A third-party cookie is a cookie set not by the website being visited but by another domain serving that site, such as an ad network, analytics provider or social media plugin. It is the opposite of a first-party cookie. Because the provider can recognise the visitor on every site where it reads its cookies, it is the main tool of cross-site tracking.
The test is the domain that writes the cookie: a cookie set from the visited site's own domain is first party, while one set from the domain of an embedded service is third party. Ad networks, social media buttons, embedded videos and some analytics tools leave third-party cookies. Because these cookies can be read on every site the provider serves, a visitor's browsing history can be stitched together across sites; profiling and targeted advertising largely rest on this mechanism. Browsers are also restricting them: Safari and Firefox block third-party cookies by default, pushing the industry towards first-party data and consent-based measurement.
Legally, a site owner using third-party cookies cannot ignore that data flows to external providers. Visitors must be told which third parties receive data, and non-essential third-party cookies require consent before they are set. Practical steps: scan the site to identify which third-party domains write cookies, list each provider with its purpose in the cookie policy, block non-essential ones until consent arrives, and remove unused legacy plugins. Remember that every embedded component (video, map, chat, share button) can bring cookies with it, so check the cookie impact before adding new ones.
Frequently asked questions
What is the difference between first-party and third-party cookies?
The difference lies in the domain that writes the cookie. A first-party cookie is set from the visited site's own domain and usually serves on-site functions such as sessions, carts and preferences. A third-party cookie is set from the domain of an external embedded service and can recognise the visitor across multiple sites. What determines the consent requirement, however, is the cookie's purpose, not the party.
Are third-party cookies going away?
They are being restricted, but they have not fully disappeared. Safari and Firefox block third-party cookies by default; on the Chrome side, the timeline and approach have changed over time and a full removal has not happened. The direction is clear: the industry is shifting towards first-party data, consent-based measurement and mechanisms like Google Consent Mode. For site owners, a consent setup is necessary regardless of this transition.
This content is for information only and is not legal advice.