A third-party cookie is a cookie set by a domain other than the website in your address bar. If you visit a retailer’s site and an advertising network embedded on that page saves a cookie under its own domain, that is a third-party cookie. Because the same network appears on thousands of sites, it can recognise your browser as you move between them.
How third-party cookies work
A web page often loads scripts, images and frames from other companies. Each of those requests can set and read cookies for the company’s own domain. The visited site never controls those cookies directly. The ad network, though, sees the same cookie on every site that carries its code, which lets it build a browsing history for that browser, show remarketing ads, cap how often you see an advert and attribute a sale to an advert you saw elsewhere.
A first-party cookie is set under the domain you are visiting. That holds even when another company’s script creates it. The difference is the domain the cookie belongs to, not who wrote the script.
Where browsers stand
Safari has blocked third-party cookies by default for several years through Intelligent Tracking Prevention, and Firefox isolates them per site by default. Chrome, the most used browser in the UK, spent years planning to remove them, with the UK’s Competition and Markets Authority overseeing Google’s proposals. Google then dropped the plan. At the time of writing (October 2026), Chrome still allows third-party cookies by default, and most of its Privacy Sandbox replacements have been wound down.
Why it matters
For a UK business, the browser position matters less than the law. PECR requires consent before setting non-essential cookies, first-party or third-party, and advertising cookies are not essential. That applies whatever Chrome does. The ICO has said it will act against sites that drop advertising cookies without valid consent, and a banner that loads ad tags before anyone clicks Accept does not give valid consent.
Practically, a large share of UK visitors either use Safari on iPhone or decline advertising cookies. Remarketing audiences shrink and ad platforms see fewer conversions than really happen. That is why first-party data and server-side approaches have grown, not because third-party cookies disappeared.
Third-party cookies also bring a data protection question beyond PECR. When an ad network sets its own cookie on your site, it receives information about your visitors, and you usually share responsibility for that under UK GDPR. Your privacy notice should name those companies and explain what they receive.
Common mistakes
- Thinking Chrome’s U-turn changed the rules. Consent under PECR was always required and still is.
- Assuming first-party means exempt. A first-party advertising or analytics cookie needs consent too, with limited exceptions.
- Not knowing which third parties are present. Embedded videos, chat widgets and social share buttons can all set cookies.
- Planning measurement around Chrome alone. Safari and declined consent already remove much third-party data.
How to act on it
Run a cookie audit: load your site in a fresh browser, decline everything on the banner and list every cookie that still appears, noting its domain. Anything set by a third party before consent needs fixing, usually by gating its tag behind your consent platform. Then strengthen what does not depend on third-party cookies: server-side tracking, enhanced conversions and your own customer data.
Building advertising measurement that respects consent and still gives platforms enough signal is a core part of my performance marketing service.
