tl;dr EU-located servers are neither necessary, nor sufficient.
Recent decisions by courts and regulators (many in the past month or so) have clarified how and which data transfers from the EU to the US are in violation of GDPR. The current landscape this is: a transfer of personal data to a Controller subject to the US CLOUD Act is in violation of GDPR.
Let me go through several important things you should know:
* EU-located servers are insufficient. A fine was issued to Cookiebot (Danish) for using Akamai CDN, even though the court acknowledged the servers were located in the EU and the contract was with Akamai's EU subsidiary. A server owned by a US company is subject to US warrants, which is what violates GDPR.
* Every rulings I've read mentions the CLOUD Act explicitly. As far as I'm aware, US companies not subject to the CLOUD Act might be GDPR-compliant. Maybe. At the least, it hasn't been found illegal yet. The CLOUD Act applies to 'telecom' companies, a definition which includes Google and Amazon.
* BREXIT: The EU has an adequacy decision with the UK, meaning no special protections are needed. The UK still has an adequacy decision with the US. So if you're in the UK and only dealing with data subjects in the UK, this is not necessary for UK-GDPR compliance. In the EU, a UK-based hosting provider is totally fine, assuming they're not subject to CLOUD Act.
* The GDPR definition of "Personal Data" is nowhere in the same league as "PII, " and thinking they're similar is generally a mistake. To a first approximation, PII only refers to plaintext data that can be used to commit identity theft. Personal Data is any data point that can be connected to an individual. Examples of things the courts have ruled are personal data included IP addresses, and the randomly-generated first-party cookie that Google Analytics uses to tell that two hits came from the same user (and nothing else). GDPR explicitly contrasts anonymous data with pseudonymous data, and the latter is (usually) personal data.
* There are a handful of other countries which do have an adequacy decision in place, including Isreal, Japan, Canada, and New Zealand. Using companies based in those countries is easy to do from a GDPR perspective.
If you want to find more about the current legal state of data transfers to the US (which is in a period of serious flux right now), the place to start searching is Schrems II, which is the lawsuit that forced legal recognition by the EU of the state of data privacy in the US. The recent wave of rulings (which is still ongoing) were part of 101 lawsuits filed by noyb, the non-profit started by Max Schrems to press this issue.