I'm familiar with both the US and UK privacy regimes, and I'd say Stallman's concerns (which
were specifically about "Big Brother"-style data collection, rather than individual data
abuse) are valid. EU data protection leaves a great deal of governmental access to data
unregulated (or poorly regulated), and the DPA's excemptions
(http://www.opsi.gov.uk/Acts/Acts1998/ukpga_19980029_en_5#pt4) provides any number of
loopholes for the misuse of personal data.
That's always assuming that future misuse would be under (or even care about) current
statutes.