Retargeting without third-party cookies: what actually changed
Retargeting without third-party cookies still works, and the panic that drove three years of “cookieless” planning has largely passed. Google kept third-party cookies in Chrome and, in October 2025, wound down most of the Privacy Sandbox project it had built to replace them. Cookie-based retargeting runs as before in Chrome.
The catch is that nothing fixed the parts that were already broken. Cookies never worked in Safari or Firefox, and EU consent rules limit tracking in every browser. So the smart move, building retargeting on first-party data, is exactly the same as it was. The deadline disappeared; the direction did not.
What did Google actually decide?
The reversal came in three steps, and the dates matter because a lot of advice online is still stuck on the old plan.
- July 2024, Google said it would not force-deprecate third-party cookies, proposing a one-time user choice prompt instead.
- April 2025, Google dropped even that prompt, keeping cookies under existing Chrome privacy settings.
- October 2025, Google retired most Privacy Sandbox APIs, including the Topics API and the Protected Audience API, citing low adoption. The UK Competition and Markets Authority released Google from its Privacy Sandbox commitments the same day.
For a buyer, the takeaway is short: third-party cookies in Chrome are staying, and the APIs that were meant to replace them are mostly gone.
So is retargeting fine now?
Partly. Chrome is roughly two-thirds of global browsing, so a large share of retargeting audiences still addresses cleanly. But two gaps remain, and they were never about Google’s deadline.
Safari and Firefox have blocked third-party cookies by default for years, so a meaningful slice of traffic was already invisible to cookie-based retargeting. On top of that, signal loss from consent choices and mobile tracking limits reduces how many users you can legally and technically reach. Treating Chrome’s reprieve as “problem solved” leaves that gap unmanaged.
This is why we still build retargeting the durable way on our retargeting service, regardless of what Chrome does next.
How to build retargeting that survives signal loss
The fixes are practical, and most pay off immediately rather than as future-proofing.
- Start from first-party data. Build audiences from site events, cart activity, purchases and consented CRM lists. These work in every browser and describe real intent better than broad third-party segments.
- Match server-side. Send conversion and audience signals through a server endpoint rather than relying only on browser tags, which recovers events that browser restrictions would otherwise drop.
- Cap frequency honestly. Hold around 3 to 5 impressions per user per day and exclude recent purchasers. Retargeting display CTR runs near 0.7% against 0.05 to 0.1% on cold inventory, so the audience is responsive; over-serving wastes that goodwill.
- Layer contextual targeting. Place ads against relevant content for the users you cannot address with first-party data, so reach does not collapse where consent is missing.
- Measure view-through, not just clicks. Display earns through assisted and view-through conversions; judging retargeting on last-click alone understates it.
What about EU consent and TCF v2.3?
In the European Union, the real constraint was never cookie availability. It is consent. The ePrivacy Directive and GDPR require consent before non-essential tracking, so a retargeting tag cannot fire until a user agrees.
Since the transition deadline in February 2026, TCF v2.3 is the operative version of the IAB Europe Transparency and Consent Framework, and Google requires it for buying in Europe. Consent strings built without the new mandatory vendor disclosure are treated as invalid. In practice this means your consent management platform, and your opt-in rate, decide how much of your EU audience you can retarget at all. Improving consent capture often unlocks more addressable audience than any targeting tweak.
The bottom line
Retargeting without third-party cookies is not a future scenario to prepare for; it is how a well-built program already runs. Chrome keeping cookies buys time, not a pass. First-party data, server-side matching, contextual coverage and clean consent are what keep retargeting working as signal erodes.
For the wider mechanics behind all of this, see our explainer on what programmatic advertising is, and the display advertising glossary for any term here you want defined.