Earlier quoted context omitted.
> You also need a cookie banner in EU in case your website uses any cookies that are not necessary to serve the content. Not quite, for two reasons: - The law doesn't care about cookies, it cares about personal data, which includes any data which can individually identify someone (like a cookie associating them with a user account). If you're collecting or processing any personal data, that requires consent; even if…
You're only talking about the GDPR. But the cookie banners aren't there because of the GDPR, they're there because of the ePrivacy Directive. It's this directive (which pre-dates the GDPR) that makes it illegal to store or access data on the end user's devices without consent unless it is strictly necessary for the provision of the service.
How is that different to what I said above? (Modulo "s/without consent/implicit consent/g")