Tracking Technologies
What is Third-Party Cookies?
Third-party cookies are cookies set by a domain other than the website the user is visiting — typically by embedded advertising and tracking scripts — enabling companies to recognize and follow the same user across many different sites.
When a page on example-store.com loads a script or image from adnetwork.com, the ad network can set a cookie scoped to its own domain. Because that same adnetwork.com code is embedded on thousands of other sites, the cookie lets the network recognize the same browser everywhere it goes. That simple mechanism built the cross-site tracking economy: behavioral ad targeting, retargeting, frequency capping, and attribution all traditionally ran on third-party cookies.
Regulators moved first. Under the EU's ePrivacy rules and GDPR, third-party tracking cookies require prior opt-in consent, and enforcement against non-compliant banners has been steady since the CJEU's 2019 Planet49 decision confirmed that pre-ticked boxes and implied consent are invalid. US state laws attack the same behavior from a different angle, giving consumers the right to opt out of the 'sale' or 'sharing' of personal information that these cookies facilitate.
Browsers moved next. Safari's Intelligent Tracking Prevention and Firefox's Enhanced Tracking Protection block third-party cookies by default. Chrome — the largest browser — announced deprecation plans in 2020, delayed them repeatedly, and ultimately walked back full removal in favor of keeping user controls, so third-party cookies still function for a large share of traffic. The result is a fragmented landscape where the same tracking works in one browser and silently fails in another.
The industry's replacements — server-side tracking, hashed-email identity graphs, first-party data collection, and cohort APIs — change the plumbing but not the privacy obligations: consent and opt-out rights attach to the tracking and sharing, not to the cookie technology that happens to implement it.
Why it matters for eCommerce
Retargeting and lookalike audiences — the workhorses of eCommerce advertising — were built on third-party cookies and are migrating to consent-dependent alternatives like Meta's Conversions API. Two obligations follow you through that migration: opt-in consent before tracking in the EU, and honoring Do Not Sell or Share opt-outs in US states. Neither goes away when the cookie does.
Frequently asked questions
- Are third-party cookies going away?
- Partially. Safari and Firefox already block them by default, but Chrome reversed its plan to remove them entirely. Cross-site tracking continues through third-party cookies where available and through server-side and identity-based methods where not.
- Do third-party cookies require consent?
- In the EU and UK, yes — prior opt-in consent before they are set. In California and other US states, their use for advertising triggers the right to opt out of sale or sharing, including via the Global Privacy Control signal.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
Inventory the third-party cookies on your site