If your compliance roadmap still has a line item for "prepare for third-party cookie deprecation," delete it. Google isn't deprecating third-party cookies. It just finished deprecating the six-year project that was supposed to replace them.
Your team spent 2021 through 2024 preparing for a cookieless web that never arrived, and now the story has flipped again: on October 17, 2025, Google retired ten of the remaining Privacy Sandbox APIs and effectively closed the initiative. If your first reaction is relief that you can stop rebuilding your ad stack, your second reaction should be caution. Nothing about this retirement touches your obligation to run a cookie banner, and treating it as a compliance off-ramp is the fastest way to end up on the wrong side of a regulator.
Key Takeaways
- Google retired ten Privacy Sandbox APIs on October 17, 2025 (Attribution Reporting, Topics, Protected Audience, and seven others), ending the project meant to replace third-party cookies.
- Third-party cookies remain in Chrome indefinitely; GDPR and ePrivacy consent requirements for them are completely unchanged by this decision.
- Google Consent Mode v2 has nothing to do with Privacy Sandbox and is still mandatory for EEA/UK traffic on Google Ads, GA4, and DV360.
What Google actually announced, in order
Three separate announcements, eighteen months apart, get conflated into one story. They aren't the same event.
July 2024: Google confirmed it would not go ahead with its original plan to phase out third-party cookies in Chrome by a fixed deadline. This was the first reversal, and it's the one our earlier analysis of Google's cookie deprecation reversal already covered in depth.
April 22, 2025: Google went a step further and dropped its fallback plan too. It had floated a standalone "choice prompt" that would ask Chrome users, once, whether they wanted third-party cookies on or off. In Google's own announcement, VP Anthony Chavez confirmed the company would not build that prompt, and left cookie preferences where they'd always lived: buried in Chrome's Privacy and Security settings.
October 17, 2025: This is the news your compliance calendar actually needs. In an official Privacy Sandbox blog post, Chavez announced the retirement of ten remaining Sandbox APIs, including Attribution Reporting, Topics, Protected Audience, Protected App Signals, Private Aggregation, Shared Storage, On-Device Personalization, SelectURL, SDK Runtime, and IP Protection, across both Chrome and Android. In Chavez's own words, "After evaluating ecosystem feedback about their expected value and in light of their low levels of adoption, we've decided to retire" the technologies. Three narrower pieces survive: CHIPS (partitioned first-party cookies), FedCM (federated login), and Private State Tokens (anti-fraud signals), and Google says it will keep pursuing an interoperable attribution standard through the W3C rather than through its own API.
Put together, the mechanism state is simple: third-party cookies are staying, by default, indefinitely, and the browser-native replacement for them is dead. Low adoption wasn't the only pressure on Sandbox: the UK Competition and Markets Authority, the European Commission, and the US Department of Justice had all separately raised competition concerns about how Google's proposed replacement would reshape the ad market, adding regulatory friction to a project that was already struggling for industry buy-in.
Why none of this touches your consent obligations
Here's the mechanism a lot of ad-tech coverage skips past: Chrome's cookie behavior and your legal obligation to get consent for cookies are governed by two completely separate things. Chrome's setting determines whether a cookie can technically be dropped on a device. The ePrivacy Directive (in the EU) and equivalent state and national laws elsewhere determine whether you're allowed to drop it without asking first, and that determination was never contingent on what Chrome's default happened to be.
Article 5(3) of the ePrivacy Directive has required prior consent for any non-essential cookie, first-party or third-party, since long before Google ever proposed deprecating anything. The European Commission's formal withdrawal of the long-stalled ePrivacy Regulation proposal in February 2025 didn't change this baseline either. It left the existing ePrivacy Directive, as implemented and amended across member states, as the operative law. So the practical consequence for a reader who built a compliant banner and consent architecture for the "cookies stay" scenario, which is the scenario every serious CMP vendor has been advising since mid-2024, is: none. Nothing needs retrofitting. If your banner already requests consent before any non-essential cookie fires and logs that decision, October's announcement is a non-event for your legal posture.
Where this actually bites is if your organization quietly assumed "Google is handling cookies now" and let banner discipline slip. It doesn't, and it isn't. A clear cookie consent process is still the only thing standing between your site and a regulator finding non-essential cookies firing pre-consent, and that finding doesn't care whether the cookie in question was ever slated for Privacy Sandbox replacement.
Micro-CTA: If you're not certain your current banner is still blocking non-essential cookies until consent is captured, run a free scan through Secure Privacy's cookie consent solution before assuming you're covered.
What actually did change operationally
Two things are genuinely different for some organizations, and they're both narrower than the headlines suggest.
First, if your team had engineering time invested in Topics API integration, Protected Audience auctions, or Attribution Reporting for measurement, that work is now a dead end. Those APIs are retired, not paused, and Google has been explicit that it isn't reviving them. Budget and roadmap time earmarked for Sandbox integration should be reallocated, most naturally toward first-party data strategy and cookieless tracking approaches that don't depend on any single vendor's browser API surviving.
Second, and this is the myth this article exists to bust: Google Consent Mode v2 is entirely unaffected. Consent Mode is not a Privacy Sandbox technology. It's a signaling layer between your CMP and Google's own ad and measurement products (Google Ads, GA4, Display & Video 360, Search Ads 360), and, per Google's own consent mode documentation, it became mandatory for EEA and UK traffic back in March 2024, under a completely separate compliance track tied to Google's own advertiser terms, not to the cookie-deprecation timeline. If you're using a Google-certified Consent Mode v2 implementation, the Sandbox retirement changes nothing about how that signal fires, what it reports, or whether you still need it. You do.
| Category | Status before October 2025 | Status after October 2025 |
|---|---|---|
| Third-party cookies in Chrome | Retained by default since 2024 reversal | Unchanged: retained by default, no deprecation date |
| Privacy Sandbox APIs (Topics, Attribution Reporting, Protected Audience, etc.) | Active, in limited use | Retired; not being revived |
| CHIPS, FedCM, Private State Tokens | Active | Still active, unaffected |
| GDPR/ePrivacy consent requirement for cookies | Applies to all non-essential cookies | Unchanged; applies identically |
| Google Consent Mode v2 (EEA/UK) | Mandatory since March 2024 | Unchanged; still mandatory |
Common issues and fixes
"We paused our banner work in 2024 assuming cookies were going away." Resume it now. The 2024 reversal already meant cookies weren't going away; October's Sandbox retirement only confirms it further. Audit your current banner against ePrivacy Directive Article 5(3) requirements today rather than waiting for another announcement.
"Our ad team thinks Consent Mode is part of Privacy Sandbox and got quietly deprioritized." Separate the two explicitly in any internal documentation. Consent Mode v2 sits on Google Ads and GA4 infrastructure, not Sandbox infrastructure, and losing it costs you conversion modeling and remarketing audiences in the EEA regardless of what happened to Topics or Attribution Reporting.
"We built Sandbox-dependent measurement and don't know what replaces it." Nothing officially does yet; Google's own stated path is a W3C interoperable attribution standard with no committed date. Treat any Sandbox-dependent build as retired infrastructure, not a project to keep maintaining.
FAQ
Do I still need a cookie banner now that Google isn't deprecating third-party cookies?
Yes. Your obligation to get consent before setting non-essential cookies comes from the ePrivacy Directive and GDPR, not from Chrome's default cookie behavior, and that legal requirement hasn't moved regardless of what Chrome does by default.
Did retiring Privacy Sandbox kill Google Consent Mode?
No. They're unrelated systems. Privacy Sandbox was a set of browser APIs meant to replace third-party cookies for ad targeting; Consent Mode v2 is a consent-signaling layer for Google's own advertising and analytics products, and it remains mandatory for EEA and UK traffic.
What happened to the Privacy Sandbox APIs specifically?
Google retired ten of them on October 17, 2025, including Topics, Attribution Reporting, and Protected Audience, across Chrome and Android, citing low adoption. Three narrower technologies (CHIPS, FedCM, Private State Tokens) continue.
Does this mean third-party cookies are safe from deprecation permanently?
Google has given no new deprecation date and has walked back two separate deprecation plans since 2024. "Indefinitely retained by default" is the accurate description of the current state, not a permanent guarantee, so ongoing monitoring still matters.
If we invested in Privacy Sandbox integration, is that work wasted?
The APIs themselves are retired and won't be revived, so integration work tied specifically to Topics, Attribution Reporting, or Protected Audience should be considered sunset. First-party data infrastructure built alongside that work generally is not wasted.
Does this change anything about IAB Europe's Transparency and Consent Framework?
No. TCF governs how consent signals are communicated to vendors across the programmatic ecosystem and operates independently of any single browser's cookie-deprecation plans.
Should we update our cookie policy or consent banner because of this announcement?
Only if your existing banner has gaps unrelated to this news, such as pre-ticked boxes or cookies firing before consent. This announcement itself doesn't require any banner changes.
Nothing in this cycle changes what a defensible consent setup looks like. It changes what your ad-tech roadmap should stop spending time on. If your banner, blocking, and logging were already built for a world where third-party cookies stick around, this is a non-event. If you're not sure they were, a scan-based compliance check will tell you in minutes, not another planning cycle.




