I've started using encrypted partitions on DropBox/GDrive/BTSync (using encfs and BoxCryptor).
I've added JottaCloud - a Norwegian cloud storage provider, to get some storage outside US/NSA jurisdiction (and I'm using encjs encrypted storage on there too).
I've made sure all my published GPG keys are still working and have strong passphrases. I've started using GPG again occasionally just for the LULZ - so it'll not stand out quite so obviously if/when I need to use it in anger.
I'm considering my email options. I've got encrypting all non-encrypted email on the way into a mail server working as an experiment, but the questions of where to do that remain - my DigitalOcean VPS is no less likely to be under NSA compulsion than gmail, I don't trust my local (Australian) government to not be leaning just as hard on server hosting suppliers in Australia. I'm currently leaning towards hosting my personal mailserver at home strongly encouraging (or perhaps even enforcing) STARTTLS encrypted mail transport, running via a VPN tunnel to an internet connection at an inexpensive VPS with a non-US based provider. Since much of my mail is local (corresponding with other people inside Australia), I'm trying to decide whether an Australia based VPS perhaps under control of the local intelligence services but not requiring the bulk of my inbound (probably unencrypted) mail to hit any trans-ocean/crossing-national-boundaries backbones, would be a lower risk than a Norwgian or Icelandic based VPS which is more jurisdictionally difficult for ASIO and the NSA but which requires my inbound mail to cross those high-value-target-for-firehose-sniffing cross border backbones.
I've been raising cloud data storage legal jurisdiction based on the cloud's physical location and the cloud company's nationality whenever appropriate at meetings (which gets interesting responses with health/financial/childcare clients, and bored dismissiveness from just about everybody else… "Oh, you're storing PII patient data? Does storing that on Amazon S3, even if encrypted, meet your regulatory requirements?" I'm looking forward to the "Ahhh, so you're providing information to pharmaceutical managed mental health patients. Have you considered the privacy leak that Google Analytics represents? WHat disclosures and/or provacy assurances have you made to your users?" discussion next week…)