I get it, but the operative point is not "potentially harder", but "literally impossible" to enforce -- unless the corp has some presence in the EU of course.
FWIW, I just checked Wikipedia to sanity-check my memory of our lawyers' guidance. Important differences from our discussion, if my read is correct:
GDPR does not apply to "EU citizens anywhere in the world", it applies to the personal data of "living persons ... inside the EU" or with data processed there.
(So GDPR would apply to a US citizen who is present in the EU, and/or being a user/customer of a vendor that operates in the EU)
From the "Misconceptions" section[0]:
> ## Misconceptions
>
> GDPR applies to anyone processing personal data of EU citizens anywhere in the world
>
> In fact, it applies to non-EU established organizations only where they are processing data of data subjects located in the EU (irrespective of their citizenship) and then only when supplying goods or services to them, or monitoring their behaviour.
(So GDPR would
not apply to a EU citizen who is present in the US at the time of "processing", whether that's a service or product sale, etc)
This is important to my company. We are US-based, but have EU citizens as customers. For regulatory reasons, we block customer activity from outside the US, and we are not able to comply with GDPR (but we do have to be aware of CCPA[1] which has some similarities).
[0] https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
[1] https://en.wikipedia.org/wiki/California_Consumer_Privacy_Ac...