Beyond privacy disclosures, Apple expects a baseline of technical security — data in transit encrypted, sensitive data not left exposed — and requires disclosure if the app has experienced a data breach affecting users.
Rare as a standalone rejection, but comes up when a security researcher's public report about an app's data handling reaches Apple before the developer has disclosed or fixed it.
"Your app transmits user data without adequate security measures in place, which is not permitted per guideline 1.6."