I don't work with music at all, so most of this update doesn't mean much to me. However, it's nice to see the export window was improved—I want my single-click behavior, damn it.
The telemetry is limited to update-checking and error reports. Distributions will disable update-checking because they already handle updating Audacity. Error reports need to be manually submitted. It's possible that most distributions just disable networking altogether when building Audacity, if it even exists in their repositories at all. Fedora's package is waaay out of date. Arch disables networking altogether.
Audacity has still instituted a CLA. This is quite worrying. But nothing has happened yet.
I should have specified that the Audacity CLA allowed Muse Group to relicense Audacity from GPLv2 to GPLv3. Yes, I agree with you that not all CLAs are bad. While you keep the copyright to all your contributions, because the copyright is assigned to them (? I'm not actually sure about this), they can relicense it. The CLA agreement.
There was quite a lot of confusion and outrage about this at the time, so I can't recall whether Muse Group specifically said they wanted to include Audacity in Apple's app store or this was given as an example of why the CLA could be beneficial. My rebuttal was this is not a particularly noble cause. There was also the argument that the FSF requires you to sign a CLA for its own projects so it can reserve the right to relicense it if it benefits the project. My rebuttal to this was...well, it's the FSF. The day the FSF relicenses their software under a non-free license is the day they die.
All in all, I'm not worried yet.