Third-Party Cookie
Data & TrackingAlso: 3rd Party Cookie · Cross-Site Cookie
Quick definition
A third-party cookie is a small file set by a domain other than the website you are actually visiting, usually an advertising or analytics company. Because the same third party is present across many sites, it can follow a person from site to site and build a profile of their behaviour. This is what powered classic retargeting and cross-site ad measurement, and it is exactly why browsers and regulators have spent years dismantling it.
Where it shows up in the data
The core function. Because the same third party is embedded across many sites, its cookie recognises a person everywhere, which is how retargeting followed you around the web.
Safari and Firefox block third-party cookies by default and Chrome has moved to give users control. Each step shrinks the reach of cookie-based tracking.
As third-party cookies fade, the durable alternatives are data you collect directly with consent, server-side tracking and owned channels like email.
What it actually means
Every cookie is set by a domain. A first-party cookie is set by the site you are on, for example to remember your login. A third-party cookie is set by a different domain that the page loads content from, typically an ad network or analytics vendor. Because that vendor appears on thousands of sites, its cookie lets it recognise the same person across all of them. That cross-site recognition is the engine of behavioural retargeting and much of programmatic ad measurement. It is also a privacy problem, which is why Safari and Firefox block third-party cookies by default and regulators have pushed hard against silent cross-site tracking. The result is a shift back to first-party data, consented tracking and server-side measurement.
The third-party cookie is not dead so much as already unreliable. Half your audience has been blocking it for years.
How it shows up
The decline shows up as shrinking remarketing audience sizes, gaps between ad-platform reported conversions and analytics, and rising reliance on modelled conversions. In browser developer tools you can see which cookies are first-party and which are third-party for any page.
The Australian context
Australian traffic skews heavily to Safari on mobile thanks to iPhone share, so third-party cookie blocking already affects a big portion of the local audience. First-party data strategies and Pii-safe measurement are the sensible response for Australian businesses.
Where people get this wrong
Related terms
Common questions
Are third-party cookies gone?
Not entirely, but Safari and Firefox already block them by default and Chrome has moved to restrict them. For a large share of your audience they no longer work, so treat cookie-based tracking as unreliable.
What replaces third-party cookies?
First-party data you collect directly with consent, server-side tracking, owned channels like email and modelled measurement from the ad platforms. The theme is owning the relationship rather than renting cross-site tracking.
Do first-party cookies still work?
Yes. First-party cookies set by the site you are visiting still power logins, shopping carts and first-party analytics. It is the cross-site third-party cookie that is being phased out.
Debrief
Get the next one
No spam. No fluff. Just the next article, straight to your inbox.
Keep exploring
About New Rebellion
New Rebellion is a marketing intelligence consultancy. We build tools, score Australian businesses on how their marketing actually performs, and publish Debrief every day. This dictionary is part of how we work in the open.
How we think →