Hi there are 8 principles to data protection -
on ICO.org.uk
fair and lawful
purposes
adequacy
accuracy
retention
rights
security
international
read the policy and see what it says about confidentiality, what information does it say can be shared, and how are the principles of data protection applied ie. how long are records kept, why are they kept, where are they kept, who has access to them.
Hth