@drmasterchief That's because it's neither based on the GDPR nor on the old Data Protection Directive, but on the ePrivacy Directive. Also, one needs to differentiate between cookies that are necessary to perform a service explicitly requested by the user (no consent required) and cookies not necessary (consent required).
Furthermore, already back in 2014, the Dutch issued a fine of 25,000 EUR for a failure to solicit a cookie consent: https://www.cookielaw.org/blog/2014/12/19/dutch-cookie-law-fine-is-largest-so-far/