The test is in the regulation itself and it turns on targeting rather than access. GDPR applies to a business outside the EU when it offers goods or services to people in the EU, or when it monitors their behavior there. The critical point is that a website simply being reachable from Europe does not qualify. Regulators look for evidence that you meant to serve that market: pricing in euros, translation into an EU language, shipping options to European countries, marketing aimed at those customers, or a domain extension for a member state. A Las Vegas contractor whose site occasionally gets a visitor from Berlin is not targeting Europe, and no obligation attaches.
When it does apply, the obligations are substantive rather than cosmetic. You need a lawful basis for processing personal data, which for marketing usually means genuine consent that was freely given and clearly recorded. You must tell people what you collect and why, honor requests for access and deletion within a month, keep a record of your processing activities, and report qualifying breaches to a regulator within seventy two hours. You also need agreements with the vendors who process data on your behalf. Penalties are widely quoted at up to four percent of global annual turnover, which is real but is reserved for serious cases rather than a small business with an imperfect cookie notice.
The useful thing to understand is that GDPR is not the regulation most likely to reach a Nevada business. California residents are far more probable customers than German ones, and the California privacy law applies to businesses meeting revenue or data volume thresholds that a growing company can eventually cross. If you are going to prepare for one regime, prepare for that one, and check the thresholds against your actual numbers rather than assuming you are exempt forever.
What is worth doing regardless of which law applies is the same short list, because it is good practice and it makes compliance a small step rather than a project. Collect only the data you actually use. Say plainly on your site what you collect and why. Do not add people to a marketing list without a clear action on their part. Keep a note of which tools hold customer data. And be able to delete somebody on request. That posture covers the common cases under most privacy regimes, and this is general information rather than legal advice, so anything with real exposure attached is worth a conversation with an attorney.