this is the reply
Sysadmin has full privileges to do that. It is an issue of security control on your environment.
One thing you can think of is to create a server level trigger and do not allow user to disable encryption but again sysadmin can drop that trigger as well and disable encryption