Show a basic level of respect for your users' privacy whether or not it's not a legal requirement.
Do you have a compliant privacy policy, data retention policy, breach notification policy? Have you named a data privacy officer? Do you have a written process for erasure requests?
You’re probably right that the ads are a problem but ain’t nobody getting GDPR compliance for free.
Besides, most websites need to update their privacy policy to be accessed in California anyway. The Californian privacy protection rules aren't as strict as the GDPR, but they are very similar. I don't really buy the "it's expensive to comply" argument a lot of American companies seem to use because of this.
The companies want to collect and trade your personal information to the highest bidder, the GDPR got in their way and now these companies are acting out.