For #2 – since it seems you're in more a 'privacy' realm than a 'compliance' realm, it may be worth the time to peruse the White House's framework – http://www.whitehouse.gov/sites/default/files/privacy-final.... – from this past Feb (which has links/refs/comparisons-across privacy standards) and then the CSA's Cloud Controls Matrix : https://cloudsecurityalliance.org/research/ccm/ : or the whole CSA GRC stack : https://cloudsecurityalliance.org/research/grc-stack/ : which should help you assess which provider/service is right.
The prescriptive controls in PCI can help you design your data access & handling strategy, but you have to remember that PCI is highly focused on protecting a sixteen digit number and you'll need to determine what your critical data components are from a privacy perspective to effectively map against PCI or other control frameworks.