It’s not compliant. You might be serving eu citizens living in other countries. I’ve had to implement gdpr regs for a US only company. This isn’t compliant with GDPR.
Sorry, that’s not correct, the GDPR applies to EU Citizens and Non-EU Citizens located within the EU, and an EU Citizen’s Data if it’s moved outside the EU while the person is still located within the EU. An EU Citizen located outside the EU is not covered, as they would be under the laws and regulations of wherever they’re located.
I literally had to work with lawyers to cover this. GDPR covers EU citizens across the planet. Doesn’t matter where you are. I don’t know where you got your information from, but mine came from both the law, and FinTech lawyers whose job it is is to know this stuff.
My info came from my missus who managed the GDPR compliance for 2 of the top 5 largest pharmaceutical companies on the planet for the of the largest blue chip IT infrastructure provider on the planet. GDPR does not supersede local regulations even if you are a citizen of the EU. A website refusing to do business to IP addresses in the EU does not make it non compliant with GDPR, if an EU citizen physically leaves the EU to a country where GDPR doesn’t apply, it doesn’t magically apply because the keyboard senses an EU finger is on those keys. If someone moves from France to Canada, and uses a local website that doesn’t comply with GDPR, do they automagically get a fine for non compliance? Best they can do is refuse delivery if you try to order something to be shipped back home.