The point of this pst is that foreign business will be affected, AFAICT, Europeans have always held the Internet to a stricter standard than Americans and have passed stricter laws around everything from what data can be retained to the behaviour of tracking cookies.I run businesses in the UK that deal with personal data and sometimes use US companies to do so.
There is a specific provision intended to fix the problem of exporting personal data outside the EEA to be processed in the US, which would otherwise be prohibited because US laws are inadequate in this area: the US Department of Commerce operates a Safe Harbor scheme, recognised by the European authorities, which US businesses can participate in to demonstrate that they handle data with sufficient care to satisfy European standards.
The problem is that if the US government is going to permit itself to access data contrary to the claimed protections anyway, then the Safe Harbor scheme is demonstrably unfit for purpose, and any legal shield it provides to European businesses that want to use US-based services to process personal data is in doubt.
This problem is hardly a new discovery, but until recently, the issue was being dealt with quietly, with European officials making occasional mutterings about being in contact with the US government to resolve the conflict here. As of the past week, I'm not sure that's going to carry much weight any more.
This leaves a paradoxical position for any business wanting to operate legally in both the US and Europe. It's not clear whether the huge players like Google or Facebook could avoid the problem by changing their corporate structures, if doing so means that a parent organisation in the US would not be required to disclose personal data held and processed only in Europe by a separate European legal entity under European data protection law. In practice, this might be worse news for US businesses that aren't yet big enough to play the corporate structures lottery, and for those European companies who benefit from services provided by such companies and might have to make other plans. Obviously quite a few smaller Internet services well known on HN would fall into that category.
If you'd asked me a year ago how the paradox would be resolved, I would probably have cynically suggested that the EU authorities would ask how high when the US authorities told them to jump, as they have done previously with things like travel and banking data. But now that this has become a major public issue that people are actually talking about, any attempt to do that seems likely to turn out very badly for European authorities whose popularity is already at an all-time low. I suspect far more Europeans resent the constant privacy intrusions and security theatre of modern life than many across the Atlantic may realise, probably because the consequences of excessive state surveillance are still within living memory in many European countries, and because all around the Med we've been watching timely reminders playing out over the past 2-3 years.