Earlier quoted context omitted.
Do keep in mind that "want" isn't exactly accurate. No IT team wants to spend any time/effort maintaining that crap, the business doesn't want to shell out for it either since it's expensive, and the ops team doesn't want yet another thing mucking with traffic. Yet we have one because it's required by law. Wanna take a guess at what companies make sure it stays required by law?
Please tell me what law applies to most companies that do this?
The laws (in the US, at least) are typically written such that some part of the administration is deputized to promulgate technical standards and rules, most of which delegate to the NIST, but sometimes to industry bodies. Laws like this include HIPAA, FERPA, FISMA, and GLB.
There are lots of industry standards you can reference (such as the Cloud Security Alliance Common Controls Matrix), but the government will generally look at things from the perspective of NIST publications, such as NIST 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations". So, basically, what the government thinks private enterprise should be doing to comply with legal requirements to protect sensitive information.
In that document, there are a number of "controls" an organization should have in place, in particular, it should audit any and all data transfers, and ensure such transfers can be traced back to a unique user.
Even within that framework, you aren't going to necessarily find a blanket "read everyone's mail!" edict. Instead, what you are going to do, is make an assessment, as an organization, about what you think you need to do in order to withstand any potential lawsuits that may arise from any kind of disclosure.
If we made software engineers individually liable for these things the way civil and mechanical engineers are, things would look very different.
[Ed: misspelled FERPA]