Firstly I don't work for O2 but I work in the mobile industry. O2 should only be passing your number to trusted sites (and to get on that list is pretty hard). We have reported it to them via various internal contacts we have. Hopefully they will fix this soon!
No site served over unencrypted HTTP can be considered trusted. So there's no circumstance under which they should insert this header, since they can't modify HTTPS requests.
In such a circumstance, carriers may consider this "trusted".