If data theft is a problem then a combination of CMOS password as well as OS password could be the best (although not the safest

) bet.
If you only keep XP password, then someone can still use a bootable CD like Knoppix and look around in your XP partition for interesting files.
IMHO, as long as someone has a physical access to a PC, data is never 100% safe