---------------------------
Title: Third-Party Cookies: What They Are, Why Google Is Not Removing Them, and What Replaced Them in Other Browsers
URL: https://www.cookiebot.com/en/google-third-party-cookies/
---------------------------

# Third-Party Cookies: What They Are, Why Google Is Not Removing Them, and What Replaced Them in Other Browsers

Google abandoned its plan to phase out third-party cookies in Chrome in July 2024, and confirmed in April 2025 that no replacement consent prompt would be introduced either. Third-party cookies remain active in Chrome by default, but advertisers and publishers still need to obtain consent to process user data under laws such as the GDPR. Learn what's changed, what alternatives Google has built, and why consent remains pivotal.

## At a Glance

- Google abandoned its plan to fully deprecate third-party cookies in Chrome, confirming in April 2025 that no separate choice prompt would be introduced.
- Third-party cookies remain active in Chrome by default, though Safari, Firefox, and other privacy-focused browsers have blocked them for years.
- Consent obligations under laws such as the GDPR apply to cookies and similar tracking technologies regardless of whether Chrome deprecates them.
- Google's Privacy Sandbox tools, including Topics and Protected Audience, remain available as alternatives to third-party cookie tracking.
- Since January 2024, publishers using Google AdSense, Ad Manager, or AdMob have needed a Google-certified consent management platform to serve ads to EU, EEA, and UK visitors.

For years, Chrome's plan to phase out third-party cookies loomed as a defining moment for digital advertising. That moment never quite arrived. In July 2024, Google abandoned its deprecation plan altogether, and in April 2025 it confirmed that Chrome would not introduce a replacement consent prompt either. Third-party cookies remain active in Chrome by default today, managed through the browser's existing privacy settings.

None of this changes the underlying requirement. Websites still need to obtain consent before placing cookies or processing personal data for tracking and advertising, under laws including the GDPR. This article looks at what's actually changed with Chrome, what Google's Privacy Sandbox offers as an alternative, and why consent remains the constant in a shifting landscape.

*This article has been reviewed by Cookiebot's data protection experts.*

## What Are Third-Party Cookies and How Do They Work?

Third-party cookies are small text files placed on a visitor's browser when visiting a website. There are two types of cookies:

1. **First-party cookies** are created by the website the visitor is visiting. They enable the site to recognize the visitor's device and store information that can improve their browsing experience, like saving items in a shopping cart or remembering that the visitor is logged in.
2. **Third-party cookies** are placed on a visitor’s browser by a website other than the one they’re currently visiting. They can track visitors across websites, which enables you to gather data about visitors' browsing habits, preferences, and interests. This information is then used to deliver personalized advertising experiences.

Third-party cookies are one among many tracking technologies that you can employ on websites for the benefit of running analytics solutions, marketing platforms and social media integrations in addition to online advertising.

Third-party cookies are regulated under the EU's [ePrivacy Directive](https://www.cookiebot.com/en/eprivacy-regulation/), which requires websites to obtain user consent before any non-essential cookies are set. [Cookiebot CMP](https://www.cookiebot.com/en/cookie-consent-solution/), part of Usercentrics, enables websites to manage consent for both third-party and first-party tracking technologies. The European Data Protection Board (EDPB) has also published the [Guidelines 05/2020 on consent](https://www.edpb.europa.eu/documents/guideline/guidelines-052020-on-consent-under-regulation-2016679_en).

## What Is the Difference Between First-Party and Third-Party Cookies?

Both types of cookies are small text files stored in a visitor's browser, but they differ in who sets them and what they're used for. The table below sets out the main distinctions.

AspectFirst-Party CookiesThird-Party CookiesSet ByThe website the visitor is currently onA domain other than the one the visitor is currently onTypical PurposeSite functionality, such as remembering login state or shopping cart contentsCross-site tracking for advertising, analytics, and retargetingTracking ScopeLimited to the single websiteCan follow a visitor's activity across multiple, unrelated websitesCommon UsesSession management, language preferences, basic analyticsInterest-based advertising, conversion tracking, social media integrationsBrowser Support (2026)Supported by default across all major browsersBlocked by default in Safari and Firefox; on by default in Chrome, managed via Privacy and Security settingsConsent RequirementsMay still require consent depending on purpose and jurisdictionGenerally requires consent under laws such as the GDPR

### Why Are Third-Party Cookies Under Scrutiny?

Third-party cookies not only serve the website they’re placed on, they also serve their providers, and the adtech industry at large revolves around mass data harvesting, profiling, and real-time bidding.

In return for optimization services on your website, a lot of third-party cookies will amass enormous amounts of personal data from your visitors without their consent or often even their knowledge. That information is traded and sold in the digital advertising industry and elsewhere.

The types of personal data that third-party cookies harvest range from individual IP addresses, sensitive search and browser history, specific details about devices, to private information about health, sexuality, family, political convictions, religious beliefs, and much more.

The problem with third-party cookies is not only the amount of personal data they collect, or the sensitive nature of that data. All of the data that third-party cookies collect can be put together to create extensive profiles on users consisting of thousands upon thousands of data points, such as your Google searches in the last five years, your credit card transactions, your profile on dating apps, and so on.

Inferences are made about the user's personality and life from these profiles, which can be sold to advertisers, who in turn will target their ads on a micro, individual level.

Third-party cookies supply this raw, privacy-infringing data to a nearly trillion-US-dollar adtech industry that relies on these inferences to predict the behavior of users, which advertisers pay for every day in real-time bidding auctions that make up the mechanics [of how personalized ads are shown to users on your website](https://brave.com/rtb-evidence/).

## What Is the Current Status of Third-Party Cookie Deprecation in Chrome in 2026?

In January 2020, [Google announced that Chrome would phase out support for third-party cookies](https://blog.chromium.org/2020/01/building-more-private-web-path-towards.html) in the browser, starting with trials on conversion measurement and personalization by the end of 2020.

Google's decision to remove Chrome's third-party cookie support was part of a larger [Privacy Sandbox launched in August 2019](https://usercentrics.com/knowledge-hub/google-chrome-privacy-sandbox/), a series of initiatives “to develop a set of open standards to fundamentally enhance privacy on the web.”

Google's Privacy Sandbox initiatives focused on:

- How to deliver ads to people without collecting identifying data from users' browsers.
- How to enable conversion measurements for advertisers without individual user tracking across the web.
- How to detect and prevent fraud on ads, e.g. bots clicking on ads instead of real users, and fight spam.
- How to strengthen user privacy on the web against cross-site tracking.
- How to safeguard users from hidden data tracking practices.

However, on June 24, 2021, after considerable industry pushback and a debate about what would replace them, [Google announced a two-year delay](https://techcrunch.com/2022/07/27/google-delays-move-away-from-cookies-in-chrome-to-2024/?guccounter=1) for the third-party cookie phase-out to the end of 2024.

Google began restricting third-party cookies for a small percentage of Chrome users in early 2024, but in July 2024 it abandoned the deprecation plan altogether, and in April 2025 confirmed it would not introduce a replacement consent prompt either. Third-party cookies remain on by default in Chrome, managed through existing Privacy and Security settings. This is where Google's plans remain in 2026.

Google is not the first to consider the shift away from third-party cookies. Mozilla’s Firefox, Brave Software’s Brave, and Apple’s Safari browsers have been blocking third-party cookies for years, while major publishers and media houses [like the New York Times](https://www.axios.com/new-york-times-advertising-792b3cd6-4bdb-47c3-9817-36601211a79d.html) also are in the process of transitioning away from third-party advertising data entirely.

Google's initiative to kill third-party cookies in Chrome was [met by resistance from the ad tech industry](https://www.cnbc.com/2020/01/16/advertising-trade-groups-oppose-google-chrome-cookie-plan.html), especially from marketers and advertising agencies. They were worried that the blanket stop to third-party cookies would hurt the internet economy and particularly startups and urged Google to keep third-party cookies in operation until tried and tested alternatives were available and in place.

## What Will Replace Third-Party Cookies?

There's no single technology stepping in to take third-party cookies' place. Since Google abandoned its Privacy Sandbox APIs in October 2025, the industry has settled into a more fragmented set of approaches, and website owners are relying on a mix of the following.

### First-Party Data

Many businesses are shifting toward data collected directly from their own visitors, through account logins, newsletter sign-ups, and on-site interactions, rather than relying on cross-site tracking supplied by third parties.

### Server-side tracking

Running analytics and marketing tags through a server rather than the browser can reduce reliance on client-side cookies and gives site owners more control over what data is collected and how.

### Contextual advertising

Rather than targeting individuals based on browsing history, some advertisers are returning to placing ads based on the content of the page itself.

### Browser-specific tools

Safari's Intelligent Tracking Prevention and Firefox's Enhanced Tracking Protection have blocked third-party cookies by default for years, and each browser maker continues to develop its own privacy-focused alternatives independent of what Chrome does.

### Consent-based approaches

Whatever combination of these technologies a website uses, consent remains the constant requirement under laws such as the GDPR — a consent management platform helps track what tracking technologies are active and can support obtaining and documenting the consent those laws require.

No replacement has reached the scale that third-party cookies once had, and it's worth treating any of the above as one part of a broader strategy rather than a like-for-like substitute. Cookiebot CMP, part of Usercentrics — the global leader in consent management — scans websites for all third-party and first-party cookies, blocks them until consent is given, and documents consent records for GDPR and ePrivacy Directive compliance, among other global privacy laws.

Learn more: Cookieless Tracking: What It Is, How It Works, and the Best Tools

## Do I Still Need Cookie Consent Without Third-Party Cookies?

The end of third-party cookies doesn't mean the end of the need for user consent.

There are numerous tracking technologies available to determine a user's identity across websites. Unless Chrome and other web browsers discontinue support not only for third-party cookies, but also for any other kind of similar [website tracking](/en/website-tracking/) techniques, users will still be tracked by some technologies as they browse the internet.

Tracking technologies can also be nested in the services used on websites and apps, so site owners may not always even know what data is being collected by third parties without [deep scanning](https://www.cookiebot.com/en/cookie-scanner/).

That's why consent remains the central requirement of many of the world's major data protection laws, led by the [European Union's General Data Protection Regulation (GDPR)](https://www.cookiebot.com/en/gdpr/) and reflected in laws the GDPR has influenced, like [Brazil's LGPD](https://www.cookiebot.com/en/lgpd/).

Under the jurisdiction of these laws, your website must obtain the consent from users before activating cookies, or collecting or storing any data on their browsers, or processing personal data for tracking and advertising, regardless of the technology used.

Your website is also obliged to clearly inform visitors about the tracking technologies you use, detailing the providers, purposes, and duration of data collection.

You must also safely document the consents obtained and be able to provide the data in the event of an audit or data subject access request. New consent must typically be obtained if the processing conditions change, like the purposes for processing, or after a certain period of time, the length of which is different under each law. Under many laws, users must also be able to change or revoke their consent preferences as easily as they gave consent.

### Consent and Google Ads and Analytics Platforms

Google has already started introducing features and requirements that make consent pivotal to use some of its services and protect user privacy. Recent laws with strong data privacy components, like the EU’s [Digital Markets Act (DMA)](https://usercentrics.com/digital-markets-act-dma/), with requirements that explicitly target Google and other influential tech companies, are at least one likely catalyst for such changes.

[Google Consent Mode](https://www.cookiebot.com/en/google-consent-mode/) launched in September 2020 and enabled websites to collect aggregate and non-identifying data as well as display contextual advertisement if visitors chose not to give their consent to statistics and marketing cookies. With [Google Consent Mode v2](https://www.cookiebot.com/en/google-consent-mode-v2-integration/), implemented in November 2023, it has evolved into more of a signaling tool, and users’ consent preferences determine whether Google tags collect and process full or anonymized data.

As of January 2024, publishers who use Google’s AdSense, Ad Manager, or AdMob products must use a [Google-certified consent management platform (CMP)](https://www.cookiebot.com/en/google-certified-cmp-requirement-cookiebot/) to serve ads to website visitors from the European Union (EU), European Economic Area (EEA) and the United Kingdom (UK). To receive certification, a CMP must integrate with the Interactive Advertising Bureau Europe’s Transparency and Consent Framework ([IAB TCF v2.2](https://www.cookiebot.com/en/iab-tcf-cookies/)), which aids in aligning with data privacy laws like the GDPR and its strict consent requirements.

## What Was Google's Privacy Sandbox Meant to Replace Third-Party Cookies With?

Google's Privacy Sandbox initiative proposed a set of APIs designed to support advertising functionalities without relying on tracking users across different websites. By October 2025, Google had retired most of these APIs, citing low industry adoption. Here's what was on offer, and what remains.

### Topics

Topics was designed to let browsers convey information about users' interests to third parties without tracking user activity or disclosing their personal information. Google retired the Topics API in October 2025, citing low industry adoption.

### Protected Audience

Formerly called FLEDGE (First Locally-Executed Decision over Groups Experiment), Protected Audience was designed to let advertisers run ad auctions using JavaScript code within the browser itself, supporting targeted remarketing to custom audiences. Google retired the Protected Audience API in October 2025.

### Private State Tokens

Formerly called Trust Tokens, Private State Tokens are designed to enable websites to determine whether a user is real or a bot without engaging in passive tracking. According to Google, [these tokens are encrypted](https://developers.google.com/privacy-sandbox/protections/private-state-tokens) and cannot be used to identify individual users. They can be used to protect advertisers against fraud and enhance user privacy by eliminating the invasive tracking commonly associated with third-party cookies.

Private State Tokens have **not** been retired. Google has explicitly confirmed it will keep maintaining them, alongside CHIPS and FedCM.

### Attribution Reporting

Attribution Reporting was designed to measure conversions from ad clicks and views without tracking user activity across websites, using event-level and aggregate-level reporting. Google retired the Attribution Reporting API in October 2025, though it says it will continue contributing to an interoperable 'Attribution' standard through the W3C's Private Advertising Technology Working Group.

For a full list of APIs and other measures, you can view [Google’s Privacy Sandbox website](https://privacysandbox.com/open-web/).

Most of these proposed approaches were retired before reaching wide adoption, and Google has abandoned its plan to deprecate third-party cookies in Chrome altogether. Website owners and advertisers should expect to keep relying on a mix of first-party data, existing cookie-based methods, and server-side tracking for the foreseeable future.

## How to Audit and Manage Third-Party Cookies on Your Website

Before you can manage third-party cookies, you need to know which ones your website is actually using. Many site owners are surprised by what turns up, since tracking technologies are often nested inside third-party scripts and services without being immediately obvious. A few steps can help bring this under control.

1. **Run a cookie scan.** A cookie scanner such as [Cookiebot™ CMP's cookie checker](https://www.cookiebot.com/en/cookie-checker/) can identify the cookies and tracking technologies active on your site, including less obvious ones like pixel tags and local storage trackers.
2. **Categorize what you find.** Group cookies by purpose, such as necessary, functional, statistics, and marketing, so visitors can make informed choices about each category rather than an all-or-nothing decision.
3. **Set up consent collection.** A consent management platform can help present these categories to visitors, record their choices, and pass those choices through to the tools and scripts your site runs.
4. **Document and store consent records.** Many data protection laws require you to be able to show what consent was given, when, and for what purpose, in case of an audit or data subject request.
5. **Re-scan periodically.** New scripts, plugins, and third-party integrations get added to websites all the time, often without anyone flagging the tracking technologies they bring with them, so a one-off scan won't stay accurate for long.

Handled this way, cookie management becomes an ongoing part of running the site rather than a single project you complete and set aside.

## Preparing for Third-Party Cookie Deprecation, Even Without Google

Google no longer intends to eliminate third-party cookies in Chrome, having abandoned its deprecation plan in 2024. Even so, third-party cookies are already blocked by default in other major browsers, so website owners should understand and prepare for a landscape where reliance on them is increasingly unreliable.

To prepare for these changes, you need to know which third-party cookies your website uses and you can use a [cookie scanner](https://www.cookiebot.com/en/cookie-scanner/) to find out.

Cookiebot™ [consent management platform (CMP)](https://www.cookiebot.com/en/cookie-consent-solution/)’s cookie checker enables you to conduct a free audit of your website’s cookies. Cookiebot CMP finds all cookies and online trackers used on a website, including:

- HTTPS/JavaScript cookies
- Dynamic cookies set during the user’s interaction with the website
- HTML5 Local Storage trackers
- Flash Local Shared Object trackers
- Silverlight Isolated Storage cookies/trackers
- IndexedDB trackers
- Pixel tags
- Ultrasound beacons

## What cookies are active now on your website?

Find out in minutes what cookies and trackers are collecting personal data on your website. Learn your privacy compliance risk level.

[Start scan](https://www.cookiebot.com/en/cookie-checker/)

In a future without third-party cookies, Cookiebot CMP will still detect the technologies in use to collect personal data from visitors, such as Google’s proposed browser APIs for conversion measurement, remarketing and real time ad auctions.

Cookiebot™ can also help you obtain valid consent under data privacy laws like the GDPR, which is required not only for cookies, but also for other similar website tracking techniques in a cookieless world.

## The Most Used Solution for Compliant Use of Cookies and Online Tracking

- Used on **2.4M** — websites and apps
- Manages **8.8B** — monthly user consents
- Supports **47+** — languages
- Powers **600,000+** — customers

## "Click, click, click, done."

Learn how easy comprehensive consent management can be. Customized banners, geotargeting, automated updates — and more.
Get started for free for 14 days, no credit card required.

[Start free trial](https://admin.cookiebot.com/signup)

---

## Footer

### Product
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/en/cookie-consent-solution/)
- [Usercentrics for Wix](https://www.cookiebot.com/en/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/en/new-wp-cookie-plugin/)
- [Cookie checker](https://www.cookiebot.com/en/cookie-checker/)
- [Pricing](https://www.cookiebot.com/en/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/en/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/en/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/en/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/en/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/en/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/en/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/en/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/en/microsoft-consent-mode-cmp/)

### Partners
- [Become an affiliate](https://www.cookiebot.com/en/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/en/resellers/)
- [Find a partner](https://www.cookiebot.com/en/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/en/blog/)
- [Digital Markets Act Hub](https://www.cookiebot.com/en/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/en/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/en/google-consent-audit-fixes/)
- [Developer documentation](https://www.cookiebot.com/en/developer/)
- [Cookiebot vs CookieYes](https://www.cookiebot.com/en/cookiebot-best-cookieyes-alternative/)
- [Cookiebot vs OneTrust](https://www.cookiebot.com/en/onetrust-alternative/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/en/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/en/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject Requests

[Privacy Policy](https://www.cookiebot.com/en/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/en/cookie-declaration/) · [Data Processing Agreement](https://www.cookiebot.com/en/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/en/legal-notice/) · [Accessibility Statement](https://www.cookiebot.com/en/accessibility-statement-wcag-compliance/)