Earlier quoted context omitted.
Those very much falls in the shady part. The first option, redirect, is not GDPR-compliant, because then the "consent" cannot be considered freely given, and thus is not valid The second option is really borderline, and could work out for a US-only news website, for example (arguing it doesn't cater to European residents), but would be non-compliant for a business which knowingly serve European residents.
> The first option, redirect, is not GDPR-compliant, because then the "consent" cannot be considered freely given, and thus is not valid. I don't quite understand the reasoning on that one. In Europe, and pretty much everywhere else, there are a bazillion interactions every day in the form of one party offering to provide some good or service only if the other party agrees to something. For example, the grocery store…
Why? Presumably because most users don't see the real cost of giving away their personal data (either they never recognize the cost, or see it too late).
To make sure this is held up, the GDPR uses some tools; one is that consent is freely given, the other is ban on tie-in sales: you cannot demand PII from users that isn't necessary for the service you provide.
If you provide news or stories as a service, you cannot demand location data from your users, because you can provide the service without that.