The idea that "email is insecure" is not a widely known one.
If this ever is to stop there needs to be a strict ban on using email for these things combined with checks and serious consequences for violations. But that will not happen anywhere soon because guess what, the government that would have to create these rules violates them routinely.
It's still PII, but at least it isn't your PII. The droids that process these things are not going to change their means of communication or list of requirements for your deal, so you just have to ensure that the information being plugged into their systems is the information of a placeholder person (ie your attorney/business manager) instead of your own.
If I use PGP-encrypted mail, I have to trust that the receiver is not stupid. If I use Signal, I have to trust that Google is not evil. Hmm...