To gird against this, the major credit-card companies in 2006 formed an industry group called the PaymentCardIndustrySecurity Standards Council, which establishes minimum technical protections for businesses that accept credit cards.
And, in the payments industry, self-policing is in place through the PCI-DSS (Payment CardIndustry Data Security Standard) which, while not a federal law, has become law in some states.