I don't think that's correct. My understanding was that GDPR applies to organizations that are used by EU citizens or residents. See:
> Under the GDPR, organizations may be in scope if (i) the organization is established in the EU, or (ii) the organization is not established in the EU but the data processing activities are with regard to EU individuals and relate to the offering of goods and services to them or the monitoring of their behavior.
- https://stripe.com/guides/general-data-protection-regulation...