No, the third-party cookie is not back. Google cancelled its plan to remove cookies from Chrome, but Safari and Firefox still block them and ad blockers cover the rest. The cookie was already dead for reliable cross-site tracking. The fix is to keep building first-party and server-side data regardless of Chrome.
A client forwarded me the Google announcement with one line attached: “Do we still need the first-party project?” It was the most expensive question a marketing team asked all year. The answer is yes, and the reversal changes nothing about it.
Why the reversal gets misread
Google cancelled third-party cookie deprecation in Chrome on 22 April 2025. Then in October 2025 it killed all ten remaining Privacy Sandbox APIs, after the UK Competition and Markets Authority found 85% attribution inaccuracy in testing (multiple sources, Dec 2025). The replacement did not work, so Google kept the old thing.
Marketers read the headline as a reprieve. Cookies survived, so the pressure to move was off. Some paused their first-party investment on the strength of it.
That is the trap. The headline is about Chrome. Your tracking problem was never only about Chrome. Safari and Firefox still block third-party cookies by default, and they were doing it long before Google’s announcement. Add ad blockers, and roughly a third of traffic was never reachable by cookie in the first place (Seresa, 2026).
So the cookie was already dead for reliable cross-site tracking. Chrome simply declined to attend the funeral. Reading that as a reason to stop is the actual obstacle here. The awareness is high. The conclusion is wrong.
The evidence
Two numbers tell the whole story. The Privacy Sandbox, Google’s cookie replacement, showed 85% attribution inaccuracy in CMA testing (multiple sources, Dec 2025). That is why Google reversed: the alternative was worse than the problem. And roughly a third of traffic was never reachable by cookie anyway, once you count Safari, Firefox and ad blockers (Seresa, 2026).
Put those together. The cookie never covered a third of your audience, and its official successor cannot attribute accurately. Neither of those facts changed on 22 April 2025. The only thing that changed is that Chrome stopped a countdown. If you built your measurement on cookies, a third of it was already fiction.
Is this you?
Five checks. Answer each yes or no.
- Did your team slow or pause its first-party data work after the Chrome reversal?
- Do you still rely on third-party cookies to attribute conversions across sites?
- Do you know what share of your traffic comes from Safari and Firefox?
- Can you measure a customer’s behaviour without a third-party cookie in the loop?
- Are you collecting events server-side, or only through the browser?
Three or more answers on the wrong side means you are measuring a third of your audience with tools that never reached them.
What it costs
The cost is not a line item. It is a slow drift back into blindness.
You keep funding cookie-based tracking that misses a third of traffic, so your reports look precise and are quietly wrong. You attribute revenue to the channels the cookie can see, not the ones that worked, which is the same failure that broke multi-touch attribution. You feed that skewed data into models and personalisation, and they scale the skew, because poor inputs are the multiplier on every AI project.
Then there is the pause itself. A team that stopped its first-party build in mid-2025 lost a year of compounding. First-party data gets better the longer you collect it. A paused year is a permanent hole in the record you can never backfill.
What actually works
The right move did not change with the reversal. It is the same move it was before.
Keep building first-party data. Collect customer events on properties you own, with consent, and tie them to identity you control. This works in every browser, survives ad blockers, and survives the next policy reversal, whichever way it goes. Consent is not a blocker here, it is a data type you design for.
Move collection server-side. Browser-based tags are what ad blockers and cookie controls kill. Server-side collection captures the same events on your infrastructure, so a third of your traffic stops being invisible. This is the single highest-return technical change on this list.
Restart any paused project this week. If a team hit pause on the strength of the Chrome news, that is the one thing to fix, and it is fast, because the work was already underway. You are not starting a programme. You are un-pausing one.
That last point is why this obstacle is a quick win. The correct action was already in motion at most firms. The only task is to stop the teams who stopped.
Get the full cookie-reversal playbook.
Go deeper on customer data maximization
Three ways forward. Pick the one that fits where you are.
- Get the playbook. Practical notes on turning the customer data you already own into revenue, straight to your inbox. Join the newsletter at the foot of this page.
- Take the assessment. Score your customer data maximization in four minutes and see your top revenue blockers. Start the assessment →
- Book a meeting. Bring your data problem. Leave with a prioritised fix, not a platform pitch. Book a call →
Post 6 of 25 in the Customer Data Maximization series. Previous: How do you handle consent and privacy without killing personalisation?. Next: Why has multi-touch attribution broken, and what replaces it?.
Frequently asked questions
Did Google bring back the third-party cookie?
Google cancelled its plan to remove third-party cookies from Chrome on 22 April 2025, and killed its ten remaining Privacy Sandbox APIs in October 2025 (multiple sources, Dec 2025). That kept the cookie alive in Chrome only. It does not bring the cookie back where it was already blocked.
Do Safari and Firefox still block third-party cookies?
Yes. Safari and Firefox still block third-party cookies by default, and they did so before Google's reversal. Add ad blockers and roughly a third of traffic was never reachable by cookie at all (Seresa, 2026). Chrome keeping the cookie does not change any of that.
Why is the cookie reversal being misread?
Many marketers saw the Chrome headline and read it as a reprieve, so they slowed their first-party shift. The conclusion is wrong. The cookie was already dead for reliable cross-site tracking across other browsers and ad blockers. Chrome simply declined to attend the funeral.
Should we still invest in first-party data after the reversal?
Yes. Keep building first-party and server-side data collection regardless of Chrome. It works across every browser, survives ad blockers, and survives the next policy reversal. The reversal is a reason to continue, not to pause. Teams that paused made the one avoidable mistake here.
What is server-side data collection?
Server-side collection captures customer events on your own servers rather than relying on the browser to send them to third parties. It is not blocked by browser cookie controls or ad blockers, so it gives you a more complete, first-party record of what your customers actually do.