It works the other way around; the American company is granted a special privilege to retrieve EU citizen data.
I'm not sure they are "retrieving" data. People register on the website and upload stuff they want to be processed and used.
I mean, sometimes the government steps in when you willingly try to hand over something on your own will, such as very strict rules around organ donation, I can't simply decide to give my organs to some random person for arbitrary reasons even if I really want to. But I'm not sure if data should be the same category where the government steps in and says "no you can't upload your personal data to an American website"