Hi Tim,
I am also in the UK and have a similar concern.
The dumbed down version of the legislation (rather helpfully) asks: "Am I satisfied the information is being held securely, whether it's on paper or on computer? And what about my website? Is it secure?"
I can confidently say I have absolutely no idea.
Did you manage to resolve the issue?
Ta
Splodge