And European companies are also sued for breaking GDPR. Recently, the CNIL fined Criteo, a French adtech company, for 40M€. Multiple other fines in the 1M+€ range (Carrefour, Total, AG2R…) for French companies.
You can go on Enforcement Tracker, you will find a lot of small fines against EU entities, and few but heavy fines against US entities. I don't think this is protectionism, but rather that EU companies fare better than US companies in environments with historically strong privacy laws, precisely because they are subject to these regulations from day 1.
> They are using the data in compliance with their ToS, which is decided post-facto to be in violation of the GDPR.
A ToS is a contract, and contracts can violate the law. Nothing surprising here.