Yes, and that sucks. Adding more overly broad extraterritorial laws is going in the wrong direction.
Note that a common response by foreign banks to FATCA is to refuse to do business with Americans, which is very likely the best course of action. So it shouldn't be surprising when companies take similar precautions because of GDPR.