That regulation would not have come into existence if there were no privacy problems caused by the ones that have to comply to the regulations
But the GDPR and ePrivacy directives don't protect us from nefarious cross-site tracking cookies.
Prior to the GDPR, websites just tracked us.
Now they track us AND present an irritating warning that users have learnt to mindlessly "accept"