That is specifically not possible under GDPR. It doesn't matter where your company sits, if you store data from europeans (or people living in europe) you have to follow the GDPR with potential for severe punishment. There really is no loophole afaik.
Does that mean the company has to follow it even for non-European users?
And being FB, they really do not have a choice, since the EU do have leverage over them because they're doing business here.
Hope that simplifies things.
They can also file a case in the country that you do belong you to get you to pay your fines in the original country. This sometimes works.
This would be an enormously stupid move. It guarantees not only failure but an acidic backlash.
[1] https://www.reuters.com/article/us-facebook-privacy-eu-exclu...
This is an indication that they won't apply GDPR globally (for users in e.g. India or Brazil), but they don't have a choice for the EU users.
The discussion is here:
https://news.ycombinator.com/item?id=16872542
I don't see it in a quick scan, but I wonder if that means all the revenue from those countries will no longer be shielded from US taxes, which might indicate how seriously FB see the GDPR as a threat.
EDIT: pdkl95 mentions in another comment, they claim it doesn't.
They're also not allowed to infringe on the data rights of other users which is why the friends list export is so anemic, for example.