Dear René (that's me obviously),
The Data Protection Act requires "adequate" security measures against theft and abuse of personal information. There are no strict rules, so everyone can take there own measures to how that requirement is met.
SSL seems an adequate method for ordering and contact forms, so if you do, then you meet the requirements, in my opinion. Also protect your database of course. But if you have another way to be safe, or you think that e-mail addresses in a non-SSL contact form are safe enough, then there is no rule that stops you.
...
For orders and payments, often the payment provider requires SSL (or already uses), which is a contractual requirement that you have to meet. Also mark Thuiswinkel.org makes demands that you must have SSL, and who will not succeed, can not carry their quality mark.
You may publish this on the forum.
Sincerely,
Arnoud Engelfriet