Earlier quoted context omitted.
No, it is just client storage. The law is explicitly only about client storage: >Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 9…
It is GDPR and not PECR that sites responded to with the cookie banners that we deal with today, and GDPR covers a much broader surface area ("processing of personal data")
What happened when the GDPR came in was twofold:
1. Everyone became acutely aware of data protection legislation, because the GDPR actually had teeth when it came to enforcement.
2. The ePD referenced the Data Protection Directive, and when the GDPR came in to force all references to the DPD became references to the GDPR.
The consequence of #2 is that the hand-wavy "implicit consent" that sites relied on to avoid cookie banners (why show a banner asking for consent if you can just assert you do have consent?) went away - the GDPR made it clear that consent must be explicit.