There is an excellent article on this whole subject by
Garfinkel -- I don't remember the title or publication. He
described collecting a bunch of secondhand PCs and
investigating what was left on them, and discussed various
cleanup tools and how well they defend against attempts to
recover data.
If a decisionmaking person is worried about this issue but
interested in hard facts, that article may be helpful to
provide those facts.
Maybe not the original article, but a good synopsys: