You should be a lot more worried about Facebook.
This pretty much applied to US government warrantless wiretaps as well come to think of it. Unfettered access isn't so hot if you like your privacy.
I'm pretty sure that is not really a hard task
We have 300 IT systems with 8000 users that take care of 700000 citizens. There is an ungodly amount of information on who accessed what and when. Data security, even post GDPR is a total illusion.
We’re working to build better access control, by indexing data and mapping user rights to job functions, but even then things are going to get lost in the audits.
Let’s say I’m a foreign spy who happens to be the company’s DBA. Audit logs don’t really help you there since it’s not particularly noteworthy that I was in the DB.