There is probably no further action necessary. As long as you are not targeting people in Germany in particular, a German court would not open a case against you. Indications that you are specifically targeting people in Germany are if you use the German language or have more than the occasional visitors or customers from Germany. Of course, there is always a grey area as to where the real limits lie.
For detailed information see the "Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)" (pdf), available at https://edpb.europa.eu/sites/default/files/files/file1/edpb_...
Some core citations from this document (p.12-14):
--- begin quote ---
Article 3(2) of the GDPR provides that “this Regulation applies to the processing of personal data of
data subjects who are in the Union by a controller or processor not established in the Union, where the
processing activities are related to: (a) the offering of goods or services, irrespective of whether a
payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of
their behaviour as far as their behaviour takes place within the Union.”
The application of the “targeting criterion” towards data subjects who are in the Union, as per Article
3(2), can be triggered by two distinct and alternative types of activities carried out by a controller or
processor not established in the Union. In addition to being applicable only to a controller or processor
not established in the Union, the targeting criteria largely focus on what the “processing activities” are
“related to”, which is to be considered on a case-by-case basis.
In assessing the conditions for the application of the criteria, the EDPB therefore recommends a
twofold approach, in order to determine first that the processing relates to personal data of data
subjects who are in the Union, and second whether it relates to the offering of goods or services or to
the monitoring of data subjects’ behaviour in the Union.
[Then some examples are given. A U.S. company providing a personalized travel app for tourists visiting London, Paris and Rome falls within the scope of the GDPR. But ...]
The EDPB also wishes to underline that the fact of processing personal data of an individual in the
Union alone is not sufficient to trigger the application of the GDPR to processing activities of a
controller or processor not established in the Union. The element of "targeting" individuals in the EU,
either by offering goods or services to them or by monitoring their behaviour (as further clarified
below), must always be present in addition.
Example 9: A U.S. citizen is travelling through Europe during his holidays. While in Europe, he
downloads and uses a news app that is offered by a U.S. company. The app is exclusively directed at
the U.S. market. The collection of the U.S. tourist's personal data via the app by the U.S. company is
not subject to the GDPR.
--- end quote ---