Third-Party Cookies
Third-party cookies are small text files placed on a user's device by a domain other than the website the user is actually visiting. They are commonly associated with cross-site tracking, advertising, and analytics, because the same third-party domain can recognize a user across many different websites. Because they typically serve purposes beyond what is strictly necessary to deliver a site, they generally require prior consent under EU rules, though obligations vary by jurisdiction.
A third-party cookie is a cookie set under a domain different from the top-level or first-party domain of the site the user is browsing, enabling the setting party to read and write state in a cross-site context. Functionally, this cross-site recognition underpins use cases such as ad targeting, conversion measurement, and cross-domain analytics. In the EU and UK, the ePrivacy Directive as implemented nationally governs the storing of and access to such cookies on a user's device and, for non-exempt purposes, generally requires prior, freely given, specific, informed, and unambiguous consent; any personal data subsequently processed also falls within the scope of the GDPR. These are separate legal requirements, and consent under one does not automatically satisfy the other. US state privacy regimes such as the CCPA/CPRA in California typically approach cross-site tracking through an opt-out model rather than opt-in, so applicable obligations depend on the relevant jurisdiction. The classification of a cookie as third-party turns on the domain that sets or accesses it rather than the file format, and similar cross-site tracking may also be achieved through pixels, SDKs, local storage, or fingerprinting, which fall within the same consent rules. Browser and platform restrictions on third-party cookies affect their technical availability but are distinct from, and do not replace, legal consent obligations.
Why it matters
Third-party cookies sit at the center of most cross-site tracking, advertising, and analytics activity, which makes them one of the most scrutinized technologies in cookie consent compliance. Because a single third-party domain can recognize a user across many unrelated websites, these cookies generally serve purposes that go beyond what is strictly necessary to deliver a site. In the EU and UK, that typically means they require prior, freely given, specific, informed, and unambiguous consent under the ePrivacy Directive as implemented nationally, before they are placed on or read from a user's device. Getting this wrong exposes organizations to regulatory risk and undermines the trust users place in a site.
Who it's relevant to
Inside Third-Party Cookies
Common questions
Answers to the questions practitioners most commonly ask about Third-Party Cookies.