There's a post on reddit about some dude who gave his phone to a friend (wiped it, new iCloud, everything), and the undeleted photos are from when OP owned the phone.
With a factory reset the phones encryption keys will be destroyed and nothing should be retrievable from that device. Even if the data isn't overwritten, without the encryption key no one could read it.
At least that's my understanding of the modern safety- and encryption features of recent phone models/mobile OS's.
The worst part: Apple's iCloud is end-to-end encrypted and even Apple can't see the users files, at least that is what they say.
If what the dude on Reddit states is true, then this is bad, really really bad! 😮
It does happen I have a buddy who sold his phone to another buddy they reset it but there was still random files and stuff on it even after factory reset