A third-party cookie is a cookie that is set not by the website you are visiting but by a third domain embedded within that site. When you browse a news website and it loads a Google Ads script, a Meta Pixel or a data management platform tag, those external services can place cookies on your browser from their own domains. Because those same services are embedded on millions of other websites, they can read their cookies whenever you visit any site in their network, building a detailed profile of your browsing behaviour across the entire web without you explicitly being aware of it.

This cross-site tracking capability is what made third-party cookies so valuable to digital advertisers for over two decades. A retailer could target someone who visited their product page while that person was later reading a recipe blog, watching a YouTube video or checking the weather. The ad network, not the retailer, held the cookie that made this possible. Retargeting audiences, frequency capping, conversion attribution and audience modelling all depended on this infrastructure.

The problem is that users never consciously agreed to be tracked this way, and the sheer scale of behavioural profiling attracted intense regulatory scrutiny. Safari began blocking third-party cookies by default in 2017 through its Intelligent Tracking Prevention feature. Firefox followed with Enhanced Tracking Protection. Chrome, which commands the majority of global browser market share, has been progressively restricting third-party cookies as part of the Privacy Sandbox initiative. For South African advertisers, this means the foundation of cross-site retargeting and audience building is shifting fundamentally.

The transition forces businesses to rely more on first-party data, server-side tracking and contextual targeting. Google Ads Enhanced Conversions, which hashes and matches first-party signals such as email addresses, is one of the primary replacement mechanisms. Meta's Conversions API sends conversion data directly from the server without relying on the Pixel's browser-based cookie. These solutions maintain a reasonable level of measurement and targeting capability without third-party cookies.

Third-Party Cookie In Practice

The scenario below is an illustrative example, not a Juicy Designs client result. The outcomes described indicate the scale of effect that third-party cookie mitigation work typically produces, so treat them as indicative rather than measured.

Picture a Johannesburg automotive dealership running a Google Display retargeting campaign that has historically relied on Google's third-party cookie to identify users who visited its vehicle listings and show them ads while they browse other websites. As browsers restrict this cookie, the Google Ads account would typically show a shrinking remarketing audience size for Safari and Firefox users, and the dealership's cost per conversion would be likely to rise as the effective audience narrows.

The fix would be to configure the Google tag to run in first-party mode (using the dealership's own subdomain as the cookie domain), implement Google's Enhanced Conversions by passing hashed email addresses from CRM enquiry forms, and build a first-party customer match audience from the vehicle enquiry database. Taken together, these steps could plausibly recover a meaningful portion of the measurement and audience capability that browser restrictions had eroded, without any dependence on cross-site tracking cookies.

How third-party cookies work

A third-party cookie is set by a domain other than the one a user is visiting, typically an advertising or analytics network embedded across many sites. Because the same network's cookie is present on site after site, it can recognise a user as they move around the web and build a profile of their browsing, which powered cross-site tracking, retargeting and much of programmatic advertising. First-party cookies, by contrast, are set by the site itself and used for things like keeping you logged in. The distinction matters because it is third-party cookies specifically, the cross-site tracking kind, that privacy regulation and browser changes have targeted, reshaping how digital advertising measures and targets people.

Marketing after third-party cookies

As browsers restrict third-party cookies and privacy rules tighten, the cross-site tracking advertisers relied on is fading, and the response is a shift in where targeting data comes from. First-party data, collected directly from your own customers with consent, becomes the foundation. Contextual advertising, placing ads by the content of a page rather than the person's history, returns to prominence. Privacy-preserving measurement, modelled and aggregated rather than individually tracked, replaces some of the lost precision. For businesses the practical move is to invest in owned data and direct relationships, since these are durable and consented, rather than depending on third-party tracking that is disappearing regardless of any single browser's timeline.

FAQ

Are third-party cookies still active in Chrome?

Google has been progressively restricting third-party cookies in Chrome after multiple delays to its deprecation timeline. As of mid-2026, Chrome still allows third-party cookies for most users but prompts users to review their settings. Safari and Firefox have blocked them by default for several years. Advertisers should not rely on third-party cookies for accurate measurement going forward.

How do South African advertisers adapt to the loss of third-party cookies?

SA advertisers are adapting through server-side tracking that sends conversion data directly from the server to ad platforms, building first-party data assets such as email lists and CRM databases, implementing enhanced conversions in Google Ads, and using contextual targeting based on page content rather than user profiles. These strategies maintain measurement accuracy without relying on cross-site tracking.

What is the difference between first-party and third-party cookies?

A first-party cookie is set by the site you are visiting, used for functions like staying logged in. A third-party cookie is set by another domain embedded in the page, typically to track users across many sites for advertising. It is the third-party kind that privacy changes have restricted.

What is replacing third-party cookies?

A mix rather than a single successor: first-party data collected directly with consent, contextual targeting based on page content, and privacy-preserving, aggregated measurement. The shift favours owned data and direct customer relationships over cross-site tracking.

Want a team that knows these metrics cold?

Founder-led digital marketing for South African businesses since 2015. 4.9-star rated, 64+ clients, no long-term contracts.