The problem is that this includes literally everything on a cloud service. My emails and documents on Gmail/Google Drive is my personal data. My email on Fastmail is my personal data, even if they’re privacy friendly. So that service would be illegal.
Even having an account at all, and being able to see that I have a subscription, or that I previously watched that video, is personal data they collected.
So the Privacy Policy is what you “agree” to let the company do with that data. How do you even begin to differentiate the superfluous stuff they track just for ads, on a technical level without workarounds?
And then think about banning “transferring personal data to a 3rd party.” Does that mean I can’t host account data on AWS, or use a hosted database, be causing I’m transferring data to a different company which can presumably also access it? That’s what the privacy policy has to allow, and why sites have so many “partner services”