The long answer is a bit more complicated by it will result in the same answer. Companies in EU can send data over to NA to have it "processed". Once there, the data is outside the protection of EU law, and can be sold without hindrance.
My understanding of my (EU) country law is that you cannot send data outside the EU to have it processed if the data is deemed "sensitive". Even if you are allowed to export it, you have to guarantee that data won't sold once it has left EU.
But for the general case (ie a normal business venture), people are already using services that will exploit/refine any personal data being sent there. Gmail is one, but Facebook is a better example. Facebook will use the data even if it about someone who aren't a Facebook user. Cloud services could be doing things, but I am not sure its true in practice yet. Mobile apps are already getting and selling data, and has a long history of doing exactly that.
Webshops that use paypal are sending their customer data to paypal. If one read their privacy policy, one can see that they use the data to: a) compare information and verify it with third parties. b) Send to companies that perform marketing and "other services" for paypal. c) Send aggregated statistical data to their business partners. d) send any data to eBay Inc. corporate family—like eBay, Skype or Shopping.com (https://cms.paypal.com/au/cgi-bin/marketingweb?cmd=_render-c...)
I am currently building a data crunching company in the EU. I chose, both from a legal and marketing standpoint, not to export any of my (customers') data outside of EU. In fact, I chose not to export any data outside of my country's borders.
It simplifies (a bit) my legal paperwork, but it also serves as a marketing claim along the tune of "we are doing no evil with your data, and not putting them into the hands of anyone else".
Though, the last time I read a report on the audit of Safe Harbor[2] and US companies that say they abide by it, I decided not to recommend trusting our data to US companies.
1: http://export.gov/safeharbor/
2: http://www.galexia.com/public/research/assets/safe_harbor_fa...
This would breach principle 8 of the data protection act unless the same legal safeguards are placed around the data in North America
http://www.ico.gov.uk/for_organisations/data_protection/the_...
It is illegal in the EU to transfer data out of the EU without this safeguard, done variously by contract (EU model contract), two party agreement, assessment of adequacy, or approved safeguards (safe harbour).