Stronger audit controls are the way to go for deterring this kind of abuse. Having an audit log of all privileged access, and having a different department review it (employee X accessed user Y's data, which LE request was this for?) isn't necessarily a huge burden: LE requests aren't frequent enough to justify not doing this.

