You are wrong, cf. GDPR article 3. The Belgian DPA even ruled that GDPR is unenforceable if the controller is not located in EEA, does not serve anyone in EEA, and does not monitor EU individuals. https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_161/2...