I think this behavior is covered by existing criminal law. If not, the law needs to be updated.
Replace “phone“ with “web server”, and you will find legal precedents showing that much of the behavior is criminal.
In particular, it is clearly not legal to walk the file system tree to obtain access to private data you were explicitly denied access to, and then directly profit from the data you illegally harvested.
Failing to strip exif location data, even though gps access was denied? That’s a gray area, at worst.
They seem to contravene the computer owner's explicit choices about allowed access.