Small correction: the indie devs just building cools shit are
fine under GDPR. The indie dev who wants to monetize his community while not caring about the externalities of possibly leaking their information has a headache.
If your business model depends on creating undesirable externalities for your "users" then you don't have my sympathy. The only shame is that we still need to enforce GDPR properly on large players, but that's a political and social thing, not per se a problem with the law itself.
And the oh so horrible cookie banners: the solution would be to not track people. If you aren't fully acting in the users interest, the cookie banner is easy to implement, or maybe not even required. So whenever you are annoyed by a cookie banner, it should be directed at the company, not the law.