{"data":{"id":"us-nc/n.c.-gen.-stat.-143-800","jurisdiction":"us-nc","citation":"N.C. Gen. Stat. § 143-800","heading":"State entities and ransomware payments.","body":"(a)\tNo State agency or local government entity shall submit payment or otherwise communicate with an entity that has engaged in a cybersecurity incident on an information technology system by encrypting data and then subsequently offering to decrypt that data in exchange for a ransom payment.\n(b)\tAny State agency or local government entity experiencing a ransom request in connection with a cybersecurity incident shall consult with the Department of Information Technology in accordance with G.S. 143B-1379.\n(c)\tThe following definitions apply in this section:\n(1)\tLocal government entity. - A local political subdivision of the State, including, but not limited to, a city, a county, a local school administrative unit as defined in G.S. 115C-5, or a community college.\n(2)\tState agency. - Any agency, department, institution, board, commission, committee, division, bureau, officer, official, or other entity of the executive, judicial, or legislative branches of State government. The term includes The University of North Carolina and any other entity for which the State has oversight responsibility. (2021-180, s. 38.13(a).)","path":["Chapter 143. State Departments, Institutions, and Commissions","Article 84. Various Technology Regulations."],"source_url":"https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_143/GS_143-800.html","current_through":"S.L. 2026-30","vintage":"","retrieved_at":"2026-08-27T18:22:33Z","sha256":"ca48a857f5f477ec70c2defdb0fd01e8526d8429cc9d82cf2e78e8e742f8388e","source_id":"us-nc","stale":false,"prev":"us-nc/n.c.-gen.-stat.-143-791","next":"us-nc/n.c.-gen.-stat.-143-805"},"notice":"GroundRules: Original legal text. Not legal advice."}
