If you are processing payments or storing/vaulting credit cards using US services, how are you complying with the Data Protection Directive [1]?
Is the service Safe-Habor-registered? [2]
[1] http://en.wikipedia.org/wiki/Directive_95/46/EC_on_the_protection_of_personal_data
[2] http://www.export.gov/safeharbor