Which rule actually applies
Cookies are governed by Article 5(3) of the ePrivacy Directive, not directly by the GDPR. It requires consent before storing or accessing information on a user’s device, with an exception only for what is strictly necessary to provide a service the user explicitly requested.
The GDPR then supplies the standard for what consent means: freely given, specific, informed and unambiguous, by a clear affirmative action (Article 4(11) and Article 7). Pre-ticked boxes and continued scrolling are not consent, which the Court of Justice settled in Planet49 (C-673/17).
The three failures
First, loading before consent. Many sites show a banner while the tags have already fired. The banner is then decoration and the breach has already happened.
Second, no equal refusal. If "Accept all" is a button and refusing needs two clicks through a settings panel, consent is not freely given. Regulators across several member states have been explicit about this.
Third, no way to change your mind. Withdrawal must be as easy as giving consent (Article 7(3)), which in practice means a permanently reachable link or button, not a one-time banner.
What counts as strictly necessary
A session cookie holding a booking in progress, a cookie remembering the consent choice itself, load balancing, and security. These need no consent.
Analytics does not qualify, however much you want it to. Nor do advertising pixels, embedded maps that set cookies, or a video embed that tracks. If a third party sets it and your service works without it, it needs consent first.