Logging sensitive customer information like credit card numbers creates security vulnerabilities and violates PCI-DSS compliance requirements. Log files can be accessed by unauthorized personnel or leaked in data breaches. The overhead argument is irrelevant compared to the security risk.