It's a university email, not Pentagon backend accounts.
It is a stupid law because they're being way too thorough and abrasive when they shouldn't.
How much do you wanna bet the German parliament is not protected in the same way... actually don't answer that... here's an article published today about a stupid vulnerability in the Bundestag's internal chat app: https://zero.bs/osintrecon-vs-pentestschwachstellenscan.html