What I want is Little Snitch on steroids built into the OS where every process, including all native ones, including UI apps, are blocked from network connectivity by default, and the user gets an easy monitor of outgoing traffic with TLS/SSL inspection built in (you'd need some OS API to enable that). Kind of like granular oauth permissions, apps should have to declare which outgoing they have, a description/why, an…
We could go to our EU representatives and ask for them to make it mandatory. Though I suspect it'll go down the same way as the GDPR, at least at first. (Lessons have already been learned of course)
I don't think adding technical layers to block these data leaks is going to work long term.