For starters, one thing that the big global companies did was carefully internally segment EU/non-EU users so that they make the technical implementation and business processes to comply with GDPR, but apply these things only when necesseary, and keep the data processing of their (very profitable) USA users the same. A small or medium website most likely went either with privacy-for-everyone or ignore-the-GDPR, but any large global company can afford separate flows and has large enough financial incentives in mining that data so that it makes sense to differentiate.
For example, Equifax has a bunch of subsidiaries in EU who have to follow GDPR - and mostly are following it, or at least make a decent show in attempting so; but the main USA Equifax business could not bother with it, to great benefit of Equifax itself and detriment of all the USA citizens whose data Equifax mismanaged.