We produce custom handmade leather bags and desk accessories at our workshop based in Saint Petersburg. Through our own independent website, we sell both locally and to European Union countries like Germany, France, and the Netherlands. Our average order value for the EU is around 180 EUR, and we ship about 25-30 orders a month.
We accept payments in euros via international payment gateways. We store the customer's name, shipping address, phone number, and billing details on our system. We also run targeted ads directly aimed at audiences in these countries.
I read on a forum that even if you're outside the EU, you fall under GDPR simply by offering goods or services to individuals there. Does this regulation really bind us when we have no physical office or legal representative in the EU? What are the bare minimum requirements we must meet on our website and in our data flows?