You're circling around the point.
> Like most things, you need to comply with the laws of every country you do business in
How do you know if you are doing business in the EU without verifying the citizenship of the people who buy from you? If I'm selling a digital product, how do I know whether or not EU citizens are buying it?
You suggest below:
> As long as you don't target EU residents, you don't need to comply with the GDPR. Just don't advertise to europeans, don't talk about having european customers, don't ship to european adresses and/or don't localize to languages from countries where you don't do business.
This is the COPPA strategy, choice #3. It suggests that as long as you can pretend you don't know your customers are EU residents, it's fine to collect data on them. If that's the case, that's a much less effective law then we could otherwise have.
In regards to COPPA, you bring up the central problem yourself:
> COPPA is IMHO a flawed law, the general privacy protections should have just been extended to everyone. Age verification and consent validation were never going to work and it seems patently ridiculous to require companies to collect more data to protect privacy.
You're right, age requirements are a joke. We still don't have a reliable way to validate age without violating privacy. These types of laws only work if they're based on one of the three choices I listed in my post:
1. Universally applying the law to everyone, regardless of context.
2. Accepting that validation requires collecting and managing data, and being OK with the fact that we're going to collect and manage data to do validation.
or
3. Trusting consumers to self-validate and self-sort themselves.
The first option has sovereignty problems -- it doesn't work in a multi-nation, multi-state world. Even with something like COPPA, this strategy falls apart because a big part of COPPA is parental consent, and there's no way to universally apply a parental consent law. At some point, you have to decide whether or not you're going to validate the relationship between the child and the parent.
The second option is fine if you want to control your data, but means that we need to give up some anonymity -- maybe make a national database, or have some kind of proof-of-age or digital passport or something.
The third option is fine if you want to stay anonymous, but means that data protection laws have fewer teeth, because consumers will lie, which gives companies plausible deniability over violations.
What we can't do is have both 2 and 3. We can't say, "we won't require anyone to do any invasive validation, and also the validation will be really good and accurate." With GDPR, we either accept that many EU residents will unwittingly (or deliberately) do business with companies that are not beholden to GDPR, or we accept that businesses will need to validate the citizenship of their customers.