That they are doing it for a 'good cause' (often debatable) is somewhat irrelevant, that is a risk/reward calculation that the country/agency/spy needs to make themselves.
If a a friendly country of the Dutch government wants to access records of a Dutch company (Booking.com), there are numerous legal methods to access this data. What's instead happening is that the CIA hacks NL companies and the Dutch RIVM hacks American ones and they share information/metadata with each other so that they can make and end-run around the legal constraints of both nations.