DMA15

Direct marketing, 1872 to the cookie

The Wire

The Long Unwinding

From Firefox's third-party cookie restrictions (2019) through Safari's Intelligent Tracking Prevention to Google's repeated deferral of the Privacy Sandbox — the documented sequence by which the cookie's role in cross-site tracking was narrowed.

More in The Wire

Laptop screen showing search results for babysitting services and nanny agencies

Browser by browser, the cookie's role in cross-site tracking was narrowed.Photo: cottonbro studio / Pexels

The third-party cookie's collapse was not a single decision but a series of retreats — browser by browser, year by year — whose cumulative weight changed the mechanics of digital direct marketing.

A Technology That Outlived Its Tolerance

When Lou Montulli wrote the HTTP cookie specification at Netscape in 1994, he was solving a shopping-basket problem: how could a server recognise a returning browser without requiring a login? The solution was elegant and narrow. What it became was something else. By the early 2000s, advertising networks had extended the same mechanism across domains, placing third-party cookies on millions of sites simultaneously, so that a user reading a news article and later browsing a clothing retailer could be recognised as the same individual and served an advertisement that demonstrated that recognition. The mechanism was invisible to most users and, for nearly two decades, unrestricted by the major browsers that carried it.

The legal architecture began shifting first. The European Union's ePrivacy Directive of 2002, amended in 2009 (with national implementation by 2011) to require informed consent before non-essential cookies could be set, created the consent-banner landscape that European internet users would come to know as ambient noise. But browser-level restriction arrived more slowly and, when it came, arrived in sequence — Safari's early and aggressive posture, then Firefox's default blocking, then, then the prolonged and unresolved drama of Google's Privacy Sandbox.

Browser by Browser, Year by Year

Mozilla's Firefox had experimented with tracking-protection features through the mid-2010s, but the formal, documented shift to default third-party cookie restriction came with Firefox's Enhanced Tracking Protection, rolled out to all users in September 2019. The policy blocked third-party cookies from domains classified as trackers by a list maintained by Disconnect.me, a privacy-focused organisation whose classifications Mozilla adopted as its standard. The practical effect was significant: advertising networks and data-brokers whose tracking pixels and cookie-syncing operations depended on unrestricted cross-site access found themselves excluded from a browser accounting for a meaningful share of desktop traffic. The restriction was not absolute — it targeted listed domains rather than all third-party cookies — but it marked the moment a major general-purpose browser moved blocking from opt-in feature to factory default.

Apple's Safari had moved earlier in a different register. Intelligent Tracking Prevention, introduced in 2017, applied machine-learning classification to identify domains used primarily for cross-site tracking and progressively degraded the cookies they set, eventually purging them after seven days regardless of their stated expiry. Subsequent iterations tightened the window. By 2020, Safari was enforcing a one-day cap on the lifetime of cookies set through cross-site tracking contexts, and first-party cookies created via document.cookie — the client-side mechanism — were subject to expiry limits that had no parallel in earlier browser behaviour. Because Safari commands the dominant share of mobile browsing in several major markets, these restrictions carried immediate economic consequence for retargeting and attribution businesses built on persistent cross-site identifiers.

Wikidata page for Netscape Navigator showing a browser screenshot, aliases, and logo

A few bytes handed back on the next request, written in 1994 to hold a shopping basket together.

Photo: Wikidata for Digital Preservation - custom-built Wikidata interface with Netscape Navigator item Q235419 · Wikimedia Commons

An early Netscape Navigator browser window on a mid-1990s CRT monitor, an adult seated at the keyboard

Navigator, 1994.

Photo: Ruben Boekeloo / Pexels

The two browsers together represented a substantial portion of the consumer web, and by 2020 the advertising-technology industry was operating in an environment where a user's trackable trail had already grown fragmentary across a significant fraction of sessions. What remained — and what concentrated attention — was Google Chrome, which accounted for the largest single share of global browser usage ↗ and on which most of the programmatic advertising infrastructure had been calibrated.

The Privacy Sandbox and Its Deferrals

In August 2019, Google announced what it called the Privacy Sandbox: an initiative to develop open standards that would allow interest-based advertising to continue without third-party cookies identifying individuals across sites. The stated timeline was a two-year transition. Third-party cookies in Chrome would be deprecated by early 2022, the company indicated. Publishers and advertising networks began restructuring their technical stacks in anticipation.

The deadline moved. In June 2021, Google pushed the target to late 2023, citing the need for the industry to have adequate time to test replacement technologies. The most scrutinised of those technologies was Federated Learning of Cohorts — FLoC — which proposed grouping users into interest-based cohorts computed locally on the browser, so that advertisers could target categories without the underlying individual identifier leaving the device. The approach drew criticism from privacy advocates, who argued that cohort membership could itself function as a fingerprinting vector, and from regulators. The United Kingdom's Competition and Markets Authority opened an investigation into the Privacy Sandbox in January 2021, concerned that removing third-party cookies while introducing a Google-controlled alternative could entrench the company's advertising dominance. The resulting commitments Google made to the CMA — documented in the regulator's published undertakings — required that any replacement system be developed with regulatory oversight and that Chrome's own advertising products receive no preferential access.

FLoC was quietly retired in early 2022, replaced by Topics API, a revised mechanism that assigned users to a small set of weekly interest categories drawn from their browsing history, stored on the device and shared selectively with advertising requests. The conceptual shift from cohorts to topic labels addressed some of the fingerprinting concerns but did not resolve the fundamental regulatory attention the project attracted. Testing continued through 2022 and into 2023, while the deprecation deadline receded again — this time to the second half of 2024.

Then, in April 2024, Google announced a further deferral, acknowledging that it did not expect to complete third-party cookie deprecation in Chrome during 2024. The company cited the need to resolve outstanding questions with regulators and to allow further industry testing. For the advertising-technology sector, the announcement compressed into a single moment the accumulated frustration of a five-year planning exercise conducted against a target that kept retreating. The cookies, for the moment, remained.

What the Sequence Left Behind

The practical legacy of the long unwinding was not the disappearance of cross-site tracking but its stratification. In Safari and Firefox environments, third-party cookie-based tracking had already been substantially disrupted, and the industry had responded with a set of workarounds whose legitimacy varied: server-side tagging, first-party data strategies, identity graphs stitched from hashed email addresses, and probabilistic fingerprinting methods that privacy researchers documented as persisting despite browser restrictions. Where cookies had once provided a standardised, auditable mechanism, the alternatives were more opaque and unevenly regulated.

For direct marketing — a practice defined since its catalogue origins by measurable response and traceable customer behaviour — the disruption was structural rather than cosmetic. The attribution chain linking an advertising exposure to a confirmed transaction, which the third-party cookie had made technically routine across two decades, became contested in environments where the cookie no longer operated. Advertisers returned, with varying enthusiasm, to modelled attribution, media-mix approaches, and the cultivation of house files — the proprietary customer data that Robert Kestnbaum's RFM model had always prioritised over rented audience access. The oldest instrument in direct marketing reasserted itself: the customer relationship a company had already earned and recorded in its own systems.

The cookie did not die on a fixed date. It underwent a slow restriction whose pace was set by competing institutional interests — browser makers, regulators, advertising networks, and legislators across multiple jurisdictions — and the outcome remained, as of the most recent documented deferrals, unresolved. What the sequence established beyond dispute was that a twenty-year consensus about how the web tracked commercial behaviour had ended, and that no consensus on what would replace it had yet formed.