https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
---
The regulation applies if the data controller (an organization that collects data from EU residents) or processor (an organization that processes data on behalf of data controller e.g. cloud service providers) or the data subject (person) is based in the EU. Furthermore the regulation also applies to organizations based outside the European Union if they collect or process personal data of EU residents. According to the European Commission "personal data is any information relating to an individual, whether it relates to his or her private, professional or public life. It can be anything from a name, a home address, a photo, an email address, bank details, posts on social networking websites, medical information, or a computer’s IP address."
---
The US doesn't sue foreign pot shops because the sale happens abroad and they have decided to not bother with that but they absolutely could enacted such a law if they wanted. Who is there to stop them? The US actually does apply some of its laws abroad. Here is an example that is similar to yours https://www.insightcrime.org/news/analysis/as-us-prosecutes-...
Again, the problem is only enforceability. If they can't get hold of any money, a verdict is useless.
Some day you’ll wake up, and notice all your corporate bank accounts are empty and frozen.
* It was never about all cookies. It was about 3rd party cookies.
* An agreement was only necessary if you were transferring a user's private data to a 3rd party.
It was a huge privacy leak. The EU tried to shut it down, so the world's corporations decided to keep doing what they were doing without changing a thing, whilst mocking cookies, and by proxy, the user's whose data they were fleecing.