Google cross-references your declared data collection against what reviewers can observe the app doing. Any mismatch — even one omitted data type — can trigger a rejection.
Usually caused by the form not being updated after a new SDK or permission was added to the app since it was last submitted.
"Your app's Data safety section doesn't accurately reflect the data collection and sharing practices described in your app's privacy policy."