These records are usually: sensitive*

* General financial information is sensitive, but any credit cards or account numbers are restricted. These records may contain or be combined with other information which may increase the risk and classification level. Context must be considered when assigning final classification.

Applicable Laws

Payment Card Industry (PCI): PCI SSC Data Security Standards Overview

Gramm-Leach-Blilely: UCOP Gramm-Leach-Bliley (GLB) Act Compliance (pdf)

Sec. 700-40: Policy on Credit and Debit Card Acceptance and Security

ZotPortal: Credit Card Processing