That's not quite correct. It requires the collection of available metadata only. It does not require that encrypted messages be decrypted, unless the provider holds the keys rather than the user. Still, it's not a great bill.

And I guess VPNs are not end to end encrypted. The provider would still be able to access your data if they want to unlike something like Tor. So, it will be the death of privacy focussed VPNs. But presumably things like Signal and Apple's disk encryption will be fine as only the user holds the keys.