It's funny you should mention that. A few years back, the operation of the shared Twitter ban list used by the Twitter left was, ah, slightly disrupted by the fact that it was being run by a British person who thought the Data Protection Act didn't apply to them and eventually received a polite official letter pointing out how completely wrong they are. (For context, their justification for why it didn't apply were that they were storing the data on a US service which had no contractual obligation to protect the data, and the list contained just about every kind of information categorized as sensitive under the DPA in the comments field... sexual orientation, political affiliation, all sorts.)
Anyway, I remember pointing out at the time that the Data Protection Act had been used to shut down corporate blacklisting efforts run by people with very good lawyers and much cleverer attempted loopholes than theirs, and that their chances of somehow finding a loophole where everyone else had failed were basically zero.