Building a more private web: A path towards making third party cookies obsolete
- Document
- 22 August 2019
- Event
- 22 August 2019
- Retrieved
- 16 September 2026
The revenue mechanism
On 22 August 2019, Google published a post titled 'Building a more private web', announcing what it called the Privacy Sandbox: a plan to build new, browser-based standards letting advertisers target and measure ads without an outside script reading a shared, cross-site identifier stored in a third-party cookie. The mechanism described works differently from cookie-based tracking: instead of an ad-tech company reading the same cookie value on many sites to build a profile of one browser, the browser itself would compute or hold signals locally and expose only limited information to callers. Google framed this as a multi-year undertaking, saying new web standards 'generally take multiple years' to adopt. The announcement tied the plan directly to publisher revenue, warning that simply blocking cookies, the approach some other browsers had taken, would remove a funding mechanism many publishers relied on, citing research suggesting publisher funding could fall sharply without a replacement in place.
What the documents show
The 2019 post commits to a direction, not a date: it names goals, such as restricting fingerprinting sooner and building broader replacement mechanisms on an unspecified multi-year track, without setting a deprecation date for third-party cookies. Five years later, Google's own update on the Privacy Sandbox timeline, published 22 July 2024, shows how that plan played out: rather than deprecating third-party cookies as it had repeatedly signalled it would, Google said it would instead build a browser control letting people choose whether to keep them, a change it described as something it was 'discussing with regulators', naming the UK's Competition and Markets Authority and Information Commissioner's Office. Together, the two documents show a five-year gap between a stated direction and a stated mechanism, during which the premise shifted from removing cookies outright to offering a browser-level choice.
The assumptions exposed
The 2019 announcement assumed publishers would need a replacement targeting mechanism before cookies disappeared, and that regulators and the ad industry could align on one within a bounded number of years. Neither assumption held on the original schedule. The publisher-funding figure Google cited in 2019 was, on its own account, drawn from third-party research about a general cookie-blocking scenario, not a measurement of what happened under Privacy Sandbox; treating it as a forecast for an individual site over-reads a source that does not support that use. The 2024 post is itself a statement of intent rather than a completed transition: it describes what Google says it will build, not a shipped, audited outcome.
What to check before you rely on it
A publisher planning ad revenue around a cookie-replacement timeline should treat every date here as provisional until it has shipped in a stable Chrome release. This is an editorial checklist, not guidance from Google.
- Has the mechanism I am relying on shipped in Chrome stable, or is it still a stated plan?
- Is the figure I am reading Google's projection, third-party research Google cited, or an audited outcome?
- What did the most recent Google post say has changed since the version I last read?
A publisher should treat 'coming' and 'shipped' as different facts.
Sources & reading trail
Google's own 2019 announcement of the Privacy Sandbox plan, its stated multi-year timeline, and its stated rationale about publisher funding.
Source published: 22 August 2019 · Retrieved: 16 September 2026
Google's 2024 post shows the 2019 plan changed: cookies would not be deprecated as previously signalled, replaced instead by a new browser-level choice.
Source published: 22 July 2024 · Retrieved: 16 September 2026
Programme terms, standards and reports establish the entry; the assumptions reading is Publisher Revenue Guide editorial analysis. This retrospective draft does not imply the site published on the event date.