For six years, the digital advertising industry prepared for a world without third-party cookies, commissioning panels, restructuring measurement stacks, and building replacement infrastructure from scratch.
In July 2024, Google reversed course entirely, announcing it would not phase out third-party cookies in Chrome, which carries roughly two-thirds of global web traffic.
By April 2025, Google confirmed it would not even introduce a standalone user prompt, and in October 2025 it dismantled most of the Privacy Sandbox, the elaborate replacement apparatus it had spent years constructing.
The surviving Sandbox features, CHIPS for cookie partitioning, FedCM for sign-in, and Private State Tokens for fraud signals, are infrastructure plumbing rather than targeting tools.
Nothing about Google’s reversal changed a single obligation under any privacy statute, and the legal environment has grown considerably less forgiving than any browser setting ever was.
Safari has blocked third-party cookies by default since 2020, Firefox partitions them, and Brave blocks almost everything, meaning roughly a fifth of global traffic was already cookieless regardless of Chrome’s decisions.
As of early 2026, twenty states operate comprehensive consumer privacy laws, with Indiana, Kentucky, and Rhode Island joining on January 1, 2026, and Oklahoma and Alabama pushing the total past twenty-one by April.
At least twelve states now require businesses to honour the Global Privacy Control as a universal opt-out mechanism, including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas.
The Global Privacy Control is a header the browser transmits automatically, meaning a consumer visits a site, the signal arrives with the request, and the law expects businesses to recognise and suppress relevant data flows before anything fires.
On September 9, 2025, the California Privacy Protection Agency, the Colorado Attorney General, and the Connecticut Attorney General announced a coordinated investigative sweep targeting businesses that fail to honour opt-out preference signals.
The Walt Disney Company settled California Attorney General claims for $2.75 million, announced February 11, 2026, tied in part to honouring rights requests across its services.
California’s Delete Act created a centralised Delete Request and Opt-out Platform known as DROP, with consumers filing deletion requests since January 1, 2026, and registered data brokers required to begin processing those requests on August 1, 2026.
The statutory definition of data broker is deliberately broad, reaching any business that knowingly collects and sells personal information of consumers with whom it has no direct relationship, with no revenue threshold attached.
Brokers that fail to act on deletion requests face fines of $200 per request, per day, and by early July 2026 more than six hundred brokers were registered with over a quarter of a million consumer requests already queued.
The Federal Communications Commission’s one-to-one consent rule was vacated by the Eleventh Circuit in Insurance Marketing Coalition Ltd. v. FCC on January 24, 2025, with the Commission issuing a conforming rule on August 29, 2025.
Florida, Oklahoma, Washington, and a growing roster of other states maintain and expand their own mini-statutes, several imposing requirements stricter than the federal floor, and carrier rules frequently demand consent granularity that federal law does not.
Hashed-email identifiers such as the UID2 framework remain useful but carry a critical legal caveat: hashing is not anonymisation, and a hashed email that resolves to an individual remains personal information under state law.
Contextual targeting, which reads the page rather than the person, is the one durable signal that survives every browser policy and every state statute without implicating consent obligations.
Server-side tracking, often sold as a compliance escape hatch, is not one, as both California’s sale-or-share framework and European ePrivacy rules reach server-to-server transfers directly.
The efficiency frontier for personalisation no longer runs along the axis of how much data can be collected but along whether a legal basis travels with that data through every enrichment, every resale, and every server-to-server hop.

