Google Chrome Is Ending Third-Party Cookies: How Should Marketers Respond?


Third-party cookies used to be one of the most essential resources in digital marketing. But on January 4, 2024, Google announced plans to phase out third-party cookie support in Chrome.
Google said it would block third-party cookies as part of testing new privacy protection features.
Then, in April of that year, a follow-up announcement about the strategy drew renewed attention from marketers worldwide. Why did Google announce the end of third-party cookies, and where should digital marketing go from here?
What Are Third-Party Cookies?

Defining Third-Party Cookies
A third-party cookie is a cookie issued by a domain other than the website the user is actually visiting. These cookies track and analyze users’ online behavior and are used for marketing purposes like targeted advertising.
Why Are Third-Party Cookies So Sensitive?
The personal data third-party cookies collect includes individual IP addresses, search and browsing history, and specific device information. And that’s not all — data touching on health, family, political beliefs, and religious beliefs can get swept up too.
In other words, it’s not just the sheer volume of personal data being collected, but the sensitivity of that data. Third-party cookie data alone is enough to build profiles on thousands upon thousands of users.
Those profiles even make it possible to predict a person’s personality and life circumstances — and advertisers use that to build precisely targeted ads.
How Have Third-Party Cookies Actually Been Used?

Third-party cookies have played a central role in helping advertisers and marketers collect and analyze user behavior data online. That, in turn, let them serve more personalized ads and content — boosting marketing performance in the process.
For example, a shopper browsing news or a blog might see an ad in their feed for the exact sneakers they hesitated over buying that morning, or something similar.
That happens because ad AI recognizes the cookie that tracked the user browsing sneakers at an online store and judges them a high-probability buyer, then serves the ad accordingly. Because this actually does translate into higher purchase rates, it has been a major driver of successful performance marketing.
Naturally, some users find this unsettling. But plenty of others see ads that match their interests as genuinely useful information rather than an intrusion.
Why Google’s Third-Party Cookie Deprecation Has Marketers on Edge

In recent years, major browsers — including Google and Apple — have been ending third-party cookie support in the name of privacy protection. As a result, the advertising and marketing industry has had to scramble for new alternatives.
That said, Google has also backed off somewhat, saying it wants to carefully weigh feedback from the industry and regulators before deciding. Google (Alphabet) decided to push its Chrome third-party cookie phase-out timeline from 2024 to 2025.
Since then, Google has adjusted the plan multiple times in response to concerns from regulators and industry. You can check the latest developments on third-party cookies and the current state of Privacy Sandbox technology directly on Google’s official Privacy Sandbox page — we’d recommend checking the latest status there before finalizing your response strategy.
We remain committed to engaging closely with the CMA and ICO and we hope to conclude that process this year. Assuming we can reach an agreement, we envision proceeding with third-party cookie deprecation starting early next year.
— Google, on its Privacy Sandbox timeline
So with roughly six months left before the third-party cookie phase-out begins, how are marketers actually responding?
Lessons From iOS Opt-Out
App Tracking Transparency (ATT) is Apple’s opt-in privacy framework, which requires every iOS app to ask users for permission before sharing their data. It works through a pop-up that lets users allow or deny tracking.
Newer versions of iOS include this privacy feature, which means mobile apps have to request permission before collecting tracking data from users.
Put simply: what used to happen automatically now requires a prompt. On any device updated to iOS 14.5 or later, users are asked whether they’ll allow tracking before browsing, with the option to block it outright.
The average opt-in rate (users who chose to allow app tracking) came in at 34% in 2023 (per an analysis of 2023 ATT opt-in rates, up from 29% in 2022). The rest are presumed to have opted out — and this led to complaints that Facebook campaigns weren’t performing as efficiently or effectively as before.
In response, advertisers started leaning on in-app data collection tools like lead forms and chatbots. These methods weren’t as effective as third-party cookies, but they didn’t run into the same privacy restrictions.
Facebook had previously projected that ATT opt-in would cost it more than $10 billion in revenue — and its stock price did in fact take a hit. Experts note that while user privacy protections have genuinely improved, that may have come at the cost of some of the web’s diversity and openness.
What Replaces Third-Party Cookies in Chrome?

Google’s Privacy Sandbox initiative focuses on the following:
- Delivering ads to people without collecting identifying data from their browsers
- Enabling advertisers to measure conversions without tracking individual users
- Detecting fraud and spam, such as ad-click bots
- Strengthening user privacy on the web with respect to cross-site tracking
- Protecting users from covert data tracking practices
Building on this, there are four main ways Chrome plans to address the end of third-party cookies.
Topics is an anonymous grouping method based on user interests. According to Google’s official Privacy Sandbox documentation, the Topics API aims to serve interest-based ads without sharing the specific sites a user visited across the web. Fenced Frames refers to anonymized user groups that advertisers can target while still protecting user privacy. Both approaches offer the advantage of serving relevant ads without exposing personal information.
Private State Tokens is a technology that lets user information be stored and shared securely. Attribution Reporting is a method for measuring ad effectiveness without exposing users’ personal information. Together, these two tools make it possible to improve user experience, measure ad performance, and run effective ad campaigns without relying on third-party cookies.
That said, actually putting Private State Tokens to work in real ad and marketing operations takes significant resources — which is a real drawback, since it’s difficult for anyone but larger enterprises to use it effectively.
What About Performance Marketing?
Beyond Google’s Privacy Sandbox initiative, a variety of other responses are taking shape.

Meta is building a system that lets advertisers optimize ads and improve marketing performance through the Conversions API, even without third-party cookies. According to Meta’s official documentation, the Conversions API sends web and offline events to Meta directly from the server rather than the browser, making it less susceptible to browser loading errors, connectivity issues, and ad blockers.
According to data Meta has published, advertisers who set up the Conversions API alongside the Pixel saw cost per result improve by roughly 13% and attributed purchase events increase by an average of 19%.
Beyond that, strategies that build owned website traffic and put first-party data to work in marketing are gaining attention as well. Since precise targeting based on third-party cookies is no longer possible, the strategy is to build broad traffic and put it to work in marketing instead.
What both approaches have in common is that they rely on first-party data collected directly from your own website. That’s an advantage from a privacy standpoint, and it also enables more accurate user profiles — which supports more effective targeting.
That said, compared to third-party cookies, there are real gaps — and if you want to maintain existing performance levels, projections suggest you’ll likely need to increase your budget by 5-25% or more.
Is There a Real Answer to Chrome’s Third-Party Cookie Deprecation?
SEO-Driven Content Marketing
Content marketing can be an effective marketing strategy even without third-party cookies. Providing useful content that matches users’ interests and needs strengthens the relationship between a brand and its customers.
And given that performance marketing targeting is bound to keep getting less precise, being able to target through the substance of your content itself — reaching customers whose interests connect naturally to your product — is bound to deliver strong results.
Being able to track visitors to your own website as first-party data, without relying on third-party cookies, also helps maximize the efficiency of your performance marketing.
In the past, performance marketing could deliver strong results even without support from owned media. Now, businesses need to shift quickly toward a structure where SEO drives organic search traffic to owned media, and performance marketing then converts that larger base of prospects.
Growth is committed to helping businesses deliver strong marketing results even amid rapid change. Even after the end of third-party cookies, we’ll keep supporting sustainable business growth through diverse data collection methods and differentiated strategy.
If you want to apply this to your own business — you can see Growth’s approach on our performance marketing services page, and if you need a concrete diagnosis of your situation, reach out via contact us. We answer with an eye toward the one customer who becomes revenue, not just traffic volume.
Frequently Asked Questions About Third-Party Cookie Deprecation
Is Google Chrome really getting rid of third-party cookies?
Yes — Google has announced that it will end third-party cookie support in Chrome within 2025. This is expected to have a major impact on the advertising and marketing industry, bringing significant changes to conversion tracking, ad targeting, and more.
Does my website use third-party cookies?
Websites generally use both first-party and third-party cookies. Third-party cookies are created by a domain other than your own and are typically used for advertising or analytics purposes. Site administrators can check which cookies their own website uses.
Are third-party cookies legal?
Third-party cookies can be used legally, but collecting personal data without user consent can create problems. Most countries prohibit collecting personal data without consent under regulations like GDPR and CCPA. In South Korea, businesses are required under the guidelines for drafting a privacy policy to provide basic disclosures about cookies, including how they’re used and for what purpose.
What’s replacing third-party cookies in Google Chrome?
As an alternative to third-party cookie support, Google is rolling out “Privacy Sandbox.” Privacy Sandbox is Google’s umbrella term for a set of technologies aimed at removing third-party cookies from the web.
What happens once third-party cookies are gone?
Once third-party cookies disappear, existing marketing approaches — ad targeting, conversion tracking, and more — are expected to change significantly. Marketers will need to explore new strategies, including alternative ID solutions and content marketing.
What can replace third-party cookies?
Content marketing is one of the main ways to replace third-party cookies. By providing useful content tailored to users’ interests and needs, it strengthens the relationship between a brand and its customers.
Should I delete third-party cookies?
Deleting third-party cookies can log you out of sites or clear saved preferences. So it’s worth being careful when deleting them, and checking that doing so doesn’t break any website functionality you rely on.
What happens if I block all third-party cookies?
Blocking all third-party cookies can prevent some websites from functioning normally. Certain website features rely on third-party cookies, and blocking them may cause those features to stop working. It’s best to check what impact blocking has on website functionality, and allow cookies selectively where needed.
How do I make my website GDPR-compliant?
GDPR compliance requires being transparent about how you collect and process personal data. If you use cookies or need to send marketing emails, you need to obtain and manage user consent for handling their personal data.
GDPR requires a legal basis for processing personal data — consent, contract, or legal obligation. That means putting technical and administrative security measures in place to prevent data breaches, along with regular reviews and improvements to maintain ongoing GDPR compliance.

