GDPR is all about user data AFAIK. If I understand it correctly it avoided the trap that is to single out specific implementations.
Also it seems either I or someone else misread the context. I'm in the broader GDPR context while someone else seems to be in the older cookie law context.