> In reality they have no incentive to police this kind of behaviour until they are called out on it.
Access to personal information of users is "policed" internally, proactively, and you can get fired over it. It's one of the things they hammer into your head the first month of bootcamp after you join. The internal tooling and frameworks have all sorts of built-on heuristics to catch this [1], and there's internal teams who're continuously improving these security measures.
[1] this = accessing information not related to your job duties