In a bid to equip the country with a robust data protection system, the draft of the Digital Personal Data Protection (hereinafter, “DPDP”) Bill was released by the Ministry of Electronics and Information Technology (hereinafter, “MeitY”) on November 18, 2022. It is notable that this is not the first time the government has introduced such a legislation. The Data Protection Law has been in the pipeline for almost five years. There has been a lot of hue and cry about the previous Bill and it is apposite to say that the current Bill is also not free from any controversy. However, the key point to highlight is how these recommendations, revisions, and discourse surrounding the Bills proved to be of the essence for us, the people. The quest for a robust law and the unideal circumstances raises eyebrows regarding the intentions of the government and all the other stakeholders in implementing or trying to implement a regime focused on the individual’s right to privacy as well as maintaining the sovereignty of a country’s data. The authors in the present article, while analyzing the anomalies of the latest DPDP Bill, 2022, compare its provisions with the standards going around the globe. In addition, reference is also made to the provisions of earlier Bills to comparatively analyse the contentious points. Besides, the authors also try to answer how a flawed data protection law would prove to be deadlier than no law. There is no doubt that a robust data protection law is the need of the hour, but the real challenge is, at what cost?