Google’s Privacy Sandbox is Dead. The Fight for Real Online Privacy Continues.
In April, Google announced the final abandonment of its “Privacy Sandbox” and its planned deprecation of third-party cookies. This announcement comes as a federal judge considers remedies to address his finding that the company illegally maintained a monopoly in search, and on the heels of a separate ruling that Google maintains illegal monopolies in two key online-advertising markets. While it’s unclear what relationship, if any, may exist between these antitrust trials and Google’s about-face on privacy, this is a sad and embarrassing end to the “Privacy Sandbox” that Google promised in 2019.
Background
Google’s announcement of the “Privacy Sandbox” described it as an initiative “to create technologies that both protect people’s privacy online and give companies and developers tools to build thriving digital businesses.” In particular, Google promised to end support for third-party cookies — a mechanism widely abused for cross-site surveillance — which other browser vendors had already moved away from. Instead, the company offered to work with industry and other stakeholders to develop designed-for-purpose alternative mechanisms (known as the Privacy Sandbox APIs) that would maintain certain advertising, login, and fraud prevention functionality without enabling expansive tracking of user activity.
This announcement seemed to combine respect for privacy with a feasible alternative approach to advertising. There is clear evidence that third-party cookies are unnecessary to support online advertising[1] and widespread consensus on the importance of privacy from cross-site tracking (see W3C’s Privacy Principles, endorsed by the W3C and its members, or the Technical Architecture Group’s more direct note, Third Party Cookies Must Be Removed).
But since the initial announcement Google has repeatedly delayed and watered down its plans to remove third-party cookies, even as it added new advertising-related targeting functionality. Many observers — and Google itself — pointed to a supposed tension between privacy and competition to explain these delays, arguing that the company needed to move cautiously in order to avoid illegally preferring its own advertising properties. In an agreement with the UK’s Competition and Markets Authority (CMA), for instance, Google consulted with the CMA and industry representatives to that end. That process was done in consultation with the Information Commissioner’s Office (ICO), which had documented widespread violations of privacy law enabled by third-party cookies. But despite significant delays, the result seemed to offer few actual privacy advances.
In late 2024 Google cancelled its initiative to remove third-party cookies from Chrome and instead announced plans for a user prompt to give users some control. This news was a deep disappointment for privacy advocates, but warmly welcomed by advertising companies. Google provided no timeline for when privacy improvements would finally arrive, and as of April 2025 that plan has also been abandoned: users won’t see a prompt to choose whether or not to allow third-party tracking cookies, but will have to dig around in existing settings to find basic and overdue privacy protections.
What does this mean for users?
Users of Google’s Chrome browser, currently the most widely used browser on both desktop and mobile[2], will continue to be tracked, profiled, and targeted in invasive ways that they may not understand and likely won’t be able to control. Users will see creepy ads follow them around the web, including across the different devices they use. More importantly, users’ personal data will be handed over to data brokers who build profiles to sell to other companies, law enforcement, and foreign governments. Methods to opt out will remain unreliable and hard to find.
It’s clear now that Google will maintain Chrome’s privacy-hostile features, not in order to make a better browser but to benefit its advertising business and the business priorities of its advertising partners. Users may, for now, be able to configure their Chrome browser to block third-party cookies, but this precedent suggests that future decisions may also undermine online privacy if it benefits Google to do so.
Because of Google’s dominant roles in both the browser and advertising markets and the need for interoperability on the web, this set-back won’t just hurt users of Chrome, but will also make it harder for other browsers, publishers, and advertisers to implement privacy protections and forms of online advertising that are more respectful of privacy. It seems likely that Google will further starve Privacy Sandbox API development of resources, given the reduced incentives for adoption.
What have we learned?
Google made repeated promises to remove third-party cookies and replace them with more privacy-respecting alternatives: in blog posts (August 2019, January 2020, October 2020, January 2021, July 2022, May 2023, September 2023, October 2023, December 2023, April 2024, July 2024), numerous statements to the press, years of meetings in standards bodies, agreements with regulators, and announcements in public events. Given its about face, any future plans or promises from Google on privacy in the advertising context will understandably be met with skepticism.
More vigorous regulatory enforcement that combines expertise in both privacy and competition will be necessary to see genuine privacy improvements for the majority of web users alongside competition in ad tech markets. While Google’s various Privacy Sandbox announcements and the UK Competition and Markets Authority claimed an interest in broad stakeholder feedback, it became increasingly clear over time that each was only interested in direct feedback from other ad tech firms. With a lack of serious engagement or pressure from privacy regulators, government, academia, and consumer advocates were sidelined and ultimately ignored. A single jurisdiction’s competition authority is an ineffective substitute for the expertise of privacy regulators or academic and public interest privacy experts.
In light of the experience of this delayed, failed corporate project over the past five years, it is difficult to see how meaningful privacy improvements will be achieved for the most popular browser without meaningful regulatory pressure. Given the Trump administration’s gutting of federal consumer protection agencies, Congress’s continued failure to pass a national comprehensive privacy law, and the weakness of most state privacy laws, that pressure may not materialize in the U.S., at least in the near future. Appropriate antitrust remedies could potentially help by removing barriers to competition from more privacy-protecting browser vendors and more privacy-preserving advertising systems. We will be following the next steps in the US Department of Justice’s antitrust cases against Google closely, though, with likely legal appeals to come, any remedy there probably also will take years to implement.
What is next for privacy in online advertising?
As CDT has repeatedly warned, backing off of privacy protections in browsers reduces the incentive for ad tech firms to migrate to more privacy-preserving technologies for advertising. More privacy-preserving advertising is achievable, and many in industry, civil society, and academia have invested extensively in the design of those mechanisms. Google has set those efforts further back in an anti-competitive way that temporarily benefits those companies that rely on an unsustainable, privacy-hostile status quo.
Google’s move also squanders years of engineering work from many of its own employees, as well as others throughout industry and academia. Some have lost, or may lose, their jobs. That’s a frustrating loss for those workers, although we hope their expertise and efforts can be matched with companies committed to building more privacy-friendly products.
Despite these setbacks, the need to move past these opaque and ubiquitous forms of tracking remains. Some alternative identifiers that have been proposed largely replicate or even expand on the harmful abuses of third-party cookies. The productive way forward is instead to pursue respectful, privacy-preserving forms of online advertising. Despite the delay and distraction of Google’s purported privacy sandbox, the industry is making progress on privacy-preserving methods of measurement and attribution of advertising. We see those efforts making progress in the W3C’s Private Advertising Technology Working Group, for example.
While some advertising companies may not willingly embrace online privacy, users have both legal and technical tools to assert their rights. Laws in many jurisdictions prohibit cross-site tracking by default, or provide users with a simple way to opt-out. To that end, CDT is working with allies to standardize the Global Privacy Control at W3C. Technical features to limit various forms of tracking (including among others: bounce tracking, browser fingerprinting, IP address tracking, and tracking through personal information) are under development and standardization at W3C and IETF.
Where companies are willing to make prompt and meaningful progress on privacy in online advertising, we remain interested in collaborating with them.
The norms of conversational advertising are being written right now by companies. Policy should be written alongside them, and it should start with recognizing that surreptitious manipulation at scale built on intimate information is itself a privacy harm, and a privacy law can, in part, solve some of those issue
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.
Changing Course to Get It Right: The Advisory Committee Reviews Its AI Evidence Rule
CDT is keeping a close eye on Proposed Federal Rule of Evidence 707, which would govern when AI-generated information can be admitted as evidence in federal court — and many state courts where the federal rules are routinely adopted — without a human expert to explain it.