I've worked in these environments too and others where it's fine to create "DMZ" VLANs.
Personally I wouldn't run DMZ VLANs, I'd run a separate switch, but it's all down to individual budgets and so forth.
I've been told by pentesters that you can bleed data between VLANs.
Very interesting this, now you have done it.. got me all worked up
I am going to see if I can detect any leak of data between VLANS at home