Osman Husain
A cookieless world is a web where browsers block or isolate third-party cookies by default, so sites can't use them to follow people across the internet. Safari, Firefox and Brave already do this. Chrome doesn't, because Google dropped its plan to remove them. First-party cookies keep working, within Safari's limits. Fingerprinting and pixels, which read device information, fall under the same EU and UK consent rules as cookies.Part of the web is already cookieless. In September 2026, browsers that block or isolate third-party cookies by default carried about a fifth of web page views worldwide and a third in the US, according to StatCounter's figures. Most of the rest ran on Chrome, where Google kept third-party cookies after announcing in 2020 that it would remove them.
With Chrome still allowing third-party cookies, the question that matters for most sites is how consent rules treat the tools built to replace them. In the EU and UK, those tools follow the rule for cookies: consent first, unless an exemption applies. Collecting and honoring that consent is the job of consent management.
What does cookieless mean?
Cookieless means a browser breaks the cross-site link that third-party cookies create. A third-party cookie is set by a domain other than the one in the address bar, usually an ad or analytics service embedded on many sites. Because the same service appears on site after site, its cookie lets it recognize one browser wherever it goes.
A first-party cookie is set by the site being visited. Logins, shopping carts, language settings and analytics tools such as GA4 run on first-party cookies. Cookieless browsers accept them, so only the cross-site link disappears.
Browsers block third-party cookies to stop that cross-site tracking. Apple described its 2020 decision to block all of them in Safari as a privacy improvement that left no exceptions for cross-site tracking. The phrase cookieless future described the day Chrome would block third-party cookies too. Google dropped that plan, so the cookieless future exists today only in browsers that already block or isolate them.
Cookieless tracking is the set of methods that try to rebuild the cross-site link, or measure visits, without third-party cookies:
- browser fingerprinting, which combines device and browser traits into an identifier
- tracking pixels and tracking links that carry identifiers in images or URLs
- IP-based tracking
- hashed email addresses or phone numbers used as shared identifiers
- server-side collection, where the browser sends data to the site's own server first
Most of these methods read or send information from the visitor's device, so the EU and UK consent rules for cookies usually reach them too.
Are third-party cookies going away?
Third-party cookies aren't going away in Chrome in 2026. As of October 2026, Chrome on computers and Android allows them by default and blocks them by default only in Incognito, according to Google's Chrome policy text. In April 2025, Google said it would keep letting users choose in Chrome's settings instead of removing third-party cookies. It hasn't announced a new cookie policy since October 2025.
Cookie deprecation is the name for Google's plan to remove third-party cookie support from Chrome. The plan reached 1% of Chrome browsers in January 2024, and Google dropped it in July 2024 after several delays:
| Date | What Google did |
|---|---|
| January 2020 | Announced a plan to phase out third-party cookies in Chrome within two years |
| June 2021 | Delayed the phase-out to mid to late 2023 |
| July 2022 | Delayed the start to the second half of 2024 |
| January 2024 | Started restricting third-party cookies for 1% of Chrome browsers, a test called Tracking Protection |
| April 2024 | Said it would not finish the phase-out in 2024 |
| July 2024 | Dropped deprecation and proposed a user-choice prompt instead |
| April 2025 | Dropped the prompt too and kept the existing settings |
| October 2025 | Retired most Privacy Sandbox technologies |
| January 2026 | Began deprecating the retired APIs, including Protected Audience, in Chrome 144 |
| August to October 2026 | Began removing them in stages, including Private Aggregation in Chrome 152 |
Articles that give a 2024 end date for third-party cookies in Chrome describe a plan Google abandoned that year.
Why did Google retire the Privacy Sandbox?
Google's Privacy Sandbox was a set of Chrome technologies meant to serve advertising use cases without third-party identifiers. Google retired most of them in October 2025, citing their low adoption and industry feedback about their value.
The UK's Competition and Markets Authority had investigated the plan's effect on competition since January 2021. It closed its case the same day and released Google's commitments, because Google no longer planned to restrict third-party cookies.
What's left of the Privacy Sandbox?
The Privacy Sandbox technologies Google kept include CHIPS (partitioned cookies), FedCM (federated sign-in) and Private State Tokens. Google's feature status page also lists the Storage Access API, bounce tracking mitigations and storage partitioning among the features it kept.
Google removes the ad-targeting and measurement APIs, including Topics, Protected Audience and Attribution Reporting, from Chrome in stages that run through late 2026. In late September 2026, Topics removal had reached 1% of stable Chrome, with full rollout planned after mid-October.
IP Protection, which Google had promised for Incognito in 2025, was retired before it launched. The CMA's decision notes that IP addresses remain available in both regular and Incognito browsing.
Which browsers block third-party cookies by default?
As of October 2026, Safari and Brave block third-party cookies by default, and Firefox isolates them in a separate store for each site. Chrome allows them in regular windows on computers and Android, and Edge allows them except for known trackers.
| Browser | Page-view share, Sept 2026 (worldwide / US) | Third-party cookies by default | Other tracking limits by default |
|---|---|---|---|
| Chrome | 66.36% / 53.82% | Allowed on computers and Android; blocked in Incognito | No IP masking: IP Protection was retired |
| Safari | 18.27% / 30.42% | All blocked since March 2020 | Known fingerprinting scripts limited since Safari 26; caps on script-written first-party storage |
| Edge | 6.04% / 7.51% | Allowed in regular windows; blocked in InPrivate | Cookies and storage blocked for known trackers at the default Balanced level |
| Firefox | 2.8% / 3.33% | Isolated per site; known tracking cookies blocked | Stronger fingerprinting protection in the default Standard mode since Firefox 151 (May 2026) |
| Brave | 0.45% / 0.61% | Blocked, along with third-party storage | Shields on for every site |
Safari, Firefox and Brave together carried 21.5% of worldwide page views and 34.4% of US page views in September 2026. Those totals come from StatCounter's worldwide and US counts, with Brave's share taken from its downloadable data.
The 21.5% figure is a floor. It leaves out Chrome's Incognito and Edge's InPrivate windows. It also leaves out browsers on iPhone and iPad, which Apple's App Store rules put on WebKit outside the EU and Japan, and WebKit turns tracking prevention on by default.
Safari's tracking prevention also limits first-party cookies. Cookies and other storage written by a site's scripts are deleted after seven days of Safari use without the person interacting with the site. On pages reached through links with click IDs, script-set cookies are capped at 24 hours. So a site that never used third-party cookies can still lose track of returning Safari visitors.
Does a cookieless world still matter?
The cookieless world still matters despite Chrome's decision. Browsers that block or isolate them already carry a fifth of web page views worldwide and a third in the US. Chrome users can turn third-party cookies off in settings, and Incognito blocks them by default. The tools built to replace cookies answer to the consent rules that cover cookies in the EU and UK.
Work done to prepare for Google's planned phase-out mostly carried over. Consent signals, first-party data collected with consent, and modeled measurement work in every browser, Safari and Firefox included. Work built on Chrome's own replacements didn't: Google drops Topics, Protected Audience and Attribution Reporting from Chrome through late 2026, and IP Protection never launched.
The cookieless shift affects visitors, site owners and advertisers differently:
- People browsing in Safari, Firefox or Brave carry fewer cross-site cookies. Fingerprinting, pixels and hashed IDs can still follow them, subject to consent rules where those apply.
- Site owners see shorter returning-visitor histories on Safari, and gaps in analytics wherever visitors decline consent.
- Advertisers keep EEA audiences in Google's ad products only when consent signals come with them, and rely on modeled conversions for visitors who decline.
Does cookieless tracking need consent?
In the EU and UK, cookieless tracking usually needs the same consent as cookies. The law regulates any storing or reading of information on a person's device, and a cookie is only one way to do that.
Article 5(3) of the ePrivacy Directive allows that storage or access only with consent. It has two exemptions: access needed only to transmit a communication, and access strictly necessary for a service the person asked for.
The European Data Protection Board's scope guidelines for Article 5(3), finalized on October 7, 2024, say the rule covers similar technologies as well as cookies. They note that EU regulators confirmed in 2014 that fingerprinting is covered. They also say a site's code that tells the browser to send information back is gaining access, even if a different company receives the data.
A technique that falls under Article 5(3) needs consent unless one of the two exemptions applies. The EDPB guidelines settle which techniques the rule reaches; they don't decide when an exemption applies.
| Technique | How it identifies or measures people | EU position (EDPB Guidelines 2/2023) | Other sources |
|---|---|---|---|
| Tracking pixels and tracking links | An image or URL parameter carries an identifier back to a server | In scope under section 3.1: delivery is storage, and collecting the identifier is access | The UK ICO's storage guidance names pixels and link decoration; California lists pixel tags as unique identifiers |
| Browser fingerprinting | Browser and device traits combined into an identifier | Covered, as EU regulators confirmed in 2014; reading request headers, cache tags (ETags) or HTTPS settings (HSTS) for fingerprinting can trigger the rule | The ICO says consent is needed for fingerprinting used for ads; France's CNIL names it in its cookie guidelines |
| IP-based tracking | The IP address alone used to follow browsing | Can be in scope, unless the tracker can show the address didn't come from the user's device | California lists IP addresses as unique identifiers |
| Hashed identifiers | An email or phone number hashed on the device and sent as an ID | In scope when site code tells the browser to send it | The CNIL named hashed identifiers among cookie alternatives that need consent for ads |
| Local processing | The device computes a result and sends it on | In scope once the result is sent to a server | The ICO's rule covers any technology that stores or reads device information |
| Server-side collection | The browser sends data to the site's server, which forwards it | Not mentioned by name; scripts that tell the browser to send data are in scope | Google's own server-side setup collects consent in the browser |
France's CNIL said in 2021 that the end of third-party cookies doesn't mean the end of tracking. It added that advertising tracking based on browser or device information needs the person's informed choice, whatever the technique.
Does browser fingerprinting need consent?
Browser fingerprinting needs consent in the EU and UK on the same terms as cookies, and the UK's ICO says fingerprinting for advertising always needs consent. Its exceptions guidance says online advertising can't rely on any exception. The ICO finalized that guidance on April 29, 2026, and it covers fingerprinting where it stores or reads information on a device.
Google's ad platform policy change, announced in December 2024 and effective February 16, 2025, drew a public rebuke from the ICO. The ICO read the change as Google no longer prohibiting fingerprinting by organizations using its ad platform products, and called it irresponsible.
Google's own policy announcement says Google will be less prescriptive with partners about how they target and measure ads, and doesn't mention fingerprinting.
Does server-side tracking need consent under GDPR?
Server-side tracking stays under EU consent rules when the visitor's browser is told to send the data. Article 5(3), the ePrivacy rule that works alongside the GDPR, covers that access. The EDPB guidelines never mention server-side tagging, but they count any script that makes the browser send information as gaining access.
Moving the tags to a server changes where data is processed, not how it leaves the device.
Google's own server-side setup collects consent in the browser and passes it to the server, where Google's tags adjust what they send. Google presents server-side tagging as a way to block or anonymize data while acknowledging cookie consent.
UK cookie consent rule changes
The UK widened and loosened its cookie consent rule on February 5, 2026. That's when changes from the Data (Use and Access) Act 2025 took effect. The rule now also covers information a device sends out automatically. The ICO's example is wifi probe requests.
The same change added new exceptions that need no consent. Two matter for most websites: analytics used only to improve a site, and settings that adapt how a site looks or works. Both require clear information and a simple, free way to object. Neither covers advertising, and the ICO says the analytics exception isn't for identifying or tracking people.
How does California treat cookieless tracking?
California treats cookieless tracking the same way as cookies, because its privacy law defines key terms by what a business does with data. Its definition of cross-context behavioral advertising, meaning ads targeted on a person's activity across other businesses' sites and apps, names no technology. Its definition of a unique identifier lists IP addresses, beacons, pixel tags, mobile ad identifiers and probabilistic identifiers alongside cookies.
California regulations also require businesses that sell or share personal information to honor opt-out preference signals. The California Attorney General says Global Privacy Control must be honored as a valid request.
Lawsuits under California's wiretap law, CIPA, target cookieless tools as well as cookies. A California Senate bill analysis for SB 690, quoting the American Bar Association, describes the cases as focused on cookies, pixels, tags and beacons. The bill's sponsor puts the count at roughly 4,000 suits, and the Meta Pixel lawsuits are one group of them.
SB 690, signed on September 30, 2026, narrows who can bring one kind of CIPA claim. Under California law, a pen register records addressing or routing information but not the contents of a communication.
From January 1, 2027, only the Attorney General can bring pen register and trap-and-trace claims against businesses over website or app tracking. That includes pending claims filed in the two years before. Wiretap claims under section 631 are unchanged.
Is GA4 cookieless?
GA4 isn't cookieless: its tags use first-party cookies to tell users and sessions apart, and without consent they send limited data or none. Companies evaluating Enzuzo raise this data loss on sales calls: one described opt-in consent as the point where "we're gonna lose a lot of data."
Google Consent Mode recovers part of the data lost when visitors decline consent. In advanced mode, Google's tags load before the visitor chooses and, while consent is denied, send what Google calls cookieless pings. Those pings can include a timestamp, user agent, referrer, consent state and whether an ad-click ID was in the URL.
Google uses cookieless pings to model the behavior of visitors who decline, once a property passes its traffic thresholds.
Whether the pings themselves need consent in the EU depends on whether an Article 5(3) exemption applies. Advanced mode sends them before the visitor chooses. The EDPB treats a script that makes the browser send information as accessing the device, and its guidelines don't say which exemptions fit which uses.
Alternatives to third-party cookies
Among the alternatives to third-party cookies, first-party data collected with consent does much of the work those cookies did. Modeled measurement and the browser features Google kept cover parts of the rest. Google defines first-party data as information customers share directly with a business through its own sites, apps, stores and other direct contact.
Zero-party data, such as quiz answers, is information people deliberately give a business, and it's one form of first-party data.
| Alternative | What it relies on | Consent position |
|---|---|---|
| First-party data | Information people share with the business directly: accounts, purchases, sign-ups | Google's policy requires consent for third-party sharing where the law requires it; in the EEA, Customer Match needs consent signals |
| Contextual targeting | The content of the page, not the visitor's history | Needs no cross-site profile, though ad delivery and measurement can use technologies covered by consent rules |
| CHIPS and FedCM | Browser features Google kept: partitioned cookies and federated sign-in | Same rules as other cookies and storage; CHIPS keeps a separate cookie jar per top-level site |
| Hashed-email identity solutions | An email address hashed into a shared ID | In scope of Article 5(3) when site code sends it; the CNIL says ad use needs consent |
| Server-side collection | The site's own server receives data before passing it on | Consent collected in the browser whenever the browser sends the data |
| Data clean rooms | A shared service where two companies analyze combined data under rules that limit its use | The consent behind each data set still governs its use |
| Modeled measurement | Statistical estimates of conversions and behavior from consenting visitors | Built on consent signals, such as Google Consent Mode |
Data clean rooms let two companies combine and analyze their data under rules that limit how it's used. FTC staff give the example of a newspaper and a grocery chain checking which subscribers bought after seeing an ad. In a 2024 post, they wrote that most clean-room services aren't privacy preserving by default, because those limits have to be configured.
The same FTC staff post says clean rooms don't change a company's obligations to consumers.
What does a cookieless world mean for advertising?
Cookieless advertising targets and measures ads without third-party cookies, using first-party audiences, contextual placement and modeled conversions. It depends on consent signals, because they decide which visitors an ad platform may measure and target. Google's EEA consent requirements say advertisers must collect consent from users in the European Economic Area and share it with Google to keep measurement, personalization and remarketing.
Since March 2024, EEA users without those signals drop out of the GA4 audiences used for ads, and Customer Match needs consent for ad personalization.
Privacy choices also govern advertising in the UK and California, through consent in the UK and an opt-out in California. In the UK, advertising can't use any of the new consent exceptions. In California, sending data to another company for cross-context behavioral advertising counts as sharing whatever the technology. The opt-out applies to pixels and server-side tags as much as to cookies.
Retargeting in a cookieless world reaches only people whose privacy choices allow it. In Chrome it can still run on third-party cookies where consent rules permit them. Elsewhere it runs on first-party lists, such as customer lists uploaded to Customer Match. Attribution relies on modeled conversions for visitors who decline, and Google says those models are most accurate when cookieless pings fire.
How to prepare for a cookieless future
For a website that runs analytics or ads, preparing for a cookieless future means building measurement and advertising on consent, whichever identifier a browser allows. The site's owner can:
- List every tracker on the site, not only cookies: pixels, link parameters, fingerprinting scripts, server-side endpoints and embedded tags.
- Describe those trackers in the cookie or privacy notice, because the EU rule requires clear and comprehensive information before consent.
- Hold non-essential scripts until a visitor consents, in every region where the law requires it.
- Set consent rules by region: opt-in where the law requires it, opt-out and Do Not Sell or Share choices where it doesn't.
- Send Google Consent Mode v2 signals for EEA, UK and Swiss traffic, which Google's consent policy covers.
- Honor Global Privacy Control and other opt-out preference signals.
- Build first-party data through accounts, sign-ups and purchases, with consent recorded for advertising use.
- Confirm that recorded consent covers it before uploading customer lists to an ad platform or matching them in a clean room.
- Ask identity vendors how hashed-email IDs get consent before site code sends them.
- Test the site in Safari and Firefox, where storage limits already apply, before trusting analytics trends.
- Recheck Chrome's third-party cookie defaults after Google finishes removing the retired Privacy Sandbox APIs.
Enzuzo's consent management platform covers four of those steps: script blocking, regional consent rules, Consent Mode signals and Global Privacy Control. It can hold non-essential scripts until a visitor consents once script blocking is set up. On Growth plans and above, it can show opt-in, opt-out or no banner by region.
On Pro and Enterprise plans, Enzuzo detects Global Privacy Control and applies the opt-out automatically.
Enzuzo is also a Google-certified CMP Gold Partner for Consent Mode v2 and supports Microsoft UET Consent Mode. Both come with every plan of Enzuzo's consent management platform, including the free one.
Frequently asked questions
What does it mean to be cookieless?
For a website, being cookieless means recognizing visitors without third-party cookies; for a browser, it means blocking or isolating third-party cookies by default. A website goes cookieless by its own choice, while a browser makes that choice for every site its user visits. A cookieless website usually keeps the first-party cookies that run logins and carts.
What is a cookieless browser?
A cookieless browser blocks or isolates third-party cookies by default. Safari has blocked them since March 2020, Brave blocks them along with third-party storage, and Firefox keeps a separate cookie store for each site. Chrome on computers and Android allows them outside Incognito. Edge allows most of them, blocks known trackers' cookies, and blocks all of them in InPrivate.
Is Google getting rid of third-party cookies?
Google isn't getting rid of third-party cookies in Chrome. It dropped its removal plan in July 2024, dropped a replacement prompt in April 2025, and said Chrome will keep letting users choose in settings. As of October 2026, Chrome on computers and Android allows third-party cookies by default and blocks them by default only in Incognito.
Are cookies going away completely?
Cookies aren't going away completely. Some browsers block or isolate third-party cookies, but first-party cookies still run logins, carts and site analytics. Safari limits how long cookies set by scripts last. Google also kept CHIPS, which gives an embedded service a separate cookie store for each site it appears on.
Is there a way to use analytics without cookies?
Analytics can run without cookies, but cookieless analytics usually reads or sends information from the device, so it isn't automatically exempt from consent. France's CNIL exempts audience measurement only when it's for the site alone, produces anonymous statistics and doesn't track people across sites. The UK exempts analytics used only to improve a site, with clear information and a way to object.
Are tracking cookies illegal?
Tracking cookies aren't illegal, but they need consent in the EU and UK before they're set, unless they're strictly necessary for a service the visitor asked for. In California, businesses using them for cross-context behavioral advertising must offer an opt-out. Visitors can refuse them through a site's consent banner or their browser settings.
Does a cookieless website still need a cookie banner?
A cookieless website may still need a consent banner if it uses pixels, fingerprinting, hashed identifiers or other technologies that store or read information on a visitor's device. In the EU and UK, the consent rule for cookies applies to those methods too. A site that stores or reads nothing beyond what's strictly necessary may not need one.
What is replacing third-party cookies?
A mix of methods replaces third-party cookies: first-party data collected with consent, contextual targeting, modeled measurement, and browser features Google kept, such as CHIPS and FedCM. Hashed-email identity solutions and fingerprinting do part of that work too. In the EU and UK, both need consent wherever a cookie doing the same job would.
Osman Husain
Osman is the content lead at Enzuzo. He has a background in data privacy management via a two-year role at ExpressVPN and extensive freelance work with cybersecurity and blockchain companies. Osman also holds an MBA from the Toronto Metropolitan University.
LinkedIn →More related blogs
Your next read
Start managing consent
the easy way.
Free forever plan available. No credit card required.