It's not clear to me that these laws are mutually exclusive.
1. "the USA PATRIOT ACT, which states that companies incorporated in the United States must hand over data administered by their foreign subsidiaries if requested."
2. "European Union legislation requires companies to protect the personal information of EU citizens"
It could be that the US gov't requested data on non-EU citizens which happened to be stored in EU data-centers.