A similar law is still going strong in The Netherlands. As of this year, most Dutch sites greet you with an annoying pop-up.
Annoyance, related to privacy. I vote for being "annoyed".
Requiring explicit permission to store cookies on a user's browser is more likely to encourage privacy-invading companies to use the browser's fingerprint instead. This fingerprint can be loosely tied to a real world identity, and across sites too. The user wouldn't have any knowledge of such happening and they also wouldn't have any degree of control over it. At least presently it's trivial to block the most common form of tracking: HTTP cookies.