>The second exception is for organizations with fewer than 250 employees. Small- and medium-sized enterprises (SMEs) are not totally exempt from the GDPR, but the regulation does free them from record-keeping obligations in most cases (see Article 30.5).
Nope a small American firm can infringe those rights and face zero consequences. A US Multinational with operations in Europe can't.
So implicitly -- bigger companies are targeted as they have more of a global footprint.