Exactly this. I've seen many EU folk assume if a site doesn't bother with GDPR it must be malicious. When really it's just easier to avoid the EU since they decided they think their laws can apply worldwide.
What happens btw if an American company just ignores GDPR but still welcomes European visitors? Why would they care about EU law?
EU claims EU law applies to US sites if a EU citizen visits it. This has yet to be tested in court though. I'm incredibly skeptical that it can be enforced.