← All articles

The end of third-party cookies never happened: what that changes for your business

In 2023 everyone announced the disappearance of third-party cookies in Chrome. Google backtracked, then buried Privacy Sandbox. What that really changes for your measurement.

Dots Papers cover for the article on what really changed with third-party cookies

In short

  • Third-party cookies have not disappeared from Chrome. Google gave up on removing them unilaterally in July 2024, then abandoned the idea of a dedicated choice screen in April 2025. The setting stays buried in the browser preferences.
  • The replacement plan is dead. In October 2025 Google withdrew most of the Privacy Sandbox APIs, including Topics and Protected Audience, for lack of adoption.
  • Your measurement degrades anyway. Safari and Firefox have blocked third-party cookies for years, iOS shortens the lifespan of cookies written in JavaScript, blockers keep spreading, and consent remains mandatory in Europe.
  • The right answer has not moved. First-party data, consented collection, server-side measurement, and accepting a share of modelling.

This article was published in March 2023 under a different title. In it we announced, like almost the whole industry, the imminent end of third-party cookies in Chrome. That forecast was wrong, which is why we are rewriting it entirely rather than letting it age quietly.

Between 2020 and 2025 the deadline was pushed back four times. Then Google changed its position, before dismantling the technical apparatus meant to replace cookies. A marketing lead who had budgeted a “cookieless” migration in 2023 ended up with a project with no date and no destination.

The useful question in 2026 is therefore no longer “when will third-party cookies die”. It is rather: why are my acquisition figures degrading when Chrome has removed nothing at all? The answer comes down to three mechanisms, and not one of the three depended on Google.

First-party and third-party cookies: the distinction almost everyone confuses

A cookie is a small file placed by a site in the browser. What separates the two families is not their contents but the domain that places them and can later read them back.

A first-party cookie is set by the domain the visitor is looking at. It carries the session identifier, the basket, the chosen language, and your analytics tool’s visit identifier. Without it your site can no longer recognise a visitor from one page to the next.

A third-party cookie is set by a domain other than the one in the address bar: an ad network, a social platform, a retargeting tool. Because the same third-party domain is called by thousands of sites, it can stitch together one person’s visits across the web. That cross-site tracking capability, and only that, was the problem. Retain this practical consequence: display advertising and retargeting rest on the third-party cookie, while your analytics and your conversion funnel rest on the first-party one. Many companies panicked in 2023 for the wrong reason, believing their internal measurement was about to go dark.

What actually happened between 2020 and 2025

Five years of announcements fit into four dates.

Date What Google announced Real effect for advertisers
January 2020 Removal of third-party cookies in Chrome, with the Privacy Sandbox APIs as replacement None. The deadline is pushed back four times, each delay presented as the last
July 2024 Unilateral removal abandoned: the browser would let the user choose Control moves to the visitor. The problem is displaced, not solved
April 2025 The dedicated choice screen is abandoned Third-party cookies on by default. Turning them off means going into privacy settings, which a minority of people do
October 2025 Most Privacy Sandbox APIs withdrawn, including Topics, Protected Audience and the Attribution Reporting API, for lack of adoption Neither removal nor replacement. Only a few pieces survive, including CHIPS for partitioned cookies and FedCM for federated sign-in
Timeline of Google’s announcements on third-party cookies in Chrome, January 2020 to October 2025.

Not one of those four dates removed anything from Chrome. Yet measurement degraded over the same period, for reasons that had nothing to do with Google.

Why the problem did not go away

Safari and Firefox never waited for Chrome

Safari has blocked third-party cookies entirely since March 2020 with Intelligent Tracking Prevention. Firefox generalised the same blocking with Total Cookie Protection, on by default since 2022. On a consumer site that already accounts for a significant share of visits, often the most qualified on mobile.

First-party cookies are being trimmed too

This is the point most 2023 articles missed. On Safari, a first-party cookie written in JavaScript on the browser side has its lifespan capped at seven days, and sometimes twenty-four hours when the visit comes from a link identified as advertising.

The direct consequence: a visitor who discovers your site on a Monday and buys three weeks later is counted as a new direct visitor. Your acquisition cost then looks higher than it is, and your long-cycle channels are undervalued. This mechanism is live today, with no decision from Google required.

Consent stays mandatory, whatever a browser decides

In Europe, placing a tracker that is not strictly necessary requires prior consent, and that obligation depends on no browser vendor. A technical decision by Google changes nothing about the ePrivacy directive or the guidance of data protection authorities.

On top of that, ad blockers and consumer VPNs cut part of the calls before the question of consent even arises. The signal therefore degrades through an accumulation of small losses, not through a single dated event.

The mistake that costs most Concluding the subject is closed because Chrome removed nothing. On Safari, a first-party cookie written in JavaScript expires after seven days: the buyer who returns three weeks later flips into direct traffic. Long-cycle channels then look more expensive than they are, and budget gets cut on the campaigns that work.

What a business should actually do

The useful roadmap is the same as in 2023, with one difference: it is no longer driven by a deadline, it is driven by continuous erosion. That changes the pace, not the direction.

First workstream, first-party data. Customer accounts, newsletters, loyalty programmes, after-sales contact: these touchpoints produce data you own and nobody can switch off. It is the foundation of our whole data and analytics approach.

Second workstream, measurement reliability. Moving collection server-side lets you set first-party cookies with a normal lifespan and reduces losses caused by blockers. We cover the mechanism and its limits in our article on the silent lie of server-side tracking. Our group publishes a dedicated platform, DataFirefly Server-Side, built by Datafirefly Limited, the sister company of Dotsland.

Third workstream, the quality of consented collection. A readable banner, a refusal as easy as an agreement, and a short explanation of what you do with the data raise the acceptance rate more reliably than an aggressive design. A consent rate won properly beats a technical workaround.

Fourth workstream, accepting modelling. Advertising platforms statistically estimate unobserved conversions, and Google Analytics 4 works on that principle. Your reports therefore contain a share of reconstruction, and good practice is to reason in trends and gaps rather than in absolute values down to the visitor.

What to take away The direction has not changed, only the motivation has. You no longer build a first-party base to meet a date announced by Chrome, but because the signal erodes continuously, through browsers, blockers and consent. These four workstreams belong in a plan, not in an emergency.

The fake cookieless solutions to refuse

The vacuum left by the delays created a market of providers selling “cookieless” without the word covering much. Three offers keep coming back, and all three deserve a firm answer.

The offer The sales pitch What it actually is
Fingerprinting Recognise a device by its resolution, fonts and settings, so no cookie and no banner Regulators treat it as a tracker: consent is required, with one extra constraint, the user cannot delete it
Server-side collection sold as a consent exemption Data transits through your own domain, so the banner would become unnecessary The technical architecture changes, never the legal basis. The promise sells you a penalty risk
Universal identifiers Replace the third-party cookie with a hashed email address shared between players Traceable consent required at every link in the chain, and low real coverage: a possible complement, not a foundation
The three most common “cookieless” offers and what they are worth under European law, as of 2026.

Measuring your dependence on third-party cookies in five steps

Here is the audit we run on a first engagement. It takes half a day and needs no development work.

  1. Inventory the third-party domains set on your site. Open your browser’s Application tab, list the cookies set by a domain other than yours, and match each line to an identified provider. Anything you cannot name should be switched off.
  2. Segment your conversions by browser. Compare the conversion rate measured on Chrome, Safari and Firefox. A marked gap against Safari signals a measurement problem, not a commercial one.
  3. Compare your analytics figures with your back office. Take one month of real orders and set them against your measurement tool’s total. The gap, as a percentage, is your signal loss rate.
  4. Estimate how much media budget depends on the third-party cookie. Display retargeting and imported audiences do; paid search and affiliate much less. That ratio is your real exposure.
  5. Measure your stock of first-party data. Count active opt-in contacts over twelve months and compare that to your customer volume. Below thirty percent, your dependence on platforms is your first risk.

Frequently asked questions

Are third-party cookies still usable in 2026?

Yes in Chrome, which still allows them by default after Google gave up on removal. No in Safari and Firefox, which have blocked them for several years. An advertising setup that depends on them therefore works on only part of your audience, and that share is slowly shrinking.

Why did Google abandon the removal of third-party cookies?

Three factors combined: pressure from competition authorities, notably in the UK, who feared it would strengthen Google’s position in online advertising; opposition from part of the industry; and very low adoption of the replacement APIs. Google withdrew most of those APIs in October 2025.

Does server-side tracking let us skip the consent banner?

No. Server-side collection improves the technical reliability of measurement, but it does not change the legal basis of the processing. Prior consent stays required for any tracker that is not strictly necessary, wherever the code runs. Any provider claiming otherwise is exposing you to a penalty.

Is a first-party data strategy still worth investing in?

Yes, more than before. The motivation is no longer a removal date announced by Chrome, but the continuous erosion of signal caused by browsers, blockers and consent. A base of consenting contacts and an active customer account remain the only data assets no outside decision can take from you.

How do I know if iOS cookie limits are skewing my measurement?

Compare the share of sessions attributed to the direct channel between Safari and Chrome over the same period. If direct is markedly over-represented on Safari, the seven-day cap on JavaScript-written cookies is the most likely cause. Server-side collection with the cookie set by the server corrects much of that gap.

What we now look at first

The announced disappearance of third-party cookies had one merit: it pushed many companies to build a direct relationship with their customers. The fact that the deadline never came does not make that work useless, it only removes the artificial urgency.

What we see with our clients is that the performance gap no longer plays out on tracking technology, but on the quality of the data they hold and the reliability of their measurement. A company that knows what a customer is genuinely worth over twelve months allocates media budget better than one optimising on a reconstructed signal.

Unsure how dependent your marketing is on third-party cookies? We start by comparing your real back-office conversions with what your measurement tool reports, browser by browser: the gap, in figures, shows within an hour where the real problem sits. Let’s talk.

Want to apply this to your own business?

Get in touch →

Further reading

Leave a comment

Your email address will not be published. Required fields are marked *

17 − 5 =