GDPR applies if you are a European citizen visiting a website while on holiday in USA, for example. It doesn’t seem to me that GDPR stops when crossing a border. Which is why it has so much worldwide reach.
That is not a commonly held interpretation of the law, especially if the entities collecting & processing the data are not in the EU.