Analytics and Tracking

Privacy Sandbox

Also called Google Privacy Sandbox

Google's programme to replace third-party cookies in Chrome with browser-based targeting and measurement features, most of which Google has since retired.

Quick facts: Privacy Sandbox

Category
Analytics and Tracking
Also called
Google Privacy Sandbox
Level
Advanced
Affects
Third-party cookie availability in Chrome, ad targeting and remarketing, ad measurement plans, ad tech vendor choices
Where to see it
Google's Privacy Sandbox and Chrome developer pages, the CMA's case page for the Google Privacy Sandbox investigation, ad platform documentation
In this article4
  1. How the Privacy Sandbox worked
  2. Why it matters, and the UK part of the story
  3. Common mistakes
  4. How to act on it

The Privacy Sandbox was Google’s programme to replace third-party cookies in Chrome with browser features that would allow ad targeting and measurement without tracking individuals from site to site. At the time of writing (October 2026), Google has announced the retirement of most of those features and Chrome still supports third-party cookies, so for most UK businesses it is now background history rather than something to plan around.

How the Privacy Sandbox worked

Google launched the initiative in 2019 and said in early 2020 that Chrome would phase out third-party cookies. The plan was to move the jobs those cookies did for advertisers into the browser itself, with each job handled by a separate interface:

  • The Topics API, in which Chrome noted broad interest categories from a person’s recent browsing and shared a few of them with sites, instead of detailed browsing histories.
  • The Protected Audience API, first called FLEDGE, which ran remarketing auctions inside the browser so that the list of sites someone had visited stayed on their device.
  • The Attribution Reporting API, which reported ad conversions in delayed or aggregated form rather than linking an ad click to an identifiable person across sites.
  • Smaller pieces covering fraud prevention, cookies partitioned by site, and limits on browser fingerprinting.

Ad tech companies were asked to test these in Chrome, and from early 2024 Chrome switched off third-party cookies for a small share of users as a trial.

Why it matters, and the UK part of the story

The Privacy Sandbox got particular attention in the UK because the Competition and Markets Authority (CMA) opened an investigation in early 2021. Its concern was that removing third-party cookies from Chrome while Google kept its own data could strengthen Google’s position in digital advertising. In February 2022 the CMA accepted legally binding commitments from Google about how the changes would be designed, tested and introduced, working alongside the ICO on the privacy side. That gave a UK regulator an unusual say over a change to the world’s most used browser.

The plan then changed several times. In 2024 Google said it would no longer remove third-party cookies outright and would offer Chrome users a choice instead. In 2025 it dropped that separate choice prompt and later said it would retire most of the Privacy Sandbox APIs, pointing to limited adoption across the industry. These announcements moved quickly, so check the current position on Google’s and the CMA’s own pages before relying on any detail here.

The practical lesson for a business owner is that the long-forecast end of third-party cookies in Chrome did not arrive as planned, yet tracking still erodes from other directions: Safari’s Intelligent Tracking Prevention, Firefox’s tracking protection, ad blockers and, above all on UK sites, visitors who decline cookies on your banner.

Common mistakes

  • Paying for a cookieless tracking project designed around Privacy Sandbox APIs that are being retired.
  • Assuming that because Chrome still accepts third-party cookies, you may set them without asking. PECR consent rules apply whatever the browser allows.
  • Treating the Privacy Sandbox as a compliance measure for your own site. It was a browser change, never a substitute for a lawful consent setup.
  • Relying on older articles that give firm dates for cookie removal and planning budgets around deadlines that never came.

How to act on it

Build measurement that does not depend on any single browser feature. In practice that means first-party data collected with permission, consented conversion data sent from your server or CRM through tools such as Google’s enhanced conversions and Meta’s Conversions API, and a regular check of platform figures against your own sales records.

If an agency or ad tech supplier still describes the Privacy Sandbox as the future of targeting, ask what their product uses today and what happens to it as the APIs are withdrawn. I review exactly this kind of dependency when I set up tracking for performance marketing campaigns, so budgets are not tied to technology that may disappear.

Do and do not

Do

  • Check the current status on Google's and the CMA's own pages before planning around it
  • Build measurement on consented first-party data and server-to-server conversion data
  • Ask vendors what their product depends on today

Do not

  • Pay for projects built on Privacy Sandbox APIs that are being retired
  • Assume third-party cookies in Chrome can be set without consent
  • Plan around cookie removal dates from old articles

Questions people ask about this

Has Google removed third-party cookies from Chrome?

No. At the time of writing (October 2026), Chrome still supports third-party cookies, although people can block them in their settings and they are blocked by default in Incognito windows. Safari and Firefox already block many third-party cookies by default, which affects tracking far more for most UK sites.

What did the CMA have to do with the Privacy Sandbox?

The Competition and Markets Authority investigated whether Google's plans would harm competition in digital advertising, and in 2022 accepted binding commitments from Google on how the changes would be developed and rolled out. It worked with the ICO, which looked at the privacy effects. The CMA's case page records how the commitments have changed since, so check it for the current position.

Do I need to change anything on my website because of the Privacy Sandbox?

For most UK businesses, no. What does need attention is consent: analytics and advertising cookies need a proper opt-in under PECR whatever Chrome supports. Focus on a working cookie banner, consented server-side conversion data and comparing platform numbers with your own sales.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.