> Makes me wonder if their stuff is GDPR-compliant without consent.

GDPR service providers and partners do not have to consent. Consent is for the users.

Services providers have to tell you when they collect your data, and they will most likely fail to do that if they don't even know their partner injects code.

*So you're liable if you host on cloudflare.*

Now, they somehow avoid this :

>when enabling Web Analytics, you can choose to drop requests from European and UK visitors if you so desire (listed here specifically), meaning we will not collect any RUM metrics from traffic that passes through our European and UK data centers. The version of Web Analytics that will be enabled by default excludes data from EU visitors (this can be changed in the dashboard if you want).

By default, it is only enabled for visitors from out of the EU, like so many services that respect your privacy and your concerns are their first priority