Skip to content
Tuesday, September 8, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Privacy
Privacy

Cookies and trackers explained: what actually follows you around the web

First-party cookies log you in; third-party cookies follow you site to site — and while the industry retires the oldest tracker, fingerprinting and cross-device identifiers keep the ad economy watching.

Malik Johnson, · June 11, 2026 · 4 min read
ShareXFacebookLinkedInTelegramEmail
Newsstand with many magazines symbolizing cross-site tracking
Cookies and trackers explained: what actually follows you around the web | AI-generated illustration

A cookie is a small file a website stores in your browser to remember something; the privacy problem comes from third-party cookies — set by advertising and analytics companies embedded across millions of sites — which stitch your browsing into one profile readable anywhere their code runs. The first kind is mostly benign and functional: it keeps you logged in, holds your cart, remembers preferences. The second kind built the surveillance-advertising economy, and its slow retirement — Google's multi-year, much-delayed phase-out of third-party cookies in Chrome, alongside the blocking Safari and Firefox have shipped for years — has not ended tracking; it has shifted it toward fingerprinting, logged-in identifiers, and alternative data pipelines.

What are the types?

What happened to third-party cookies?

A decade of pressure: regulators in Europe subordinated them to consent under the GDPR's ePrivacy rules — hence the cookie banners; Safari blocked third-party cookies by default in 2020 (ITP), Firefox via Enhanced Tracking Protection for years before; Chrome, holding the majority share that mattered, announced its phase-out in 2020 and then repeatedly delayed it through regulatory and industry objections — by 2024-2025 Google had settled on a user-choice model rather than full deprecation, leaving the ecosystem to continue alongside opt-out mechanisms. The practical result: in Safari and Firefox the classic third-party cookie is largely dead, in Chrome it persists under growing friction, and the advertising industry has spent the transition building alternatives that do not need it.

Related stories: Browser fingerprinting explained: how sites recognize you without cookies · What a VPN actually protects — and the five things it doesn't.

What replaced it?

Partly logged-in walled gardens — platforms tracking you inside their apps where browser rules never applied; partly first-party data collection, where retailers and publishers do their own profiling; partly fingerprinting and IP-based inference; and partly "privacy-preserving" APIs of the kind Google proposed through the Privacy Sandbox project, whose on-device ad-interest design drew years of regulatory scrutiny and competition concerns. The net privacy change is real but modest: cross-site tracking got costlier and less accurate, not impossible, and the consent banners the GDPR produced became their own nuisance industry.

What can you actually do?

  1. Block third-party trackers in the browser: Firefox's Strict mode and Safari do this by default; Chrome users can add a reputable content blocker. This removes the classic cross-site cookie without breaking logins.
  2. Keep first-party cookies on unless you enjoy logging into everything — clearing them constantly mostly punishes you.
  3. Use browser profiles or containers to separate contexts — work, shopping, reading — so profiles cannot merge across your roles.
  4. Limit supercookies and storage abuse: modern browsers isolate and purge these automatically; keeping the browser current is the whole action there.
  5. Handle cookie banners minimally: reject where the choice is genuine; where a site makes refusal painful, decide whether the site is worth it — and note that the banner itself signals the site's data appetite.
  6. For app-based tracking, use the OS-level controls — Apple's App Tracking Transparency prompt and Android's ad-ID reset and deletion — which govern the identifiers cookies never touched.

Where is this heading?

Toward identity rather than cookies: logged-in ecosystems, first-party data, and — on the regulatory side — consent-or-pay models, Global Privacy Control signals, and state opt-out laws pressuring the same machinery from another angle. The tracker's job never disappeared; it fragmented. For readers, the durable defenses are structural — content blocking, profile separation, and minimizing the number of logged-in trackers you carry through daily life — because every one of them works across whichever tracking technology the industry ships next.

Frequently Asked Questions

What is the difference between first-party and third-party cookies?
First-party cookies are set by the site you visit and keep you logged in and your cart intact. Third-party cookies are set by ad and analytics companies embedded in pages across the web, letting them follow your browsing from site to site.
Are third-party cookies gone?
Safari and Firefox block them by default; Chrome announced a phase-out in 2020 but repeatedly delayed it, settling on user-choice mechanisms. Meanwhile trackers shifted to fingerprinting, logged-in identifiers, and first-party collection.
Does clearing cookies stop tracking?
It removes stored identifiers, which helps against classic cookies, but not against fingerprinting, pixels, or identifiers tied to logged-in accounts. Browser-level tracker blocking plus profile separation does more than manual cookie clearing.
Why are cookie banners everywhere?
European ePrivacy rules require consent before setting non-essential cookies, and sites serving EU visitors apply the banners globally. The banner's existence tells you the site runs non-essential trackers you can refuse.