In theory, the EU data protection directive was supposed to protect us from companies with an EU presence (like Google) moving our data outside the EU - specifically, when we interact with a company with an EU presence, they're not supposed to move data to any country with lesser data protection laws. That seems reasonable - they set up shop in the EU, after all, they chose to follow our law.
Instead, we ended up with the US-EU Safe Harbour, which allows companies with an EU presence to move our data to the US, where despite a set of rules and certifications the company would have to follow, those rules still do not protect our data to the extent that it would be protected in the EU - when they're even followed.
Instead, we ended up with the US-EU Safe Harbour, which allows companies with an EU presence to move our data to the US, where despite a set of rules and certifications the company would have to follow, those rules still do not protect our data to the extent that it would be protected in the EU - when they're even followed.