>As if he read all laws of his own country that apply to him.
Drone.ci is treating GDPR like any other law by steering well clear of the territory it regulates. The US also has stringent rules about online gambling, payment processing, pornography, copyrighted material, etc. Normal website operators don't become familiar with these rules or how to thread a business through them. They simply don't engage in regulated activity at all, unless making a deliberate and well-capitalized entrance with the help of lawyers and compliance professionals. (Obviously there are some high-profile counterexamples, but those are, well, high-profile).
If the GDPR were a law about data brokerage or advertising, then forum operators would be similarly far away from it. But it's a law about the handling and storage of data related to people, which you definitely do if you're running a forum. Ordinary websites have never been that close to the boundaries of legality before, so people are scared.