https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
>3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
The directive:
(1) does not target cookies, but methods to store information, or gain access to information stored;
(2) allows strictly necessary purposes without consent or popups;
(3) requires consent for other purposes.
The directive talks about cookies in recital 25, but only as an example.
The GDPR replaces the Data Protection Directive (Directive 95/46/EC), and along that, references made to it in ePrivacy. But it does not bring anything new about cookies.
Though, I agree with you: the GDPR is well made–apart from the litigation part, but that's going to change with the GDPR Procedural Regulation. ePrivacy is good too, but 5(3) aged poorly, unfortunately.