I think we need a law that government agencies must support out of band identity proofing.
The root of the problem is that government agencies can request personal details and if the tech company fails to comply then the tech company is sanctioned. However the government agency forces the tech company to provide details in an insecure way often over email. If the tech company tries to demand reasonable security then the law enforcement agency views this as non-compliance and starts the sanctions.
Somewhat pointless given that for most of these companies this would have to be an international effort. Google will hand over your info if the "authorities" from Azerbaijan request it.
That would first require a reduction in institutional law enforcement hypocrisy that is culturally-incompatible with "rules for thee, but not for me."