One is for intended target and second time with public key provided by law enforcement.
And perhaps there should be a third independent actor who would hold the private key (in hardware without extraction possibility hopefully) and on request basis would decrypt something for law enforcement and provide supervision and statistics for citizens. Ok one problem would be then that if that machine breaks there is no way to decrypt anything encrypted for that public key :D.