Would it suffice to post a popup in your UI, "This website is not certified for the EU. If you are in the EU, you MSUT NOT use this website. Click HERE to certify that you are not in the EU" ?
Or are website operators responsible even if unauthorized attackers hack in to their system and leave a "personal data" trail?