The GDPR doesn't even mention cookies.
It's the ePrivacy Directive that regulates them (or, more precisely, "information stored in the terminal equipment of a subscriber").
And the ePrivacy Directive does, in fact, define what's allowed without notifying the user:
"any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user."