Glossary

Third-party cookie

A cookie stored on a domain other than the one the visitor is on, historically the backbone of cross-site advertising and now widely restricted by browsers.

Set on
A domain other than the site
Browser status
Blocked by default in several browsers
Consent status
Unchanged by browser restrictions

What it is

When a page loads a resource from another domain, that domain can set a cookie of its own. Because the same domain appears across many sites, it can recognise the same browser in each of them, which is what made cross-site advertising work.

Browser treatment of third-party cookies differs and continues to change. Vendors may instead use first-party storage, server-side collection or identifiers derived from data a site supplies, so “first-party cookie” does not by itself mean “first-party recipient”.

Restriction is not exemption

A blocked cookie does not mean nothing happened

A request may still leave the browser and disclose data such as an IP address, URL, referrer or user agent. Device-storage rules and general data-protection rules are related but distinct: a request with no device storage or access may still process personal data under the GDPR, while the ePrivacy terminal-equipment rule depends on storage or access. Do not infer one conclusion from the other.

This is why verification looks at network requests rather than just at the cookie jar. A scan that only counted cookies would report a clean result for a page that is still calling an advertising endpoint on every load.

Common questions

If browsers block them, do I still need consent?

Yes. Consent attaches to the purpose and to the act of storing or accessing information, not to whether one particular browser allowed it. Some of your visitors use browsers that still permit it, and the outbound request happens either way.

Is first-party storage a way around consent?

No. Moving an identifier from a third-party cookie into first-party storage changes the mechanism, not the purpose. The scanner classifies by vendor name precisely so that the move does not hide the tracker.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.