Last updated: October 1, 2026.

This article replaces an earlier piece I wrote in 12th July 2024 under the same title. Back then I wrote that Google Chrome planned to fully restrict third-party cookies by Q3 2024. That plan no longer exists.

I will start with an admission. When I wrote the original version of this article, I told you to prepare for the end of third-party cookies. I was wrong about the ending.

In July 2024, Google reversed its four-year-old plan to deprecate third-party cookies in Chrome. In April 2025, it confirmed the reversal: no forced phase-out, no new standalone consent prompt. Then in October 2025, Google retired most of the Privacy Sandbox APIs it had built as replacements, including Topics and Protected Audience, citing low adoption.

The headline changed completely. The strategy advice did not, and that is the more interesting part. In this update I will walk through what actually happened, what the browser landscape looks like in 2026, and why the conclusion I reached in 2024 (build on first-party data and direct relationships) survived the reversal.

A Brief Recap: What Third-Party Cookies Do

Third-party cookies are small pieces of data placed on your browser by domains other than the site you are visiting. Ad networks and analytics providers use them to recognise the same user across different websites, which is what makes cross-site retargeting and detailed attribution possible.

First-party cookies, by contrast, are set by the site you are actually visiting. They keep you logged in and remember your cart. They are not the target of any major restriction.

For years, browsers competed on blocking the third-party kind. Safari blocked them by default in 2020 and Firefox isolated them in 2022. Chrome held out, because Google's ad business depends on the ecosystem those cookies support. That holdout, and how it ended, is the story of the last two years.

What Actually Happened: A Timeline of the Reversal

The original version of this article, published in July 2024, said Chrome would fully restrict third-party cookies by Q3 2024. Here is what happened instead.

In January 2024, Chrome restricted third-party cookies for 1% of users to let the ad industry test. Temporary exceptions and grace periods kept critical site features working.

On July 22, 2024, Google announced it would no longer deprecate third-party cookies. Instead, it proposed a new Chrome experience where users would make an informed choice. The UK's Competition and Markets Authority (CMA), which had been monitoring Google's plans under binding commitments since 2022, was a major pressure point. A forced phase-out risked handing Google's own ad stack an advantage.

On April 22, 2025, Google announced it would "maintain our current approach to offering users third-party cookie choice in Chrome" and would not roll out the standalone prompt either. The deprecation plan was shelved for good.

On October 17, 2025, Google took the final step. It announced it would retire ten Privacy Sandbox technologies, among them Topics, Protected Audience, Attribution Reporting, Private Aggregation, Shared Storage, IP Protection, and the Android SDK Runtime. The reason given: low adoption and insufficient expected value.

What survives from the Privacy Sandbox is the unglamorous infrastructure: CHIPS (partitioned cookies that cannot track across sites), FedCM (privacy-preserving federated login), Private State Tokens (fraud prevention), and the Storage Access API. The official status page shows the full breakdown.

One historical footnote. The original version of this article named Google's Federated Learning of Cohorts (FLoC) as an emerging alternative. Google dropped FLoC in 2022 in favour of Topics, and Topics is now retired too. Every named successor has come and gone. The cookie itself is still here.

The Browser Landscape in 2026

"Did third-party cookies disappear?" now has a different answer per browser. The landscape is fragmented, and that fragmentation is the practical reality to plan around.

Browser Third-party cookie default Since
Chrome Allowed (user can block; Incognito blocks) Reversal confirmed April 2025
Safari Blocked (ITP) March 2020
Firefox Partitioned per site (Total Cookie Protection) June 2022
Edge Tracker storage limited (Balanced mode) Ongoing
Brave Blocked Ongoing

Safari blocked third-party cookies by default in March 2020, and also caps JavaScript-written first-party cookies at seven days. Firefox's Total Cookie Protection does not delete cookies but locks each website's cookies in a site-specific container, making cross-site identification structurally impossible.

Add up Safari, Firefox, Brave, Chrome users who block cookies or browse in Incognito, and ad-blocker users, and a substantial share of web traffic (often estimated at half or more) is effectively cookieless regardless of what Chrome does. In Japan the effect is even larger, because roughly two-thirds of smartphones are iPhones and mobile Safari is a dominant browser.

Why the Strategy Advice Did Not Change

The original article's core advice was to move towards first-party data, direct audience relationships, and consent-based marketing. The reversal made that advice more durable, not less. Three reasons.

First, Chrome's decision did not reopen the closed browsers. Safari and Firefox restrictions never depended on Chrome's plans. If your measurement relied on third-party cookies, it was already losing a large slice of your audience, and it still is. Chrome keeping cookies available restores nothing there.

Second, the replacement stack is gone. Teams that spent 2023 and 2024 preparing Topics or Protected Audience integrations now hold work pointed at retired APIs. The lesson generalises: any strategy that depends on a single vendor's roadmap carries this risk. Strategies built on your own domain, your own consent records, and your own customer data do not.

Third, regulation kept moving in the opposite direction. While Chrome loosened its technical plan, privacy law tightened. I will come back to this.

What Changed for Marketers, Creators, and SEO Practitioners

The 2024 article listed expected impacts: lower targeting precision, a shift to first-party data, harder measurement, consent-based marketing. Here is the 2026 scorecard.

Ad targeting has degraded but not been destroyed. Cross-site retargeting still works in standard Chrome. It does not work in Safari, Firefox, Brave, or Incognito. Audience lists decay faster than they used to. Precision targeting through browser cookies is now a partial tool, best treated as one channel among several.

Measurement and attribution are genuinely harder now. Consent banners, iOS restrictions, and browser partitioning mean conversion data drops out of browser-based measurement everywhere. The working answer is server-side: Google Tag Manager's server container, Meta's Conversions API, and Google Ads' Enhanced Conversions route data from your server to ad platforms, with hashed first-party identifiers such as email addresses as the matching key. Teams that built this during the cookie-deprecation scare kept it, because it improved data quality regardless.

For programmatic spending, I recommend discipline over panic. The emergency-grade migrations and "Privacy Sandbox readiness audits" that agencies sold in 2023 and 2024 should come off the budget. The durable work is consent management, first-party data capture, and measurement plumbing that survives any browser's default setting.

Content and contextual targeting came out of this upgraded. When user-level tracking gets unreliable, what the page is about becomes a stronger signal again. Contextual advertising (matching ads to content instead of browsing history) needs no cookies at all, and language models have made contextual analysis far more precise than keyword matching used to be. For content creators and SEO practitioners, this is why high-quality, intent-matched content appreciates in value. It is the signal that survives.

The 2026 Update for Japanese Businesses

The original article cited survey data from Nyle Inc. showing Japanese companies leaning into content marketing, cookie-less platform ads, and first-party data. That direction proved correct. The 2026 picture adds a regulatory layer that is now the binding constraint in Japan.

The revised Telecommunications Business Act (外部送信規律) has been in force since June 16, 2023. It applies to most commercial websites, not just telecom operators. When your site transmits user information to an external service (analytics tags, ad pixels, embedded videos, chat tools), you must notify or publish the recipient, the information sent, the purpose, and an opt-out method (総務省). This obligation exists regardless of what any browser does with cookies.

The revised Act on the Protection of Personal Information, passed in July 2026, goes further. It creates a category of "contact-reachable personal-related information" (連絡可能個人関連情報) covering cookie IDs, email addresses, and phone numbers, and bans their improper use and wrongful acquisition. It also introduces the first surcharge (課徴金) system under Japan's privacy law. Main provisions take effect within two years of promulgation, with some enforcement beginning January 2027.

What this means practically: browser settings are no longer the main event for Japanese businesses. Consent management and disclosure are. A consent management platform (CMP) that records who agreed to what, ties tag firing to consent status, and keeps your external-transmission disclosure page current is now standard equipment, not a nice-to-have.

The small-business angle also survives from the original article. When user-level data is scarce, the advantage of large incumbents' data hoards shrinks. Competing on content quality and a direct relationship with your audience is a strategy a small team can execute. That is exactly the problem we built Kafkai to solve: turning your expertise into consistent, well-structured content that earns attention without depending on anyone's tracking data.

A Practical Checklist for 2026

If you are revisiting your setup after the reversal, this is the order that matters.

  1. Check your browser mix and consent rates first. In analytics, split traffic by browser and look at how much of it Safari and Firefox represent. Measure consent-banner acceptance. That tells you the real size of your cookieless exposure.
  2. Audit what your site sends externally. List every tag and embed that transmits user data, and publish the disclosure the Telecommunications Business Act requires (recipient, information, purpose, opt-out).
  3. Stand up consent management. A CMP tied to your tag manager, with a "reject" option as easy as "accept", and records you can produce later.
  4. Move measurement server-side where it matters. Server-side GTM, Meta's Conversions API, and Enhanced Conversions recover measurement quality for consented users without depending on browser cookie behaviour.
  5. Keep building first-party data. Membership, email, and loyalty programmes generate consented data that no browser update can take away.
  6. Do not build around retired APIs. If any vendor or agency proposes a Privacy Sandbox API integration, the answer in 2026 is no.

Wrapping Up

Third-party cookies did not disappear. Chrome kept them, and Google retired the replacement stack instead. But the forces that made the original prediction plausible (Safari and Firefox blocking, tightening privacy law in Japan and elsewhere, users declining consent) all still stand.

The marketers who did the durable work during the deprecation years (first-party data, consent management, server-side measurement, and content worth reading) lost nothing when Google changed its mind. The ones who waited for a browser vendor to decide their data strategy got two more years of uncertainty and nothing to show for it.

That is the real takeaway of the last two years, and it is why I can update this article without changing its advice. Own your data, own your consent records, own your content. Everything else is a dependency on somebody else's roadmap.