> If tech companies and nation states started enforcing/obeying laws based on the Nationality Principle, then FB/Google/AMZN and other data collecting firms would be allowed to ignore GDPR on the principal that the developers are in the US and thus they don't have to follow local laws.
The developers are in the US. They don't have to follow local laws anywhere else. This is a fundamental principle of international relations dating back to the Treaty of Westphalia in 1648. This international order is a major reason why we can have nice things, like peace, instead of unending war.
It is, of course, possible for the nation to ban these entities from conducting business in their jurisdiction. If such entities preferred to stay out of Europe and lose that business, it would be further possible for the nation to ban its citizens from accessing Facebook and similar businesses via the Internet; the general pursuit of liability consequences which Europe has attached to the GDPR has produced a sort of soft-ban, as any European who has seen a notice from a US newspaper can attest. This is of course quite ugly, but typical GDPR-boosters sometimes seem to think that anyone who doesn't kowtow to the European order is fundamentally Evil and would like to distract you with this fact, while they seek stronger ways to protect their citizens from treacherous foreign newspapers.
We are able to maintain a stable global system with international trade in no small part because most jurisdictions don't try to do the same, legislating what foreign actors may and may not do in their own countries as a condition of their business. This system is eroding — the GDPR didn't actually start it, the US did — and it is likely to have many unfortunate consequences in years to come. Among other things, Europe is of the opinion that GDPR and its fines must be enforced in future trade agreements, but it is fundamentally incompatible with the US Constitution and its first amendment (the "Right to be Forgotten" in particular).