Third-party cookies contextual advertising is the direction digital marketing has been moving toward since browsers began restricting cross-site tracking. Cookies come in several kinds: essential cookies that make a site work, functional cookies that remember choices such as language, performance cookies that collect statistics and third-party cookies placed by external providers, which follow users across sites and build profiles for advertising.
Pressure on browser makers grew for years, and Safari, Firefox and Edge restricted third-party cookies before Chrome, which holds the largest share of the browser market, announced its own plan. Google later changed course and kept third-party cookies with user choice, while continuing to develop privacy-preserving alternatives. The strategic direction has not changed: cross-site profiling is harder, and advertisers who depend on it have to adapt.
What the shift changes
Without cross-site identifiers, profiling an audience becomes less precise, and generic messages tend to convert worse. Publishers that relied on third-party data for advertising revenue face the largest adjustment. Industry estimates cited at the time put potential publisher revenue losses at up to USD 10 billion, with some projections suggesting declines between 50% and 70% for publications that did not adapt their data strategy. The budgets move toward platforms that collect data directly, such as social networks, marketplaces and publishers with registered audiences.
For advertisers, the consequence is a heavier reliance on first-party data. Information collected through a CRM, a contact base or an offline relationship becomes the foundation of campaigns, and it requires consent and lawful handling under the GDPR. Contextual targeting returns as a practical alternative: placing a message on a page about a relevant topic rather than against a profile of an individual, which works without identifying the user.
The Privacy Sandbox and Topics
Google's first attempt, FLoC, grouped users into interest cohorts in the browser. Regulators raised concerns under the GDPR because adding a user to a cohort created an identifier and processed personal data without explicit consent, and the project was abandoned. The successor is Topics, part of the Privacy Sandbox: the browser derives a small number of topics from recent browsing, keeps them for three weeks and shares only a few with participating sites and their advertising partners, without contacting external servers. Users can view, remove or disable the topics.
Topics offers advertisers fewer and broader categories than the profiling they were used to, and it is easier to understand than the opaque cohorts of FLoC. Whether it restores the effectiveness of audience targeting remains open, and the framework continues to evolve. The practical conclusion for a business is to reduce dependence on tracking that browsers may remove and to build an owned audience with clear consent.
What companies should do
The transition rewards three things. Collect data directly, with transparent consent and a documented legal basis. Keep the technology able to work with contextual signals as well as audience segments. Measure performance in a way that does not rely on a single identifier, so that the loss of one signal does not blind the campaign. The shift is uncomfortable for advertisers who grew up on third-party data, and it aligns advertising with the privacy rules that now apply across the European Union.
With third-party cookies gone, first-party signals matter more, including customer WiFi as a data channel owned directly by the business.
Have a project in mind?
Do you know where to start?
The goal is to pin down the problem, the priorities and the timing.
Book a first callFrequently asked questions
Are third-party cookies disappearing?
Safari, Firefox and Edge restrict them, and Chrome moved to a model with user choice while developing alternatives. Cross-site tracking is more limited than before.
What is contextual targeting?
It places an ad based on the topic of the page the user is viewing, without building a profile of the person, and it works without third-party cookies.
What replaces third-party data?
First-party data collected with consent, contextual signals, and aggregated methods such as the Privacy Sandbox, each with different precision.
Do small businesses need to act?
They should reduce reliance on third-party tracking and build an owned, consented audience, because the direction of regulation and browser policy points the same way.
Sources
Google — Privacy Sandbox and Topics API: https://privacysandbox.google.com/
Google Chrome — testing and updates on privacy in the web: https://blog.google/products/chrome/update-testing-privacy-sandbox-web/
IAB Tech Lab — Project Rearc and addressability standards: https://iabtechlab.com/project-rearc/
European Commission — data protection in the EU and the GDPR: https://commission.europa.eu/law/law-topic/data-protection_en