Probably the most common DPA breach I'd say is websites requiring gender and title. There is very rarely a need to collect this information. At best it may be required in a clinical setting but even then biological sex is more important than self-identified gender or title.
I've had this discussion multiple times with RDG when it's been raised as a problem that Raileasy don't ask for title!
With the exception of one particularly insufferable customer (who also objected to "Hi" and other informalities like "Kind regards" and "Whoops" in a user-friendly error message) I think the almost all of the customers I've come into contact with in the different industries I've worked were quite happy to be addressed using their first name.
The title is just completely irrelevant 99% of the time. I don't care if you're a Lord, a Baron, a Reverend or an Admiral - you'll be treated with the same respect as everyone else and referred to in the same way as everyone else, too.
Incidentally, there are still a few industries where they seem to really struggle
not referring to you as "Mr Williams"; the legal and medical fields come to mind. When I had to stay in hospital for a surgical procedure it was the staff who introduced themselves properly, used my name and spoke to me (like every other human being speaks to me) that put me at ease. It didn't mean they weren't clear about their role or their qualifications - "Hi, I'm [first name], the consultant anaesthetist today" is sufficient to explain what you're there to do and your scope of practice. I think some people want to try and reinforce a "power dynamic" of sorts (this is rather common in the United States) where there is this very explicit hierarchy of authority which has to be put on show - but you can absolutely respect what a professional has to say, trust in their expertise and participate in shared decision-making whilst both using a first name.
My accountant manages to consistently uses my first name, why can't my conveyancing solicitor or dentist?
Banking used to be a bit like this, but there are enough modern banks nowadays (e.g. Monzo) that have dragged the industry into the 21st century to be able to avoid it.
I mean this respectfully but I do think there's a generational aspect to all of it as well, the people who tend to complain are almost always Senior Railcard holders...
In any case I don't really see why someone who would voluntarily trust a company with a full credit card number wouldn't also trust them with a phone number.
The only technical point I'd make here is that the credit card number will almost always be handled by an actually competent payment provider company (and you can often tell this is happening technically if you know how to look at it). Phone number and other out-of-scope-of-PCI (Payment Card Industry) data will be directly handled by the company you're dealing with -
usually. So I might not trust Raileasy to take my credit card number directly, but I might have more trust that the other data they do take directly themselves is fine for them to handle.