Credit card numbers are sensitive financial data that must never be logged in plaintext. Doing so violates PCI DSS compliance and creates severe security risks if logs are compromised or accessed inappropriately. 'Good logging practice' (B) and 'troubleshooting' (C) are invalid justifications - security takes precedence. The 'overhead' argument (D) is irrelevant; the issue is security, not performance.