At a minimum a judge signed warrant should be required for any data access.
Second, a third-party annual security and data audit, with power to revoke licenses if findings aren't mitigated within a reasonable time frame.
Finally, a civilian oversight committee with real power to sanction bad actors.