Thanks Doreen_P I have done some further reading and I'm actually really concerned by this.
I wasn't aware that our employees' sensitive personal information was being retained by Flare.
Looking at the screenshots of what they see when they onboard, they might reasonably expect they are only providing that information to us, their employer, as we do not use Flare for provision of employee benefits. I cannot see anywhere in the onboarding invitation that makes reference to Flare's privacy policy that would give the employee an opportunity to consent to this. Furthermore there are aspects to this privacy policy that are troubling to me, inlcuding potential disclosure to market research companies, recipients in a foreign country, and for purposes of direct marketing.
I thought that having the employee self-onboard was a great idea because I have been on the other end of trying to decipher people's handwriting and sweating over making a mistake entering their bank details. But I know for myself, I wouldn't be comfortable with some random company retaining all the information required to commit identity fraud and compromise my TFN. Especially one I hadn't voluntarily or knowingly engaged with. Even within our organisation, we keep access to that information very restricted, only management can access.
We will immediately be stopping using this onboarding function and I will be contacting Flare to destroy any personal records of our employees. I think MYOB should be contacting people and making them specifically aware of what it is doing with employee records, so that people can make their own informed decision.