The problem here is not that it was only the mobile number, rather that these sites are able to link your mobile number to the content that you have viewed. There's a scenario here in which sites that had collected this information could publish (or otherwise leak, i.e. through hacking) lists of mobile numbers to URLs visited.
In an age of lax privacy protections and data-sharing it's not hard to obtain people's mobile numbers. What would happen when a potential employer googles your mobile phone number and finds the crawled data?
Steps we now need to take:
1) Some kind of request to get the full list (Subject Access Request under DPA, as pointed out below?)
2) If there is no opt-out process, lodge a Data Protection complaint to the ICO
Although (as far as I know) the FOI Act only applied to public bodies (government and organisations like universities). So O2 wouldn't need to comply with a request under that act. Not sure if the ICO could force them to disclose that info, but I doubt it.
http://en.wikipedia.org/wiki/Freedom_of_Information_Act_2000...
2.) People probably opted in to this without realising. Do they need to supply an opt out, if it was a condition of signing up in the first place?