How can I be non-compliant with GDPR? If I could care less about it, is it enough for me to do nothing? Should I expect that European users should find out themselves that they my website is not GDPR-compliant? Or I must actively ban EU IPs?
>>vbezhe+(OP)
If you actively choose not to pursue compliance, you should make it clear in your own privacy policy that the site is not for use by EU/EEA citizens and also use IP geolocation to block their requests.
>>cbg0+X
You should require users to positively certify that they are not EU/EEA citizens, and refuse service if they are. Blocking by IP is a good idea but not sufficient.