No they don’t. The GDPR is location scoped so the data of an EU citizen given to an hotel while on vacation in the US isn’t protected by GDPR but the data of an US citizen giving their data to a hotel in the EU while on vacation is.

That is my understanding as well. Not a lawyer but recently looked into it since we have US, EU, and non-EU European employees and we were looking at token usage tracking tools (which would appear to potentially fall under employee surveillance or at the very least require explicit consent)

Not sure the exact legalese but legal put together a consent form for anyone wanting to do the PoC