For years, marketers were told to prepare for the day third party cookies would disappear from Chrome. That day never arrived in the form the industry expected. As of September 26, 2026, the third party cookie status is different by browser: Chrome still supports them in regular browsing, Safari blocks them by default, Firefox blocks cross site tracking cookies by default and Edge still allows them unless settings or tracking controls restrict them.
That does not mean the industry went back to where it started. Years of preparation changed how advertisers collect signals, resolve identities, measure campaigns and build first party data. The cookie deadline disappeared, but much of the work built around that deadline remains.
Key Takeaways
- Chrome did not complete the planned third party cookie phaseout in regular browsing.
- Safari and Firefox had already restricted cross site cookies years before Chrome changed course.
- The Privacy Sandbox is no longer the broad replacement programme once planned for a cookieless Chrome.
- Identity resolution, clean rooms, server side measurement, MMM and incrementality testing remain important.
- The practical question now is where your business still depends on a shared browser cookie.
Where Things Stand Today, Browser By Browser

The easiest way to understand the current position is to stop talking about “the web” as if it has one cookie policy. Each major browser now handles third party cookies differently.
| Browser | Current Position | What It Means For Marketers |
| Chrome | Third party cookies remain available in regular browsing. Users can allow or block them. Incognito blocks them by default. | Cookie based workflows can still work for users who allow them, but cannot be treated as universal. |
| Safari | WebKit blocks third party cookies by default. Cookie access can be granted through the Storage Access API in supported situations. | Cross site cookie tracking has been restricted for years. |
| Firefox | Cross site tracking cookies are disabled by default. Total Cookie Protection isolates cookies by site. | Traditional cross site tracking is heavily restricted. |
| Edge | Third party cookies are allowed by default unless users, policies or tracking prevention settings restrict them. | Availability depends on browser settings and tracking protection. |
Chrome Still Supports Third Party Cookies
Google abandoned the plan to remove third party cookies from general Chrome browsing and instead kept the existing user choice approach. Chrome’s current help documentation still gives users the option to allow or block third party cookies, with blocking enabled by default in Incognito.
Safari Blocks Third Party Cookies By Default
WebKit says Intelligent Tracking Prevention blocks all third party cookies by default, with the Storage Access API providing a controlled route for legitimate embedded use cases.
Firefox Blocks Cross Site Tracking Cookies
Firefox also does not treat third party cookies as a normal cross site tracking mechanism. Its current documentation says cross site tracking cookies are disabled by default for all Firefox users, while Total Cookie Protection gives each site its own cookie storage boundary.
Edge Still Allows Third Party Cookies
Edge is more permissive at the cookie level. Microsoft documents third party cookies as allowed by default unless the user changes the setting, while its Balanced and Strict Tracking Prevention modes block different levels of tracking activity.
The Current State Is Different By Browser
Current state: third party cookies are neither fully alive nor universally dead. Their usefulness now depends heavily on the browser, user settings, and implementation.
The Timeline, Briefly
The story started with a clear promise and ended without the promised technical event.
| Date | What Happened |
| January 2020 | Google said Chrome intended to phase out third party cookies within two years. |
| June 2021 | Google moved the planned Chrome phaseout to a three month process beginning in mid 2023. |
| July 2022 | The target moved again, this time to the second half of 2024. |
| January 2024 | Chrome began restricting third party cookies for 1% of users for testing. |
| April 2024 | Google said it would not complete the phaseout during the second half of 2024 and envisioned starting the process in 2025. |
| July 2024 | Google changed direction and proposed giving users a choice instead of removing third party cookies from Chrome. |
| April 2025 | Google confirmed it would maintain the existing user choice approach and would not introduce the planned standalone prompt. |
| October 2025 | The UK Competition and Markets Authority released the commitments that had governed Google’s Privacy Sandbox work after concluding they were no longer necessary under the new approach. |
The original 2020 plan was to make third party cookies obsolete through Privacy Sandbox technologies and then remove their support from Chrome within two years. In 2021, the target moved to late 2023. In 2022, it moved again to the second half of 2024.
Chrome then moved from planning to testing. It restricted third party cookies for 1% of users in January 2024, but the full rollout never happened. In April 2025, Google confirmed that it would maintain the existing approach instead of introducing a new standalone user prompt.
Timeline graphic: Show the 2020 two year promise, 2021 move to 2023, 2022 move to 2024, 2024 change of direction and 2025 confirmation.
That is the important distinction for this article: cookie deprecation was repeatedly delayed and ultimately abandoned as a Chrome wide phaseout.
What The Industry Built While It Waited
The preparation was not wasted because the problem was bigger than one browser deadline.
First Party Data Became More Important
The first shift was toward first party data. Instead of assuming a browser based identifier would follow a person across websites, companies invested more heavily in customer databases, consented identifiers and direct relationships.
The IAB’s 2026 outlook found that 57% of surveyed buyers expected to focus more on first party data acquisition and partnerships in 2026.
Identity Resolution Replaced The Shared Cookie Model
The second shift was identity resolution. The goal changed from simply reading a shared cookie to connecting permitted first party records across systems. Publisher advertiser matching systems now use privacy controls and encryption rather than requiring a universal third party cookie.
Google’s PAIR documentation, for example, describes a publisher advertiser matching approach that does not rely on third party cookies or shared IDs.
Data Clean Rooms Added A New Layer
Then came data clean rooms. These environments allow companies to compare or activate against sensitive datasets without simply handing raw customer records to another company.
They added another layer of infrastructure, integration work and governance, but they also became useful for privacy constrained measurement and audience collaboration.
Server Side Measurement Reduced Browser Dependence
Server side measurement followed a similar logic. Instead of sending every measurement request directly from the browser to multiple vendors, companies can route data through infrastructure they control.
That can require cloud resources, implementation work and ongoing maintenance, but it gives teams more control over what data leaves their systems.
Measurement Shifted Toward Models And Experiments
The measurement layer changed too. Marketing mix modelling and incrementality testing gained importance because neither requires a universal browser identifier.
Current industry guidance is explicitly moving toward combining MMM, experimentation and attribution rather than treating one method as sufficient.
The Preparation Changed The Market
So the cost of preparation was not one cookie replacement invoice. It appeared as engineering, data integration, vendor infrastructure, clean room work, analytics and measurement capability.
That work remains useful even though the original Chrome deadline disappeared.
What Actually Degraded, And When
The biggest misunderstanding is that signal loss started when Google was supposed to switch off Chrome cookies.
It did not.
Safari Started Restricting Third Party Cookies Earlier
Safari’s Intelligent Tracking Prevention began restricting third party cookies in 2017 and became much stricter over time. In March 2020, WebKit introduced full third party cookie blocking by default across Safari.
Firefox Followed With Tracking Protection
Firefox took another path. Enhanced Tracking Protection began blocking known third party tracking cookies by default in 2019. Its current system goes further by isolating cookies through Total Cookie Protection.
App Tracking Changed The Signal Landscape
The app environment changed separately. Apple’s App Tracking Transparency framework requires apps that track users across apps and websites owned by other companies to request permission. That changed the availability of cross app signals on Apple devices even though it was not a browser cookie rule.
Regulation Added Another Layer
Regulation and consent requirements added another layer.
Signal Loss Was Gradual, Not One Event
The result was gradual signal loss rather than one dramatic event. By the time Chrome changed direction, advertisers had already spent years dealing with browsers, apps and privacy controls that limited deterministic tracking.
What Still Depends On Third Party Cookies?

Some systems still depend on them because Chrome has not removed the underlying capability.
Retargeting And Cross Site Frequency Management
The clearest examples are workflows built around a shared cookie identifier across different websites. That can include certain forms of retargeting, cross site frequency management and attribution paths where the vendor expects the same browser identifier to appear at multiple points.
Not Every Platform Still Needs Them
The important word is certain. A platform may have already replaced a cookie based workflow with first party identifiers, login data, server side signals or modelling. You cannot determine dependency from the name of the product alone.
Viewability Does Not Require Cross Site Identification
Viewability is different. An ad can be measured for whether it had an opportunity to be seen using delivery and visibility signals. The IAB and MRC standards define viewability separately from whether a user can be identified across websites.
Measurement Can Work Without Third Party Cookies
The same applies to measurement more broadly. Google Analytics, for example, mainly uses first party cookies for website measurement and can also use modelling when some events cannot be directly observed.
How To Find Your Own Dependency
Do not estimate your exposure from a browser market share chart. Check four things:
- List every vendor cookie. Identify which cookies are set by your domain and which come from another domain.
- Map the use case. Record whether each cookie supports login, advertising, retargeting, frequency, attribution, measurement or another function.
- Break performance down by browser. Look for differences in conversion, attributed revenue, audience size and remarketing reach across Chrome, Safari, Firefox and Edge.
- Test without third party cookies. Chrome DevTools can simulate restricted third party cookies and show which cookies are blocked. The Network panel also identifies cookie problems.
That gives you a dependency map based on your own implementation rather than an industry headline.
What Happened To Privacy Sandbox?
Privacy Sandbox is no longer simply “the replacement for third party cookies.” Its role changed after Google decided to keep third party cookies in Chrome under the existing user choice model.
Google Changed The Original Plan
Google’s April 2025 decision changed the role of Privacy Sandbox. Because Chrome would continue supporting third party cookies, several advertising APIs built around a future without those cookies were no longer needed in their original form.
Some Privacy Sandbox Technologies Remain
The current Privacy Sandbox status page, last updated August 14, 2026, shows that Chrome continues to support technologies including CHIPS, FedCM, Storage Access and storage partitioning.
These technologies still address areas such as privacy, storage and identity without simply restoring the old cross site tracking model.
Several Advertising APIs Are Being Removed
The same status page lists several advertising and measurement technologies for deprecation and removal. These include Attribution Reporting, Protected Audience, Topics, Shared Storage, Private Aggregation and Related Website Sets.
Chrome’s 2026 release notes also confirm that the browser has started removing Privacy Sandbox APIs developed around the earlier third party cookie phaseout plan.
Privacy Sandbox Is No Longer One Big Replacement
So if a team asks whether Privacy Sandbox is still “the future of advertising,” that is too broad a question.
Parts of it remain, particularly technologies related to privacy and storage boundaries. But the original package of advertising APIs designed to replace third party cookies at Chrome scale is being wound down.
The Read
The third party cookie question is settled in one sense and unsettled in another. The old answer was supposed to be simple: Chrome would remove the cookie and the industry would move to a new system. That did not happen. Instead, Safari and Firefox restricted the signal years ago, Edge remains more permissive and Chrome kept the cookie while changing the path around it.
The more useful conclusion is that the cookie deadline is over, but the measurement transition is not. A measurement lead should check one thing this quarter: which campaigns, vendors and reports would materially change if every third party cookie disappeared tomorrow?
- If the answer is “none,” the business has already moved on.
- If the answer is “several,” the work was never really about waiting for Google.
It is about removing a dependency that the rest of the web stopped treating as reliable years ago.



