Actually it's a bit more complex (but not much) than what is described: 1st party may need user consent when they will use personal datas for something that is not the intended service (legitimate use). For example, for a shopping cart: cookies are necessary for the service, so no problem. For fraud detection : no problem because it's a legitimate use. But if you start tracking with a user cookie what pages your user…
Toot/thread author here. You are of course right. I couldn't pack all details in those toots. I had to break it down to the absolute basics that are often misunderstood: Not every cookie needs consent. The way this is presented nowadays in these popups is deliberately misleading and trying to move the blame to some anonymous political entity when in reality it simply isn't that way.
> Where such devices, for instance cookies, are intended for a legitimate purpose, such as to facilitate the provision of information society services, their use should be allowed on condition that users are provided with clear and precise information in accordance with Directive 95/46/EC about the purposes of cookies or similar devices so as to ensure that users are made aware of information being placed on the terminal equipment they are using. Users should have the opportunity to refuse to have a cookie or similar device stored on their terminal equipment.