Context: the deprecation that didn't happen, and why the advice still stands

For nearly four years, digital marketing strategy was built around a single assumed deadline: Google would remove third-party cookies from Chrome, the world's dominant browser, and the targeting and measurement techniques the industry had relied on for two decades would stop working. That deadline was repeatedly pushed back, and in April 2025 Google confirmed it would not happen at all — a reversal significant enough to genuinely change the "why now" behind first-party data strategy, even though the underlying advice to build one has not actually changed.

The data: what Google actually did, and what was already true regardless

Google's Chrome team announced in July 2024 that it would abandon plans to remove third-party cookies outright, introducing instead a new user-facing choice prompt, and confirmed in April 2025 that full deprecation was off the table. The reversal followed years of delay driven partly by pushback from the UK's Competition and Markets Authority, which had been formally monitoring Google's proposed "Privacy Sandbox" replacement technology over concerns about its competitive impact on rival advertising technology providers, and partly by continued industry criticism that the Sandbox approach was not a workable substitute for existing targeting methods.

What the Chrome reversal did not change is that Safari and Firefox — a meaningful, non-trivial share of global web traffic — have blocked third-party cookies by default since 2020. Marketers optimising purely for a Chrome-centric world were always missing a real slice of their audience where third-party tracking had effectively already ended years earlier. The "cookie-free future" framing was always somewhat imprecise: it was already partly the present for a significant share of users, and Chrome's reversal changes the timeline for full universality without eliminating the underlying trend.

BrowserThird-party cookie statusSince
SafariBlocked by default2020
FirefoxBlocked by default2020
ChromeNot deprecated (reversed April 2025)N/A

What's changing: why first-party data still matters, for different reasons

With the Chrome deadline removed, the strongest remaining case for first-party data strategy is not "prepare for cookies disappearing" but three separate, durable arguments: accuracy, regulatory exposure and resilience against any future policy reversal. First-party data — collected directly from a business's own customers through website registrations, email subscriptions, purchase history, loyalty programmes and app usage — is inherently more accurate than third-party data ever was, because it comes from an actual, consented customer relationship rather than inferred or aggregated signals. UK and EU privacy law, specifically the Privacy and Electronic Communications Regulations (PECR) and UK/EU GDPR, requires proper consent for tracking regardless of which specific technical mechanism — cookies, fingerprinting, or any future replacement — is used, meaning a compliant first-party data strategy is not contingent on any single browser vendor's cookie policy at all.

"Building a first-party data strategy because you thought Chrome was banning cookies was always the wrong reason. The right reason was always that owned customer data is more valuable, more durable and more compliant than rented third-party signals — and that argument didn't change when Google changed its mind." — a view that gained currency across marketing industry commentary following the April 2025 reversal, as agencies reassessed strategies built around the now-cancelled deadline.

What it means for you (UK small business marketers)

If your marketing strategy over the past two years was built specifically around a Chrome cookie deadline that has now been cancelled, the practical adjustment is not to abandon first-party data investment but to reprioritise: the urgency of an imminent hard cutoff is gone, but the underlying value of owned customer data, and the ICO's consent requirements under PECR, have not changed at all. Server-side tagging — routing tracking data through your own server infrastructure rather than relying purely on browser-based scripts — remains worth investing in regardless of the cookie decision, since it reduces dependence on any single browser's tracking policy and is less affected by ad blockers, which a meaningful share of UK users run regardless of cookie settings. For the measurement side of this, our guide on measuring marketing ROI as a small business covers how to build attribution that does not depend entirely on third-party tracking infrastructure outside your control.

First-Party Data Strategy: Preparing for a Cookie-Free World
Photo: Support Startup / Wikimedia Commons (CC BY-SA 4.0)

Email remains, somewhat counterintuitively for a channel often described as old-fashioned, one of the highest-value first-party data assets a small business can build, precisely because it is entirely independent of any browser cookie policy — an email subscriber relationship, properly consented under PECR, persists regardless of what Chrome, Safari or Firefox decide about tracking technology. Building genuine first-party value through email, loyalty schemes and account registration, rather than treating first-party data purely as a cookie replacement, is the framing that survives policy reversals like Google's, a point our guide to social media advertising for small businesses also touches on when comparing owned-channel versus rented-platform marketing investment and where each fits in a resilient overall strategy.

What to watch next

Watch whether Google's decision proves durable or faces renewed regulatory pressure — the CMA's monitoring of Privacy Sandbox commitments continues regardless of the deprecation reversal, and further intervention remains possible if competition concerns resurface. Also watch the ICO's ongoing enforcement priorities under PECR and UK GDPR, since consent-based regulation, not browser technology, is now the more durable constraint shaping how UK marketers can legally collect and use customer data — a distinction worth building strategy around rather than the more volatile question of any individual browser vendor's cookie policy.

Frequently asked questions

Wait — is Google actually still deprecating third-party cookies in Chrome or not?

No, not as originally planned. After multiple delays to its original 2022 deprecation target, Google announced in July 2024 that it would introduce a new user-choice prompt in Chrome rather than removing third-party cookies outright, and confirmed in April 2025 that it would not proceed with deprecation at all. This reversed years of industry planning built around an assumed Chrome-wide cookie ban, and left Chrome — still the dominant browser by market share — as the one major browser that has not blocked third-party cookies by default.

If Chrome isn't removing cookies, does first-party data strategy still matter?

Yes, for reasons that predate and outlast the Chrome decision specifically. Safari and Firefox have blocked third-party cookies by default since 2020, meaning a meaningful share of web traffic was already effectively cookie-free regardless of what Chrome does. UK and EU privacy regulation (PECR and UK/EU GDPR) requires proper consent for tracking regardless of the technical cookie mechanism used. And first-party data is simply more accurate — it comes directly from a business's own customer relationship rather than inferred or aggregated third-party signals — independent of any browser policy.

Why did Google reverse its cookie deprecation plan?

Google cited ongoing feedback from regulators, publishers and the advertising industry about the complexity and unintended consequences of its proposed 'Privacy Sandbox' replacement technology, alongside continued scrutiny from the UK's Competition and Markets Authority, which had been monitoring the deprecation plan for its potential competitive impact on rival ad-tech providers. Industry analysts also noted that Google's own advertising business is heavily exposed to any disruption in third-party tracking capability, giving it commercial as well as technical reasons for caution.

Does this change what small businesses should actually do about marketing data?

Not fundamentally — the practical advice to build genuine first-party data relationships (email lists, loyalty programmes, account registrations, with proper consent) remains sound regardless of the Chrome decision, both because Safari and Firefox users are already cookie-free and because owned customer data is more valuable and durable for a small business than a targeting mechanism dependent on any single browser vendor's shifting policy.

Sources

  1. Google — Privacy Sandbox and third-party cookies update
  2. Information Commissioner's Office — guidance on cookies and similar technologies
  3. Competition and Markets Authority — Privacy Sandbox commitments monitoring