Earlier quoted context omitted.
Well, GDPR compliance is one thing. It could be very expensive if you have European customers and get caught doing this.
If they don't have any offices or assets in Europe, then the EU can't do anything against them for breaking GDPR.
«This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union;»
So the GDPR applies. The EU can of course sanction violators outside, but given the current political climate it is likely to be more difficult than before.