Say you host your own WordPress blog with comments enabled. A few of your posts get to the front page of Hacker News, and you collect a couple hundred comments from California techies. Your WordPress instance is breached because you didn't patch a zero day vulnerability quickly enough. You have to personally notify every California resident of the breach, and California's Attorney General.
Government regulation means that part of your job in self-hosting a simple blog is knowing that CCPA exists, along with every similar regulation passed by every other state, now and into the future.
Worse, you may not even realize you're holding regulated "personal data" and how much. Maybe you try to avoid this liability by turning off comments and uploads, but you don't realize your web server has access logs enabled, and some state or country considers this personal data as well. GDPR does for one.