Earlier quoted context omitted.
Why does an unmonetized website about US court cases, presumably targeted towards Americans, need to care about GDPR?
It was just an example; similar issues occur under the CCPA and other legislation. (Assuming no user is covered by GDPR, which is likely not the case.)
1. do extra work to make your service comply with laws in areas you don't live or have any customers
2. put a blanket IP ban in place for these places where you don't live or have customers
3. do nothing
Bigger companies will do number 2, and individuals/small business/small and unmonetized projects will do number 3.