All Blog Posts

Third-Party Tracking: What It Is, Who Is Liable, and How to Control It

Close
Read time
11 mins
Published
Sep 30, 2026
Share

  • Third-party tracking is a set of a website visitor’s data collected by a domain other than the one you are in, usually for marketing purposes.
  • First-party vs third-party tracking is different based on who sets and collects information from the cookie: you or an external service provider. 
  • Websites that rely on third-party tracking act as a “joint controller,” sharing responsibility with the vendor that implements tracking cookies, widgets, and pixels.
  • Common third-party tracking mechanisms include cookies, tracking pixels, software development kits (SDKs), and browser fingerprinting.
  • A consent management platform like Cookiebot by Usercentrics helps to technically ensure that no third-party tracking happens before receiving a positive consent signal from your website visitor.

Third-party tracking is a common way to collect visitors’ behavioral data and affects almost every digital experience these days. The tracking technologies like cookies, pixels, or browser fingerprinting are present on almost every website, getting cues of our online habits, using this information to personalize customer experience, and predicting what we are more likely to buy.

Given its hidden nature and sensitivity of personal data it collects, third-party tracking raises severe privacy concerns. Website owners share joint responsibility for the third-party cookies they install, thus need to understand how to personalize user experience within compliance requirements framing. This guide will help you see how third-party tracking works, in which cases you and third-party websites are responsible for it, and how to manage third-party trackers on your website to respect visitor privacy and regulatory compliance requirements.

What Is Third-Party Tracking?

Third-party tracking is a set of hidden mechanisms that external service providers implement on websites to collect visitor data. The primary reason for third-party website tracking is to gather additional information about a visitor to deliver a more personalized and satisfying experience. 

The hidden nature and external destination of third-party tracking raises visitor concerns, as website visitors cannot fully control who collects their personal data, in which moment it happens, and whether a third-party collector respects their data subject rights. In 2026, 71% of consumers find AI-driven personalization intrusive, according to Usercentrics' 2026 State of Digital Trust Report – highlighting the importance of clear communication before layering AI-based personalization on top of third-party data collection. 

Though being a legal mechanism to personalize user experience, third-party tracking can raise trust issues when its extent and methods start looking dishonest to people.

What Are Third-Party Trackers?

The key mechanisms for third-party tracking include:

  • Cookies: Tiny data files that a website loads into a browser to detect the next time you return as a visitor.
  • Tracking pixels: Pixel tracking uses images that are invisible to a visitor and collect device information of a website visitor and their interaction with a given customer flow on a website.
  • Browser fingerprinting: A unique trail of your browser, with the details on its type, your operating system, time of visit and more.
  • Software development kits (SDKs): Pieces of code within the building blocks of mobile apps that collect visitor data, track their behavior, and help with analytics, attribution, and monetization.

Third-Party Cookies vs. First-Party Cookies

The key difference between third-party cookies and first-party cookies lies in their ownership and execution. First-party cookies are implemented within a website by that same website; third-party cookies come from an external tracking platform and share information across several websites. 

Due to their nature, websites usually use first-party tracking and third-party tracking cookies to collect different information: first-party cookies usually remember details relevant to user experience (such as login details, previous choices in a cart, and language preferences), while third-party tracking cookies (or cross-site tracking cookies) track visitor browsing behavior (like page visited and session time) and use this information to personalize experience for a visitor. Still, first-party cookies can also collect behavioral data, and third-party cookies may support website functionality (like video players, maps, and chat widgets).

The key issue is where the data goes. While first-party data collection stays within one domain, third-party cookies can establish connection between numerous servers on their side and on their own. Thus, compared to first-party tracking, website owners usually find it harder to keep third-party tracking compliant, as they do not directly control the data processing or its onward sharing.

Third-party tracking raises legal concerns because it's harder for visitors and websites to control, and third-party trackers can get and accumulate sensitive information on their side and then sell detailed visitor profiles to other companies.

Installed on various websites, third-party tracking cookies become capable of connecting dots and building a detailed profile of any visitor. The frequency is the problem: a one-time website visit a day is not likely to reveal a visitor or do them much harm – but visiting several websites for several days feeds more information to third-party trackers, letting them create a detailed portrait of one’s online behavior, habits, and personality.

Managing third-party cookies can put a big burden on small websites, as they should understand which trackers exactly third-party servers install, how they behave, and what to do to make them compliant.

Browser Limitations of Third-Party Tracking

Acknowledging the murky strategies third-party trackers can adopt, some browsers introduced their restrictions to limit them. For example, Firefox introduced Enhanced Tracking Protection to disable third-party tracking cookies on their browser by default, and Safari prevents cross-site tracking on its side.

Google first announced in 2020 that it would phase out third-party cookies in Chrome. After repeated delays and a 2024 trial that disabled third-party cookies for one percent of Chrome users, Google confirmed in April 2025 that it would not proceed with removing third-party cookies or adding a consent prompt for them — Chrome users can still manage them in existing browser settings. In October 2025, Google retired most of the Privacy Sandbox APIs that had been built as replacements.

The browser restrictions on third-party tracking may mean losing accuracy in marketing campaigns, as visitors with ad blockers become invisible to them. Still, you can rely on first-party collection or server-side tagging to get accurate data for marketing campaigns without risking overreliance on third-party tracking tools.

Third-Party Tracking and Compliance Risks

Global data privacy regulations impose rules for collecting and processing personal data to address these issues, and the exact provisions and non-compliance penalties differ by jurisdiction.

Data privacy regulationEU GDPR, ePrivacy DirectiveUK GDPR, PECRCCPA/CPRA (California)COPPA (U.S.)
Key provisions for website ownersAsk for opt-in consent before collecting personal informationAsk for opt-in consent before collecting personal informationProvide privacy notice, honor opt-out requests, support Global Privacy ControlProvide parental notice if directed to children under 13, obtain verifiable consent
Penalty for non-complianceUp to EUR 20 million or 4 percent of global annual turnoverUp to GBP 17.5 million or 4 percent of global annual turnoverUp to USD 7,988 per violationUp to USD 53,088 per violation, per day

GDPR

The EU’s General Data Protection Regulation (GDPR), UK GDPR, and the ePrivacy Directive (referred to as “cookie law”) require obtaining visitor consent before sharing visitors’ personal data with third-party trackers if it is a chosen lawful basis for data processing. 

A compliant consent should be freely given, specific, informed, and unambiguous (Art. 4(11) and Art. 7 GDPR), and the most common way to collect it is to introduce a cookie banner with no pre-ticked boxes, coercion, hidden buttons, or unclear statements.

Read more on GDPR cookies and the compliance rules

Configuring website behavior so it respects visitor consent choices is key. As the 2023 study published in ARES shows, almost half of 200 Android apps and their corresponding iOS versions contacted third-party tracker domains even when the visitors had not given consent to be tracked.

CCPA

Similar to GDPR, California Consumer Privacy Act (CCPA) requires total transparency with visitors. The U.S. state law requires providing a clear notice at collection (with a “Do Not Sell Or Share My Personal Information” link) and easy way to opt out of consent. Website visitors under age 16 must give opt-in consent before a business sells or shares their personal information with third parties for cross-context behavioral advertising or similar purposes.

Learn more about Global Privacy Control as an opt-out requirement under CCPA and other U.S. state privacy laws

Note that CCPA applies to for-profit businesses with over 100,000 consumers or households annually, gross annual revenue exceeding USD 26,625,000, or over 50 percent or more of annual revenue coming from selling consumers’ personal information.

COPPA

The Children's Online Privacy Protection Act (COPPA) requires websites directed to children under 13 in the U.S., or with actual knowledge that children under 13 from the U.S. are visitors, to provide notice to parents and obtain verifiable parental consent before third-party trackers collect personal information from a child. The regulation requires to regularly audit data handling practices applied by the third-party websites.

Who Is Liable for Third-Party Tracking

Liability for third-party tracking doesn't sit with one party. It splits across the vendor running the tracker, the website that installed it, and sometimes both at once, depending on who actually controls the data.

  • Third-party websites: Companies such as Meta, Google, and TikTok may have direct responsibility for the personal data they collect, use, combine, or disclose through their tracking technologies. Their obligations depend on the processing they independently determine and on the applicable data protection laws. 
  • Website operators: Once you install a third-party tracker on your website, you become responsible for what fires on your domain, even if you didn’t write the script for the third-party tracker used. The responsibilities include identifying the tracker, providing appropriate information, obtaining prior consent where required, configuring the tag correctly, honoring withdrawal or opt-out signals, and selecting and supervising an appropriate vendor.
  • Joint controllership: A website operator and a third-party provider may be joint controllers where they jointly determine the purposes and essential means of a particular processing operation. The form of cooperation includes a transparent allocation of responsibility based on their actual involvement in third-party tracking.

In the US, this liability extends beyond privacy regulation. A growing number of class-action lawsuits under state wiretapping laws — most notably California's Invasion of Privacy Act (CIPA) — now target websites whose third-party tracking cookies, tracking pixels, chat widgets, or session replay tools capture visitor activity before consent is given. Courts have allowed these claims to proceed even when a website has a cookie banner in place, if the underlying trackers still fire before a visitor makes a choice. 

The practical fix is the same one that reduces exposure under GDPR and CCPA: an accurate inventory of every tracker running on the site (including tools you no longer actively use or forgot to remove), configured to fire only after consent. If obsolete code continues to run or leaves identifiers that remain accessible or operational, you are liable for it until the technology is disabled, removed, or otherwise brought under control.

How to Control Third-Party Tracking in a Compliant Way

The exact ways to control third-party tracking on a website include limiting third-party tracking to a necessary minimum, getting a consent management platform (CMP) to set up a compliant website behavior, and relying on alternative ways to collect data for marketing purposes (like first-party tracking and server-side tagging).

For pessimistic website owners, blocking third-party tracking entirely may seem the only way to remain compliant, but you can take a more nuanced approach – and determine the balance between personalization of user experience and respect for their data subject rights.

Identify and Minimize Third-Party Tracking Cookies on Your Website

Audit your website and detect all the third-party scripts, including “orphan” ones, and check their compliance under data protection laws applicable to you.

Then, you can use Cookiebot CMP to automate compliant cookie consent and set up tags and triggers in Google Tag Manager (GTM) so that your website acts according to visitor consent choices. To maintain accuracy of your marketing campaigns, configure Advanced Mode, as it helps to balance measurement and compliance while respecting privacy and visitor consent.

Please accept marketing cookies to view this video

Accept cookies

Prioritize First-Party Data for Marketing

With first-party data collection, you get to ask your visitors for their personal information directly and through your own domains, which keeps data processing within your organizational control and increases visitor trust.

To make it work for your analytics and CRM, find the balance between effectiveness and data minimization purposes to collect the exact first-party data you need. This way, you can partially replace and enrich third-party tracking, use data your competitors cannot buy from third-party data vendors, and minimize compliance risks.

Implement Server-Side Tracking

Server-side tracking helps store information on internal servers instead of relying on third-party cookies for cross-channel marketing campaigns. By relying on tools like server-side tagging, you can eliminate the need to rely on the visitorr's browser to collect their personal data and send it directly to your server.

Note that server-side tracking doesn’t bypass consent requirements. You still need to implement Google Consent Mode and prevent non-essential browser tags from firing before obtaining visitor consent. Still, it can be more controllable and may reduce some exposure compared with browser-based third-party tracking because data is routed through a server-side control layer.

Protect Your Privacy Online

As an individual visitor, you can daily delete cookies and your browsing history, apply ad blockers and other privacy controls on websites, and change your privacy settings on social media platforms.

How Cookiebot Can Help Website Owners Use Third-Party Tracking in a Compliant Way

With Cookiebot CMP and website scanning solution, you can detect third-party trackers automatically and ensure their compliance with EU’s GDPR, California’s CCPA/CPRA, Brazil’s LGPD, South Africa’s POPIA, Canada’s PIPEDA and many other data privacy regulations. It lets you wire up prior consent and offer opt-out, depending on the website visitors’ location, through highly customizable cookie banners.

Here is what you’ll get with a Google-certified CMP from Cookiebot:

  • A website scanner to detect cookies
  • Audit report to improve website compliance
  • A customizable cookie banner to collect visitor consent
  • A pre-built template to configure in GTM
  • Seamless integration with Google Consent Mode and Global Privacy Control. 

Cookiebot offers a Free plan for one-domain websites up to 50 subpages and Premium (with 14-day free trial) plan for website owners who want to get more control over banner customization and user experience personalization.

Legal disclaimer: Usercentrics does not provide legal advice, and information is provided for educational purposes only. We always recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.

Frequently asked questions

Third-party tracking is the set of trackers like scripts, pixels, and code snippets an external vendor installs on other websites to collect their website visitors’ data. It is usually used for targeted advertising, cross-site behavior monitoring, and campaign performance analysis.

Yet, the current extent and methods of third-party tracking may raise public concerns – especially when individuals’ personal data becomes the means of international trade between tech giants or a Big Data unit in the political competition for voters.

Third-party tracking commonly applies external code, data transmission, and cross-site profiling to collect information from websites and build detailed visitor profiles on the side of a third party tracker. The common technologies used for this aim include third-party cookies, tracking pixels, browser fingerprinting, and SDKs on mobile apps.

Website owners are responsible for all the scripts running on their websites, even if they are installed from third parties, while the third-party websites hold responsibility for the way they collect and use obtained data from the website visitor – for example, for building detailed visitor profiles. The joint responsibility comes into play when there is an arrangement between you and a third party on mutually agreed roles and responsibilities for third party tracking.

Individual visitors can use ad blockers to prevent third-party websites from running their trackers, while website owners need to conduct a detailed audit, configure the initial consent state to “Reject all,” and configure tags and triggers for website behavior with the CMP template in Google Tag Manager (GTM).

As managing third-party tracking can become a massive burden on small websites, getting an automated tool like Cookiebot CMP facilitates the website scan and GTM configuration. To limit the third-party tracking data for marketing activities, website owners tend to refer to alternative methods like server-side tagging and first-party workarounds under recent browser updates and privacy regulation requirements for third-party tracking.

Though third-party tracking is not illegal by its nature, the way it works on a given website and the way a third party uses the obtained information is heavily regulated. In Europe, GDPR and ePrivacy Directive require the website owner to obtain a visitor consent before running third-party scripts. To comply with the U.S. state laws like CCPA mandate to provide a transparent privacy notice and user-friendly ways to opt-out from third-party tracking. Check out the privacy regulations in your jurisdiction to mitigate compliance risks.

Yes, third-party trackers require prior consent before running to be compliant with GDPR and ePrivacy Directive. To address the requirement, website owners need to wire up a consent management platform or a tag manager to configure the consent mode and block third-party tracking mechanisms before the visitor consent is obtained. Essential scripts for website functionality can run without consent.