As of October 2, 2026, Chrome still leaves third-party cookies to each user’s choice. On April 22, 2025, Google said Chrome would maintain its current approach and would not add a new standalone prompt for third-party cookies. The Chrome 153 release notes, dated September 8, 2026, still cite that decision.
What did Google decide in April 2025?
Google’s announcement gave its reasons. Publishers, developers, regulators and the ads industry still disagreed about changes that would affect cookie availability. Adoption of privacy-enhancing technologies had accelerated, and the regulatory landscape had changed since Google announced the Privacy Sandbox initiative in 2019 and entered a formal engagement with the CMA and ICO in 2022.
The decision has three parts. Chrome keeps its current approach to third-party cookie choice. It adds no new standalone prompt. Users keep the controls in Chrome’s Privacy and Security Settings.
The post also said the Privacy Sandbox APIs might now have a different role to play, and it promised an updated roadmap for them in the coming months. Google’s next update on those plans came on October 17, 2025 and is summarized below.
What is true in Chrome today?
Here is the status as of October 2, 2026, taken only from Google’s own pages:
- Third-party cookies remain a user choice in Chrome’s Privacy and Security Settings, according to Google’s April 2025 post.
- Incognito mode already blocks third-party cookies by default, and Google said in the same post that it would keep improving protections there.
- On October 17, 2025, Google announced it would retire a list of Privacy Sandbox technologies, including Topics, Protected Audience and Attribution Reporting.
- The Chrome 153 notes describe Protected Audience, Related Website Sets, Shared Storage and Attribution Reporting as planned for deprecation and removal, and name the cookie decision as the context.
Plans move quickly. The April post said Google planned to launch IP Protection in Q3 2025. The October post then listed IP Protection among the retired technologies.
These are statements about Chrome only. This article makes no claim about any other browser, and the newest Google page used here is the September 8, 2026 release notes.
Why would a buyer still plan for signals that do not depend on cookies?
A cookie is a small value a browser stores for a site. It identifies a browser only where the browser keeps it and the user’s settings allow it. Because Chrome leaves that setting with each user, cookie coverage inside Chrome is the sum of individual choices, not a platform guarantee.
Cookies are also a browser feature. Mobile apps, many connected TV apps and out-of-home screens run outside a browser, so a cookie cannot identify anyone there. A plan built on one signal inherits that signal’s gaps in every environment. A plan that uses several can still bid sensibly when one is missing, because the bid request carries whatever the publisher sends and the buyer decides which signals to act on.
Google also retired many Privacy Sandbox technologies, citing expected value and low levels of adoption in its October post. The Chrome 153 notes describe Protected Audience as interest-group advertising without third-party cookies. It and Topics are both on the retirement list, so there is no Chrome-built replacement for cross-site interest targeting to wait for. The October post adds that Google will keep working on an interoperable Attribution standard through the W3C’s Private Advertising Technology Working Group.
What can a buyer ask a DSP?
Ask which of these signals a campaign relies on, and what happens to delivery when one is missing:
- Context: what the page, app or stream is about.
- Publisher-defined cohorts passed in the bid request.
- Identity tokens that a publisher chooses to pass.
- Consent and privacy strings that say what data use is allowed.
- First-party lists the advertiser supplies.
A good answer names the signal for each line item and says what the fallback is. A weak answer says “we use cookies” or “we use AI” and stops there.
How does Vectravia handle this?
Context Engine targets by IAB Tech Lab Content Taxonomy categories, keywords and page-level context, so it needs no user identifier at all. It works on web, in-app, CTV and audio content signals. Because it uses no user identifier, its inputs do not depend on any browser’s cookie settings.