For five years the same line has appeared in every other marketing deck: third-party cookies are dying, so build first-party data. The first half has now been disproven. Google called off the deprecation in 2025 and retired the replacement project shortly afterwards. The second half still holds, just for different reasons than the ones that were sold at the time. That shifts the question. It is no longer whether you collect data, but how much of what already sits in your systems can actually be used. Let us work through it: what was really decided in 2025, how much of your traffic was never in the cookie game anyway, and which four filters turn 10,000 contacts into a few hundred.
What actually happened in 2025?
In January 2020 Google announced it would remove third-party cookies from Chrome within two years. Five years of delay followed. On 22 April 2025 Anthony Chavez, VP of Privacy Sandbox, wrote the sentence that ended it: "we've made the decision to maintain our current approach to offering users third-party cookie choice in Chrome, and will not be rolling out a new standalone prompt for third-party cookies". No removal, no choice prompt, everything stays in Chrome's settings where it already was.
Six months later the replacement went too. On 17 October 2025 the same team retired ten Privacy Sandbox technologies, among them Topics, Protected Audience and the Attribution Reporting API. The reasoning is in the post verbatim: "After evaluating ecosystem feedback about their expected value and in light of their low levels of adoption, we've decided to retire the following Privacy Sandbox technologies". Three narrow pieces remain: CHIPS, FedCM and Private State Tokens.
Two things follow for practitioners. Anyone who justified a data programme with the deadline alone has lost the argument. And anyone who concludes the topic is settled is confusing a cancelled date with a solved problem. Cross-domain attribution does not work any better today than it did before the cancellation, it is simply no longer in the calendar.
Does that mean you can carry on as before?
No, and for a reason that never depended on Google. Chrome is only part of the market. Safari has blocked third-party cookies fully since March 2020, Firefox has blocked third-party tracking cookies by default since September 2019 and has isolated the rest since 2022, and Brave was never configured any other way. None of these browsers were waiting for a deadline.
Do the sum for your own market. For July 2026 Statcounter puts Chrome in Austria at 48.19 per cent, Safari at 21.27, Edge at 10.64 and Firefox at 9.95 per cent. Safari and Firefox together are 31.22 per cent: close to a third of your Austrian traffic was never in the cookie game, regardless of any announcement. In Germany the same figure is 25.18 per cent, because Chrome is stronger there.
So the deadline was never the event. The event was a gradual loss of visibility that has already happened. That is exactly why your own data base still matters: it is the only part of the measurement that does not depend on a stranger's browser setting.
What is your data base actually worth?
The number that ends up in the deck is almost always the row count in the CRM. That is not an asset, it is a storage figure. Only the share that survives four filters is usable, and the filters multiply.
First, consent, and consent for the purpose you have in mind rather than for something adjacent. Second, resolvability: the same person must not sit in the system as three records with three spellings, or you will count them three times and contact them three times. Third, recency, because an address from 2021 is a guess, not an audience. Fourth, linkability: a record that cannot be tied to behaviour on your site or to a purchase cannot predict anything.
Whether your own answer is 18 or 40 per cent is not the point. The point is the multiplication. Four rates that sound harmless on their own leave you with a fraction. And every euro spent on reach to turn 10,000 into 12,000 works against that multiplication rather than improving it. The cheaper lever is almost always on the right-hand side of the sum. This is also where the topic differs from plain data hygiene, which we covered in CRM hygiene before AI: there the question is whether automations run cleanly, here it is how large your usable base is in the first place.
Why "first-party" is not a legal category
A common misreading: whatever happens on your own domain needs no consent. That is written nowhere. In Germany, section 25(1) TDDDG governs access to end devices, and the wording knows no first or third party: "Die Speicherung von Informationen in der Endeinrichtung des Endnutzers oder der Zugriff auf Informationen, die bereits in der Endeinrichtung gespeichert sind, sind nur zulässig, wenn der Endnutzer auf der Grundlage von klaren und umfassenden Informationen eingewilligt hat." The exception in subsection 2 number 2 applies only where access is strictly necessary to deliver the service the user has explicitly requested. Audience measurement does not qualify, including your own.
Austria says the same in section 165(3) TKG 2021. The Austrian data protection authority puts it plainly enough in its FAQ that no interpretation is needed: "Für alle 'technisch nicht notwendigen Cookies' muss eine Einwilligung eingeholt werden." For all cookies that are not technically necessary, consent must be obtained. The authority does mention sorting cookies by domain, but as a description, not as a permission. First-party analytics needs the same consent as somebody else's pixel.
On top of that sits purpose limitation under Article 5(1)(b) GDPR. Data collected to fulfil an order does not automatically become a newsletter base, and certainly not training material. Miss that and you build a base that is large on paper and unusable in practice. Which is why sound consent management belongs in the data strategy rather than in the legal department: it decides how much of your base counts at all. And moving measurement to the server with server-side tagging relocates the plumbing, not the consent requirement.
Which number to use instead of a benchmark
The obvious shortcut is an external comparison. The consent platform Didomi reports in its 2026 European benchmark a consent rate of 75.1 per cent for Western Europe, 89.3 per cent for Eastern Europe and 71 per cent for France, drawn from its own consent interactions during 2025. The 18-point spread between two regions makes the case against the number better than any critique: if geography moves it that much, industry, banner design and traffic source move it at least as much. These are also vendor figures with no sample size disclosed per country.
Take three of your own numbers instead, monthly, from your own systems. The consent rate per purpose rather than overall. The share of contacts that resolve to a single person. And the age distribution of the last interaction. Those three tell you more about your data base than any industry average, and they are the only ones you can honestly measure against next quarter. Knowing them also tells you when building owned reach pays off and when it merely fills storage.
Three levers for the next few weeks
Run the base through the filters once. Four filters, four percentages, one result. The number at the end is your real base, everything above it is storage. It takes an hour, and the conversation about the next reach budget goes differently afterwards.
Check consent against the purpose, not against the tick box. One line per intended use: which purpose, which legal basis, which part of the base is covered. What is not covered does not shrink by being ignored.
Measure your consent rate per purpose. From your own consent log, monthly, not from a benchmark. It is the multiplier every later piece of data work hangs on.
If you want to know what survives those four filters in your own base, we are happy to run the numbers with you. It usually takes an hour and changes the priorities for the next quarter. 📊
