What's being asked for is absolutely a breach of the UK Data Protection Act and the providing company would be immediately legally liable for revealing this information.
I see this public discussion (bearing in mind no names have been revealed) quite invaluable in raising awareness of this sort of harmful request.
One should expect that any email they send will at some point be posted for public consumption and compose emails accordingly
Email is not a secure or private means of communications, the faster people learn and accept this the better off everyone will be
One thing you learn the good way or the hard way when you start to run companies is that any email should be considered part of a public audit trail, regardless of whatever unenforceable boiler-plate .sig text the legal beagles insist is appended. It can all end up in the public record as part of court evidence, or from man-in-the-middle capture, or Snowden-style whistle-blowing...or invent your own scenario.
In this case, the auditor was asking the poster to do something rather illegal, and certainly extremely unwise, to the point of compromising both the poster's career and his employer's business. Given those points, I'd say that publishing the emails constitutes fair self-defence, and the auditor - to put it bluntly - is very lucky that the poster was too professional to name and shame both himself and his company.