Earlier quoted context omitted.
I’m in Europe on vacation, and while GDPR seems to be a good thing, there is nothing more annoying than a cookie policy pop up for every single site you visit. I know what cookies are. I know how they are used. I don’t need a reminder every time I visit a site. I think they way over shot their goal there.
The stupid thing is that GDPR says nothing about requiring those policy pop ups, that law was discontinued (amended) when GDPR took effect. But no requirements for these pop ups remain
It's covered by PECR. There's a good overview of the rules here: https://ico.org.uk/for-organisations/guide-to-pecr/cookies-a...
The main change GDPR brought to it (as I understand it) is that it introduced stricter rules about how consent works. But even though GDPR doesn't specifically require cookie warning, it does require that you get informed consent from people before you store personally identifiable information about them; in many cases this effectively means getting their permission before using tracking cookies.
So tl/dr, it's primarily PECR that covers cookie handling, but GDPR also plays a role.