Ever thought that complying with those "random" personal data protection laws shows a respect for users decency and privacy in your own country, as well as those users in the UK/EU?
Whoever told you that was scamming you
At the time I was doing this, it was part of a very large company that quarterly ran audits of all their own systems for security and legal compliance, and they did GPDR as one of their things to audit against.
So we were not scammed, we had our internal employees do their job.
GDPR doesn't require you to perform audits, unlike other Regulations or certifications
"It's just a checkbox in cloudflare to not show up there" is so effortless that you need a compelling reason to ignore how easy it is.
And if you don't already have traffic analysis showing that 30% of your readers and thus 30% of your ad revenue is coming from the European continent... You spend the 45 seconds it takes to find the check box and you click. Then worrying about maybe possibly getting screwed by some far away legal something or other is irrelevant.
What’s the corollary for the patriot act? AFAIK, its provisions would only affect immigration and travel, which happen inside a country’s borders.
Patriot Act, FISA, Cloud Act allows the USA to basically impose its justice over other countries. And it's never in the interest of its citizens.