Edit: I'm getting downvoted -- just in case it helps to clarify, I'm not trying to say anything anti-GDPR here... I'm just genuinely surprised these ostensibly US-only companies feel obligated to follow it and genuinely asking why? Is there an actual legal risk to non-compliance for them? Given the already low level of effort just to detect an EU-based IP address and show the patronizing error message, it seems like they must have had some motivation to even do that much and I'm just wondering what that was.