What Is Cookie Privacy?
Cookie privacy is about what websites can learn about you through the small files they store in your browser, and who else gets to read them. This guide explains what cookies actually track, how first-party and third-party cookies differ, why browsers and regulators have spent years reining them in, and what you can do to protect your privacy whether you run a website or simply use one.
First-party vs third-party cookies#
A first-party cookie is set by the website whose name is in your address bar, on its own domain, and only that site can read it. When you sign in to a shop, the cookie that keeps you logged in is a first-party cookie. It stays with that shop, does its job, and never leaves. These cookies raise few privacy concerns because the site you chose to visit already knows you are there.
A third-party cookie is set by a different domain that is embedded inside the page, such as an advertising network, an analytics service, or a social media widget. The key detail is that the same third-party domain is embedded across thousands of unrelated sites. Because it is the same domain each time, it can read its own cookie on every one of those sites and connect what it sees into a single record. A news article you read, a product you looked at, and a video you watched can all be linked to the same profile, even though those sites have nothing to do with each other. That cross-site linking is exactly what cookie privacy is about.
First-party vs third-party cookies
Browsers have quietly made this harder over the years through a cookie setting called SameSite, which controls whether a cookie is sent when a request comes from another site. Since early 2020, Chrome treats any cookie that does not state a SameSite value as SameSite=Lax, meaning it is not sent on cross-site requests at all. For a cookie to work in a third-party context it now has to explicitly declare SameSite=None; Secure, which also forces it onto an encrypted connection. This does not end cross-site tracking on its own, but it made the third-party cookie something a site has to ask for on purpose rather than get by accident.
Why cookie privacy matters#
The concern with cross-site tracking is not that a company knows you visited one page. It is that a profile assembled from hundreds of pages can infer things you never chose to share. A pattern of visits can suggest a health condition, a financial situation, a pregnancy, or a political leaning, and that inferred profile can be used to target advertising, priced and traded between data brokers, or exposed in a breach. You did not hand any single site that picture of yourself, yet it exists because the same tracker was watching across all of them.
For the people being tracked, the problem is a loss of control. Tracking happens silently in the background, the profile is invisible, and there is rarely a clear way to see it or delete it. For the businesses running websites, poor cookie privacy is both a trust problem and a legal one. Visitors increasingly notice and resent being followed, and regulators now issue real fines over how tracking is done. The rules differ by region, and the full legal picture for the European Union is covered in our guide to GDPR cookie consent requirements, but the short version is that non-essential cookies increasingly need a genuine choice behind them.
How browsers handle cookie privacy#
Much of what has changed about cookie privacy did not come from laws at all. It came from the browsers themselves, and this is where the picture in 2026 surprises people who stopped paying attention a couple of years ago.
Apple's Safari has blocked third-party cookies by default for every user since 2020, through a feature called Intelligent Tracking Prevention. Mozilla's Firefox followed in 2022 with Total Cookie Protection, which takes a slightly different route. Rather than blocking third-party cookies outright, it gives each website its own separate cookie jar, so a tracker's cookie set on one site cannot be read on another. The effect is the same, cross-site tracking through cookies stops working. Brave, a privacy-focused browser, blocks third-party cookies and trackers by default as well.
Chrome is the plot twist. For years Google announced that it would remove third-party cookies from Chrome and replace them with a set of privacy-preserving browser tools called the Privacy Sandbox. That removal kept slipping, and then it reversed. In April 2025 Google confirmed it would keep third-party cookies in Chrome and would not add a new prompt asking users to choose, leaving the existing browser settings as the way to turn them off. In October 2025 Google went further and began winding down most of the Privacy Sandbox tools, citing low adoption, though a few narrower pieces survive, including partitioned cookies, which isolate a third-party cookie to the single site that set it.
Who blocks third-party cookies by default
The result is a landscape almost nobody predicted. Third-party cookies are still switched on by default in Chrome, which is by far the most used browser, while the project meant to replace them has been shelved. If you use Chrome without changing anything, third-party cookies still work. Safari and Firefox users have been protected from them for years. So the practical state of your cookie privacy now depends heavily on which browser you use, which was not true when everyone assumed the third-party cookie was on its way out everywhere.
How the law protects cookie privacy#
Because browsers no longer agree on how to treat cookies, the law has become the more consistent force. In the European Union and the United Kingdom, two rules work together. The General Data Protection Regulation, or GDPR, treats a cookie identifier as personal data when it can single out a person, and the ePrivacy Directive requires consent before any non-essential cookie is stored or read. In practice that means analytics and advertising cookies have to wait for a clear opt-in. The full set of requirements, and how to check your own site against them, is covered in our companion guides on GDPR cookie consent requirements and how to verify cookie compliance.
The United States has no single federal cookie law, but a growing set of state laws fills the gap. California, Colorado, Connecticut, and others give people the right to opt out of the sale or sharing of their personal information, which covers a lot of cross-site advertising. Crucially, several of these laws now require businesses to honour a browser signal that broadcasts that opt-out automatically, so a person does not have to click a refusal on every site.
That signal is Global Privacy Control, or GPC. When it is on, the browser adds a small header, Sec-GPC: 1, to its requests and exposes a matching property that sites can read, which together tell every site that the visitor is opting out. Firefox, Brave, and DuckDuckGo can send it, and it is available as an extension for browsers that do not, including Chrome, which does not send it on its own. Enforcement is not hypothetical. California fined the retailer Sephora 1.2 million dollars in 2022 in part for ignoring GPC signals, the California Privacy Protection Agency settled with an automaker in 2025 over a broken opt-out, and in September 2025 the regulators of California, Colorado, and Connecticut launched a joint sweep against businesses that fail to honour the signal.
How to protect your cookie privacy#
What you can do depends on whether you are browsing the web or running a site. Both sides have a few concrete steps that make a real difference.
If you are browsing the web
- Choose a browser that blocks third-party cookies by default, such as Safari, Firefox, or Brave, or turn on third-party cookie blocking in Chrome's privacy settings.
- Turn on Global Privacy Control, which is built into Firefox, Brave, and DuckDuckGo and available as an extension elsewhere, so your opt-out reaches every site automatically.
- Use a private or incognito window when you do not want cookies kept, and clear your cookies periodically to reset any profiles built on them.
- Read the banner before you click. Choosing to reject non-essential cookies, or accepting only what you want, is the point of the choice being there.
If you run a website
- Keep third-party cookies and tracking tags to a minimum, and load non-essential ones only after a visitor has agreed.
- Set your own cookies with the right SameSite value so they are not exposed in cross-site contexts by accident.
- Honour opt-out signals like Global Privacy Control, and get valid consent before any non-essential cookie where the law requires it.
- Keep a clear cookie policy that matches what your site actually sets, and check regularly, since a single new plugin or tag can start loading trackers early.
If you run a site and want to see this from the outside, you can scan any page for free and watch which cookies and trackers it sets before and after consent, and whether a real consent mechanism is in place. For the security of the cookies themselves, such as whether login cookies carry their protective flags, the Cookie Security Checker and our guide to how to secure cookies go a level deeper.
FAQ#
What is cookie privacy?
Cookie privacy is about what a website can learn about you through the small files it stores in your browser, and who else gets to read them. A cookie that only the site you are visiting can read, such as one that keeps you logged in, is a minor privacy concern. A cookie set by an advertising network embedded across many sites is a much bigger one, because it can follow you from site to site and build a profile of what you do online.
Are cookies bad for privacy?
Not all of them. First-party cookies, set and read only by the site you are on, are how logins, carts, and preferences work, and they raise few privacy concerns. Third-party cookies are the problem. Because the same tracker is embedded on many different sites, it can recognise you on each one and stitch your activity into a cross-site advertising profile. That cross-site tracking is what browsers and privacy laws target.
Did Chrome get rid of third-party cookies?
No. Google spent years planning to remove third-party cookies from Chrome, but in April 2025 it decided to keep them and not add a new consent prompt, and in October 2025 it began winding down the Privacy Sandbox project that was meant to replace them. Third-party cookies are still on by default in Chrome today. Safari and Firefox, by contrast, have blocked or isolated them by default for years, so Chrome is now the last major browser that still allows them out of the box.
What is the difference between first-party and third-party cookies?
A first-party cookie is set by the website in your address bar, on its own domain, and only that site can read it. It handles things like staying logged in or remembering your language. A third-party cookie is set by a different domain embedded in the page, such as an ad network or a social widget. Because that same domain appears on many sites, it can read its cookie on each one and track you across the web.
How can I protect my cookie privacy?
Use a browser that blocks third-party cookies by default, such as Safari, Firefox, or Brave, or turn on third-party cookie blocking in Chrome's settings. Turn on Global Privacy Control, which is built into some browsers and available as an extension for others, to broadcast an opt-out to every site you visit. Browse in a private window when you do not want cookies kept, clear cookies periodically, and review a site's cookie settings before accepting everything.
References
- Full third-party cookie blocking and moreWebKit
- Total Cookie Protection by default for all usersMozilla
- The next step in Privacy Sandbox (April 2025)Google Privacy Sandbox
- Update on plans for Privacy Sandbox technologies (October 2025)Google Privacy Sandbox
- SameSite cookies explainedweb.dev
- Global Privacy ControlGPC
- Settlement with Sephora over CCPA violationsCalifornia AG
- Our response to Google's policy change on fingerprintingICO
Related articles
See What a Site Tracks Before You Trust It
Run a free scan to see which cookies and trackers a site sets before and after consent, and whether a real consent mechanism is in place.