August 25, 2026
min read

Google Kept Third-Party Cookies: What the Privacy Sandbox Reversal Means for Advertisers

Young man with curly hair wearing a black shirt outdoors against green foliage background.


Alexander Perleman
, Head Of Product @ groas
Ex-Goldman Sachs and Stanford Computer Science

alex@groas.ai

LinkedIn
Illustration for: Google's Third-Party Cookie Reversal, Explained: What the 2024–2025 Privacy Sandbox Updates Actually Mean for Advertisers

I told a home services client spending about $22k a month to budget for a cookieless rebuild in Q4 2023. New consent setup. Server-side tagging. A first-party audience plan for when Chrome remarketing pools went dark.

It was responsible advice at the time. It also became a very expensive insurance policy for an event that did not happen.

If you built the same contingency plan, you are not behind. Google moved the deadline three times, then reversed course twice. The useful work was not wasted, but the emergency was.

Two official updates matter here, both from Google VP for Privacy Sandbox Anthony Chavez.

On July 22, 2024, Google proposed “an updated approach that elevates user choice. Instead of deprecating third-party cookies, we would introduce a new experience in Chrome”.

That was the reversal. Then, on April 22, 2025, Chavez said Google had “made the decision to maintain our current approach to offering users third-party cookie choice in Chrome, and will not be rolling out a new standalone prompt for third-party cookies”.

Chrome still supports third-party cookies, and no new standalone cookie prompt is coming. The controls remain in Chrome’s Privacy and Security settings.

That is the news. The more important story is what did not change: advertisers were already losing signal elsewhere, and the infrastructure built for a cookieless future still earns its keep.

The two announcements that changed the plan

2024: Google dropped cookie deprecation

Google spent four years telling ad-tech vendors and media buyers that third-party cookies would be deprecated by late 2024. Pressure from the UK’s Competition and Markets Authority (CMA), publishers, and the wider ad ecosystem made that plan hard to ship.

In July 2024, Google said it would not kill cookies outright. It proposed an in-browser experience that would let users make an explicit choice instead.

The 2024 plan shifted from removal to user choice.

2025: Google also dropped the standalone prompt

That prompt idea lasted about nine months. In April 2025, Google abandoned it. Chrome keeps its existing approach to third-party-cookie choice in standard browsing, the controls remain in standard Chrome settings, and Incognito mode continues to block them.

For all the keynote slides and agency whitepapers produced between 2020 and 2024, Chrome’s cookie handling largely stayed where it was.

What still matters in Google Ads

Remarketing: still running, but not a reason to relax

If you manage standard Display remarketing, YouTube audience targeting, or third-party data segments in Google Ads, your day-to-day targeting did not break. Standard cookie-based remarketing tags on Chrome desktop and Android can still collect and match audience lists.

But do not treat that as permission to ignore audience decay. Safari and Firefox have blocked third-party cookies by default for years. Consent banners, device switching, and platform restrictions still thin out the neat browser-level audience pool people once relied on.

Keep remarketing running, but stop treating browser cookies as the whole audience strategy.

Measurement: consent and first-party matching still do the work

This is where advertisers misread the reversal. Chrome keeping third-party cookies did not restore signal lost to consent choices, iOS restrictions, or Safari.

Enhanced Conversions and Consent Mode v2 still determine how much usable conversion signal reaches Google Ads. Consent mode lets you control how Google tags behave based on consent choices. When users deny consent, tags limit data collection and may use modeling to fill gaps.

I explain the split to clients this way:

  • Enhanced Conversions sends hashed first-party data, such as an email address or phone number, so Google can match a conversion when a cookie is unavailable.
  • Consent Mode tells Google what it is allowed to do with that data.

If you implemented server-side tagging, hashed conversions, and advanced Consent Mode during the cookieless scare, keep it. That work improved the quality and resilience of your data. Chrome’s reversal does not change that.

Treat measurement setup as plumbing, not a privacy-panic project.

Privacy Sandbox APIs: do not build around them

The honest answer in 2025 is blunt: there are now very few Privacy Sandbox technologies an advertiser should build around.

I used to keep a slide with Topics, Protected Audience (formerly FLEDGE), and Attribution Reporting as the three APIs to watch. On October 17, 2025, Google announced it would retire those technologies, citing low adoption and ecosystem feedback. The list includes Attribution Reporting, Protected Audience, Topics, Private Aggregation, Shared Storage, IP Protection, and others.

Google said it would continue work on an interoperable attribution standard through the W3C and support CHIPS and FedCM. For most advertisers spending under $50k a month, though, there is nothing here to implement today.

If your developer is pitching a Protected Audience integration as future-proofing, politely tell them that future was cancelled.

The practical split is simple:

  • Keep: first-party data capture, Consent Mode v2 in advanced mode, Enhanced Conversions for web and leads, and offline conversion imports where lifetime value matters.
  • Watch: Google’s interoperable attribution work. Do not allocate development time until there is a shipping specification.
  • Stop worrying about: Topics and Protected Audience audiences, or re-architecting measurement around Attribution Reporting.

Chrome did not kill your remarketing, then Google retired much of the replacement stack. Place your bets accordingly.

The advertiser checklist worth keeping

Keep building first-party data

The mistake I see now is advertisers pausing first-party data work because Chrome did not pull the plug. That is backward.

The case for customer lists, offline conversion tracking, and direct CRM syncs was never only about surviving cookie deprecation. It is about giving bidding systems better signals than your competitors provide. Customer Match lists and CRM data can work across Search, YouTube, and Performance Max in ways third-party browser cookies never could.

When an autonomous engine like groas adjusts bids in real time, it needs actual conversion values and verified leads flowing back into the system. Not vague tracking pixels that disappear when a user moves from desktop to mobile.

First-party conversion data is the asset. Cookies were always just one delivery mechanism.

Stop paying for work that leads nowhere

Clean up the task list:

  1. Stop paying consultants to build around retired Privacy Sandbox APIs. If an agency lists a Privacy Sandbox API readiness audit as a monthly deliverable, strike it from the invoice.
  2. Stop treating cookie deprecation as a looming emergency. Chrome third-party cookies remain available under its current approach. You do not need panicked budget reallocations or migrations to third-party ID graphs.
  3. Double down on the plumbing that affects ROAS. Verify Consent Mode v2, turn on Enhanced Conversions for web and leads, and feed offline sales data back into Google Ads so Smart Bidding can optimize toward better business signals than raw click volume.

Google changed its mind twice in ten months. Let Google argue with regulators. Your job is simpler: capture clean first-party data at conversion, route it into your ad accounts, and let modern automation handle the bids.

Do the durable work. Ignore the expired emergency.