Calendar An icon of a desk calendar. Cancel An icon of a circle with a diagonal line across. Caret An icon of a block arrow pointing to the right. Email An icon of a paper envelope. Facebook An icon of the Facebook "f" mark. Google An icon of the Google "G" mark. Linked In An icon of the Linked In "in" mark. Logout An icon representing logout. Profile An icon that resembles human head and shoulders. Telephone An icon of a traditional telephone receiver. Tick An icon of a tick mark. Is Public An icon of a human eye and eyelashes. Is Not Public An icon of a human eye and eyelashes with a diagonal line through it. Pause Icon A two-lined pause icon for stopping interactions. Quote Mark A opening quote mark. Quote Mark A closing quote mark. Arrow An icon of an arrow. Folder An icon of a paper folder. Breaking An icon of an exclamation mark on a circular background. Camera An icon of a digital camera. Caret An icon of a caret arrow. Clock An icon of a clock face. Close An icon of the an X shape. Close Icon An icon used to represent where to interact to collapse or dismiss a component Comment An icon of a speech bubble. Comments An icon of a speech bubble, denoting user comments. Comments An icon of a speech bubble, denoting user comments. Ellipsis An icon of 3 horizontal dots. Envelope An icon of a paper envelope. Facebook An icon of a facebook f logo. Camera An icon of a digital camera. Home An icon of a house. Instagram An icon of the Instagram logo. LinkedIn An icon of the LinkedIn logo. Magnifying Glass An icon of a magnifying glass. Search Icon A magnifying glass icon that is used to represent the function of searching. Menu An icon of 3 horizontal lines. Hamburger Menu Icon An icon used to represent a collapsed menu. Next An icon of an arrow pointing to the right. Notice An explanation mark centred inside a circle. Previous An icon of an arrow pointing to the left. Rating An icon of a star. Tag An icon of a tag. Twitter An icon of the Twitter logo. Video Camera An icon of a video camera shape. Speech Bubble Icon A icon displaying a speech bubble WhatsApp An icon of the WhatsApp logo. Information An icon of an information logo. Plus A mathematical 'plus' symbol. Duration An icon indicating Time. Success Tick An icon of a green tick. Success Tick Timeout An icon of a greyed out success tick. Loading Spinner An icon of a loading spinner. Facebook Messenger An icon of the facebook messenger app logo. Facebook An icon of a facebook f logo. Facebook Messenger An icon of the Twitter app logo. LinkedIn An icon of the LinkedIn logo. WhatsApp Messenger An icon of the Whatsapp messenger app logo. Email An icon of an mail envelope. Copy link A decentered black square over a white square.

Probe into data breach at Highland Perthshire resort after details of 2,400 members leaked online

Loch Rannoch Highland Club
Loch Rannoch Highland Club

Bosses at a Perthshire holiday resort have been accused of an “inexcusable” security breach after posting the personal emails and phone numbers of more than 2,400 members on their website.

The Loch Rannoch Highland Club, which counts former Tory leader Sir Iain Duncan Smith amongst its visitors, was reported to data protection watchdogs after publishing 243 pages of sensitive information.

The blunder has angered some timeshare owners who have already fallen out with the club committee over a series of redundancies and walk-outs.

Anger over sackings and walk-outs at popular Highland Perthshire tourist resort

Club chairman Cliff Hunter said the members’ details were removed “within hours” of going online and insisted only a small number of people had viewed them.

 

Investigation

The Information Commissioner’s Office (ICO) has confirmed it is probing the incident and has urged anyone with concerns to get in touch.

Until it was shut down, the members section of the Loch Rannoch Highland Club (LRHC) website – which was fully accessible to the public – contained a lengthy list of timeshare owners’ email addresses and phone numbers, alongside their club reference numbers.

The list was reported to the ICO by owner Ann Blythe, who is proprietor of the Perth-based UK Resort Exchange.

She said: “One of the other owners had alerted me. He came across it by accident.

“I couldn’t believe what I was seeing. The club has some very prominent members and I’m sure they would be horrified to know their details have been put out there like this.”

The club was attacked by vandals following a row about the use of contract workers.

Apology demand

Among the best known guests was politician Iain Duncan Smith, who visited the timeshare complex at least once in 2016.

He asked for an apology from the club after details of his visit appeared in a newsletter sent to members.

“I seem to have been used unwittingly as part of a marketing promotion without my permission,” he wrote at the time. It is not clear if his details were among the 2,400 published on the website.

Another owner, Ian Taylor said the members’ list was an “inexcusable breach” of GDPR rules and regulations.

“The personal information of all members was available to all and sundry throughout the world. This is gross negligence and it is totally irresponsible for the LRHC website to publish personal and private data, without the consent of the individual.”

Mr Taylor has written to Mr Hunter, urging him to resign and call an extraordinary general meeting to elect a new committee.

Mr Hunter told The Courier: “As soon as the club was made aware of what had happened, this small loophole was immediately closed.”

He said: “The page was only visible by searching the site for that particular page, which was only accessible through the members area and was never available as a menu item or click on the public-facing portion of the site.

“Additionally, this section of the website had only been online for a matter of hours, and that page had only been viewed a couple of times.”

Page spotted

The Courier understands the page was spotted on Wednesday night and was shut down at about 3pm the following day.

Mr Hunter said he had spoken to club lawyers and a representative from the ICO, claiming they were “satisfied with the explanation of what had occurred, that the loophole had been closed and no further action is necessary.”

A ICO spokeswoman told The Courier: “We are aware of a potential incident at Loch Rannoch Highland Club and are making enquiries.

“Anyone with concerns about how their data has been handled can report them to us and we will look into the details.”