Forum Discussion

Danos's avatar
Danos
Contributing Cover User
2 months ago

Serious Concerns About MYOB’s New Verification Requirement

a { text-decoration: none; color: #464feb; } tr th, tr td { border: 1px solid #e6e6e6; } tr th { background-color: #f5f5f5; }

I am extremely concerned about MYOB’s recent policy requiring businesses to provide personal identification and trust documents simply to continue using invoicing—even when we do not use online payment services.

Here are the key issues:

Sensitive Information in Emails
MYOB included my Payments Client ID, Serial Number, and Business Name in an email. Email is inherently insecure and should never be used to transmit sensitive identifiers. This raises serious questions about MYOB’s commitment to privacy and data protection.

Lack of Legal Justification
MYOB claims this requirement aligns with “minimum standards” for confirming beneficial ownership, yet provides no reference to any specific legislation or compliance framework. Why should businesses that only use traditional invoicing be subjected to intrusive verification?

No Alternative for Long-Standing Customers
MYOB admits communication was inadequate but insists verification cannot be bypassed. For businesses that have never used online payment services, this is unreasonable. There should be:

  • An opt-out option for Secure Invoicing.
  • A traditional invoicing path without mandatory identity checks.

Competitive Disadvantage
Other major accounting platforms do not impose such requirements for basic invoicing. If MYOB’s logic were applied broadly, companies like Microsoft would demand personal ID to use Word or Excel—an absurd scenario that highlights the flaw in this approach.

MYOB currently holds about 17% market share in Australia. Continuing with policies that disregard customer concerns will inevitably reduce this share even further. A fact that the management should seriously consider if they want to continue in business!

My Position
This verification requirement is unacceptable. Even if MYOB provides clarifications or assurances, I will not comply. It is unnecessary, intrusive, and sets a dangerous precedent. If MYOB cannot offer a solution that respects customer privacy and operational needs, I will migrate to an alternative platform.

I encourage other users who share these concerns to speak up. If MYOB does not address this issue promptly, escalation to the Office of the Australian Information Commissioner (OAIC) and the Australian Competition and Consumer Commission (ACCC) may be necessary.

MYOB should show the utmost respect to its clients—because we are the ones who keep MYOB in business.

6 Replies

  • Grasso62's avatar
    Grasso62
    Member
    1 month ago

    I’m not happy to verify my details either.  I may look to another provider for my invoices.  When I started it was only $12 a month for a limited time period and now I’m paying $34.  I only use the invoice for my clients and my purchases.  I’m not connected via credit payments , Apple Pay etc so therefore I do not wish to provide my information to MYOB.. it’s all part of the digital id system to control everything we do!! 

  • MYOB have just for the third time blocked me from invoicing clients. Under duress previously I gave them trust information etc etc.  Today they have block my account again this time they want a PHOTO of a deceased trust person..WTF....ARE YOU KIDDING ME! I think I need to take legal action on what this is costing me. MYOB is definitely not worth the hassles it brings with it time for a change.

  • Danos's avatar
    Danos
    Contributing Cover User
    2 months ago

    Hi Earl,

    Thank you for your response. However, your reply does not address the core issue I raised.

    My concerns are not about encryption or general privacy statements. They are about why MYOB now requires highly sensitive personal identification documents—such as a photo of my driver’s licence—for a feature (invoice sharing) that previously worked without such intrusive measures. This raises serious questions about necessity, proportionality, and compliance with the Privacy Act’s principle of data minimisation.

    A few specific points:

    1. Purpose Justification
      Please explain why verifying my identity with personal documents like a driver’s licence is essential for simply sharing invoices. What risk assessment led to this requirement?
    2. Third-Party Involvement
      You mention verification via “third-party systems.” Who are these third parties? What guarantees exist that my data will not be stored, shared, or used beyond this process?
    3. Legal Basis
      Under the Privacy Act, organisations must collect only what is reasonably necessary for their functions. How does requiring a photo of my driver’s licence for invoice sharing meet this standard?
    4. Alternatives
      If online payments can be disabled, why is verification still mandatory for invoice sharing? This seems inconsistent with the stated purpose.

    Finally, I ask that any further response from MYOB be substantiated with clear facts and references, not general statements or vague links. The current reply contains generic assurances and phrases like “read more HERE,” which do not provide clarity.

    Unless MYOB provides a detailed explanation and a less intrusive alternative, I will have no choice but to escalate this matter to the OAIC and ACCC for review.

    I look forward to your prompt and transparent response.

     

  • Danos's avatar
    Danos
    Contributing Cover User
    2 months ago

    Concerns About Verification Policy, Confidentiality & Branding

    I appreciate MYOB’s attempt to explain the recent verification changes, but several issues remain unresolved and need serious consideration:

    Confidentiality of Subscription Identifiers
    MYOB states that Client ID, Serial Number, and Business Name are not personal information. In reality, these uniquely identify my company and account. Anyone with these details could misuse them or create another MYOB account. Including such identifiers in emails is a security risk and contradicts MYOB’s own commitment to confidentiality.

    Contradiction in Security Logic
    If downloading invoices and sending them manually is allowed without verification, this completely undermines MYOB’s stated purpose of protecting businesses from invoice tampering. If manual sending is acceptable, why block direct emailing from our own account as before? We have never used MYOB’s email system and do not intend to—it is inefficient and intrusive. This restriction appears to serve no security purpose and instead seems designed solely to force users to comply with MYOB’s requirements.

    Branding on Client Communications
    MYOB’s practice of stamping invoices with its logo when using its email system is unacceptable. I pay MYOB to use its product; MYOB does not pay me to advertise its brand. If MYOB wants to promote its business through client invoices, it should ask permission and make this optional—not arrogantly impose it.

    Legal Basis and Alternatives
    MYOB refers to “broader beneficial ownership guidance” but does not cite any specific law requiring this verification for businesses that do not use online payments. Please clarify the legal basis or provide an alternative that does not disrupt long-standing workflows.

    I have been a loyal MYOB client for over 25 years, but these changes make me question whether MYOB values customer autonomy and confidentiality. If this policy remains rigid, I will consider switching to platforms (MYOB does not allow using names of competitive products! I wonder why???) that do not impose such intrusive requirements.

    MYOB, please review this policy and provide:

    • The legal/regulatory basis for verification.
    • Confirmation that sensitive identifiers will not be included in emails.
    • A practical alternative for clients who do not use MYOB’s email system or online payments.

    Other MYOB users: Have you faced similar concerns? How are you handling this change? Please share your experiences so MYOB understands the broader impact on its clients.

  • Earl_HD's avatar
    Earl_HD
    MYOB Moderator
    2 months ago

    Hi Danos,

    To continue sharing invoices, you will need to verify your business, please see our information about Secure Invoicing . Otherwise, your invoice sharing will be restricted to the downloading of PDF files. 

     

    For your privacy concerns, MYOB takes privacy seriously and takes all measures to comply with the Privacy Act see 

     

    MYOB Group Privacy Policy for Australia

     

    We understand your concerns regarding the safety and privacy of your data when submitting documents to MYOB for secure invoicing. Here’s how we ensure that your data is kept secure and private:

    1. Data Encryption: All documents and personal information you submit through MYOB's secure invoicing system are encrypted during transmission and storage. Encryption ensures that only authorized parties can access the information.
    2. Secure Uploads: Documents can be securely uploaded through our dedicated upload portal (https://onlineinvoicepayments.fileupload.myob.com/). This ensures that your documents are sent directly to MYOB’s secure servers without passing through insecure intermediaries.
    3. Confidential Handling: MYOB treats all personal and business information with the highest confidentiality. Access to your data is restricted to authorized personnel who need it for verification purposes only.
    4. Privacy Policy: MYOB complies with all relevant privacy laws and regulations, as detailed in our privacy policy. This policy outlines how we collect, use, and protect your personal data. You can review our privacy policy to understand better how your data is handled.
    5. Purpose Limitation: The information you provide is used solely for the purpose of verifying your identity and business details to enable secure invoicing. This process helps protect your business from fraud and unauthorized access.
    6. Verification: The verification process involves checking your identification details with issuers or official record holders via third-party systems, which are also subjected to stringent privacy and security standards.

    Once Secure Invoicing is enabled, you have full flexibility to choose whether you would like to offer the new payment options. If you do choose to offer these, your customers have full flexibility of how they choose to pay. With the default settings there is no cost to your business, unless you change the settings after verification. However, you do not need to accept online payments if you continue with the business verification process. You can turn online payments off in your settings, you can read more about this HERE.

     

    Regards,
    Earl

  • EarthingWA2013's avatar
    EarthingWA2013
    Cover User
    23 days ago

    Good to know, defiinitely look at other programs and my accounts program is $60 per month. Also same don't want their debt system, don't want payment programs just a basic accounts package. No wonder everyone is leaving MYOB, their 17% market share definitely wont be increasing.