1. Alice limiting what she reports is a function of her phone software; this is trivially doable by just not broadcasting beacons, or after-the-fact by not reporting your beacons (or reporting false beacons) for certain times.
2. The number of minutes is a threshold decided by epidemiologists, programmed into people's phone, as a public-policy heuristic. It doesn't need to be perfect, just to catch a lot of the actual contacts in its filter while avoiding too many false positives - even quarantining 50 or 60% of contacts can reduce spread by a lot!
3. You could be compelled to release data, but all you would get is a list of beacons; you'd then have to also subpoena/steal everyone else's records of whose beacons they saw (this data stays on local devices!) and correlate encounters with actual locations. This is HARD - like, nation-state actor hard. Like, nation-state intelligence agency hard, probably beyond the reach of your average criminal-justice apparatus.
4. DP3T already has open-source implementations (e.g. https://github.com/DP-3T/dp3t-app-android).
5. If your threat model is "my phone/OS manufacturer will publish code that doesn't follow the protocol", then you're screwed anyway. (And in fact, Apple and Google aren't following this protocol, they're coming out with their own joint system that they claim is DP3T-inspired.)