It has the same issue as many laws that assert extraterritorial jurisdiction on internet entities: it isn't too difficult to deal with as long as only the EU has it, but if a bunch of other countries also adopted very similar laws it could be prohibitively expensive for small entities to deal with.
The main reason for that is Article 27.
For an organization that does not have a presence in the EU but for which GDPR applies, it seems to cost a minimum of around $500/year to comply. That seems to be the low end for the services that provide Article 27 representation.
That might not be too bad...as long as only the EU implements such privacy legislation. But several countries have talked about similar privacy legislation. If they all have something like GDPR's Article 27, it could quickly get out of hand.
You don't need an Article 27 representative if all of the following apply to your processing of personal data:
• the processing is occasional,
• it does not include, on a large scale, processing of certain special categories of data or personal data related to criminal convictions and offenses, and
• it is unlikely to result in a risk to the rights and freedoms of natural persons.
There's a lot of fuzziness in that. Even if other countries have similar exceptions, each country might resolve the fuzziness a different way, which could make it a major pain to figure out for which countries you need a representative.