Everything you need to know about third party cookies

Third party cookies are one of the main reasons ads seem to follow you around the internet.

They help websites, advertisers, and analytics tools recognize users across different sites, build behavior-based profiles, measure campaigns, and personalize ads. This guide explains what third-party cookies are, how they work, what data they can collect, and why browsers are changing the way they handle them. We’ll also look at what these changes mean for website owners, marketers, and anyone who wants to understand what happens when they click “accept cookies.”

New to the world of cookies? Start with our guide on what “accept cookies” means. And if you run a website, we’ll also cover which third-party cookies are active on your site, so you can understand what your cookie banner and privacy setup need to cover.


What are third-party cookies?

Third-party cookies are small text files placed on your device by a website other than the one you’re currently visiting. Also known as 3rd-party cookies, trackers, or cross-site cookies, they take their name from the domain mismatch: the “third party” is the external service setting the cookie, distinct from you (the user) and the site you actually navigated to.

When you visit a webpage, that page often loads content from multiple external sources: ads from ad networks, analytics scripts, embedded videos, and social media buttons. Each of those external services runs from its own domain, and each can set a cookie on your browser as part of that process, even though you navigated only to the host site. Those are third-party cookies.

The defining factor is domain matching. A cookie is first-party if its domain matches the page you’re on, and third-party if it comes from somewhere else. A cookie set by news.com while you’re on news.com is first-party. A cookie set by googleads.com while you’re on news.com is third-party, even if the ad itself is displaying right there on the page.


First-party vs. third-party cookies

First-party cookiesThird-party cookies
Who sets themThe website you’re visitingAn external service loaded by the page
DomainMatches the page URLDifferent from the page URL
Main purposeSession management, preferences, loginsCross-site tracking, advertising, analytics
Visible to usersMostlyOften not
Browser supportAll browsersIncreasingly blocked by default
Consent requiredDepends on purpose (essential uses may be exempt)Generally requires explicit user consent. See what the GDPR requires
Privacy riskLower (scoped to one site)Higher (tracks behavior across many sites)

Real-world examples

A news site with ads

You open news.com to read an article. While the page loads, it also pulls in an ad served by googleads.com. Google’s servers deliver that ad and, in doing so, set a third-party cookie on your browser stored under the googleads.com domain, not news.com’s. Later that day, you visit a travel website that uses the same ad network, and Google’s servers recognize you via that cookie, connecting your earlier browsing behavior to deliver targeted ads across both sites.

An embedded YouTube video

A blog post embeds a YouTube video partway through. Even if you never press play, your browser loads content from YouTube’s servers to render the embed, and YouTube can set a cookie on your device in the process. You’re on a third-party site, but YouTube knows you were there.

The Facebook Like button

Social sharing buttons are among the most common sources of third-party cookies on the web. A Facebook Like button loads from Facebook’s own servers, which means Facebook can set a cookie on your device and record that you visited the page, regardless of whether you clicked the button or even have a Facebook account.


How third-party cookies work

Third-party cookies are usually set when a website loads content from another company, such as an ad network, analytics provider, social media platform, or embedded video service.

When that external content loads, your browser sends a request to the third party’s servers. The third party can then place a cookie in your browser under its own domain, not the website you’re visiting.

Later, when you visit another site that uses the same third-party service, your browser sends that cookie back to the same third party automatically. This allows the third party to recognize the same browser across different websites, and over time, build a picture of browsing behavior, interests, and activity across sites.

All of this happens in the background. Browsers are designed to send stored cookies back to the domain that set them whenever a page loads content from that domain. Users don’t need to click anything for this exchange to happen.


Common use cases

Online advertising is the primary driver: retargeting campaigns, personalized ad delivery, and conversion tracking all depend on the ability to recognize and follow users across sites.

Cross-site analytics enables businesses to understand how users move across different properties and attribute conversions to specific marketing touchpoints, which requires persistent cross-site identifiers.

Social media widgets, including share buttons, embedded posts, and login widgets from platforms like Facebook, X, and LinkedIn, can track user activity on third-party sites as a byproduct of loading on the page.

Single sign-on (SSO) implementations sometimes use cookies to maintain authentication across related domains, keeping users logged in without requiring separate credentials for each.

Ad tech operations such as impression counting, frequency capping, and audience segmentation all rely on a consistent cross-site identifier to function accurately.

Most of these use cases require prior blocking: the relevant scripts should not run until a user has actively given their consent. Here’s how prior blocking works and what it means in practice for your site setup.


What data do third-party cookies collect?

Individual data points collected by third-party cookies can seem minor in isolation. The privacy concern comes from what happens when those points are combined: behavioral data stitched together across hundreds of sites over time can produce detailed profiles that go well beyond what any single data point would suggest. This is one of the core reasons the EU’s ePrivacy Directive introduced specific rules around cookies, separate from the broader GDPR framework. Read more in our ePrivacy and Cookie Law compliance guide.

Types of data commonly tracked:

  • Browsing history: Which pages you’ve visited, how long you spent on them, and how frequently you return
  • Click patterns: Which links, ads, and page elements you interact with
  • Search queries: What you’ve been looking for across search engines and individual sites
  • Purchase behavior: Products viewed, added to a cart, or purchased
  • Geographic location: Approximate location inferred from your IP address
  • Device information: Browser type, operating system, screen resolution, and device model
  • Cross-site activity: A behavioral record across multiple sites, used to build inferred interest and intent profiles

How that data is typically used:

Building user profiles for advertising and audience targeting

Behavioral targeting: serving ads based on inferred interests and browsing history

Remarketing: re-engaging users who’ve previously interacted with a product or service

Attribution modeling: understanding which touchpoints contributed to a conversion

Audience segmentation: grouping users by predicted demographics or interests

Frequency capping: controlling how often the same ad is shown to the same person


Third-party cookies now depend on the browser

Third-party cookies are now handled differently depending on the browser.

Safari and Firefox restrict or block many third-party tracking cookies by default. Chrome took a different path: after years of planned phase-outs and delays, Google confirmed in 2025 that it would not fully remove third-party cookies from Chrome. Instead, Chrome will continue to rely on user settings and privacy controls.

For website owners and marketers, this creates a fragmented landscape. Some users may be harder to track because of their browser. Others may still allow third-party cookies. That means you need to know which cookies and tracking tools your site uses, explain them clearly, and make sure your consent setup reflects what is active on your site.

Crucially, the legal requirements haven’t changed. The General Data Protection Regulation (GDPR) and the ePrivacy Directive both require explicit user consent before non-essential cookies are set, and third-party cookies almost always fall into that category. That obligation exists independently of what any browser does or doesn’t block. For a full breakdown of what’s legally required, see Cookies and the GDPR: what’s really required and our ePrivacy and Cookie Law compliance guide.

For website owners, the right approach is to audit which third-party scripts you’re loading, ensure your cookie banner captures valid consent before those scripts run, and maintain a documented record of that consent. iubenda’s Cookie Solution is built to handle exactly that, from automatic tracker detection and prior blocking to audit-ready consent logs. You’ll also want a cookie policy in place. Here’s how to generate one.


Start by checking which cookies your site uses

Third-party cookies have shaped how the web tracks, targets, and measures user behavior for decades. Their future is less certain than it once was, but they remain widely used, closely regulated, and directly relevant to anyone running a website or working in digital marketing.

The key points to take away: third-party cookies track behavior across sites, often invisibly, and in most jurisdictions, they require explicit user consent before they’re set. Browser-level changes have created an uneven landscape, but they don’t replace your legal obligations under the GDPR or the ePrivacy Directive. The responsibility for managing consent correctly sits with you as the site owner, regardless of what any browser does by default.

For website owners, the next step is making sure your consent setup reflects the cookies and trackers your site actually uses. iubenda’s Cookie Solution helps you scan your site, block non-essential scripts before consent, and keep clear records of users’ choices, so your cookie setup stays accurate and easier to manage.


FAQs

What are third-party cookies?

Third-party cookies are cookies set by a domain other than the website you’re visiting. They’re usually added through ads, embedded videos, analytics tools, or social media widgets loaded on the page.

They’re commonly used to recognize users across different websites, which is why they’re closely linked to behavioral tracking and targeted advertising.

Are third-party cookies a privacy risk?

They can be, depending on how they’re used.

A single cookie is just a small piece of data. The privacy concern comes from what happens at scale. If the same ad network or tracking provider appears across many websites, it can use third-party cookies to build a picture of someone’s browsing behavior over time.

That’s why privacy laws like the GDPR require valid consent before non-essential tracking begins. See our GDPR compliance guide for more on how those rules may apply to your site.

Can third-party cookies identify me personally?

Not directly in most cases.

Third-party cookies usually don’t store your name or email address. Instead, they assign a unique ID to your browser and connect activity to that ID.

But that data can become personally identifiable if it’s linked to an account you’re logged into, or combined with enough other information. That’s why behavioral tracking data can be treated as personal data under the GDPR, even when no name is attached.

Who can access third-party cookie data?

Usually, the company that sets the cookie. This could be an ad network, analytics provider, social media platform, or another third-party service loaded on the page.

In some cases, that data may also be shared with other partners or data providers, depending on how the service works and what permissions are in place.

How do I enable third-party cookies?

The steps depend on your browser.

In Chrome, go to Settings > Privacy and security > Cookies and other site data. In Safari, open Settings or Preferences, then go to Privacy. In Firefox, go to Settings, then Privacy and Security.

Most browsers also let you allow third-party cookies for specific websites instead of enabling them everywhere. That’s usually a more controlled option than switching them on globally.

Start by checking which cookies your site uses

Third-party cookies are still widely used, but browsers no longer handle them consistently. Safari, Firefox, and Chrome may treat third-party cookies differently, but as a website owner, you still need to understand which cookies are active on your site, explain them clearly, and collect valid consent where required.

A good first step is to scan your site and check which third-party cookies, scripts, and tracking tools are running. From there, iubenda can help you manage consent, block non-essential scripts before permission, and keep clear records of users’ choices.

Follow us on: