How was OP supposed to take responsibility for a compromised server without access to the server?
Why would Digital Ocean give them access to the server ?
If the server is compromised then it should be permanently shut down immediately.
Can somebody please comment on what the risks (security, legal or other) are for a service provider that prevent them from at least giving the customer his/her data back?
Most likely they just don't have any easy way to do it without reactivating the droplet. If so, there probably is some higher-level admin who could do it, but $5 a month doesn't buy you that support plan.
The reality is that unless you are a really big enterprise customer with your own legal team who has negotiated custom contracts and SLA's then the host can destroy your data at any time. You have no comeback unless they admit liability or negligence, that's one of the reasons the support agent could not discuss details.
Are you saying it is impossible for a secure server to be compromised?