That I can't answer. All I know is that for our PDQ terminals at work our bank wanted evidence that they were hardwired to an Internet connection, and didn't bridge any gaps over the air between the device and going out of the building.
The Bluetooth and GSM interfaces are handled inside the devices themselves - between the handset and the supplied base unit in the case of the former. I can only presume it's because the manufacturers know what traffic is going across it, but because they can't tell what's going across a wifi link, it adds an extra level of perceived risk?
My take on this is that with the bluetooth link, both ends of the radio link are operated by the manufacturer's devices, and that the manufacturer has been able to get their equipment accredited by the bank/card issuers. With a Wi-fi internet connection, they don't control the wireless access point you use, so they can't issue any guarantees for it.
Both technologies operate in the same part of the radio spectrum (2.4GHz), can encrypt their data, but can also be monitored and eavesdropped. (A wi-fi network is likely to have other devices sharing the network by design, but both networks are broadcasting their data to anyone nearby.) The only real difference I see is who manufactured the devices at each end of the link.