encryption

“But what if we just use encryption?” I get this a lot from CTOs when it comes to GDPR compliance. Can we use US cloud services if we encrypt the data?