> For instance, couldn't EME be used to make a system to protect the privacy of people sharing personal videos
Not really. If you want to use the Clear Key key system for privacy, you need to deliver the key over https. (Plain http plus Web Crypto doesn't work against an active adversary.)
To get the key over https, the hosting page needs to be https. Then, due to cross-scheme CORS being prohibited, you also have to fetch the media (MSE segments) over https.
Since https already provides privacy, Clear Key EME doesn't add privacy value beyond protecting against untrusted CDN staff. But if you deliver some JPEGs over the same CDN, you have to trust the CDN staff anyway.
Don't try to post hoc rationalize DRM-motivated constructs as privacy measures.