Telecoms and internet
Yes: if you sell broadband or connectivity under your own name, you need professional indemnity insurance, because customers rely on your advice and on how you handle orders, migrations and number ports. When a line is ordered at the wrong speed, a port fails or a site is left offline, the customer’s loss is financial and the claim comes to you, not your wholesale supplier. Public liability does not cover it. PI usually does, and cyber insurance usually covers your own costs after a breach or attack.
Part of: Professional indemnity for IT professionals
In short
Ofcom’s General Conditions apply to all providers of electronic communications networks and services, and a reseller contracting in its own name should expect the customer-facing rules to apply: compliant complaints procedures and membership of an approved ADR scheme; for complaints raised from 8 April 2026, customers can go to ADR after six weeks rather than eight. If a number port fails, the number and services must be reactivated until it completes. PECR treats providers using a third party’s network as service providers, with 72 hours to report a personal data breach to the ICO. PI covers negligent advice, ordering and migration work, but your wholesale contract usually limits what you can recover upstream.
Last reviewed 5 October 2026 by the Apex professional indemnity team.
As a reseller you buy connectivity wholesale and sell it under your own name. You may never own a cable or a cabinet, but the customer’s contract is with you, and so is the relationship: you check availability, recommend a product, place the order, manage the migration, port the numbers and handle faults. Each of those steps involves judgement, and each can leave a customer offline or paying for something that does not do the job.
When that happens, the loss is financial. A business without connectivity cannot take card payments, answer calls or reach its cloud systems. Public liability insurance has nothing to say about that; it is built for accidental injury and property damage. Professional indemnity (PI) insurance, written for telecoms and IT firms as technology errors and omissions cover, responds when a customer alleges your advice, ordering or migration work was negligent.
The wholesale supplier behind you rarely shares the problem. Its terms usually limit its liability to you, so the gap between what you promised your customer and what you can recover upstream is your exposure.
The scenarios below are illustrative. They are not real claims, but they reflect the allegations resellers deal with.
Ofcom says all providers of electronic communications networks and services must comply with its General Conditions, and that each provider must establish which conditions apply to the services it provides. A reseller contracting with customers in its own name should expect the customer-facing rules to apply. These are the rules and codes most likely to feature in a dispute.
| Rule or code | What it says | Why it matters to your PI |
|---|---|---|
| Ofcom General Conditions of Entitlement | All providers of electronic communications networks and services must comply with the General Conditions to provide services in the UK. | Each provider must work out which conditions apply to its services; a breach can support a customer’s claim. |
| Condition C4: complaints and ADR | Providers must have complaints procedures meeting minimum standards and belong to an Ofcom-approved alternative dispute resolution scheme, free for individuals, businesses with up to 10 employees and small not-for-profits. For complaints raised from 8 April 2026, customers can go to ADR after six weeks instead of eight. | Small business disputes can reach an ADR scheme quickly, so record your handling from day one. |
| Condition C1: contract requirements | Business customers with ten or fewer employees must receive key contract information in writing before they are bound, and a contract summary before they agree. | If a speed, price or term is disputed, these documents are the first evidence anyone reads. |
| Condition C7: switching and number porting | Switches should keep service running where technically feasible, and any loss of service must not exceed one working day. Customers can port their number for at least one month after switching, must not be directly charged for porting, and if a port fails the number and services must be reactivated until it is completed. | Failed migrations and ports are where reseller errors cause the most visible harm. |
| One Touch Switch | Since September 2024, residential landline and broadband customers moving between networks only need to contact their new provider, and providers must compensate customers left without service for more than one working day. | If you sell to households, switching errors carry a direct cost. |
| Business Broadband Speeds Code of Practice (voluntary) | Signatories give speed information and a minimum guaranteed speed at the point of sale, and let customers leave without penalty if speed problems are not fixed within 30 days. | Whether or not you sign up, it shows what good practice in speed advice looks like. |
| Privacy and Electronic Communications Regulations (PECR) | Service providers include those using a network managed by a third party. They must report personal data breaches to the ICO within 72 hours of becoming aware of the essential facts; the limit was 24 hours until 20 August 2025. | Data incidents involving your customers carry their own reporting clock. |
The commercial structure of reselling creates a gap PI cannot entirely fill. Your wholesale supplier’s contract typically limits its liability to service credits and excludes lost profits. Your contract with the customer may promise more: fix times, uptime, speed commitments or compensation. When an upstream fault breaches your promise, you carry the difference, and you cannot pass it back.
PI is designed for negligence: a wrong recommendation, an ordering mistake, a botched port. A pure upstream outage that you could not have prevented is usually a contract question, and many PI wordings exclude failures of networks and infrastructure you do not control. That makes your terms the first line of defence:
| Usually covered by PI | Often excluded or limited | Needs a different policy |
|---|---|---|
| Wrong product, speed or suitability advice | Outages caused by networks or infrastructure you do not control | Attacks on your systems, portals and customer data (cyber insurance) |
| Ordering, provisioning and cease errors | Service credits and compensation you have agreed to pay automatically | Fire or damage caused by faulty routers you supply (products liability) |
| Failed or delayed number ports caused by your mistakes | Contract promises your wholesale supplier will not back | Injury to engineers or visitors (employers’ and public liability) |
| Router, firewall and network configuration errors | Fines and penalties imposed by regulators | Fraudulent calls run up on hacked customer systems, where the policy excludes them (telecoms fraud or cyber cover) |
| Defence costs, including telecoms experts | Disputes over your own charges and billing | Your own lost income when a wholesale network fails (business interruption extensions, where available) |
Policy wordings differ, and all cover is subject to the policy terms. Make sure the business description covers every service you sell, including voice and number porting if you offer them.
A reseller’s data and security exposure has two sides: your own systems, which hold customer records, account credentials and ordering access, and the equipment you configure on customers’ sites.
If your portal or ordering platform is breached, cyber insurance pays for investigation, legal advice, notifying the ICO and customers where required, and restoring your systems. Because PECR gives service providers 72 hours to report a personal data breach, that support matters early. Customers’ claims that your security or configuration let them down are a liability question, answered by PI or by the liability section of your cyber policy depending on the wordings.
Check how each policy treats customer equipment you manage remotely, and whether telecoms fraud on a customer’s hacked phone system is covered anywhere. See cyber insurance explained, and if you sell voice services, insurance for VoIP providers.
Your PI limit should reflect your largest customers and the number of connections you manage, not your monthly revenue. Multi-site businesses and public sector buyers often set a PI requirement in their contracts, and one ordering or migration error can affect many customers at once.
A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:
Speak to a broker
PI for broadband and internet service resellers, placed by a named broker
Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.
Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.
Yes. Customers rely on your advice and your handling of orders, migrations and ports, and mistakes leave them offline or paying for the wrong service. Those are financial losses that public liability does not cover. PI pays defence costs and compensation when a customer alleges your work was negligent, subject to the policy terms.
No law requires broadband resellers to hold PI. Ofcom’s General Conditions set rules on contracts, complaints, switching and porting rather than insurance. In practice larger business customers, public sector buyers and some partners ask for PI with a minimum limit in their contracts or onboarding checks.
Usually not, if the fault was purely upstream and you could not have prevented it. That is a contract question, and many PI wordings exclude failures of networks you do not control. PI is more likely to respond where your own negligence, such as wrong advice or a delayed escalation, made the loss worse.
Ofcom’s General Conditions require the number and relevant services to be reactivated until a failed port is completed, and customers must not be charged directly for porting. If your error caused the failure and the customer claims its losses, PI may respond, subject to the policy terms.
Ofcom says the General Conditions apply to all providers of electronic communications networks and services, and each provider must establish which conditions apply to its services. If you supply connectivity under your own contract, plan on the complaints, ADR, contract and switching rules applying to you. Under PECR, the ICO says providers using a third party’s network are covered.
In most cases, yes. Cyber insurance usually pays your own costs when your systems or customer data are compromised, including investigation, legal advice and notification within the 72 hours PECR allows. PI, or the liability section of a cyber policy, deals with customers’ claims that your service or configuration let them down.
Apex arranges professional indemnity insurance for broadband and internet service resellers across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.
Start your PI proposal Call 0117 325 0027Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.