The test is whether you are offering goods or services to people in the European Union or monitoring their behaviour. Targeting looks like pricing in euros, offering shipping to European addresses, translating your site into a European language, or advertising in those markets. Accepting an occasional order from somebody who found you is not targeting, and neither is having a website that anybody in the world can load.
Behaviour monitoring is the second route and it is the one that catches people out. Tracking visitors across sites for advertising purposes, in a way aimed at European users, can trigger the regulation independently of whether you sell to them. For a local business running ordinary analytics on a site aimed at your own city, this is not a realistic concern.
What is considerably more likely to reach a Nevada business is California privacy law, which applies above defined thresholds involving revenue, the number of consumers whose data you handle, or the proportion of revenue from selling personal information. Those thresholds are reachable by a growing business, and the obligations begin on crossing them rather than after a grace period.
Nevada has its own statute requiring operators of commercial websites to provide a privacy notice with specified elements, and it applies at a considerably lower threshold than the California law. That is the one most likely to apply to you today, and satisfying it is a matter of publishing an accurate notice rather than building anything.
The practical position is to adopt the underlying practices regardless of which regime applies, because they overlap substantially and the cost is minimal. Tell people what you collect and why. Honour deletion requests when they arrive. Do not sell data without an opt out. Know which of your suppliers hold customer information. A business operating that way is prepared for whichever framework eventually reaches it.
Be careful about the compliance industry that has grown around this question, which sells European compliance to businesses that have no European exposure. Consent banners, data protection representatives, and elaborate documentation are appropriate for businesses actually within scope and are an unnecessary cost for a local service business in Nevada.
Watch for the situations that change the answer. Selling digital products internationally, running advertising targeted at European markets, hiring somebody in Europe, or using a platform that places you in scope through its own terms. Each of those is a deliberate step rather than something that happens accidentally, which is why the answer is stable for most businesses.
Then keep your privacy notice accurate rather than comprehensive, because accuracy is what every regime actually requires. A short document describing what you genuinely collect is more defensible than a long one assembled from templates describing practices that are not yours. This is general information rather than legal advice, and a business with genuine international exposure should have somebody qualified look at it.
Check what your own tools are doing, since compliance obligations can arrive through a platform rather than through your intentions. Advertising pixels, analytics configurations, and embedded services each transfer data somewhere, and a business that never targeted Europe can still be running tools that behave as though it did. Knowing what is installed is the practical version of this question.
Decide what you would do if somebody made a request regardless of which regime applies, because the process matters more than the obligation. Knowing where customer data lives, being able to extract or delete it, and having somebody responsible for answering is the substance, and a business that cannot do those things is unprepared under any framework.