The issue is that not every team remembers to test incognito from time-to-time.
Those popups are all cookie-hidden if the cookies are set. Easy for an engineer working regularly on the product to accrete the cookies necessary to hide most of them over time.
(Concretely in this case, I bet 99% of the engineers on that site have forgotten GDPR is a thing, especially since their compliance is being handled by third-party provider TrustArc. Easy for a frequent visitor to forget that every new visitor will get asked about the cookie use permission on the first visit).
They're likely prescribed by PR people who think of everyone in bulk and less intelligent than themselves. The people actually building the site probably hate it.
Yeah, but now I have to manage on a per site basis about half a dozen different settings. I find it a necessary evil on mobile to control bandwidth usage, but on desktop I find it easier to just not visit or immediately leave low quality websites.