---
title: HB 886. State government; prohibit state agencies and local government entities from responding to ransomware activity
collection: bills
id: 2025-2026/hb886
cite_as: HB 886, 2025-2026 Regular Session (Ga.)
canonical_url: https://georgiacommons.org/bills/2025-2026/hb886
md_url: https://georgiacommons.org/bills/2025-2026/hb886.md
text_url: https://georgiacommons.org/bills/2025-2026/hb886/text
source_url: https://www.legis.ga.gov/legislation/71892
date: 2025-04-04
status: introduced
corpus_version: bills-2026-08-28
license: Public record of the Georgia General Assembly, via LegiScan; see about.md
publisher: Georgia Commons, an independent project of Georgia Civic Data. Not the State of Georgia. Not legal advice.
up: https://georgiacommons.org/bills/2025-2026.md
previous: https://georgiacommons.org/bills/2025-2026/hb885.md
next: https://georgiacommons.org/bills/2025-2026/hb887.md
index: https://georgiacommons.org/bills/index.md
omitted: votes and history
omitted_chars: 129
omitted_url: https://georgiacommons.org/bills/2025-2026/hb886.md?full=1
bill_number: HB 886
session: 2025-2026 Regular Session
session_slug: 2025-2026
chamber: House
bill_type: bill
status_date: 2025-03-31
last_action: House Second Readers
sponsors:
  - Stacey Evans
  - Debra Bazemore
  - Tanya Miller
  - Kim Schofield
  - Park Cannon
text_version: Introduced
has_text: true
legiscan_url: https://legiscan.com/GA/bill/HB886/2025
upstream_id: 2017587
summaries_model: claude-sonnet-5
topic_tags:
  - cybersecurity
  - ransomware
  - local government
  - state government technology
  - data breaches
---

# HB 886. State government; prohibit state agencies and local government entities from responding to ransomware activity

## Text

25 LC 56 0313
House Bill 886
By: Representatives Evans of the 57th, Bazemore of the 69th, Miller of the 62nd, Schofield of
the 63rd, and Cannon of the 58th
A BILL TO BE ENTITLED
AN ACT
To amend Chapter 1 of Title 50 of the Official Code of Georgia Annotated, relating to1
general provisions regarding state government, so as to prohibi t state agencies and local2
government entities from responding to ransomware activity; to require that state agencies3
and local government entities report ransomware activity to the Georgia Technology4
Authority; to provide for definitions; to provide for related m atters; to repeal conflicting5
laws; and for other purposes.6
BE IT ENACTED BY THE GENERAL ASSEMBLY OF GEORGIA:7
SECTION 1.8
Chapter 1 of Title 50 of the Official Code of Georgia Annotated , relating to general9
provisions regarding state government, is amended by adding a new Code section to read as10
follows:11
"50-1-14.12
(a) As used in this Code section, the term:13
(1) 'Local government entity' means any political subdivision of this state, including any14
county, consolidated government, municipality, authority, school district, commission,15
H. B. 886
- 1 -
25 LC 56 0313
board, municipal corporation, governmental unit, sheriff’s offi ce, law enforcement16
agency, or any other local public body.17
(2) 'Ransomware activity' means restricting access to a comput er system or its data,18
typically by encrypting such data, with the demand for a ransom payment in exchange19
for access restoration.20
(3) 'State agency' means any department, agency, board, commission, institution, or other21
entity of the executive, legislative, or judicial branches of t he state, including public22
universities, technical colleges, and other institutions under the state's authority.23
(b) No state agency or local government entity in this state s hall submit payment to or24
otherwise communicate with an individual or organization engaging in ransomware activity25
against such state agency or local government entity.26
(c) Any state agency or local government entity experiencing r ansomware activity27
immediately shall consult with the Georgia Technology Authority . T h e G e o r g i a28
Technology Authority shall provide guidance and coordinate the response to such29
ransomware activity. The affected state agency or local govern ment entity shall be30
required to provide the Georgia Technology Authority with any i nformation required to31
appropriately address such response."32
SECTION 2.33
All laws and parts of laws in conflict with this Act are repealed.34
H. B. 886
- 2 -

## Summaries written by Georgia Commons

The following was written by claude-sonnet-5 from the text above and is not part of the bill. Quote the text, not the summary.

House Bill 886 would ban Georgia state agencies and local governments from paying ransoms or communicating with hackers during ransomware attacks, and would require them to immediately report such attacks to the Georgia Technology Authority.

### Plain-language summary

Ransomware attacks, in which hackers lock up a computer system's data and demand payment to restore access, have hit government offices around the country. This bill addresses how Georgia's state agencies and local governments must respond if it happens to them.
The bill adds a new section to Georgia law (O.C.G.A. § 50-1-14) that flatly bars any state agency or local government entity, including counties, cities, school districts, sheriff's offices, and other public bodies, from paying a ransom or otherwise communicating with whoever is behind the attack. Instead, any affected agency or local government must immediately consult with the Georgia Technology Authority, which will guide and coordinate the response. Affected entities must share whatever information the authority needs to handle the situation. The bill defines key terms like 'ransomware activity,' 'state agency,' and 'local government entity' broadly to cover nearly all of Georgia's public sector.

### What it does

- Prohibits any Georgia state agency or local government entity from paying a ransom to resolve a ransomware attack.
- Prohibits those same entities from otherwise communicating with the individuals or groups behind a ransomware attack.
- Requires state agencies and local governments hit by ransomware to immediately consult with the Georgia Technology Authority for guidance.
- Requires affected agencies to share any information the Georgia Technology Authority needs to coordinate and manage the response.
- Defines 'local government entity' broadly to include counties, cities, school districts, sheriff's offices, and other local public bodies.

### Who it affects

State agencies including public universities and technical colleges, and local government entities such as counties, cities, school districts, sheriff's offices, and law enforcement agencies across Georgia. The Georgia Technology Authority, which would take on a new coordination role, is also directly affected.

### Why it matters

If a ransomware attack hits a Georgia school district, county office, or state agency, officials would no longer be allowed to negotiate or pay to get their data back, and would instead have to bring in the Georgia Technology Authority right away, changing how these incidents get handled statewide.

### Key provisions

- Section 1 adds new Code section O.C.G.A. § 50-1-14 defining 'local government entity,' 'ransomware activity,' and 'state agency' for purposes of the law.
- Subsection (b) bars any state agency or local government entity from paying or communicating with anyone carrying out a ransomware attack against it.
- Subsection (c) requires immediate consultation with the Georgia Technology Authority when a ransomware attack occurs, with the authority directing the response.
- Subsection (c) also requires affected agencies to turn over any information the Georgia Technology Authority needs to address the attack.
- Section 2 repeals any conflicting laws.

## Status

- Status: Introduced (2025-03-31)
- Last action: House Second Readers (2025-04-04)
- Sponsors: Stacey Evans, Debra Bazemore, Tanya Miller, Kim Schofield, Park Cannon
- Official page: https://www.legis.ga.gov/legislation/71892

> The history, votes, and amendments (129 characters) are at https://georgiacommons.org/bills/2025-2026/hb886.md?full=1
