using EU infastructure...which in many cases doesn't exist yet. In particular, Europe lags significantly in "on-line" services.
Obviously it would solve some problems if this were not the case. However, given that for now it is the case, the price of enforcing a total ban on exporting personal data outside Europe would be closing down vast numbers of on-line European small businesses that aren't intentionally doing anything unreasonable or customer-hostile. Clearly this isn't going to be accepted readily by anyone involved.
A more realistic result when the dust has settled might be yet another disclosure that businesses are required to make prominently when someone buys or signs up for something, in order to be deemed to have explicit consent from the data subject to export the data. This appears at first sight to be a reasonable way to handle the ruling, and in principle I think it's hard to argue with requiring a business to disclose fairly what they're really doing with personal data. Indeed, I've noticed that in recent years organisations like my insurers have started adding terms that explicitly say they're going to export personal data and foreign governments might get access to it, and that if you want to deal with them at all then you have to accept that. (I'm not sure how I feel about such conditions when having the insurance is mandatory by law, as for example with motor insurance for drivers, and based on my experience so far it looks like literally everyone offering such insurance is now imposing similar conditions.)
Then again, for on-line businesses at least, isn't that what privacy policies have evolved to deal with? Separate to this case, under the new consumer protection rules, it seems likely that such policies would now be considered to fall under the same general rules about fairness and transparency as the main terms of a consumer contract. Assuming that is true, I'm not sure there is a huge advantage in cluttering up on-line order/sign-up forms with explicit wording about routine things, while there is certainly a disadvantage in making such forms any more complicated than they need to be. The question then becomes one of reasonable expectations about what a normal customer would consider routine.
I suppose that brings us back to approximately where we came in, other than the fact that it's now a matter of public record that the US government itself was violating those reasonable expectations and opened Pandora's box. Somehow I suspect that if some sort of basic disclosure/consent on sign-up doesn't deal with this issue, it will be addressed by adjusting the relevant European-level legislation so that disclosure to allied governments in the interests of national security is a blanket exemption, and enough people won't know or care about the implications that this will pass even though privacy advocates would surely oppose it.