches and fines. Losing e-mail addresses is bad, losing prescriptions is much worse.