* and there are European citizen dual passport shenanigans
If the company is established in the Union, then GDPR applies to all personal data processing it does. See Article 3(1): "This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not."
The question, then, is Tesla merely a company that is offering goods and services to people in the Union, but not itself established in the Union, or is Tesla established in the Union?
Point: how is the GDPR ever going to be enforced between US citizens and US companies-with-an-EU-presence?
No, they'd sue to get it from the EU one. As it's part of the same company. The rest of your questions are predicated on the core misunderstanding you have of this so don't apply.
> how is the GDPR ever going to be enforced between US citizens and US companies-with-an-EU-presence?
4 percent of the organization's annual global revenue will work quite well I'd imagine.
It also gives the right to to sue. See Articles 79, 80, and 82.
There's a nice summary here: https://privacylawblog.fieldfisher.com/2016/getting-to-know-...
Here's an interesting law review article examining these developments: The Arc and Architecture of Private Enforcement Regimes in the United States and Europe: A View Across the Atlantic, https://law.unh.edu/sites/default/files/media/rathod_-_final...
Personally in terms of public policy I prefer private action, but maybe that's because I'm American. Private actions are usually predicated on actual, individualized harm, whereas regulators can strong-arm companies without any evidence of actual harm. Theoretically it makes for a better business environment, especially for startups, legal anxiety about nuisance lawsuits notwithstanding[1]. But private action doesn't scale; if you don't permit aggregation of claims (i.e. class actions) then private enforcement can't redress systemic behaviors.[2]
[1] The anxiety is invariably overblown. I think it's because most people's eyes will glaze over when hearing stories about regulator enforcement actions. But stories about slip & fall lawsuits are both legion and relatable; like with terrorism, people develop a false sense of the legal risks and costs.
[2] I mean, it could work without aggregation if you changed the rules of litigation to really streamline individual claims, such as by shifting the burden of proof onto the defendant for certain categories of behavior. Then it would sort of act like a dynamic tax that responded to business practices. Keep your customers happy and you pay a minimum, baseline tax--the cost-of-doing-business that is whatever amount you want to pay out for fraudulent claims, not unlike what businesses already do with accounts payable and shrinkage. Do something that might upset your customers and you'll have to face an onslaught of cases that either require a quick payout or costly litigation. I imagine such a regime would look much like that with class actions, with specialized law firms that identify and aggregate plaintiffs to benefit from economies of scale, and take a cut of the proceeds. But it would still make it much easier for people to prosecute small claims themselves.
EDIT: A nasty surprise that might be, too, if it turns out there was important data via that service that you wanted to access abroad but couldn't.
It could comply the normal way.
(i) might be enforible against a US corp if they have something in the EU to do business