Sending CC info through email violates the PCI DSS. The PCI is a private organization so noncompliance is not a violation of the law.
There is no unified law across the US that deals with data privacy. Several states are starting to address this problem but there's nothing like what the EU offers.