I think it's a good thing for OS'es to have the capability to comply with laws when it does not impose undue burden on users or developers. This is to avoid there being 40 different forks/patches of a system that would probably be less transparent than having it in the upstream project.
Whether that capability is activated should always be optional. This field is optional.
Regarding this info being exposed to websites is not up to systemd. If for example firefox were to expose this info to websites without my consent I'd support a fork of firefox or stop using firefox.
As long as the info does not leave my computer I feel it is fearmongering to call it mass surveillance.