The requirements to be subject to the CCPA are any of: have a gross annual revenue of over $25MM; buy, receive, or sell the personal information of 50,000 or more California residents; derive 50% of more of your annual revenue from selling California residents’ personal information. Yes, I believe that if they emailed only sites for which that was true, I would have no issues with the study.
The requirements to comply with the GDPR are much, much stricter and have a much more outsized effect on small, non-commercial site operators. There are no exceptions to the GDPR for non-profits or non-corporate entities. (except a limited carveout for "household processing" that AIUI has been interpreted very narrowly by the courts). I do not think the GDPR is strict enough in this instance, and I think it would have outsized harms on small and non-corporate operators to email them in this way if your only criteria is "could technically be subject to the GDPR in some possible world".