If that develops further, people will be forbidden to store data outside of their country, so that the data can always be requested by local agencies.
If that develops further, people will be forbidden to store data outside of their country, so that the data can always be requested by local agencies.
But like OP (I assume) I have the privilege to live in a society where, every few years, I have the opportunity to elect our leaders and discussion about laws happens in the public and needs to find a majority in parliament. In the EU my country has a voice and our elected representatives help shape the directives and regulations.
While the US is also a democracy, I don't have any influence there at all (which is fine) and my data is foreign and is treated differently than that of US citizens. Furthermore, even if an American company does something blatantly illegal my practical recourses are severely limited by costs and distance (try suing someone in California)
I am not ready to accept that when interacting with a local business any data needs to flow across the Atlantic.
I really like the idea of having a local independent data handler who operates European infrastructure on behalf of companies like Microsoft did a few years back.
It's not, users can of course consent to data being stored elsewhere. The article explicitely points this out:
> Instead, the court took the approach that data could only be lawfully transferred to the U.S. via a mutual legal assistance treaty (Article 48 GDPR), or under Article 49 GDPR’s derogations, such as consent. It confined its lawfulness analysis to those grounds alone.