Earlier quoted context omitted.
I was also curious, so I found this: https://edpb.europa.eu/news/national-news/2021/bavarian-dpa-... The core: ... transfers of personal data to the U.S.- were not lawful. So the problem is that an US company cannot be GDPR compliant, because that conflicts with US law. Which sucks for mailchimp but makes sense.
A US company can be compliant. They just have to host EU user data in the EU.
I thought that I understood GDPR at least reasonably well: be specific about what data you collect, don't collect unneeded data, allow deletion of data, and a couple other minor caveats. But if I sell software in multiple countries, and part of my account process is collecting an email address or other PII, is that not GDPR compliant unless I set up offices in the EU?
That can't possibly be what the law actually says; nobody except the biggest US companies would be able to do any business online with EU customers if that was the case. What am I missing?