I'd have to dig deeper, but generally "storing" (or maintaining storage) is not "processing" in the local US legal vernacular. Where both apply (PCI DSS, etc), both terms are used.
In my personal (business) case, we literally cannot comply with GDPR and also BSA/AML, FinCen, Reg E, KYC, etc, simultaneously. Our "business requirements" can last 7+ years, and our customers' wishes have no bearing on them.
And while we have no operations in any EU country, we are absolutely not obligated to even consider any EU laws about the data belonging to any of our customers, regardless of their citizenship. That's the primary point I'm making here -- the EU has zero jurisdiction over anything that happens outside the EU, ever, or any entities outside the EU, despite any claims to the contrary (which, according to Wikipedia at least, are not even made).
This is intuitive, but also the very expensive legal opinion of our lawyers, who have offices in the US, EU, and EMEA, for whatever that's worth!
In the general case, and as a customer, I'm fully in support of GDPR and CCPA-like protections. They're a great idea, I think! I'm usually the privacy nut in any discussion.
But compliance is obviously more work/expense than not, and small companies are especially allergic to nonproductive work and expenses. So naturally there's resistance to the suggestion that a foreign law compels them to do more of both.
And of course, if we're talking about the US, we have a very different culture around government and regulation. "As little as possible" (except those that protect my interests) is the preference of the landed gentry, and those who would aspire to same.
Reasonable people will recognize this as absurd, but ... you can't spell "absurd" without U, S, and A.