It’s not just about being compliant.
Once they export the data outside the EU, if the parent company is based in the States for instance, how quickly will they notify of a data breach?
US companies have a disastrous track record of waiting weeks or months before notifying the authorities that they’ve been hacked and by then it’s too late to worry about GDPR compliance.
If the likes of Target (41 million credit card details hacked), eBay, Yahoo, Home Depot and other US based companies can’t be trusted at safekeeping the data, then at least stick within the EU where the risks are smaller.