Google Retires Privacy Sandbox: What Publisher Identity Strategy Looks Like Now
Google is retiring Topics, Protected Audience and most other Privacy Sandbox APIs. Third-party cookies stay in Chrome. Here is how publishers should rethink addressability.
The announcement
On October 17, Anthony Chavez, Google's vice president for Privacy Sandbox, announced that Google will retire most of the Privacy Sandbox technologies it has developed since 2019. Citing ecosystem feedback about their expected value and low levels of adoption, Google named ten technologies for retirement: the Attribution Reporting API, IP Protection, On-Device Personalization, Private Aggregation and Shared Storage, Protected Audience, Protected App Signals, Related Website Sets, SelectURL, SDK Runtime and Topics.
A small set continues. CHIPS and FedCM, which improve cookie privacy and streamline identity flows and have seen adoption from other browsers, stay in development, as do Private State Tokens for fighting fraud and abuse. Google also said it will keep working on an interoperable attribution standard through the W3C, and that Chrome will maintain its current approach to offering users choice about third-party cookies.
How we got here
The original plan was to remove third-party cookies from Chrome and replace their advertising uses with browser-based APIs. That plan was delayed several times. In July 2024, Google said it would no longer deprecate third-party cookies and would instead pursue an approach built on user choice. In April 2025, it said it would keep its current approach and would not roll out a new standalone prompt for third-party cookies. With cookies staying, the case for building on the replacement APIs weakened, and last week's announcement formalizes that.
What it means for publishers
Chrome addressability is not going away
For most publishers, Chrome is the largest browser in their traffic, and third-party cookies remain available there for users who have not turned them off. The feared collapse in Chrome addressability is not coming on the timeline the industry spent years preparing for.
But much of your traffic is already cookieless
Safari and Firefox have blocked third-party cookies by default for years. On many sites, especially those with heavy iPhone audiences, a large share of impressions already carries no third-party cookie. Those impressions have been monetizing without cookies all along, and the retirement of the Sandbox APIs does nothing for them either. The addressability gap between browsers remains, and it is often bigger than publishers realize.
Testing work can wind down
Some publishers and their partners invested in Protected Audience auctions or Topics signals. That work can now be retired in an orderly way. Remove experimental configuration from your wrapper and ad server once your partners confirm they no longer use it, rather than leaving unused code paths in production.
A practical identity strategy for 2026
- Measure addressability by browser. Break down impressions and revenue by browser and by whether a user ID or cookie was present. This single report usually reshapes identity priorities more than any vendor pitch.
- Rationalize ID modules. Prebid's User ID module supports many identity providers. Each one adds code and some add latency. Keep the ones buyers actually bid on in your traffic, confirmed by bid data, and remove the rest.
- Use your own identifiers. Publisher-provided identifiers in Google Ad Manager and first-party IDs passed through Prebid let you support frequency capping and audience segments for logged-in or known users, independent of browser cookie policies.
- Grow authenticated audiences. Newsletters, registrations and subscriptions create durable relationships and consented first-party data. They work in every browser.
- Strengthen contextual signals. Consistent page-level categories, keywords and content metadata give buyers targeting options that do not depend on identity at all. For Safari-heavy audiences, this is often the fastest win.
- Respect consent everywhere. Cookie availability does not change privacy law. Opt-out signals, GDPR consent and state privacy requirements still govern what you can do with any identifier.
Questions to ask your partners
The retirement will prompt a round of roadmap updates from SSPs, identity providers and consent platforms. A few direct questions cut through them:
- For SSPs: Which identity signals do your buyers actually bid on in my traffic today, and how does bid rate differ between impressions with and without an ID?
- For identity providers: What match rate do you achieve on my Safari and Firefox traffic, and which DSPs recognize your ID in practice, not just in principle?
- For consent platforms: Are opt-out and consent signals applied to every ID module and passed correctly in the bidstream?
- For everyone: Which Sandbox-related features are you removing, and when? Coordinate removals so unused code does not linger.
The answers should come with data from your own traffic. General claims about match rates or uplift are much less useful than a report cut by browser and device for your site.
What this means for measurement
Advertisers were counting on the Attribution Reporting API as a privacy-preserving way to measure conversions. With that API retiring, measurement will rely more on existing cookie-based methods where available, on clean rooms and modeled conversions, and eventually on whatever the W3C attribution effort produces. For publishers, the practical implication is that buyers will keep valuing inventory where they can measure outcomes. Clean supply paths, accurate viewability and strong contextual data all help buyers justify spend when measurement is imperfect.
The takeaway
The Privacy Sandbox era ended not with a new standard, but with the status quo. Third-party cookies stay in Chrome; they remain absent in Safari and Firefox; and privacy law keeps tightening. The publishers who come out ahead will be the ones who measure their real addressability, trim identity bloat, and invest in first-party and contextual data that work in every browser. HBDR helps publishers review ID modules and consent handling as part of routine wrapper maintenance, so identity decisions are driven by bid data rather than by the latest announcement.
Related Articles
AAMP 3.0 and OpenProposal: Getting Your Inventory Ready for Agent-Written RFPs
IAB Tech Lab's AAMP 3.0 introduces OpenProposal, a standard way for buyer and seller agents to exchange briefs and proposals. What it means for publishers who sell directly.
Cloudflare's Sept. 15 AI Crawler Deadline: What Recipe Publishers Should Check
Starting September 15, Cloudflare's defaults block mixed-use AI crawlers from pages that host ads. What that means for recipe and lifestyle publishers, and the settings worth reviewing.
No Breakup for Google Ad Tech: What the Remedies Ruling Means for Publishers
Judge Brinkema rejected a forced sale of AdX and ordered behavioral remedies instead. What the September 2 ruling changes for publishers, and what to do before it takes effect.