The main concern raised by that review seems not to be from data collection by them:
> Valve does say they can process anonymous data and they may share anonymous data, aggregated or not, with third parties. This is a fairly common practice and doesn’t worry us too much.
But rather that they don't make sure they're providing an ecosystem that, to their standards, protects the user from data collection by others:
> Here’s the bad news about the Steam Deck though. We can’t confirm it meets our Minimum Security Standards because we can’t confirm it uses encryption or if Valve has a way to manage security vulnerabilities.
If that's a concern, it would likewise be on any computer, I would imagine. I mean isn't the Steam Deck basically a regular e.g. desktop computer turned handheld? It's not an issue specifically about the Steam Deck unless you compare it to more closed platforms like the Switch instead of other regular computers.
And the user does have the option to harden the system, like they can any computer:
> There is a lot written out there on the internet about how to set up encryption on the Linux-based SteamOS yourself. However, we don’t think that users should have to go through that to protect their data.
Like they say, it's a matter of lacking convenience to not have that level of hardening by default.
But again, why is this an issue here, when most people using Steam from their desktop computers probably don't use encryption either.