That's a false dichotomy. You can hold an organization accountable to the law without requiring them to maintain a "master key" to your private data.
It isn't required.