What Actually Broke When Third-Party Cookies Went Away
Chrome reversed the deprecation and shut down most of Privacy Sandbox. The cookieless future was cancelled; the cookieless present arrived anyway.
For six years the industry rearranged itself around a premise that turned out to be wrong, and a great deal of published advice still assumes it. Workplace tools can collect first-party device signals without third-party cookies; this page shows one example of PC activity tracking.
Here is what actually happened, and what it means for measurement — which is a different question from what it means for the headlines.
The timeline, since most accounts of it are out of date
In January 2020 Google announced the intent to phase out third-party cookies in Chrome "within two years." Between 2021 and early 2024 the target slipped repeatedly — from late 2022 to late 2023 to mid-2024 to early 2025.
On 22 July 2024 Google signalled a strategic pivot: instead of deprecating cookies automatically, it would introduce an experience letting people make an informed choice.
On 22 April 2025 came the definitive reversal — Chrome would maintain its current approach. In an update from April 2025, Google also announced that Chrome would not introduce an additional prompt for third-party cookie consent.
Then on 17 October 2025 Google shut down most of the Privacy Sandbox APIs it had spent six years building as replacements — Topics, Protected Audience, Attribution Reporting, IP Protection and Related Website Sets among them.
So both halves of the plan were abandoned: the deprecation and most of the replacement.
A note on sources: published accounts disagree on whether Chrome now presents a privacy choice prompt. Some describe one; Google's own April 2025 update said no additional prompt would be introduced. Check Chrome's current documentation rather than a secondary article, including this one.
What this does not mean
It does not mean measurement went back to 2019.
Safari blocks third-party cookies. Firefox blocks them. Brave blocks them. That is roughly 17 to 20% of global traffic cookieless by default, independent of anything Chrome does.
The cookieless future as it was sold — Chrome-led, Privacy Sandbox-backed — is over. The cookieless present was already here.
And it does not change your legal position. Browser behaviour does not alter obligations under ePrivacy or CCPA. A cookie a browser permits still requires a lawful basis. See consent and what you can measure when people say no.
What actually degraded, and how
The important point for anyone reading a report: the loss is gradual and uneven rather than a step change, which makes it far harder to notice.
Degradation is incremental, so reporting tends to drift rather than fail outright.
The components:
Browsers that block by default — a fifth of traffic, and it is not a random fifth. Safari skews toward particular devices, demographics and countries, so the data you lose is systematically different from the data you keep. This is a selection problem, not a volume problem, and it biases every comparison you make.
Users opting into stricter settings in Chrome. A growing share of Chrome users have opted into enhanced privacy settings, and cookie effectiveness is declining steadily.
Consent refusals, which vary enormously by jurisdiction and by how the prompt is designed.
Intelligent Tracking Prevention shortening cookie lifetimes, so even permitted cookies expire far sooner than the attribution window you configured.
Ad blockers, which remove tracking entirely for a share of users.
The practical instruction is to treat cookies as unreliable rather than absent. That is a harder problem than absence, because unreliable data still produces a number, and the number looks fine.
What this breaks in measurement, specifically
Cross-site journey reconstruction. You cannot see the same user on a publisher's site and then on yours. Any report claiming a full path is reconstructing it from partial signals.
View-through attribution, which depended entirely on recognising a user who saw an ad and later converted without clicking. This is largely gone and the numbers that remain should be treated with suspicion.
Long attribution windows. A 30-day window on a cookie that survives seven days measures seven days and reports thirty.
Frequency capping and audience sizes. Audience list size decreases are caused by multiple compounding factors related to cookie erosion.
Deduplication across channels, which is why the sum of platform-reported conversions now exceeds actual conversions by more than it used to.
And the failure mode that matters most: every one of these degrades silently. The report renders, the numbers are plausible, and the trend line moves for reasons that have nothing to do with your marketing.
What does not fix it
Worth stating, because these are sold as solutions.
Server-side tracking. It does not bypass privacy requirements — consent and regulatory obligations still apply. Server-side infrastructure changes how events are processed and delivered, not whether they can be collected.
It genuinely helps with ad blockers, with ITP's restrictions on script-set cookies, and with controlling what data goes to which vendor. It does not recreate cross-site identity, and it is frequently sold as though it does. See server-side tracking: what it fixes.
Modelling. Modelling can fill gaps, but it does not restore deterministic visibility into the customer journey.
Platform-modelled conversions are estimates produced by the party being evaluated, using a method you cannot inspect. They may be reasonable. They are not observations, and treating a modelled number as measured is a category error that will eventually cost someone a budget decision.
Privacy Sandbox. Most of it no longer exists.
What actually helps
First-party data with a real identity basis. Logins, accounts, purchase history. This is durable, it is yours, and it is limited to people who identify themselves — which is a genuine constraint, not a solved problem.
Measurement that does not need user-level tracking at all. Geo experiments, holdout groups, and marketing mix modelling operate on aggregates and are unaffected by any of this. They answer a narrower question — did this spend produce incremental sales — which happens to be the question that matters. See incrementality.
This is the underrated consequence of cookie erosion: the methods that survived it are the methods that were measuring causation rather than reconstructing paths. The industry spent six years worrying about losing a measurement approach that was answering the wrong question.
Clean rooms, for matching first-party datasets with a partner's without exposing individuals. Useful, expensive, and narrower than the marketing suggests.
Honest confidence intervals. If a fifth of your traffic is invisible and another share is modelled, the number in the report is an estimate. Reporting it as a point value with no uncertainty is the actual failure. See explaining uncertainty to someone who wants a number.
What to do this quarter
Measure your own signal loss. Compare browser share in your analytics against your server logs or your order data. The gap is your blind spot, and it is specific to you rather than to an industry average.
Check whether your reported conversions reconcile with your actual orders. They will not. The size of the gap, per channel, is the most useful number in this whole area and almost nobody calculates it.
Find out which of your reported conversions are modelled, per platform. The platforms disclose this if you look, and the proportion is often higher than people assume.
Stop quoting attribution reports as fact in decisions above a certain budget. Above that line, run a holdout.
Write down your attribution window and what actually survives it. If the cookie lives seven days and the window is thirty, that is a documented discrepancy rather than a mystery.
The summary
Chrome kept third-party cookies and shut down most of the replacement. Advice written before April 2025 is describing a plan that was cancelled.
A fifth of traffic is cookieless anyway, and it is a systematically different fifth.
The degradation is gradual and silent, which is worse than a clean break would have been.
Server-side collection and modelling do not restore cross-site identity, whatever they are sold as.
And the methods that were unaffected — geo tests, holdouts, mix modelling — are the ones that were measuring incrementality in the first place. That is the real lesson of the last six years, and it is not the one most of the industry drew. Google’s published position is summarised in the Privacy Sandbox update.