Washington Post offers invalid cookie consent under EU rules – ICO

If they took money from a single EU citizen / EU-registered card to access their site - then they are trading in the EU

It's even more complicated than that. GDPR doesn't cover EU citizens, it covers people physically present in the EU. A US citizen who happens to be in the EU on business, and accesses one of those sites, is doing so under GDPR.

