Currently the US-of-A believes that US laws _always_ apply, no matter where. However that doesn't jive well with EU privacy laws. For example the easiest way to comply with the German privacy laws ( https://en.wikipedia.org/wiki/Bundesdatenschutzgesetz ) is to host inside of Germany itself (See also: AWS eu-central-1).