Earlier quoted context omitted.
That works fine if the company itself stores the data, but becomes difficult to enforce when 3rd parties store the data. Imagine a company with an EU presence stores it's EU data in US, with a hypothetical cloud provider that doesn't have an EU presence. The company would need to have a DPA with it's cloud provider. That cloud provider technically would also need a corresponding DPA with any 3rd parties that they the…
There's also the Cloud act, which makes it illegal for US cloud providers to refuse data access requests from the US government. As far as I understand, the EU is fine with you sending data to other countries, as long as those countries have the same standards for data protection . In the EU's opinion, the Cloud act, as well as the whole NSA situation, mean that the US doesn't fulfill this definition.
Yes, we have a GPDR compliant law in place, and we can interoperate with EU.