To a certain extent, there are bills of rights already - consumer protection legislation exists, and is getting better at targeting badly-made software.
Consider the EU's GDPR regulation, which forces company to handle users' private data with care. That covers everything from not selling your users' data on the open market, to paying fines of your poor security practices mean that users' confidential details get hacked. Or more recently, the CRA and PLD, which together ensure that people selling software are liable when that software causes problems - when IoT devices are sold without security, or when your phone can no longer accept security updates a couple of years after you bought it, and so on.
This is for the EU, but I know similar legislation has been implemented in parts of the US.