Forum Discussion
Hi Danos,
To continue sharing invoices, you will need to verify your business, please see our information about Secure Invoicing . Otherwise, your invoice sharing will be restricted to the downloading of PDF files.
For your privacy concerns, MYOB takes privacy seriously and takes all measures to comply with the Privacy Act see
MYOB Group Privacy Policy for Australia
We understand your concerns regarding the safety and privacy of your data when submitting documents to MYOB for secure invoicing. Here’s how we ensure that your data is kept secure and private:
- Data Encryption: All documents and personal information you submit through MYOB's secure invoicing system are encrypted during transmission and storage. Encryption ensures that only authorized parties can access the information.
- Secure Uploads: Documents can be securely uploaded through our dedicated upload portal (https://onlineinvoicepayments.fileupload.myob.com/). This ensures that your documents are sent directly to MYOB’s secure servers without passing through insecure intermediaries.
- Confidential Handling: MYOB treats all personal and business information with the highest confidentiality. Access to your data is restricted to authorized personnel who need it for verification purposes only.
- Privacy Policy: MYOB complies with all relevant privacy laws and regulations, as detailed in our privacy policy. This policy outlines how we collect, use, and protect your personal data. You can review our privacy policy to understand better how your data is handled.
- Purpose Limitation: The information you provide is used solely for the purpose of verifying your identity and business details to enable secure invoicing. This process helps protect your business from fraud and unauthorized access.
- Verification: The verification process involves checking your identification details with issuers or official record holders via third-party systems, which are also subjected to stringent privacy and security standards.
Once Secure Invoicing is enabled, you have full flexibility to choose whether you would like to offer the new payment options. If you do choose to offer these, your customers have full flexibility of how they choose to pay. With the default settings there is no cost to your business, unless you change the settings after verification. However, you do not need to accept online payments if you continue with the business verification process. You can turn online payments off in your settings, you can read more about this HERE.
Regards,
Earl
- Danos4 months agoContributing Cover User
Hi Earl,
Thank you for your response. However, your reply does not address the core issue I raised.
My concerns are not about encryption or general privacy statements. They are about why MYOB now requires highly sensitive personal identification documents—such as a photo of my driver’s licence—for a feature (invoice sharing) that previously worked without such intrusive measures. This raises serious questions about necessity, proportionality, and compliance with the Privacy Act’s principle of data minimisation.
A few specific points:
- Purpose Justification
Please explain why verifying my identity with personal documents like a driver’s licence is essential for simply sharing invoices. What risk assessment led to this requirement? - Third-Party Involvement
You mention verification via “third-party systems.” Who are these third parties? What guarantees exist that my data will not be stored, shared, or used beyond this process? - Legal Basis
Under the Privacy Act, organisations must collect only what is reasonably necessary for their functions. How does requiring a photo of my driver’s licence for invoice sharing meet this standard? - Alternatives
If online payments can be disabled, why is verification still mandatory for invoice sharing? This seems inconsistent with the stated purpose.
Finally, I ask that any further response from MYOB be substantiated with clear facts and references, not general statements or vague links. The current reply contains generic assurances and phrases like “read more HERE,” which do not provide clarity.
Unless MYOB provides a detailed explanation and a less intrusive alternative, I will have no choice but to escalate this matter to the OAIC and ACCC for review.
I look forward to your prompt and transparent response.
- Purpose Justification
- moff1 month agoContributing Cover User
Hi Earle or Whoever is moderating this
We are extremely concerned about this issue
We transferred from another system to come back to MYOB
What are you trying to do ?
Are you being paid to have another party secure information?
Honest answer only accepted
Extremely concerned about this issue
CM
- Mike_MYOB1 month agoCommunity Manager
Hi moff
I have previously summarised the change here and there have been a lot of additional comments and replies since then as well.
We also have a help page published to further explain why MYOB has made this change here
To directly address your query, this change how nothing to do with collecting information, but it is related to ensuring that only a verified/legitimate business can use MYOB software to send invoices.
This in turn will help to reduce invoice fraud in Australia while our secure invoicing platform also provides additional security to our customers through secure invoice distribution, secure payment methods and always-on fraud monitoring- frank31 month agoExperienced Cover User
would love to know how to opt out of the myob payments platform.
- Folklore1 month agoContributing User
If Microsoft, USA Defence and other major companies can have data breach then so can MYOB. Why do you need this sensitive information if we are not using your payment and funding options. I HATE DEALING WITH MYOB.
- frank31 month agoExperienced Cover User
MYOB has already had a data breach
- Mike_MYOB1 month agoCommunity Manager
Good morning frank3 , lots of comments to address here, but I will do my best.
Regarding the information included in the email
Your client ID, serial number and business name are not considered as sensitive information or related to personally identifiable information (PII).
There is no breach from MYOB by providing this information in an email.
You mentioned that verification should not include identifying employees that use MYOB for the business.
You're absolutely correct, and we do not seek this information.
Business verification is related to the business and is based on the business ownership information registered with ASIC, this could be majority shareholders, company directors, trusts and so on.
You can read about MYOBs documents for verification here
You also ask whether the 1.8% fee is paid by the consumer or by the business. And the answer, is that the choice is yours.
The default, is that the fees are charged to the person who is paying the invoice, but you can change this setting so that you are paying the fee as the business instead if you prefer.
You can read up about customer surcharging here
In another comment you made here, you ask about MYOBs use or storing of the ID information.
These verification documents are not provided directly to MYOB, nor are they stored with MYOB.
They are sent to FrankieOne for secure handling during the verification process and once completed, the documents are not retained as this is a once off process with no need to keep these documents. They are not stored or kept for 7 years as you believe
- frank31 month agoExperienced Cover User
verifying a business should never involve collecting the personal identification of the employees that use myob for that business.
- DR3211 month agoExperienced User
Hi Earl, as MYOB dislikes incorrect information being put in comments, I would like to clarify the last paragraph in your previous comment;
"Once Secure Invoicing is enabled, you have full flexibility to choose whether you would like to offer the new payment options. If you do choose to offer these, your customers have full flexibility of how they choose to pay. With the default settings there is no cost to your business, unless you change the settings after verification. However, you do not need to accept online payments if you continue with the business verification process. You can turn online payments off in your settings, you can read more about this HERE."
Firstly, if I agree to the Secure Invoicing Upgrade, then secure payments are enabled by default, your statement about 'no cost to my business, actually means that the charges are passed on to MY Customer by default. If one of MY Customers pays a bill after failing to read MYOBs fine print about accepting charges, then I'm the one who has to bear the brunt of an unhappy Customer and I'm the one who is obliged to refund those fees to keep the Customer happy.
Secondly, yes I can turn off payments in the software, however the only way I can 'opt - out' is to call MYOB by phone to arrange it. Once I opt out I am legally obliged to allow MYOB access to my bank account for a further 6 months in case of charge backs or adjustments. This is all set out in your terms and conditions, which you yourself refer to.
I hope you actually understand this scenario which is actually a question, I have a Customer who spends an average of $20000 per month, their book keeper takes time off for maternity leave so they employ a casual worker to handle their accounts payable. Around that time MY book keeper completes MY my business verification and now I have secure payments enable by default. Over the next 3 months $60000 in invoices go to my Customer, and the Customers new employee pays it all on credit card.
When the Customer calls me complaining about the $1000+ charges what do you think I should tell them?
What happens if the Customer disputes the charge?
- frank31 month agoExperienced Cover User
does your customer get belted the 1.8% fee or do you?
Looking for something else?
Search the Community Forum for answers or find your topic and get the conversation started!
Dig into MYOB Academy for free courses, learning paths and live events to help build your business with MYOB.