Editor’s note. This article was first published in May 2021 and said that Chrome would remove third-party cookies in 2022. That did not happen. It was rewritten in August 2026 with what actually occurred and what still holds. The dated predictions have been removed; the recommendations, which aged better than the deadline, have been kept and updated.
Contents
- 1 Key points
- 2 Did Chrome remove third-party cookies?
- 3 Which browsers block third-party cookies today?
- 4 So is cookie-based targeting fine now?
- 5 What is actually affected?
- 6 What should you do instead?
- 7 How does this apply to video and YouTube?
- 8 Frequently asked questions
- 9 Sources and revision history
- 10 Related reading
Key points
- Chrome still supports third-party cookies. The removal was called off in July 2024, and the fallback plan — a standalone choice prompt — was dropped in April 2025.
- The Privacy Sandbox project that was meant to replace them ended. Ten of its APIs were retired on 17 October 2025.
- Safari, Firefox and Brave still block third-party cookies by default, and have for years. Roughly a quarter to a third of browsing in most Asian markets sits behind that block.
- So the cliff never came, but the erosion is real and gradual. Planning for a single deadline was always the wrong shape for this problem.
No. The plan was announced in 2020, postponed several times, and then withdrawn.
| When | What happened |
|---|---|
| 2020 | Google announces its intention to phase out third-party cookies in Chrome, originally targeting 2022 |
| 2021–2023 | The date is pushed back more than once while the Privacy Sandbox APIs are developed and tested |
| July 2024 | Google announces it will not phase out third-party cookies in Chrome |
| April 2025 | The fallback — a one-off prompt asking users to choose — is also dropped |
| October 2025 | Ten Privacy Sandbox APIs are retired, including Topics, Protected Audience and Attribution Reporting |
The stated reasons were low adoption of the replacement APIs and continued regulatory scrutiny of the change itself. Whatever the weighting between them, the practical outcome for a media planner is simple: the mechanism you were told to plan around is still there.
Three of the four major ones, and they have for years. This is the part that was true in 2021 and is still true now.
| Browser | Third-party cookies | Since |
|---|---|---|
| Safari | Blocked by default | Intelligent Tracking Prevention, 2017 |
| Firefox | Blocked by default | Enhanced Tracking Protection, 2019 |
| Brave | Blocked by default | Since launch |
| Chrome | Not blocked by default | — |
Chrome holds the majority of browser share across Asia, which is why its decision dominated the conversation. But the inverse of that number is the useful one: the share sitting on Safari, Firefox and Brave has been invisible to third-party cookies the whole time. A campaign that depended entirely on them was never reaching everyone, deadline or no deadline.
It works where it always worked, and it degrades where it was already degrading. What changed is the shape of the problem, not its direction.
- Browser blocking continues on Safari, Firefox and Brave.
- App tracking is opt-in on iOS. Apple’s App Tracking Transparency framework, introduced with iOS 14.5, requires each app to ask permission before accessing the advertising identifier. That is a separate mechanism from cookies — one is for apps, the other for browsers — but it removes signal from the same campaigns.
- Consent regimes keep expanding: GDPR and CCPA, and in Asia the PDPA in Singapore and Thailand, PIPA in Korea, PIPL in China, and the APPI in Japan. Where consent is required and not given, the cookie is not set.
- User settings and privacy tooling remove more.
None of these arrive on a date. They compound. A team that spent 2021 to 2024 waiting for a switch to be thrown got no warning event, and in the meantime the addressable share kept shrinking quietly.
What is actually affected?
| Capability | Where it still works | Where it does not |
|---|---|---|
| Audience targeting | Chrome, and inside logged-in environments | Safari, Firefox, Brave; unconsented sessions |
| Retargeting | Same | Same — and the pool shrinks as the blocked share grows |
| Conversion measurement | Same-session and same-site conversions | Cross-site paths; attribution beyond the last click is incomplete |
| Frequency control | Within a platform’s own logged-in graph | Across sites and vendors |
Frequency control is the one most often overlooked. When it fails, the same person sees the same creative repeatedly, which is a media-waste problem and a brand problem at the same time.
What should you do instead?
The recommendations in the 2021 version of this article have held up. Here they are, updated.
- First-party data. Data you collect directly, with consent, in exchange for something the user wants. It is the only signal that does not depend on someone else’s browser policy.
- Logged-in and premium environments. Where users sign in, the publisher knows who is there without a third-party cookie.
- Contextual targeting. Selecting inventory by what the content is about rather than by who the viewer is. It needs no identifier at all, which is why it is unaffected by every mechanism listed above.
- Measurement that does not assume a complete path. Incrementality tests, geo holdouts and media-mix modelling answer questions that user-level attribution no longer can.
One item from the original article should be read differently now: shared identity frameworks. Industry ID initiatives were positioned in 2021 as the successor to the third-party cookie. They still exist and are used, but they did not become the default, and the deadline that was driving their adoption disappeared. Treat them as one option to evaluate, not as the destination.
How does this apply to video and YouTube?
Video is where identity signals were always weakest, so the contextual argument is strongest there. Connected TV in particular is shared by definition: our own survey found that around 40% of YouTube users let someone else in the household watch on their account, which means an identity signal can be accurate about the account and still wrong about the person watching. See what account sharing does to targeting.
Selecting by content sidesteps that question rather than answering it. In a matched test on YouTube, buying against a screened list of videos put 87% of impressions in the intended content category against 48% for term-based matching, using no user identifier in either case.
Frequently asked questions
Not in Chrome. Google announced in July 2024 that it would not phase them out, and dropped the fallback choice prompt in April 2025. They remain blocked by default in Safari, Firefox and Brave, as they have been since 2017, 2019 and launch respectively.
What happened to the Privacy Sandbox?
It ended. Ten of its APIs — including Topics, Protected Audience and Attribution Reporting — were retired on 17 October 2025. It had been developed as a replacement for third-party cookies; once the removal was called off, the replacement was no longer needed.
The deadline was wrong; the direction was not. First-party data, consented logged-in environments and contextual targeting all pay off against browser blocking, app-tracking opt-in and consent regimes, none of which were cancelled. What was wasted was work built specifically around APIs that no longer exist.
By selecting the environment rather than the individual. Contextual targeting places the ad according to what the content is about, so it needs no identifier and is unaffected by browser policy, consent status or device settings. First-party data and logged-in inventory cover the cases where you do need to know who the user is.
Is this the same issue as Apple’s ATT and IDFA?
Related but separate. Cookies are a browser mechanism; the advertising identifier is a mobile app mechanism. App Tracking Transparency, introduced with iOS 14.5, made access to it opt-in per app. Both reduce signal on the same campaigns, and both reflect the same shift of control toward the user.
Sources and revision history
- Chrome and Privacy Sandbox status: Google’s Privacy Sandbox announcements of July 2024, April 2025 and October 2025.
- Browser defaults: Apple Intelligent Tracking Prevention (2017), Mozilla Enhanced Tracking Protection (2019).
- Account sharing figure: GP Inc. survey, n = 833, Japan, December 2024. Full method on that article.
- Category-share figures: GP Inc. matched-condition targeting test, Japan, 2025.
- Revision history: first published 10 May 2021. Rewritten 24 August 2026 — removed the 2022 deprecation deadline and the Privacy Sandbox roadmap, added the actual timeline, browser status and current recommendations.
Browser share varies by market and moves; check current figures for your own markets rather than relying on a number quoted in an article.
Related reading
- Contextual advertising on premium publishers
- One account, several viewers: what YouTube sharing does to targeting
- Keyword targeting vs contextual targeting on YouTube
Targeting without an identifier. GP selects YouTube inventory by what the video is about, so delivery does not depend on cookies, device identifiers or consent status. Talk to your local team.

