This is false. I blogged about this topic a while ago: https://www.joyfulbikeshedding.com/blog/2018-04-17-should-no...
The criterium for whether a non-EU company needs to comply to GDPR is: does the company intent to seriously service EU citizen? This is determined based on multiple factors, such as the website's language (do they have e.g. German translations?), providing pricing in euros, testimonials from EU customers, or having a contract with a parcel company with the specific intention of delivering to EU customers. The mere fact that the website can be used by an EU citizen is not enough to have it fall under the GDPR.
Source: the book "Handbook GDPR, Compliance in practice" (page 11) by Arnoud Engelfriet & co, a Dutch IT lawyer. https://ictrecht.nl/boeken/handboek-avg-compliance-in-de-pra...