Data & identity · also called 3P cookie, third-party cookies
Third-party cookie
A third-party cookie is a small file set in your browser by a domain other than the site you are visiting, typically ad tech, letting it recognise your browser across sites.
A cookie is a tiny text file a website stores in your browser. When the site you are on sets it, it is a first-party cookie, used for things like keeping you logged in. When an embedded service, such as an ad server or tracking pixel from another domain, sets it, it is a third-party cookie. Because that same ad tech domain is embedded on thousands of sites, its cookie can recognise the same browser everywhere.
Third-party cookies powered two decades of behavioral targeting, retargeting, frequency capping, cookie syncing and multi-touch attribution. They also raised privacy concerns, and browsers responded: Safari and Firefox block them by default. Google announced plans in 2020 to phase them out of Chrome, delayed repeatedly, then reversed course in 2024 and 2025 and kept them; in October 2025 it said it would retire most of the Privacy Sandbox APIs designed as replacements.
So in 2026 third-party cookies still work in Chrome but not in Safari or Firefox, and laws such as GDPR require consent to use them for advertising. Much of the industry has meanwhile invested in first-party data, contextual targeting and alternative IDs.
Think of it like this
A third-party cookie is like a loyalty-card stamp from one company that works in every shop in the mall, letting that company follow you from store to store.
An example
You read a recipe on a food site in Canada that embeds an ad network's tag. The network sets a cookie, then recognises the same cookie on a news site an hour later and shows you a cooking-pan ad.
Related terms
First-party data
First-party data is information a company collects directly from its own customers or audience, such as purchases, sign-ups, app use and site behaviour, through its own channels.
Cookie syncing
Cookie syncing is how two ad tech companies match their separate cookie IDs for the same browser, so they recognise the same user when exchanging bid requests or data.
Privacy Sandbox
Privacy Sandbox was Google's initiative, launched in 2019, to build browser and Android APIs to replace cross-site tracking; in October 2025 Google announced it would retire most of those APIs.
Cookieless advertising
Cookieless advertising means targeting and measuring ads without third-party cookies, using approaches like first-party data, contextual targeting, alternative IDs, clean rooms and modelled measurement.
Signal loss
Signal loss is the reduction in data available to target, measure and optimise advertising, caused by browser cookie blocking, mobile ID restrictions, privacy laws, consent choices and ad blocking.
Retargeting
Retargeting is showing ads to people who have already interacted with a brand, for example by visiting its website, using its app or adding a product to a cart without buying.
Sources: Google: Update on plans for Privacy Sandbox technologies (October 2025), GDPR full text (gdpr-info.eu)