This is a question of trust. I have to trust that DO will keep my data safe, that, if the US government would be after my data, DO would prevent them from accessing it. I have to trust that DO won’t access my data.
How am I supposed to trust my, and my user’s personally identifying data, to a company that just like that revokes credit, without warning, and says "well, if you ask nicely, you can get it back"?
I’m sorry, but I can’t trust such a company.
This is completely unrealistic. If the [local jurisdiction government] is after your data, they'll have your host, ISP, and anyone else give it to them.
(Inexplicable downtime = your server being imaged.)
Believing anything else, IMO, is purely delusional.
I’m in Germany, my users are in Germany, and if I host with DO in Frankfurt, I have to trust that my data stays in Frankfurt.