Yes. Many of the privacy and data protections are not based on where the data is stored, but rather where the people who provided that data reside. For example, GDPR (an EU regulation) applies to US companies with data in the US, but only if the data they are storing belongs to EU customers.