First-party data stopped being optional in April 2025

First-party data stopped being optional in April 2025

Google spent five years promising to retire the third-party cookie in Chrome, then in April 2025 announced it would change nothing. No deprecation, no opt-in prompt. The cookie that was scheduled to die in 2022 still lives in the browser that carries roughly 70% of the world’s browsing.

If you read that as a reprieve for your measurement stack, you read it wrong. The signal loss never depended on Chrome, and it never stopped.

How the deprecation actually ended

The retreat came in two steps. In July 2024, after multiple delays, Google abandoned deprecation outright and proposed instead a new experience in Chrome that would let people make an informed choice across their browsing, per the Privacy Sandbox blog (2024). Nine months later, the choice prompt died too:

We’ve made the decision to maintain our current approach to offering users third-party cookie choice in Chrome, and will not be rolling out a new standalone prompt for third-party cookies.

That is Anthony Chavez, VP of Privacy Sandbox, on April 22, 2025, per Google (2025). Users keep the existing Chrome settings, and the status quo won. After years of regulatory scrutiny and industry pushback, no replacement satisfied everyone, so the deadline was quietly deleted.

The industry mostly read this as an extension. I read it as the end of the excuse. There is no longer a Google deadline to plan around. There is only the erosion that was already happening.

The signal was already gone where it mattered

Safari has blocked all third-party cookies by default since March 2020, per WebKit (2020), and Firefox ships its own default blocking. Per StatCounter (2026), worldwide share in June 2026 stood at 15.34% for Safari and 3.4% for Firefox against Chrome’s 69.56%. Nearly one browsing session in five never had a third-party cookie to lose. Chrome’s dominance is the only reason the industry fixated on Google’s timeline while a fifth of the web went dark years ago.

Then there is consent, which does to Chrome what WebKit did to Safari. On the European accounts I run, a user who declines the banner is unaddressable regardless of browser, and consent-mode modeling backfills the reporting with statistics rather than observations. Useful, but a model is a patch, not a signal. Apple’s App Tracking Transparency did the same to mobile app data. The cookie survived April 2025. The signal did not.

On one European lead-gen account I manage, the gap between what the ad platforms report and what actually lands in the CRM is structural: Safari users, declined consents, and shortened cookie lifetimes all fall out of the platform’s view. I stopped treating platform numbers as ground truth and started reconciling against the CRM monthly, importing the real outcomes back into the platforms. That workflow is a first-party data program in miniature, and it is where most mid-size advertisers should start.

What a working program looks like at mid-size spend

The commercial case predates the cookie drama. Research by BCG and Google found that brands deploying advanced first-party data activations achieved 1.5x to 2.9x higher revenue uplift than brands deploying none, with digitally mature brands averaging 11% incremental revenue and 18% cost efficiency, per BCG x Google (2020). Those figures are from 2020 surveys, so discount them as you see fit. Discounted by half, they still beat any bid-strategy tweak I have ever shipped.

You do not need a seven-figure CDP. For advertisers in the low-seven-figures of annual spend, I build four layers, in order:

  1. Collection. Give people a reason to identify themselves: accounts, an email program worth reading, quizzes, warranty registration. Move measurement onto your own domain with server-side tagging. Send hashed emails through enhanced conversions on Google and the equivalent server-side API on Meta.
  2. Unification. GA4’s BigQuery export joined to the CRM on a hashed email or login ID. That is a perfectly workable identity spine for a mid-size advertiser, and it costs closer to a consulting engagement than a platform license.
  3. Activation. Customer lists uploaded for matching, seed audiences built from best customers rather than all customers, suppression of people who already bought, and value-based bidding fed margin data instead of revenue.
  4. Measurement. Offline conversion imports close the loop so the platforms optimize toward deals that funded payroll, not form fills. This is the layer that pays for the other three.

Sequence matters. Activation without collection is buying someone else’s audience data with extra steps. Collection without activation is a GDPR liability with no revenue attached. Build left to right.

Two mistakes I see mid-size advertisers make with this budget. The first is panic-buying a CDP because a vendor deck equated first-party data with a platform purchase; the pipes above cover a seven-figure media budget without one, and you can graduate later if the data volume genuinely demands it. The second is renting lookalikes off third-party segments and calling it a data strategy. Rented audiences stop existing the day you stop paying. A customer list you collected, matched, and modeled is an asset that appreciates with every campaign that feeds it.

The reprieve is not a strategy

Third-party cookies got a stay of execution. Your dependence on them did not. Every browser trendline, every consent regime, every platform privacy change moves in one direction, and first-party data is the only marketing input you control end to end.

The advertisers who treated July 2024 as an extension lost two years of compounding. The ones who treated it as noise built pipes that keep working no matter what Chrome announces next. Be the second kind.