Analytics and Tracking

Privacy Sandbox

Also called Chrome Privacy Sandbox

Google's proposed Chrome replacements for third-party cookies; the programme has changed direction repeatedly and its current status is contested.

Quick facts: Privacy Sandbox

Category
Analytics and Tracking
Also called
Chrome Privacy Sandbox
Level
Advanced
Affects
Remarketing planning, measurement strategy, vendor claims
Where to see it
Google's Privacy Sandbox developer documentation, Chrome settings and flags
In this article4
  1. How Privacy Sandbox works
  2. Why Privacy Sandbox matters
  3. Where Privacy Sandbox goes wrong
  4. What to do about it

How Privacy Sandbox works

Privacy Sandbox is not one product. It is an umbrella name Google gave to a group of proposed browser features in Chrome, each meant to deliver something advertising used to get from third-party cookies, but without letting any one company follow an individual across the web.

The parts most often mentioned are an interest signal, where the browser itself works out broad subject labels from recent browsing and shares only those; an auction that runs inside the browser so a remarketing bid can be made without the advertiser learning who the person is; and an aggregate reporting mechanism that returns conversion counts in batches rather than one identifiable event at a time. Alongside these sit measures aimed at reducing device fingerprinting, which would otherwise become the obvious workaround.

The status of these proposals is genuinely unsettled, and that is the most important thing on this page. Chrome did not remove third-party cookies on the timetable first announced, parts of the programme have been changed or wound down since, and published sources disagree about which pieces remain active. Before you quote any of it in a strategy document, check Google’s own developer documentation for the current position of the specific API you mean.

Why Privacy Sandbox matters

It matters less as a technology you will configure and more as a claim you will hear. Slide decks, vendor pitches and blog posts still describe Privacy Sandbox as the settled future of measurement, and some of that material was written when the plan looked very different. Repeating it to a client is how you end up recommending something that no longer exists.

The underlying direction, though, is real and has not reversed. Browsers keep tightening what a third party can observe, regulators keep tightening what may be collected without consent, and neither trend depends on any one Google proposal surviving. The lesson to take is about the direction, not about the specific APIs.

Where Privacy Sandbox goes wrong

The first error is planning around it. Building an audience strategy on a browser feature whose future is contested wastes work you could have spent on data you own outright.

The second is citing it without a date and a source. If you write about Privacy Sandbox in a proposal, name the documentation you read and when you read it, so the reader can check whether it still holds. Anything less will age badly and will be quoted back at you.

The third is the mirror image: assuming that because the cookie deadline slipped, nothing changed. Third-party cookies are already unreliable in Safari and Firefox regardless of what Chrome does, and consent requirements apply whichever browser someone uses.

What to do about it

Treat Privacy Sandbox as something to watch, not something to implement, unless you run ad technology yourself. For almost every business, the useful work is the same as it was before the programme was announced: collect first-party data with permission, keep it clean, connect it to your own systems, and reconcile campaign reports against orders and enquiries you can count independently.

If a client or a vendor raises it, answer honestly. Say what it was intended to do, say that its status has moved more than once, and point at the current documentation rather than at a summary. An honest “this keeps changing, here is where to check” builds far more trust than a confident answer that turns out to be a year out of date.

Do and do not

Do

  • Check Google's current developer documentation before citing anything
  • Date every reference you make to it
  • Build on first-party data you collect with consent

Do not

  • Plan an audience strategy around unsettled browser proposals
  • Repeat vendor slides about it without verifying
  • Assume the delay means nothing has changed

Questions people ask about this

Do I need to do anything about Privacy Sandbox right now?

For most businesses, no. It is a set of browser-level proposals aimed mainly at ad technology companies rather than advertisers. The work that pays off either way is the same: collect first-party data with consent, measure conversions server-side where you can, and reconcile platform reports against your own sales records.

Are third-party cookies gone?

Not uniformly, and the picture depends on the browser. Safari and Firefox restrict them heavily already. Chrome's plan to remove them has been revised more than once, so a plan that assumes a single switch-off date is unsafe. Assume they are unreliable everywhere and build measurement that does not depend on them.

Why does advice about Privacy Sandbox contradict itself?

Because the programme itself has changed direction several times, and a lot of published writing was accurate when it appeared and is not now. Articles rarely get updated. The only reliable approach is to check Google's current developer documentation for the specific API in question and note the date you checked it.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.