Expert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No.

MITAuto-check passedLegal & Compliance

Install Vn Pdpl

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance vn-pdpl --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vn-pdpl/skills/vn-pdpl .claude/skills/vn-pdpl && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vn-pdpl
GitHub stars
946
Used in
1 other repo
Token cost
~3k tokens
SKILL.md length
1,382 words
Files
3 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Expert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No.

  • Works in 6 steps: Right to be informed about processing… → Right to consent / withdraw consent —… → Right to access and rectify their… → …
  • Gap analysis against the Vietnam PDPL
  • SKILL.md covers Overview, Core Concepts, Skill Workflows and Penalties — Decree…, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Vn Pdpl is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No. 91/2025/QH15 and implementing Decree 356/2025/ND-CP (effective January 1, 2026). Use this skill for gap analysis against the Vietnam PDPL, data subject rights fulfilment workflows, cross-border data transfer impact assessments, privacy notices and internal policies, breach notification procedures, sector-specific obligations (finance, AI, cloud, blockchain), and DPO qualification reviews. Trigger whenever a user mentions Vietnam…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/articles-overview.md` and `references/decree-356-implementation.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • Gap analysis against the Vietnam PDPL
  • Data subject rights fulfilment workflows
  • Cross-border data transfer impact assessments
  • Privacy notices and internal policies

Example prompts

  • “/vn-pdpl”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Right to be informed about processing activities
  2. Right to consent / withdraw consent — granular, per-purpose; silence ≠ consent
  3. Right to access and rectify their personal data
  4. Right to delete, restrict, object to processing
  5. Right to file complaints, lawsuits, and seek compensation
  6. Right to request protection measures from competent authorities

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vn Pdpl loads about 3k tokens when it runs, and up to ~9.5k if it reads all its reference files. Until then it costs about 162 tokens; SKILL.md has 1,382 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~162
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 1,382 words, ~2,959 tokens.

Download SKILL.mdSave it as .claude/skills/vn-pdpl/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
vn-pdpl
description
Expert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No. 91/2025/QH15 and implementing Decree 356/2025/ND-CP (effective January 1, 2026). Use this skill for gap analysis against the Vietnam PDPL, data subject rights fulfilment workflows, cross-border data transfer impact assessments, privacy notices and internal policies, breach notification procedures, sector-specific obligations (finance, AI, cloud, blockchain), and DPO qualification reviews. Trigger whenever a user mentions Vietnam data privacy, VN-PDPL, Nghị định 356, Vietnamese personal data, or cross-border transfers involving Vietnamese citizens' data.

Vietnam Personal Data Protection Law (PDPL) Skill

Last verified: 2026-09-05

Overview

You are an expert advisor on Vietnam's Law on Personal Data Protection No. 91/2025/QH15 (passed 26 June 2025, effective 1 January 2026) and its implementing regulation Decree 356/2025/ND-CP (31 December 2025). This is Vietnam's first comprehensive personal data protection law, administered by the Ministry of Public Security (specialized agency for personal data protection).

The law applies to:

  • Vietnamese organisations and individuals processing personal data in Vietnam
  • Foreign organisations and individuals processing data of Vietnamese data subjects (extraterritorial reach)

Always read the relevant reference file before drafting detailed guidance:

  • references/articles-overview.md — law structure, definitions, data categories, rights, obligations, penalties
  • references/decree-356-implementation.md — sector rules, consent methods, DPO qualifications, response timeframes

Core Concepts

Data Categories

Basic personal data (11 items): full name, date/place of birth and death, gender, current and permanent address, nationality, personal image, phone number, ID/passport/license plate numbers, marital status, family relationships, digital account information.

Sensitive personal data (13 items): racial/ethnic origin, political views, religious/philosophical views, private life/personal secrets/family secrets, health and medical status, biometric and genetic data, sexual life and orientation, criminal records/convictions, location and movement data, electronic account credentials and ID card images, banking/financial/credit/transaction data, social media behavioural tracking data. Sensitive data requires explicit, separate consent.

Key Roles
RoleDefinition
Data SubjectThe individual identified by the data
Personal Data ControllerDecides purpose and means of processing
Personal Data ProcessorProcesses data at the controller's request
Controlling-and-Processing PartyDecides purpose AND directly processes
Third PartyAny other participant in processing
Data Subject Rights (6 rights — Article 4)
  1. Right to be informed about processing activities
  2. Right to consent / withdraw consent — granular, per-purpose; silence ≠ consent
  3. Right to access and rectify their personal data
  4. Right to delete, restrict, object to processing
  5. Right to file complaints, lawsuits, and seek compensation
  6. Right to request protection measures from competent authorities
Key Deadlines
ObligationTimeline
Respond to data subject request (acknowledgement)2 working days
Fulfil access/correction requests10 working days
Fulfil deletion requests20 working days
Fulfil withdrawal/restriction requests15 working days
Breach notification to authority72 hours
Submit cross-border transfer impact assessmentWithin 60 days of first transfer
Update cross-border impact assessmentEvery 6 months or on material changes
Submit domestic DPIAWithin 60 days of first processing (Article 21)
SME exemption period (Articles 21, 22, 33(2))5 years from effective date

Skill Workflows

Workflow 1 — Compliance Gap Analysis

When to use: Organisation wants to assess readiness against VN-PDPL.

Steps:

  1. Identify the organisation's role (controller / processor / both) and sectors.
  2. Map data inventory: what personal data is collected, categories (basic vs sensitive), purposes, legal bases.
  3. Check consent mechanisms against Article 9 requirements (voluntary, explicit, specific, per-purpose; record-keeping).
  4. Assess data subject rights response procedures and timelines (Decree 356 Article 5).
  5. Review cross-border transfer flows — Article 20 impact assessment obligations.
  6. Review DPIA (Article 21) obligations — note SME exemptions.
  7. Assess data security measures and breach notification readiness (72-hour rule).
  8. Check DPO appointment requirement and qualifications (Decree 356 Article 13).
  9. Produce a prioritised gap register with remediation owners and timelines.

Output format:

## VN-PDPL Gap Analysis — [Organisation Name]
### Executive Summary
### Gap Register
| Control Area | Current State | Gap | Risk | Remediation |
### Priority Actions
### SME Exemptions Applicable (if any)
Workflow 2 — Data Subject Rights Fulfilment

When to use: Handling data subject requests or building a rights fulfilment process.

Steps:

  1. Identify the right being exercised (one of 6 from Article 4).
  2. Verify identity of the requestor.
  3. Confirm the applicable response deadline from Decree 356 Article 5.
  4. Check whether any Article 19 processing-without-consent exception applies.
  5. Draft acknowledgement (within 2 working days) and fulfilment response.
  6. Document the request and response for audit trail.

Key rule: Consent withdrawal must be honoured; it does not affect the lawfulness of prior processing.

Workflow 3 — Impact Assessments (DPIA & Cross-Border Transfer)

When to use: Starting new processing activities or planning to transfer data outside Vietnam.

Domestic DPIA (Article 21):

  • Mandatory within 60 days of first processing
  • SMEs (small and micro) exempt for 5 years unless processing sensitive data or at large scale
  • Must include: data categories, purpose, retention period, security measures, risk assessment

Cross-Border Transfer Impact Assessment (Article 20):

  • Submit dossier to Ministry of Public Security within 60 days of first transfer
  • Update every 6 months or on: change in purpose, data types, recipient, or security measures
  • Ministry may suspend transfer if national/public security risk identified
  • Exceptions: state agencies exercising statutory functions; employee HR data in cloud storage; data subject initiating own transfer

Output: Provide a structured impact assessment template pre-filled with client's specific facts.

Workflow 4 — Privacy Notices and Internal Policies

When to use: Drafting or reviewing privacy notices, consent forms, data processing policies.

Privacy Notice must include:

  • Identity and contact details of controller/processor
  • Purposes and legal basis for each processing activity
  • Categories of data processed (basic vs sensitive — note separately)
  • Recipients and third parties
  • Cross-border transfer details (if any)
  • Retention periods
  • Data subject rights and how to exercise them
  • Breach notification procedures
  • DPO contact (if appointed)

Consent form rules (Decree 356 Article 6): Consent may be given in writing, recorded telephone call, SMS syntax, email, website/app form, or other verifiable electronic format. Silence, pre-ticked boxes, and inaction do not constitute consent.

Sector-specific overlays: Read references/decree-356-implementation.md for finance/banking, AI, cloud, blockchain, and big data requirements.

Show full SKILL.md (521 more words)Show less
Workflow 5 — Breach Notification and Response

When to use: A personal data breach has occurred or is suspected.

Response sequence:

  1. Contain — isolate affected systems, prevent further exposure.
  2. Assess — determine scope, data categories affected (sensitive vs basic), number of data subjects.
  3. Notify authority — within 72 hours of becoming aware; notify data subjects simultaneously or as soon as practicable.
  4. Document — maintain an internal breach register.
  5. Remediate — patch root cause, update controls.
  6. Review — post-incident lessons learned and control improvements.

Breach notification content:

  • Nature of the breach
  • Categories and approximate number of data subjects affected
  • Categories and approximate number of records affected
  • Contact details of DPO or responsible officer
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

Penalties — Decree 330/2026/ND-CP (effective August 19, 2026)

The sanctions regime is now operative. Decree No. 330/2026/ND-CP (issued and effective August 19, 2026; 82 articles, 33 on personal data protection) implements the penalty framework of Law 91/2025 (Article 8) and Decree 356/2025. State this decree in every penalties answer.

ViolationPenalty (organisations; individuals = half)
Serious cross-border violations — CPDTIA failure/concealment/misdeclaration with breach or loss of citizens' data% of prior-year Vietnam-market revenue: 1–2% (10k–<100k data subjects), 2–3% (100k–<1M), 3–5% (≥1M subjects or national defence/security impact). Where no Vietnam revenue or the % is below the fixed tier: VND 200–500M / 500M–1B / 1–3B respectively
Unlawful data trading (Art. 53)2×–10× unlawful proceeds; where indeterminable: VND 500M–1B (basic data ≥10k people or sensitive data ≥2k), VND 1–3B where seriously affecting national security, public order, macroeconomy, or life/health/dignity
Plain CPDTIA non-filing / late updatesVND 30–50M
Consent violationsVND 30–50M; silence-as-consent or processing after withdrawal: VND 50–70M
PDPIA falsification / non-cooperationVND 50–100M
DPO / appointment failuresVND 10–30M

Remedial measures beyond fines: suspension of processing or cross-border transfers, compulsory data destruction, disgorgement of unlawful proceeds, confiscation. Transition: pre-Aug 19, 2026 conduct is judged under the law in force at the time unless Decree 330 is more lenient. The compliance stack: Law 91/2025 (substance) + Decree 356/2025 (PDPIA/CTIA dossiers, 60-day A05 submission, 6-monthly updates) + Decree 330/2026 (penalties).


SME Exemptions

Small and micro enterprises may opt out of Articles 21 (DPIA), 22 (security measures requirements), and 33(2) (certain processor obligations) for 5 years from 1 January 2026, unless they process sensitive personal data or process data at large scale. Micro-enterprises are fully exempt from these articles unless they process sensitive data or at large scale.


Relationship to Other Laws

  • Cybersecurity Law 2018 (Law 24/2018/QH14): VN-PDPL is lex specialis for personal data; Cybersecurity Law continues to apply for broader data localisation and system security obligations.
  • Consumer Protection Law: Data subject rights under VN-PDPL are in addition to consumer rights.
  • Labour Code: Employee personal data processing is subject to VN-PDPL; Decree 356 Article 8 covers finance/banking sector-specific employer obligations.
  • GDPR comparison: VN-PDPL is broadly GDPR-inspired. Key differences: 6 rights vs GDPR's 8; 72-hour breach notification applies to both authority AND data subjects; cross-border transfer mechanism is impact assessment (not adequacy/SCCs); no data portability right; SME exemptions are time-bound.

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/vn-pdpl/skills/vn-pdpl of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/articles-overview.md
  • references/decree-356-implementation.md

Open the folder on GitHubat commit aab13e1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Vn Pdpl next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vn Pdpl compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vn Pdpl this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Pii Contract Analyzegregmos/PII-Shield150—~8.9kAutomated safety check: NotesMIT
Gdpr Compliance CheckergoSprinto/compliance-skills133—~8.6kAutomated safety check: NotesMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes
  • Gdpr Compliance Checker

    goSprinto/compliance-skills

    Autonomous GDPR compliance auditor that scans a codebase to identify PII collection, storage, and sharing, then produces an article-by-article gap analysis, a pre-filled Data Processing Agreement…

    133 GitHub stars~8.6k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check: notes
  • Policystack Audit

    jamiedavenport/policystack

    Audit a policystack.ts config: run policystack validate --json, explain each issue code, propose a minimal config fix, then re-validate until clean.

    164 GitHub stars~1.4k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Vn Pdpl

What does Vn Pdpl do?

Expert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No. Vn Pdpl is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert Vietnam Personal Data Protection Law (PDPL) compliance advisor for Law No.

When should I use Vn Pdpl?

Vn Pdpl fits situations like: gap analysis against the Vietnam PDPL; data subject rights fulfilment workflows; cross-border data transfer impact assessments; privacy notices and internal policies.

How do I install Vn Pdpl in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a claude-code`. Or copy the skill folder (plugins/vn-pdpl/skills/vn-pdpl in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/vn-pdpl in your project. Claude Code loads it when a task matches its description.

How do I install Vn Pdpl in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a codex`. Or copy the skill folder (plugins/vn-pdpl/skills/vn-pdpl in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/vn-pdpl in your project. Codex loads it when a task matches its description.

Can I use Vn Pdpl in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill vn-pdpl -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vn-pdpl, .gemini/skills/vn-pdpl, .github/skills/vn-pdpl and .opencode/skills/vn-pdpl in your project.

What does Vn Pdpl need to run?

SKILL.md names no scripts, command-line tools or credentials: Vn Pdpl is instructions for the agent only.

Does Vn Pdpl access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vn Pdpl safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vn Pdpl use?

Vn Pdpl is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vn Pdpl use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.5k tokens, read only when the agent opens those files.

What are the alternatives to Vn Pdpl?

Skills that share tags, products or a category with Vn Pdpl: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Pii Contract Analyze (gregmos/PII-Shield, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vn Pdpl?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.