Privacy When Requesting Membership Information
What personal data to share or avoid, how identity should be checked proportionately and why an enquiry never amounts to admission.

Prepared by the HashQuarters editorial team using identified sources. General information is not a substitute for legal or medical advice.
General information; not a substitute for legal or medical advice.
This guide does not explain how to join; that information belongs on the membership page. Its focus is personal data during an enquiry: what to share, what the controller should disclose and why an enquiry or automated reply never grants membership or access.
Legal adulthood and a private higher age threshold are different concepts. Any higher threshold must be described as a documented internal condition, not a general statement of Spanish law.
Before sharing personal data
Before providing personal data, review the legal notice, privacy policy, available statutes and membership conditions. The organisation's identity, the data controller and a channel for exercising data-protection rights should be clear.
A page that talks only about atmosphere, products or instant access is missing essential information. An association should be able to explain its purposes and rules without sales language.
Minimum data for an initial enquiry
The HashQuarters information form asks only for your name and email address, together with confirmation that you have read the available privacy information. Do not send identity documents, health details or other sensitive information through these fields. The minimisation principle in GDPR Article 5(1)(c) limits collection to what is necessary; the AEPD's PA-00046-2025 decision illustrates, on its particular facts, the risk of retaining an unnecessary identity-document copy. Do not request copies in advance unless necessity, legal basis and safeguards are documented.
The PA-00046-2025 decision concerns tourist accommodation; it is cited here only as an example of the data-minimisation principle, not as a rule specific to associations.
An enquiry that reveals cannabis use, diagnoses, medication, use history or product preferences may reveal health data and require a specific analysis under Articles 6 and 9 of the GDPR. Do not request those data until the responsible person has documented necessity, legal basis, safeguards and whether an Article 35 data-protection impact assessment is required.
An automated response should confirm receipt only. It must not confer membership, book a visit or create a right of access.
How an enquiry is reviewed
The association reviews the enquiry in light of its statutes and available capacity. It may ask for clarification or decide not to continue. The website must not promise a 24-hour response, approval or a positive outcome.
Proportionate identity and age checks
If the process continues, the organisation may need to verify identity and age using a current official document. Verification should be proportionate and secure. Checking a document does not necessarily mean retaining a copy.
Before agreeing to membership, a person should be able to review the statutes, house rules, any financial obligations and the process for leaving. No amount should be presented as an entry fee or a product price.
An explicit decision, not automatic access
Only an explicit communication can confirm that the procedure is complete. Until then, do not travel to the address or treat any message as permission to enter.
Membership, when granted, is not a general authorisation to engage in conduct prohibited by other laws. Public-space, driving and health considerations continue to apply.
Visitors and data minimisation
A visitor may ask for general information, but an enquiry creates no special entitlement because of trip length, a hotel booking or an informal recommendation.
Visiting Barcelona does not create a right of admission or entry. An information request is not a booking or invitation.
Privacy throughout the process
Do not send document images through an unapproved channel. Before collecting identifying data or information that may reveal health or cannabis use, the association should explain the controller, purpose, legal basis, recipients, retention, transfers and relevant rights. If an application does not proceed, it must follow its documented retention policy and erase data where applicable.
Official sources: RGPD / GDPR · AEPD PA-00046-2025
Membership information · Private association model · What a cannabis social club is
Frequently asked questions
Does the form confirm membership?
No. A form can only begin an enquiry; it does not create membership, a booking or entry.
Is an automated email an invitation?
No. A receipt message only confirms that the enquiry arrived.
Does visitor status create a day pass?
No. Visiting Barcelona does not create a right of admission or entry.
What information should be requested?
Only information that is necessary and proportionate, after its purpose and handling have been explained. Do not send copies in advance.
How long does a response take?
No response time should be assumed. Wait for an explicit communication before traveling.
Private association
Membership information
Read the process, general requirements and access limits before submitting a request.
See how membership works →Membership · private association
Before requesting information
The Membership page explains the process and its limits. Reading it does not create a booking or guarantee admission.