@jamesthomson What Apple needs to do to follow up and prevent this - and make the EU happy at the same time! - is make a way for the customer to use third-party full device backup services not run by or affiliated with Apple, as long as the 3p app never gets to see the cleartext data (fully e2ee).
This would avoid responsibility for them hosting the encrypted data or offering it as a service, instead only shipping software (which they already ship, and which there is strong precedent you can't ban).