This is mixing a few streams.
"A government would be stupid to hand over all their citizens data to the US via US technology companies"
They have been for decades in some cases, and where is the problem, specifically?
It is possibly one of national security, less so one of companies selling data for advertising and other reasons because Slack and MSFT are reliably not doing that, and contracts with companies can make that clear. If the contracts are breached those companies can be wiped out - just the same as any other commercial issue.
So yes, it's reasonable for companies to want to have some data hosted within their own countries, but it most cases it will not matter.
For instance, kids classroom telemetry data in the US vs. Germany will make absolutely no difference.
That data is as 'safe' in the US as in Germany so long as there is a contract in place to specify how that data can be used. MSFT has no very special leverage with customer data in the US as opposed to Germany, if they are contractually bound.
GDPR is a lot about protecting users from willy nilly use of their data which is a different question that national security and other legal issues.
Theoretically, there are some concerns about US spy apparatus, but I suggest that if the CIA wants to access data in what the US deems to be in a 'lawful manner' - that having the data hosted in AWS outside the US won't make a huge difference. That kind of protection would require yet another level of thinking.