Free guide:winning new clients predictably in 2026 · 10 pages, freeGet it now

First-party data: what it is actually worth

In 2025 Google called off the cookie deprecation and then retired the replacement project. That removes the reason most companies built first-party data in the first place. The value is still there, but it sits somewhere else: in consent, in resolvability and in recency. Here is the calculation.

Cover: First-party data: what it is actually worth

For five years the same line has appeared in every other marketing deck: third-party cookies are dying, so build first-party data. The first half has now been disproven. Google called off the deprecation in 2025 and retired the replacement project shortly afterwards. The second half still holds, just for different reasons than the ones that were sold at the time. That shifts the question. It is no longer whether you collect data, but how much of what already sits in your systems can actually be used. Let us work through it: what was really decided in 2025, how much of your traffic was never in the cookie game anyway, and which four filters turn 10,000 contacts into a few hundred.

What actually happened in 2025?

In January 2020 Google announced it would remove third-party cookies from Chrome within two years. Five years of delay followed. On 22 April 2025 Anthony Chavez, VP of Privacy Sandbox, wrote the sentence that ended it: "we've made the decision to maintain our current approach to offering users third-party cookie choice in Chrome, and will not be rolling out a new standalone prompt for third-party cookies". No removal, no choice prompt, everything stays in Chrome's settings where it already was.

Six months later the replacement went too. On 17 October 2025 the same team retired ten Privacy Sandbox technologies, among them Topics, Protected Audience and the Attribution Reporting API. The reasoning is in the post verbatim: "After evaluating ecosystem feedback about their expected value and in light of their low levels of adoption, we've decided to retire the following Privacy Sandbox technologies". Three narrow pieces remain: CHIPS, FedCM and Private State Tokens.

Timeline of the cookie deprecation: in January 2020 Google announces the removal of third-party cookies from Chrome within two years. Delays follow in 2021, 2022 and 2024. On 22 April 2025 Google calls the removal off and also drops the planned choice prompt. On 17 October 2025 ten Privacy Sandbox technologies are retired, among them Topics, Protected Audience and the Attribution Reporting API. CHIPS, FedCM and Private State Tokens remain.
The announced deadline of January 2022 was never reached. Milestones: announcement January 2020, delays in 2021, 2022 and 2024, cancellation on 22 April 2025, retirement of ten technologies on 17 October 2025. Sources: Google Privacy Sandbox, "Next steps for Privacy Sandbox and tracking protections in Chrome", 22 April 2025 and Google Privacy Sandbox, "Update on plans for Privacy Sandbox technologies", 17 October 2025. Retired: Attribution Reporting, IP Protection, On-Device Personalization, Private Aggregation, Protected Audience, Protected App Signals, Related Website Sets, SelectURL, SDK Runtime, Topics.

Two things follow for practitioners. Anyone who justified a data programme with the deadline alone has lost the argument. And anyone who concludes the topic is settled is confusing a cancelled date with a solved problem. Cross-domain attribution does not work any better today than it did before the cancellation, it is simply no longer in the calendar.

Does that mean you can carry on as before?

No, and for a reason that never depended on Google. Chrome is only part of the market. Safari has blocked third-party cookies fully since March 2020, Firefox has blocked third-party tracking cookies by default since September 2019 and has isolated the rest since 2022, and Brave was never configured any other way. None of these browsers were waiting for a deadline.

Do the sum for your own market. For July 2026 Statcounter puts Chrome in Austria at 48.19 per cent, Safari at 21.27, Edge at 10.64 and Firefox at 9.95 per cent. Safari and Firefox together are 31.22 per cent: close to a third of your Austrian traffic was never in the cookie game, regardless of any announcement. In Germany the same figure is 25.18 per cent, because Chrome is stronger there.

Bar chart of browser share in Austria in July 2026: Chrome 48.19 per cent, Safari 21.27 per cent, Edge 10.64 per cent, Firefox 9.95 per cent. Safari and Firefox are highlighted because they block third-party cookies by default and add up to 31.22 per cent. In Germany, Safari at 16.33 and Firefox at 8.85 per cent add up to 25.18 per cent.
Browser share in Austria, July 2026: Chrome 48.19 %, Safari 21.27 %, Edge 10.64 %, Firefox 9.95 %. Safari and Firefox block third-party cookies by default, 31.22 % combined. Germany in the same month: Chrome 58 %, Safari 16.33 %, Firefox 8.85 %, Edge 7.28 %, blocking share therefore 25.18 %. Source: Statcounter Global Stats, Browser Market Share Austria and Germany, July 2026, measured on page views. Adding the two blocking shares is our own arithmetic; Brave and other blockers sit in "Other" and are not included here.

So the deadline was never the event. The event was a gradual loss of visibility that has already happened. That is exactly why your own data base still matters: it is the only part of the measurement that does not depend on a stranger's browser setting.

What is your data base actually worth?

The number that ends up in the deck is almost always the row count in the CRM. That is not an asset, it is a storage figure. Only the share that survives four filters is usable, and the filters multiply.

First, consent, and consent for the purpose you have in mind rather than for something adjacent. Second, resolvability: the same person must not sit in the system as three records with three spellings, or you will count them three times and contact them three times. Third, recency, because an address from 2021 is a guess, not an audience. Fourth, linkability: a record that cannot be tied to behaviour on your site or to a purchase cannot predict anything.

A four-step worked example: of 10,000 contacts in the CRM, 6,000 remain after consent for the specific purpose, 4,800 after removing duplicates, 2,640 after a twelve-month recency filter and 1,848 after requiring a linkable behaviour or purchase event. That is 18 per cent of the starting base.
Worked example with four filters: 10,000 contacts, of which 60 % have consent for the intended purpose (6,000), of which 80 % resolve to a single person (4,800), of which 55 % have interacted in the past twelve months (2,640), of which 70 % have a linkable behaviour or purchase event (1,848). Result: 18.5 % of the starting base. An assessment from our editorial work, not a measurement. The four rates are placeholders to be replaced with your own; the multiplicative effect remains either way.

Whether your own answer is 18 or 40 per cent is not the point. The point is the multiplication. Four rates that sound harmless on their own leave you with a fraction. And every euro spent on reach to turn 10,000 into 12,000 works against that multiplication rather than improving it. The cheaper lever is almost always on the right-hand side of the sum. This is also where the topic differs from plain data hygiene, which we covered in CRM hygiene before AI: there the question is whether automations run cleanly, here it is how large your usable base is in the first place.

A common misreading: whatever happens on your own domain needs no consent. That is written nowhere. In Germany, section 25(1) TDDDG governs access to end devices, and the wording knows no first or third party: "Die Speicherung von Informationen in der Endeinrichtung des Endnutzers oder der Zugriff auf Informationen, die bereits in der Endeinrichtung gespeichert sind, sind nur zulässig, wenn der Endnutzer auf der Grundlage von klaren und umfassenden Informationen eingewilligt hat." The exception in subsection 2 number 2 applies only where access is strictly necessary to deliver the service the user has explicitly requested. Audience measurement does not qualify, including your own.

Austria says the same in section 165(3) TKG 2021. The Austrian data protection authority puts it plainly enough in its FAQ that no interpretation is needed: "Für alle 'technisch nicht notwendigen Cookies' muss eine Einwilligung eingeholt werden." For all cookies that are not technically necessary, consent must be obtained. The authority does mention sorting cookies by domain, but as a description, not as a permission. First-party analytics needs the same consent as somebody else's pixel.

On top of that sits purpose limitation under Article 5(1)(b) GDPR. Data collected to fulfil an order does not automatically become a newsletter base, and certainly not training material. Miss that and you build a base that is large on paper and unusable in practice. Which is why sound consent management belongs in the data strategy rather than in the legal department: it decides how much of your base counts at all. And moving measurement to the server with server-side tagging relocates the plumbing, not the consent requirement.

Which number to use instead of a benchmark

The obvious shortcut is an external comparison. The consent platform Didomi reports in its 2026 European benchmark a consent rate of 75.1 per cent for Western Europe, 89.3 per cent for Eastern Europe and 71 per cent for France, drawn from its own consent interactions during 2025. The 18-point spread between two regions makes the case against the number better than any critique: if geography moves it that much, industry, banner design and traffic source move it at least as much. These are also vendor figures with no sample size disclosed per country.

Take three of your own numbers instead, monthly, from your own systems. The consent rate per purpose rather than overall. The share of contacts that resolve to a single person. And the age distribution of the last interaction. Those three tell you more about your data base than any industry average, and they are the only ones you can honestly measure against next quarter. Knowing them also tells you when building owned reach pays off and when it merely fills storage.

Three levers for the next few weeks

Run the base through the filters once. Four filters, four percentages, one result. The number at the end is your real base, everything above it is storage. It takes an hour, and the conversation about the next reach budget goes differently afterwards.

Check consent against the purpose, not against the tick box. One line per intended use: which purpose, which legal basis, which part of the base is covered. What is not covered does not shrink by being ignored.

Measure your consent rate per purpose. From your own consent log, monthly, not from a benchmark. It is the multiplier every later piece of data work hangs on.

If you want to know what survives those four filters in your own base, we are happy to run the numbers with you. It usually takes an hour and changes the priorities for the next quarter. 📊