It seems hard if not impossible to prevent illegal use of profile pictures. If a web browser can access them, collecting them can be automated. Even if they are only accessible through an app on iOS or Android, you could still, on a device with root access, capture the API calls and reverse engineer how to get those pictures.
So we might just assume any intelligence service already has that. The only protection against a more widespread development of those products would be legal I think.