Edit: apparently they accept EU currencies, which means they have subjected themselves to it.
http://www.privacy-regulation.eu/en/recital-23-GDPR.htm
> In order to ensure that natural persons are not deprived of the protection to which they are entitled under this Regulation, the processing of personal data of data subjects who are in the Union by a controller or a processor not established in the Union should be subject to this Regulation where the processing activities are related to offering goods or services to such data subjects irrespective of whether connected to a payment.
In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union.
Whereas the mere accessibility of the controller's, processor's or an intermediary's website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union
If you are not “offering goods or services to data subjects who are in the Union” then you are not subject to GDPR. As stated in the recital, the mere fact that a site is accessible from within the EU DOES NOT make it subject to GDPR. This recital tells you the test that is used to determine whether or not you are. It isn’t necessarily even required to block EU traffic to be immune from it, though it’s a good idea since you’re playing with fire. You simply can’t translate your site to EU only languages, create content or services that might appeal specifically to EU residents, etc.
No targeting of EU residents = no GDPR liability.
I'm gonna have to disagree with that interpretation.
If I can use their services from within EU then they are providing services to EU residents regardless whether or they explicitly say that they want EU customers and thus are subject to GDPR.
I’ve been through this with actual lawyers. There are things you can do that make you subject to GDPR without explicitly saying you want EU customers - an example might be creating a site in English but that exclusively reports German news. But, for example, if you have a US news site that doesn’t sell subscriptions to EU citizens, isn’t based in the EU, doesn’t specialize in news arising from EU countries, and doesn’t translate its content to EU-only languages, you aren’t subject to it. Again, as stated in the recital, the mere fact that an EU resident can access the site does not by itself trigger GDPR exposure.
What the GDPR says is irrelevant in sovereign countries outside EU jurisdiction.
Or do you think NY hot dog cart vendors should also follow EU laws just because they happen to sell to EU citizens?
edit: (prove that GDPR has teeth outside the EU)
If offering their service priced in the local currency of an EU member state doesn't constitute offering services to users in the EU, then I'm not sure what could possibly qualify.