Customer Impact

Data & Tracking

Third party cookies: what they are, where they disappear and what replaces them

Copy for AI

Third party cookies are cookies that are not set by the website you visit, but by another domain loaded on that page, such as an ad network or an embedded widget. Because the same domain sits on thousands of sites, it can recognise someone across all of them. Safari and Firefox block them by default, Chrome leaves the choice to the user. They are being replaced by first-party cookies, server-side tracking and your own customer data.

For marketers the question is no longer whether they disappear, but how dependent your measurement still is on them. This guide explains what they are, how browsers handle them, what that means for your ads and how to build measurement that does not lean on them.

What exactly are third party cookies?

A cookie is a small text file a website stores in your browser. Whether a cookie is first party or third party depends on the domain. MDN, Mozilla’s web documentation, puts it this way in its guide to third party cookies: if the domain and scheme of the cookie differ from the page you are viewing, it is not a cookie from the same site and is referred to as a third party cookie. That happens when a page loads content from other domains, such as images, iframes or widgets.

First party cookieThird party cookie
Set byThe site you visitAnother domain on that page
ExampleYour basket, your language choice, the GA4 cookie on your domainAn ad network loaded on many sites
Readable byOnly that domainThe external domain, on every site where it loads
Typical purposeFunctionality, analytics, your own measurementCross-site profiles, retargeting, cross-site measurement
Browser blockingRarelyBy default in Safari and Firefox

The Belgian Data Protection Authority sums up the risk: third party cookies let those parties track browsing behaviour over time and across numerous websites, and build profiles for targeted marketing. That is exactly why they are under fire.

Which browsers block third party cookies?

According to MDN’s overview:

BrowserDefault behaviour
SafariBlocks through Intelligent Tracking Prevention, on by default
FirefoxBlocks through Total Cookie Protection within Enhanced Tracking Protection, on by default
ChromeDoes not block by default, only in Incognito or when the user sets it
EdgeBlocks trackers from unvisited sites and known harmful trackers
BraveBlocks tracking cookies by default

What does that mean in practice? On a B2B site with many iPhone and Mac visitors, any measurement that leans on third party cookies has been missing a large share of traffic for years. Look at your browser split in GA4 to estimate how big that share is for you.

What did Google decide about third party cookies in Chrome?

Google announced in 2020 that Chrome would phase these cookies out, and postponed that several times. On 22 April 2025 came the change of course. Google’s Privacy Sandbox update states that Chrome is keeping its current approach of letting users choose about third party cookies, and that there will be no new standalone prompt. Users continue to decide in Chrome’s privacy and security settings.

For marketers that means:

  • Chrome keeps allowing them by default, unless the user blocks them or browses in Incognito.
  • The replacement Privacy Sandbox technologies get a smaller role. Google itself wrote that those APIs may play a different role. So do not build measurement on them.
  • The problem has not gone away. Safari, Firefox, ad blockers, cookie law and refusals in your cookie banner still limit tracking through other domains.

What does this mean for your ads and your measurement?

Many marketers think their ad measurement runs on third party cookies. With the big platforms, that is largely no longer the case today.

What you doWhat it relies onEffect of cookie blocking
Measuring conversions in Google AdsA first-party cookie on your own domain plus the gclid in the URLLimited, provided your tags and consent are right
Measuring conversions in MetaThe fbp and fbc cookies on your own domain plus the Conversions APILimited, if you use CAPI
Retargeting through ad networks on other sitesOften third party cookiesSmaller audiences in Safari and Firefox
Cross-site profiles and data brokersThird party cookiesLess and less usable
Attribution across several channelsA combination of cookies, UTMs and CRM dataGaps if you rely on cookies alone

So the real loss lies less in the platforms themselves and more in three things: retargeting through networks, visitors who refuse your banner, and ad blockers that stop scripts. How to absorb that is in the next section.

What replaces third party cookies?

There is no one-to-one replacement. There is a set of techniques that together give sturdier measurement than cookies from other domains ever did.

  1. First party data. Data you collect yourself and with consent: forms, CRM, newsletters, customer behaviour. How to build it is in our guide to first party data.
  2. Server-side tagging. Your tags run through a server on your own subdomain, so cookies are first party and you decide which data goes to which platform. See our guide to server-side tracking.
  3. Conversions APIs. Meta, LinkedIn and TikTok let you send conversions from your server, with a hashed email address instead of a cookie. Read how in our guides to the Meta Conversions API, the LinkedIn Insight Tag and Conversions API and the TikTok Pixel and Events API.
  4. Enhanced conversions and offline conversions. Google Ads recognises leads through a hashed email address and through CRM imports. See enhanced conversions for leads and importing offline conversions from your CRM.
  5. Consent Mode v2. Google models conversions of visitors who refuse, based on cookieless signals. See our guide to Consent Mode v2.
  6. Contextual targeting and your own audiences. Instead of following people across the web, you advertise on context or on your own customer lists. More on that in cookieless marketing and paid social without cookies.

For websites that offer embedded services themselves, there are also technical alternatives such as partitioned cookies (CHIPS) and the Storage Access API. Those are mainly relevant to widget developers, not to your marketing measurement.

How do you check which third party cookies your site sets?

  1. Developer tools. Open your site in Chrome, go to Application and then Cookies. You see per domain which cookies are set. Anything not from your own domain is third party.
  2. Your cookie banner scan. A consent management platform scans your site and sorts cookies into categories. Compare that list with what you actually expect.
  3. Test without consent. Refuse all cookies in your banner and look again. No marketing cookies may appear then, first party or third party.
  4. Tag Manager preview. Check which tags fire before and after consent. An ad tag that fires before someone chooses often sets cookies already.

If you find cookies from services you no longer use, clean up the tags. Old chat widgets, abandoned ad networks and test scripts often stay in place for years. We do this as standard in a tracking audit.

Yes, if they serve analytics or marketing. The Data Protection Authority states that no cookie or tracker may be placed or read without prior information and consent, except what is strictly necessary to deliver the requested service. According to the authority, an analytics cookie does not fall under that exception. The difference between first and third party does not change that obligation: the purpose is what counts. Withdrawing consent must be as easy as giving it. In the Netherlands, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) takes the same line.

First party and server-side measurement therefore help against browser restrictions and ad blockers, not against a refusal in your banner. How to set up your banner correctly is in cookie banner rules in Belgium, and which tool to choose is in choosing a consent management platform. This is not legal advice: run your setup past your DPO or lawyer.

Should you allow cookies from other domains in your own browser?

We get this question a lot too, separate from marketing. For most people blocking is a reasonable default: you are tracked less across sites. Sometimes an embedded service then stops working, such as a login window or a payment module from an external party. Chrome lets you add exceptions per site in its privacy and security settings in that case. As a marketer, test your own site in both situations, so you know what visitors with strict settings see.

How do you build measurement that does not lean on cookies from other domains?

The order we use:

  1. Map which tags and cookies your site sets today.
  2. Clean up what you no longer use.
  3. Put a correct cookie banner with Consent Mode v2 in place.
  4. Build a data layer with fixed events for every form and every appointment.
  5. Add server-side tagging and send conversions through the APIs of Google, Meta, LinkedIn and TikTok.
  6. Feed your CRM back, so platforms learn from qualified leads and deals.

What that looks like in practice is shown in our cases: at Tryve we rebuilt the conversion measurement without noise, at Kaizo we let GA4, Google Ads and Meta steer on the same booked demo. If you want such a setup for your own site, our tracking specialist builds it to measure, on request. Get in touch for a first check.

For more on privacy-friendly measurement, read our guides on Cookiebot and Matomo.

Frequently asked questions

What is the difference between first party and third party cookies?

First party cookies are set by the site you visit and can only be read by that domain. Third party cookies come from another domain on the page and can recognise you across several sites.

Are third party cookies disappearing in Chrome?

Not according to current plans. In April 2025 Google decided to leave the choice with the user and not to introduce a new prompt. Safari and Firefox do block them by default.

Does Google Ads conversion tracking still work without third party cookies?

Yes. Google Ads measures conversions with a first-party cookie on your own domain and the gclid in the URL. Enhanced conversions and offline conversions make that measurement more robust.

Is server-side tracking a way to bypass cookie consent?

No. Server-side tracking moves the technical route, not the legal obligation. For analytics and marketing purposes you still need prior consent in Belgium and the Netherlands.

How do I see which third party cookies my website sets?

Through your browser’s developer tools (Application, then Cookies) or through the scan of your consent management platform. Cookies from a domain other than yours are third party.

Free website scan

Enter your website and get an automatic scan within minutes, with concrete technical and SEO improvements. No sales pitch.

Where should we send your report?

We only use your details for your scan. No spam, unsubscribe anytime.