Curious, if Path is acquired does the purchaser also acquire the 20 year privacy assessment requirements? Does this make acquisition unlikely?
Everyone gets one sooner or later, it seems. It's a giant PITA, but everyone has the audit infrastructure in place by now, so I wouldn't expect it to matter too much.
Probably, or else Path2 made of the same investors could buy Path and get out of the agreement.