The removal of third-party cookies from Chrome is no longer the plan Google described. On 22 April 2025, the company confirmed that the existing cookie choices would stay in the settings where they already live, with no new standalone prompt. On 17 October 2025, it announced that it was retiring several Privacy Sandbox advertising technologies. Preparing your marketing in 2026 is therefore not a matter of waiting for an old deprecation timetable.
The work that pays off sits elsewhere: in the real dependencies of your own site. Which services set identifiers, under which conditions, for what purpose, and with what measurement limits? A technical option staying open in Chrome means neither complete tracking nor an exemption from consent.
What follows separates the questions that tend to get mixed up, sets out what actually changed across browsers, and describes a way of rebuilding reporting that supports a decision rather than one that simply counts events.
First-party or third-party: the wrong axis to argue about
A cookie is a piece of data kept by the browser and tied to a domain. It can hold a session open, remember a preference or recognise a browser. Whether it counts as first-party or third-party depends on the context of the site being visited. That label, on its own, says nothing about the purpose of the processing.
A tool supplied by an outside company can set cookies on your own domain. A resource served from another site can be genuinely necessary to a feature your visitors use. So when you decide what behaviour to allow, identify the service, the data and the actual use — not just the name of the cookie.
| Question | What you are looking for |
|---|---|
| Where is the identifier stored? | The domain, path and lifetime you can observe. |
| What is it for? | Sign-in, basket, measurement, advertising or another documented function. |
| When is it used? | Before any choice, after acceptance, after refusal, after withdrawal. |
| Who receives the data? | The publisher, the technical supplier and the recipients actually called. |
Filling in that table for your own site is usually more revealing than any general debate about cookie deprecation. It is also the part most teams have never done in full.
What Google decided, and the Privacy Sandbox turn
In its announcement of 22 April 2025, Google kept the existing third-party cookie settings in Chrome and dropped the plan for a separate standalone prompt. Incognito mode already blocks third-party cookies by default. Keep four things apart: private browsing, standard browsing, the choices an individual has made, and the policies applied to a managed browser in an organisation.
You will find plenty of commentary summarising this as "Google has abandoned the removal" or "third-party cookies stay on by default". Those phrases should not be stretched to cover every mode, every setting and every browser. The vendor's own announcement remains the reference point for what Chrome does.
What came next matters just as much. On 17 October 2025, Google announced the retirement of Topics, Protected Audience and Attribution Reporting, among others, citing low adoption. Presenting those APIs today as replacement plumbing to roll out gradually is out of date. That does not mean every web proposal touching privacy or attribution has stopped existing — it means you should check current documentation before committing budget to any of them.
Safari and Firefox do not take the same approach
WebKit announced full third-party cookie blocking by default in Safari on 24 March 2020. Firefox describes Total Cookie Protection, which partitions cookies per site in standard browsing. Partitioning is not exactly the same thing as rejecting every third-party cookie. Both WebKit and Mozilla document their own approaches.
The practical consequence is simple. An integration that works on your machine may behave differently on someone else's. Test the functions that carry revenue: sign-in, payment, forms, the video player, the booking widget. The point is not to work around a visitor's preferences, but to make sure the journey still works and still makes sense within the conditions they have allowed. A structured UX audit across several browsers usually surfaces these breakages faster than bug reports do.
Consent follows the purpose, not the word "first-party"
In the United Kingdom, the rules on storing or accessing information on a user's device sit in PECR alongside UK GDPR, and the ICO is the supervisory authority. The structure is familiar across Europe: consent is required for non-essential storage and access, with a narrow exemption where the technology is strictly necessary for a service the user has asked for. Other national regulators publish their own detail — in France, for example, the CNIL's framework and its questions and answers on cookies and trackers set out conditions under which some audience measurement can be exempt. If you operate in several markets, check the guidance that applies where your visitors are.
The consequence for your stack is the same everywhere. A first-party cookie, a cookieless tag or a server-side call does not become compliant by virtue of its architecture. What matters is the purpose, the data and whether the visitor's choice is respected.
So tie every trigger to a purpose and to a recorded choice. Check the behaviour in four states: before any action, after refusal, after acceptance, and after withdrawal. A visible banner is not evidence that requests were blocked. An old cookie still sitting in the jar is not, on its own, a full description of what is being processed either.
Where you rely on an exemption for audience measurement, document the configuration and the conditions you are meeting. A marketing label such as "privacy-friendly" is a claim, not a demonstration.
Adapt your reporting without promising to reconstruct every visitor
Start from a commercial objective: completed orders, qualified enquiries, appointments actually kept. Then separate the data you hold legitimately from what measurement tools can observe. It is normal for an ad platform's counter, your analytics tool and your recorded sales to disagree. They are counting different things, over different windows, under different consent conditions.
For a campaign, keep two figures apart: attributed conversions and the additional sales you actually gained. An attribution window can credit an ad within a journey that would have converted anyway. Incomplete measurement can equally miss an interaction that mattered. Where volume allows, a controlled test tells you more than a dashboard; a simple before-and-after comparison stays exposed to seasonality, pricing changes and whatever else you were doing that month. This is the discipline that separates useful paid search management from budget that simply keeps running.
Server-side tracking can improve technical control over data flows. It does not turn personal data into anonymous data, and it does not replace consent choices. Before adding any tool, ask four questions: what problem does it solve, what does it transmit, how does it handle a refusal, and what does it cost to run month after month? Framing that properly is what traffic management should be about — the numbers you use to decide, not the number of events you collect.
Spread your acquisition, with a hypothesis you can test
Search visibility, useful content, relevant partnerships, campaigns tied to an active search, contextual targeting: these answer different needs. Their value has to be tested against your own market. No channel becomes universally profitable simply because it depends less on third-party cookies.
Publishing is a good example. Content built around real search demand does not need a cross-site identifier to work, but it needs time, a subject you can speak about credibly, and a way of knowing whether it brings enquiries. Before you commit to a sector platform or a directory, set out who you want to reach, what is actually offered, how visits and enquiries will be reported, and what you will be able to observe yourself.
For a small organisation, a plain table linking spend, qualified enquiries and orders is often more decisive than another layer of technology. Keep the limits visible: missing data, a period that is too short, a change of offer, low volume. A good investment improves a concrete decision. It does not just increase the volume of events in a database.
A first piece of work at a sensible size
- Inventory the tools and the journeys that depend on a third-party service.
- Check cookies and network requests under several consent states and in more than one browser.
- Fix inconsistent triggers and any feature that breaks when cookies are partitioned or blocked.
- Agree a short list of commercial indicators, and write down what each one cannot tell you.
- Test one improvement before rolling out a new tool across the site.
This sequence holds whatever the next browser announcement turns out to be. It reduces your dependence on someone else's timetable, and it avoids the common mistake of presenting a technical change as a guarantee of either compliance or return.
Common questions
Has Chrome removed third-party cookies?
No. In April 2025 Google confirmed that the choices would remain in the existing settings. Behaviour depends on the browsing mode and the settings in place, and private browsing should not be confused with standard browsing.
Should we still be preparing for Topics or Protected Audience?
Not as the announced replacement for third-party cookies. Google said in October 2025 that it was retiring them along with other Privacy Sandbox technologies. Check the current documentation before investing in any advertising API.
Can a first-party cookie still require consent?
Yes. The storage domain does not decide the question by itself. What matters is the purpose of the tracker and the conditions in which it is used, together with the rules that apply to the tool and to your market.
Does server-side tracking remove the need for consent?
Not automatically. Changing the technical path the data takes does not change its nature or the obligations attached to it. Check what is transmitted and whether a refusal or a withdrawal is genuinely respected downstream.
What should we measure if attribution stays incomplete?
Track the things you own: qualified enquiries, orders, spend and the margin data you have, with the periods and limits written down. Treat advertising platform figures as a partial view to compare against commercial results, not as proof of cause on their own.
Do different browsers need separate testing?
Yes, for anything that carries revenue. Safari blocks third-party cookies by default and Firefox partitions them per site, so a sign-in, payment or booking flow can behave differently from one browser to another even when nothing in your code has changed.
