I've acquired over 100 used computers, and, once I saw how common leaving data on them was, I began always very promptly DBAN-ing any disks, and wiping SSDs. If it has a non-SATA interface, I destroy the medium. Similar with some kind of wipe of smartphones.
Besides wiping the disk/device seeming a responsible and considerate thing to do, it avoids remote yet severe liabilities.
A secure erase should wipe all blocks (and since it is done by the firmware, physical blocks, not logical ones), but there have been instances of buggy drives that don't actually do it properly.
Some SSDs also transparently encrypt all data written, and the key is replaced on a wipe command. Even if they don't wipe the data fully, it's now unusable, if the encryption works correctly.
Quite old SSDs might not support any of this.
Unfortunately, you can't trust the SSD firmware developers to have their shit together [1].
[1] https://techcrunch.com/2018/11/05/crucial-samsung-solid-stat...
Imagine if CompuServe still existed, but they had undergone 100% employee turnover in recent years. They'd still be liable, right?
It seems to me that when Verizon bought CompuServe, they calculated that its assets minus its liabilities totaled less than the purchase price and hence it was a good deal. If we treat leakable data as a legal liability, it should send the right financial signal - eg, maybe as a company you don't want to collect much.