Analytics and Tracking

Third-Party Cookie

A cookie set by a domain other than the website you are visiting, typically by an advertising or tracking service to recognise you across sites.

Quick facts: Third-Party Cookie

Category
Analytics and Tracking
Level
Beginner
Affects
Remarketing audiences, ad attribution, frequency capping, cookie compliance
Where to see it
Browser developer tools, consent management platform, cookie audit, Tag Assistant
In this article5
  1. How third-party cookies work
  2. Where browsers stand
  3. Why it matters
  4. Common mistakes
  5. How to act on it

A third-party cookie is a cookie set by a domain other than the website in your address bar. If you visit a retailer’s site and an advertising network embedded on that page saves a cookie under its own domain, that is a third-party cookie. Because the same network appears on thousands of sites, it can recognise your browser as you move between them.

How third-party cookies work

A web page often loads scripts, images and frames from other companies. Each of those requests can set and read cookies for the company’s own domain. The visited site never controls those cookies directly. The ad network, though, sees the same cookie on every site that carries its code, which lets it build a browsing history for that browser, show remarketing ads, cap how often you see an advert and attribute a sale to an advert you saw elsewhere.

A first-party cookie is set under the domain you are visiting. That holds even when another company’s script creates it. The difference is the domain the cookie belongs to, not who wrote the script.

Where browsers stand

Safari has blocked third-party cookies by default for several years through Intelligent Tracking Prevention, and Firefox isolates them per site by default. Chrome, the most used browser in the UK, spent years planning to remove them, with the UK’s Competition and Markets Authority overseeing Google’s proposals. Google then dropped the plan. At the time of writing (October 2026), Chrome still allows third-party cookies by default, and most of its Privacy Sandbox replacements have been wound down.

Why it matters

For a UK business, the browser position matters less than the law. PECR requires consent before setting non-essential cookies, first-party or third-party, and advertising cookies are not essential. That applies whatever Chrome does. The ICO has said it will act against sites that drop advertising cookies without valid consent, and a banner that loads ad tags before anyone clicks Accept does not give valid consent.

Practically, a large share of UK visitors either use Safari on iPhone or decline advertising cookies. Remarketing audiences shrink and ad platforms see fewer conversions than really happen. That is why first-party data and server-side approaches have grown, not because third-party cookies disappeared.

Third-party cookies also bring a data protection question beyond PECR. When an ad network sets its own cookie on your site, it receives information about your visitors, and you usually share responsibility for that under UK GDPR. Your privacy notice should name those companies and explain what they receive.

Common mistakes

  • Thinking Chrome’s U-turn changed the rules. Consent under PECR was always required and still is.
  • Assuming first-party means exempt. A first-party advertising or analytics cookie needs consent too, with limited exceptions.
  • Not knowing which third parties are present. Embedded videos, chat widgets and social share buttons can all set cookies.
  • Planning measurement around Chrome alone. Safari and declined consent already remove much third-party data.

How to act on it

Run a cookie audit: load your site in a fresh browser, decline everything on the banner and list every cookie that still appears, noting its domain. Anything set by a third party before consent needs fixing, usually by gating its tag behind your consent platform. Then strengthen what does not depend on third-party cookies: server-side tracking, enhanced conversions and your own customer data.

Building advertising measurement that respects consent and still gives platforms enough signal is a core part of my performance marketing service.

Do and do not

Do

  • Audit which third parties set cookies on your site
  • Block non-essential cookies until consent is given
  • Invest in first-party and server-side measurement

Do not

  • Read Chrome's decision as a change to UK consent law
  • Load advertising tags before the banner is answered

Questions people ask about this

Are third-party cookies being removed from Chrome?

Not at the time of writing (October 2026). Google abandoned its plan to phase them out and Chrome still allows them by default. That changes nothing about UK consent rules, and with Safari and Firefox restricting them, many UK visits already happen without them.

Do I need consent for third-party cookies in the UK?

Yes, for anything that is not strictly necessary, which includes advertising and almost all tracking cookies. PECR sets the rule and the ICO enforces it. Consent has to be given before the cookie is set, through a genuine choice.

Is the GA4 cookie a third-party cookie?

No. GA4's main cookie is set on your own domain, so it is first-party, even though Google's code sets it. It still needs consent in the UK unless it falls within an exemption, so check the ICO's current guidance on analytics cookies.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.