Earlier quoted context omitted.
GDPR applies to data processors in the EU or for data subjects in the EU. Citizenship is irrelevant.
It might be not. But those falls into weird space and we will see how things are going to be played out in practice. I still think they have to conform GDPR, especially having prior data on EU users and involvement of parent company.
The only sources which do mention those are informal and imprecise third-party summaries. But yes, this mistake has been spread widely.
The more precise compliance guides from, say, European law firms don't mention citizenship or nationality either.