As a massively inferior but better-than-nothing fallback, contractual agreements.
Otherwise, you can't.
Therefore routing across multiple independent networks (which is what a VPN is) actually does provide some additional privacy protection because it means that coordination between multiple entities is now required to see the same information that would have been available to one before, and it changes which entity with which economic interests can see the most.
Essentially, it's a competition hack. There is massive competition (and customer responsiveness) when you get close to the core, but very little for most people at the last mile. So a VPN allows you to shift you effective entry point to an arbitrary provider, and that can be quite helpful.
But assuming that AWS/DO, and their uplink providers (L3, etc) have the goal of selling reliable servers and internet, and aren't building up consumer ad profiles to sell me stuff/sell my data if it looks like one server or IP is maybe a VPN.
Sometimes, the only way to make a whitelist is to see what's not working and add it to the list.
For the iptables box, I put a second 4 port intel pro 1000 nic in my normal host, ran a VM with PCI pass through so the VM controlled the nic and used that as a router.
I think there are purpose built routers out there that will do this but it will depend on the router on how you set this up. You'd have to do research on this. Pretty sure the ubiquity routers will let you do things like this. I've done similar on open-wrt.