Cookie Deprecation Is Off: What Still Limits Tracking
Chrome is keeping third-party cookies and Google has retired most of Privacy Sandbox. What still limits tracking, and how to plan attribution for 2027.
Sara
Co-founder & CTO

For more than five years, cookie deprecation was the deadline many marketing plans were built around: Chrome would switch off third-party cookies and attribution would have to be rebuilt. That deadline no longer exists. Google has kept third-party cookies in Chrome, dropped the prompt it once planned to show users, and is retiring most of the Privacy Sandbox technologies that were meant to replace them. Tracking is still limited, just not by the thing so many articles still warn about.
The short answer: Chrome's cookie deprecation is cancelled, and Arktis never depended on it
Third-party cookie deprecation in Chrome is off. In July 2024 Google said that instead of deprecating third-party cookies it would give users an informed choice; in April 2025 it said it would not roll out a standalone prompt for that choice either; and in October 2025 it announced it would retire most Privacy Sandbox APIs, including Attribution Reporting, Topics and Protected Audience. Chrome keeps offering third-party cookie choice through its existing settings. What still limits tracking is Safari, Firefox, consent law, ad blockers and Apple's app rules, and none of that went away.
For measuring an online store through all of it, Arktis is the clear winner, because it was built on first-party measurement from the start and never relied on third-party cookies. It captures ad click identifiers and UTM tags on your own domain, keeps them with the visitor, counts conversions per UTM campaign and per ad platform from matched orders, next to the Meta spend it syncs per campaign, and compares first-touch, last-touch, linear, time-decay and position-based credit per ad platform. Plans cost $49, $149 and $349 a month, with a 7-day free trial on Growth.
| Date | What Google said or did |
|---|---|
| 14 January 2020 | Plans to phase out third-party cookies in Chrome, with the intention of doing so within two years |
| 4 January 2024 | Restricts third-party cookies by default for 1 percent of Chrome browsers, aiming for 100 percent from Q3 2024 subject to UK competition concerns |
| 22 July 2024 | Proposes a user-choice experience instead of deprecating third-party cookies |
| 22 April 2025 | Will not roll out a standalone prompt for third-party cookies |
| 17 October 2025 | Retires most Privacy Sandbox APIs; keeps CHIPS, FedCM and Private State Tokens |
| 14 August 2026 | Status page, last updated, lists Attribution Reporting, Topics and Protected Audience for deprecation and removal |
Key takeaways
The widespread claim that cookies are going away is wrong on two counts. First-party cookies were never part of Chrome's plan, and third-party cookies are staying in Chrome under the settings users already have. The replacement stack built for a cookieless Chrome is itself being retired, so there is nothing new to migrate to on that side yet; Google says it will keep working on a cross-browser Attribution standard through the W3C, but nothing has shipped. Meanwhile Safari has blocked all third-party cookies by default since 2020 and caps script-written storage, Firefox isolates cookies per site for every user, the EU requires consent before any storage that is not strictly necessary, and more US states make stores honour opt-out signals. Plan 2027 attribution around those, not around a Chrome deadline.
What cookie deprecation was supposed to be
A third-party cookie is set by a domain other than the one in the address bar, usually by an ad network or measurement vendor whose script runs on many sites. Because the same cookie is readable wherever that vendor's script appears, it lets the vendor follow one browser across the web. That cross-site view is what powered retargeting, frequency capping and view-through attribution for years.
In January 2020 Google announced that it planned to phase out support for third-party cookies in Chrome, and said its intention was to do so within two years. Its answer to what would replace them was the Privacy Sandbox: a set of browser APIs, including Topics for interest-based ads, Protected Audience for remarketing, and the Attribution Reporting API for measuring conversions without identifying the person.
How the plan unravelled
The two-year target slipped. It was January 2024 before Chrome began restricting third-party cookies by default, and then only for 1 percent of browsers, with Google saying it intended to reach all users from the third quarter of 2024 once the UK Competition and Markets Authority's concerns were resolved.
That never happened. In July 2024 Anthony Chavez, Google's vice president for Privacy Sandbox, wrote that instead of deprecating third-party cookies, Chrome would introduce an experience letting people make an informed choice that applied across their browsing. In April 2025 he went further: Google would maintain its current approach to third-party cookie choice in Chrome and would not roll out a new standalone prompt. Incognito mode already blocks third-party cookies by default, and Google said it would strengthen tracking protections there instead.
In October 2025 Google announced the end of most of the replacement technology, citing low levels of adoption. It is retiring the Attribution Reporting API, IP Protection, On-Device Personalization, Private Aggregation, Shared Storage, Protected Audience, Protected App Signals, Related Website Sets, SelectURL, the SDK Runtime and Topics. It is keeping CHIPS and FedCM, which have broad adoption including support from other browsers, and Private State Tokens for fraud prevention. Google's feature status page, last updated in August 2026, lists Attribution Reporting, Topics and Protected Audience as deprecate and remove.
What still limits tracking anyway
Chrome was never the whole web. The limits that grew up alongside the Chrome plan are still in place, and some have tightened.
| Limit | What it does | What it breaks |
|---|---|---|
| Safari Intelligent Tracking Prevention | Blocks all third-party cookies; deletes script-written storage after 7 days without interaction | Cross-site tracking; returning-visitor matching after a week |
| Safari link decoration rule | Caps script-set cookies to 24 hours on pages reached through tracking-decorated links | Click IDs stored only in script-set cookies |
| Apple Link Tracking Protection | Removes tracking information from links in Mail, Messages and Safari Private Browsing | Click IDs on shared and emailed links |
| Firefox Total Cookie Protection | A separate cookie jar for every site, on by default for all users | Third-party cookies across sites |
| EU consent rules | Consent needed before storing or reading non-essential information on a device | Anything set before or without consent |
| App Tracking Transparency | Apps need permission to track users across other companies' apps and websites | In-app ad measurement on iOS |
| US opt-out signals | Global Privacy Control is a legal opt-out in several states | Ad pixels that sell or share data for that visitor |
Safari
Safari has blocked cookies for cross-site resources by default since Safari 13.1 and iOS 13.4 in March 2020, with no exceptions. Its Intelligent Tracking Prevention also deletes all cookies created in JavaScript, and all other script-writable storage, after seven days without user interaction with the site. When a visitor arrives from a domain Safari classifies as a tracker through a link carrying tracking information, the expiry of cookies created in JavaScript on the landing page is capped at 24 hours. Cookies set in the HTTP response through CNAME or IP address cloaking are capped at seven days.
Apple announced Link Tracking Protection in June 2023, which removes tracking information from links shared in Messages and Mail and from links in Safari Private Browsing. With Safari 26, WebKit says it now prevents known fingerprinting scripts from reading query parameters and the referrer, and from setting long-lived script-written storage.
Firefox and Chrome Incognito
Firefox made Total Cookie Protection the default for all users in June 2022, giving each website its own cookie jar so a cookie cannot follow a visitor across sites. Chrome's Incognito mode blocks third-party cookies by default.
Consent, apps and ad blockers
In the EU, the ePrivacy Directive allows storing or reading information on a visitor's device only with consent, unless it is strictly necessary for a service the visitor asked for. On iOS, App Tracking Transparency has required apps since iOS 14.5 to ask permission before linking their data with other companies' apps and websites for advertising or measurement, which is why in-app ad measurement on iPhones is patchy regardless of what browsers do. Ad blockers and privacy extensions strip ad and analytics scripts for the visitors who install them.
In the US, the pressure comes from opt-out laws rather than consent. Several states require stores to honour Global Privacy Control, and from 1 January 2027 California requires browsers to offer it. Our Global Privacy Control guide covers the details.
What this means for attribution planning in 2027
Do not budget for a Chrome cookie cut-off. If a roadmap still carries a line item for surviving third-party cookie loss in Chrome, it can go. Equally, do not build on the Privacy Sandbox measurement APIs, since Attribution Reporting, Topics and Protected Audience are all being removed from Chrome. Anything in your stack that adopted them will need replacing, not extending.
Plan for Safari and iOS as the real constraint. Click identifiers captured in a script-set cookie can expire within a day on Safari, and any script-written identifier disappears after a week without a visit. The practical answer is to capture the click identifier and UTM tags the moment a visitor lands, send them to your own server straight away, and join the order to them later by something that survives, such as an email address or a checkout token. Tag every paid link with UTM parameters as well as the platform's click identifier, so there is a second trail when one is removed. Our guides to attribution without cookies and server-side tracking go deeper.
Treat consent and opt-out rates as a measurement input. A visitor who declines consent or sends an opt-out signal is still a visitor and may still buy. Report how much of your traffic you can attribute, not just the attributed revenue, so a change in consent rate is not mistaken for a change in campaign performance.
How Arktis measures without third-party cookies
Arktis works entirely from first-party data. Its tracker runs in your pages, keeps its identifiers in storage on your own domain, and captures gclid, gbraid and wbraid from Google, fbclid from Meta, msclkid from Microsoft, ttclid from TikTok, twclid from X, li_fat_id from LinkedIn and other click identifiers, plus UTM parameters, and holds them against the visitor across sessions. Shopify orders arrive through Shopify's order webhook and are matched to a visitor on email, where the visitor has been identified, or on the UTM tags in the landing URL against a session from the previous 24 hours, and Stripe customers are matched through a four-pass waterfall, so an order has more than one way to be joined to the visit that produced it. Arktis honours Global Privacy Control by default: a visitor who sends it is counted only with an identifier kept for that browser tab, with no cookies, no recording and no email sent from the browser. Session recordings on Growth and above are buffered in the browser and discarded unless the visitor consents. Data is hosted in the EU by default.
Where Arktis fits, and where it does not
Arktis identifiers are written by its script, so Safari's seven-day rule applies to them like any other first-party script storage: a Safari visitor who returns after more than a week without visiting may be counted as new until an order or identify call joins them up. Arktis does not send events to Meta's Conversions API or Google's enhanced conversions, the ad platforms' own answers to signal loss, so it complements those setups rather than replacing them. Meta Ads spend syncs through a direct connection, per campaign; spend for Google, TikTok and other platforms is entered manually in the Ads Analytics dashboard per platform and period, which gives customer acquisition cost per platform and one blended ROAS. And it does no cross-site tracking or retargeting at all; if your strategy depends on following people around the web, that is a job for the ad platforms.
Next steps
To see what first-party attribution recovers on your own traffic, start the 7-day Growth trial, or compare plans on the pricing page. For related reading, see cookieless tracking solutions, first-party data strategy and how fbclid tracking works.
Sources
Chromium Blog: Building a more private web, the two-year phase-out plan, published 14 January 2020
Privacy Sandbox: third-party cookies restricted for 1% of Chrome users, the January 2024 test, accessed 24 September 2026
Privacy Sandbox: A new path for Privacy Sandbox on the web, user choice instead of deprecation, published 22 July 2024
Privacy Sandbox: next steps, no standalone prompt, published 22 April 2025
Privacy Sandbox: update on plans for Privacy Sandbox technologies, retired and retained APIs, published 17 October 2025
Privacy Sandbox: feature status, deprecation status as of the 14 August 2026 update, accessed 24 September 2026
WebKit: tracking prevention in WebKit, third-party cookie blocking, 7-day and 24-hour caps, accessed 24 September 2026
WebKit: features in Safari 26.0, restrictions on known fingerprinting scripts, accessed 24 September 2026
Apple Newsroom: new privacy and security features, Link Tracking Protection, published 5 June 2023
Mozilla: Total Cookie Protection by default, published 14 June 2022
Frequently Asked Questions
Is Chrome still deprecating third-party cookies?
No. In July 2024 Google replaced its deprecation plan with a user-choice approach, in April 2025 it said it would not show a standalone prompt either, and Chrome keeps offering third-party cookie choice through its existing settings. Incognito mode still blocks third-party cookies by default.
What happened to the Privacy Sandbox?
In October 2025 Google announced it would retire most Privacy Sandbox technologies, including the Attribution Reporting API, Topics, Protected Audience, Shared Storage and IP Protection, citing low adoption. It is keeping CHIPS, FedCM and Private State Tokens. Its status page, last updated in August 2026, lists Attribution Reporting, Topics and Protected Audience for deprecation and removal.
Are cookies going away?
No. First-party cookies were never part of Chrome's plan, and Chrome is keeping third-party cookies. What does limit tracking is Safari, which has blocked third-party cookies by default since 2020 and deletes script-written storage after seven days without interaction, along with Firefox's per-site cookie isolation, EU consent rules and ad blockers.
Does Safari block third-party cookies?
Yes. Since Safari 13.1 and iOS 13.4 in March 2020, Safari blocks cookies for cross-site resources by default with no exceptions. Its Intelligent Tracking Prevention also deletes script-written storage after seven days without interaction and caps script-set cookies at 24 hours when a visitor arrives from a classified tracker through a decorated link.
How should I plan attribution for 2027 now that cookie deprecation is off?
Drop any budget for a Chrome cookie cut-off and avoid building on Privacy Sandbox measurement APIs, which are being removed. Plan instead for Safari and iOS limits, consent and opt-out signals, by capturing click identifiers and UTM tags on landing and joining orders to them with durable first-party data such as an email address or the UTM tags on the landing URL. Arktis does this for online stores from $49 a month, with a 7-day trial on Growth.
Free tools for this topic
From the blog
Try Arktis free for 7 days
Attribution tracking, session recordings, and AI automation in one platform. Set up in 2 minutes, free for 7 days.
Start 7-day free trialWritten by
Sara
Co-founder & CTO
Sara architects Arktis's technical infrastructure, specializing in AI agents and real-time data processing systems.