That is false. Businesses outside EU are not bound by GDPR.
The problem is when websites in EU, which are expected to follow GDPR, randomly leak information to businesses outside EU.
The problem is when websites in EU, which are expected to follow GDPR, randomly leak information to businesses outside EU.
Business outside the EU, interacting with users in the EU are bound by the GDPR. There might not really be a way (currently) to impose penalties on those businesses for violations, but they are certainly bound by them.