Data protection legislation exists to ensure that our private information is stored safely and used appropriately. But does this give us adequate protection in an age of centralised health records and DNA databases?