Why do you think "handling user data" is the only reason to employ encryption? What if the website is serving up static content that seems completely fine to you or I but the user is in a legal situation where they would be in trouble for reading it? What if the user is somebody the local police are trying to frame, so the request was normal, the response was normal, but the response was replaced with something illegal so the police can arrest for possession? Why should every router on the path be able to see what I'm reading, what I'm reading web pages about medical conditions? Why do you insist that everyone should collectively make technical decisions that serve to enable this kind of thing?
This isn't hypothetical. A country once used their position of owning the local telecom to inject javascript into web pages that would DDoS another website they didn't like. See https://en.wikipedia.org/wiki/Great_Cannon .
The web moved from HTTP-over-TCP to HTTP-over-TLS because it fixes real problems. One of the common mistakes people make when thinking about security is trying to imagine the attacks themselves and then only defending against those. Your imagination is not the limit, you're up against the collective creativity of everyone else. Encrypt your stuff and remove a whole category of possible problems.