The platforms - web-browser or operating system - that run these apps - web app or native app - for the benefit of that user - should provide well-understood intuitive experience around what is allowed/possible to be collected and used from the user's device.
Now, technical mechanisms are one major part of the solution. In this regard, these mega corps should be held to a higher standards as they run the platforms as well as the biggest apps on those platforms.
But we also need legal protections that make both the application owners and the platforms owners responsible for any abuse of the user.
This particular case is eerily similar.
Credit card fraud prevention companies do the same thing - they say they need to know as much transaction data as possible in real-time for them to know which is a legitimate transaction and which is a fraud transaction. There is misdirection and fog around how they justify this with thinly veiled technical explanations about network effects and criticisms about monopolistic by design.
The reality is fraud can be prevent by designing the product differently in the first place - chip & pin - multi-factor authentication etc. technology is present to prevent theft and fraud without having to collect so much data centrally.
In this case, similarly, to prevent DDoS attacks, there are other anonymous non-data collection oriented solutions possible. More research and collaboration is needed to evolve the Internet architecture to react to DDoS attackers and other types of technical abusers of your app, catch them and prevent them from growing. Instead, we get these centralized monopolistic solutions.