CookiePal Logo
CookiePal Logo
Log in
GDPR

Google Kept Third-Party Cookies: Why Should Websites Still Reduce Their Reliance on Them?

September 10, 2026

Book

8 min read

Google Kept Third-Party Cookies: Why Should Websites Still Reduce Their Reliance on Them?

Table of contents

back

to the top

Google Kept Third-Party Cookies: Why Should Websites Still Reduce Their Reliance on Them?

For years, marketers prepared for the end of third-party cookies in Chrome. Then Google changed direction.

Instead of fully removing third-party cookies from Chrome, Google said it would keep its current approach to user choice and would not roll out a new standalone prompt. Google explained this in its Privacy Sandbox update: Next steps for Privacy Sandbox and tracking protections in Chrome.

For some website owners, this sounded like a reason to relax. It is not. Keeping third-party cookies does not make them a safe long-term strategy.


What are third-party cookies?

A third-party cookie is usually set by a domain other than the website the user is visiting. Advertising platforms have used them for cross-site tracking, retargeting, frequency capping, audience building, attribution, affiliate tracking, behavioural advertising, and conversion measurement.

They became popular because they helped advertisers recognise users across different websites. That same cross-site tracking is why they became controversial.


Google keeping third-party cookies is not the same as “no privacy risk”

Google’s decision changed the timeline, but it did not remove the privacy issue. Third-party cookies can identify users, follow behaviour across sites, and support advertising profiles. They remain relevant to cookie consent and data protection requirements.

The UK Information Commissioner’s Office says organisations using cookies and similar technologies should explain what they use and obtain consent unless an exemption applies: Cookies and similar technologies.

Its storage and access technologies guidance also makes clear that first-party versus third-party status is not the deciding factor. Purpose, access, storage, and impact on the user matter.


Browser support is not stable enough to build around

Chrome is not the whole internet. Browsers, devices, corporate settings, and individual users treat tracking differently. Campaigns can perform differently across browsers, retargeting pools can be incomplete, and attribution can be harder to interpret. Even where third-party cookies remain available, they are not equally reliable everywhere.


Users expect more control

People are more aware of tracking, cookies, privacy settings, and data sharing. A website that relies on aggressive cross-site tracking can damage its brand, even if the tracking is technically available.

A Consent Management Platform like CookiePal helps websites offer clear choices, manage cookie categories, and block non-essential tracking until consent is given.


Consent still applies to advertising cookies

Third-party cookies used for advertising are usually not strictly necessary. A visitor can read a post, view a product, submit a form, or make a purchase without being added to a retargeting audience. Retargeting pixels, conversion tags, audience-building scripts, cross-site identifiers, affiliate tracking, behavioural advertising cookies, and some social widgets normally need consent before they run.

CookiePal’s consent management tools support consent banners, cookie scanning, and cookie auto-blocking for these non-essential scripts. Availability does not decide whether a cookie is allowed; consent, purpose, and transparency still matter.


First-party data gives websites more control

Reducing reliance on third-party cookies does not mean giving up on marketing data. It means shifting toward data collected through a clearer relationship with the user.

First-party data can include site interactions, purchases, account activity, form submissions, email preferences, product usage, support history, and consent choices. Zero-party data includes information users deliberately provide, such as preferences, survey answers, quiz responses, or communication choices.

Neither is automatically consent-free. Where cookies, analytics, advertising, or personalisation are involved, consent may still be required.


Better measurement should not depend on hidden tracking

A stronger approach builds measurement around clear consent choices, server-side controls where appropriate, Google Consent Mode, first-party conversion data, aggregated reporting, clean event design, data minimisation, and accurate privacy notices.

Google Consent Mode helps Google tags adjust their behaviour based on user choices. See Google’s setup guide.


Third-party cookie reliance creates vendor risk

Heavy reliance on third-party cookies makes a data strategy dependent on external platforms. Browser and ad-platform changes can affect tracking and reporting; consent rules can affect audience size; vendor scripts can affect performance and compliance.

Practical improvements include first-party analytics, better CRM data, direct preference collection, responsible server-side tagging, reviewed ad integrations, and a clear tag inventory. CookiePal’s features, including auto-blocking, scheduled scanning, auto-categorisation, multilingual banners, and Google Consent Mode v2 support, help teams manage tracking scripts.


What websites should do now

Start with an audit. Check which third-party cookies are active, which tools set them, whether they load before consent, whether reject all blocks them, whether they are listed in the cookie policy, and whether they are still needed.

Then prioritise advertising pixels, retargeting tags, affiliate scripts, heatmaps, and third-party widgets. For teams comparing consent tools, see CookiePal pricing.


Third-party cookie reduction checklist

  • Do we know which third-party cookies are active?
  • Are they blocked before consent where required?
  • Does reject all stop advertising cookies?
  • Are they explained in the cookie policy?
  • Do we still need every third-party vendor?
  • Are duplicate pixels installed?
  • Are landing pages and subdomains covered?
  • Are Google Consent Mode signals configured correctly?
  • Can we use first-party or zero-party data instead?
  • Can users change consent later?

Conclusion

Google keeping third-party cookies in Chrome does not mean websites should keep building around them. They remain a privacy, compliance, measurement, and trust issue. Audit your cookies, remove old scripts, improve consent controls, collect first-party and zero-party data transparently, and make sure tracking runs only when it should.

Third-party cookies may not disappear overnight, but websites that depend on them too heavily are building on unstable ground.

Explore further

Elevate Your Compliance with
CookiePal Today

View PlansTry for FREE

Privacy made simple!

Powered by WESTPOINT

© CookiePal 2026. All rights reserved. CookiePal Limited is registered in the UK. Company no. 15835702.

Terms and ConditionsPrivacy PolicyGet in Touch