I 100% agree that the best solution would be for the law to catch up and actually treat privacy as a human right. Until that time there are things which, while challenging and a hassle, do help.
I would use the same sim-card in the burner phone. Any attack by the government that they can do with your real sim card can also be done through phone number spoofing.
For email, use unique emails (things like booking+youremail@...) for reservations/bookings/tickets and have those forwarded to a second email account that you want to use during the trip. It is already good privacy hygiene to use unique emails for all types of registrations, and you will have more control when services eventually have a leak.
> (things like booking+youremail@...)
This is so trivially easy to bypass. If you're a service selling email addresses, just strip off the booking+ part and you have the "real" email address.
All my sign-up email addresses are via a catch-all email, so I can just give a service "[email protected]", or "[email protected]", so I there is no single "real" email address, and I get to track who exactly is selling my email address. So far I haven't had problems with anyone spamming "[email protected]".