Chrome Kept Cookies. DPDP Is Now Your Only Real Deadline
The reversal, in one sentence
On 22 April 2025, Google’s Privacy Sandbox team confirmed it would not deprecate third-party cookies in Chrome after six years of announcing, delaying, and redesigning that exact plan. It also scrapped the standalone consent prompt that was meant to let Chrome users opt cookies out for themselves. Cookies stay under existing browser settings, with no new removal timeline. That’s the Time Anchor this article is built around, but it isn’t the end of the story — Google wasn’t finished retreating.
Read those three numbers together and the shape of the story changes. Google didn’t just cancel a deprecation. It cancelled the deprecation, then shut down most of the replacement system it had spent six years building too. That’s not a company that solved cookieless tracking. That’s a company that walked away from the entire project.
What this does NOT mean
This is the part most Indian performance-marketing decks are getting wrong. “Cookies survived” is not the same claim as “tracking went back to 2019.” Three things did not change on 22 April 2025:
- Safari and Firefox still block third-party cookies by default — Safari since 2020, Firefox since 2019 — and were never part of Google’s announcement. If a meaningful share of your traffic is iOS/Safari, this reversal changes nothing for it.
- iOS App Tracking Transparency is untouched. It’s an Apple policy, not a Chrome setting, and it’s still the bigger practical drag on Meta and Instagram attribution for most Indian D2C brands running app-adjacent campaigns.
- India’s Digital Personal Data Protection Act (DPDP) rules keep tightening, independent of anything Google does with Chrome. Consent logging, data-handling obligations, and cross-border transfer rules are a legal requirement, not a browser feature you can opt out of by switching vendors.
The honest read is narrower than “cookies are back”: third-party cookies never went away in the first place — Google cancelled a plan, it didn’t restore something that had already been removed — and that cancelled plan benefits exactly the ~89% of Indian traffic running Chrome, on the desktop and Android surfaces where Chrome’s cookie settings apply. The other headwinds you built infrastructure for in 2023–24 are all still live.
- Jan 2020Google announces plans to phase out third-party cookies in Chrome, targeting 2022.
- 2022–2024Repeated delays through regulatory review (notably the UK Competition and Markets Authority) and industry pushback.
- Jul 2024Google shifts from full deprecation to a “user choice” model: a standalone consent prompt.
- 22 Apr 2025Time AnchorGoogle confirms it won’t ship that prompt either. Cookies stay, indefinitely.
- 17 Oct 2025Google retires 10 of the remaining Privacy Sandbox APIs, keeping only anti-fraud pieces.
- Jul 2026 (today)Indian marketing teams are still auditing 2023–24 spend that was justified by a threat that’s now cancelled twice over.
Why this matters to your budget, specifically
Here’s the part that gets skipped in most coverage of this reversal: it says nothing about what actually happened to your Meta and Google CPMs over the same period. India’s digital ad market has kept growing regardless — from roughly $14.6 billion in 2026 toward an estimated $20.46 billion by 2029, with Google and Meta still taking the largest share. Industry estimates put Meta CPM inflation in India at roughly 40–60% between 2023 and 2026 — worth flagging clearly as an agency estimate, not a Meta-disclosed figure, because the cause isn’t Chrome’s cookie policy at all. It’s competition for inventory, iOS ATT signal loss, and a genuinely larger advertiser base bidding on the same auctions.
That distinction matters because it tells you where the real cost of the last three years sits. It isn’t “we lost money because cookies disappeared.” It’s “we may have spent against the wrong threat while the real one — signal loss from Safari, iOS, and now DPDP compliance overhead — kept compounding untouched.”
| Retired (10) | Kept (3) |
|---|---|
| Attribution Reporting | CHIPS (cookie partitioning) |
| Topics | FedCM (federated login) |
| Protected Audience | Private State Tokens |
| Protected App Signals | — |
| IP Protection | — |
| On-Device Personalization | — |
| Private Aggregation | — |
| Related Website Sets | — |
| SelectURL | — |
| SDK Runtime | — |
The pattern in that table is worth sitting with: everything Google kept is anti-fraud infrastructure. Everything it cut was ad-measurement infrastructure — the exact category most “cookieless readiness” vendor pitches were built around.
The audit: sort every 2023–2025 “cookieless” line item into three buckets
Before you touch a single budget line, run it through this. It takes about fifteen minutes per vendor or retainer.
- Pull every 2023–2025 invoice or SOW with “cookieless,” “Privacy Sandbox,” or “cookie deprecation” in the description.
- Run each one through the three-question scorecard above.
- For anything scoring 0–1, get a cancellation or non-renewal date on the calendar this week.
- For anything scoring 2–4, request a revised scope from the vendor tied to DPDP or Safari/iOS attribution — not Chrome.
- Redirect the freed budget toward whichever channel is actually losing signal today: iOS-heavy Meta campaigns or DPDP consent infrastructure, not Chrome contingency.
- Brief your founder or CFO using the three-bucket language (Keep / Reprioritise / Cut) before they ask you first.
Worked example from the article: ₹18,00,000/month at 6% tagged = ₹1,08,000/month, ₹12,96,000/year.
Suggested reallocation once you know the number: 60% to Safari/iOS attribution fixes, 40% to DPDP consent-logging infrastructure.
The trap inside the “good news”
The version of this story that gets repeated in Slack channels and agency decks is “Chrome isn’t killing cookies, so we don’t need to worry about tracking.” That’s the wrong lesson twice over. First, because the two live threats — Safari/Firefox’s permanent block and iOS ATT — were never Chrome’s to fix, and they didn’t move an inch on 22 April 2025. Second, because Google didn’t just cancel the deprecation — it also killed the replacement measurement APIs eight months later, which means even the original plan for a cookieless future no longer has a supported path in Chrome. There is no cookieless roadmap left to prepare for and no urgency to abandon first-party infrastructure that serves a real, separate purpose. The mistake isn’t choosing the wrong side of the cookie debate. It’s still framing the decision as being about cookies at all, when the actual driver of your 2026 attribution gaps is Apple’s platform policy and India’s own data law.
- Google confirms it will not deprecate third-party cookies in Chrome (22 Apr 2025) — Computing.co.uk
- Google drops the planned standalone cookie-consent prompt — OneTrust
- Google retires 10 Privacy Sandbox APIs, 17 Oct 2025 — gHacks.net
- Google officially shuts down the Privacy Sandbox initiative — Search Engine Land
- Chrome’s browser market share in India, 89.19% (July 2026) — Statcounter Global Stats
- India digital ad spend market size, ~$14.6B (2026) toward ~$20.46B (2029) — GlobeNewswire
- Estimated 40–60% Meta CPM increase in India, 2023–2026 (agency estimate) — UpGrowth
- Timeline context on the original 2020–2024 deprecation plan — AlternativeTo
No — they were never removed. Google cancelled a plan to deprecate them; it didn’t restore something that had been taken away. For the roughly 89% of Indian traffic on Chrome, cookie-based tracking simply continues as it always has, under existing browser privacy settings, with no forced consent prompt and no removal date on the calendar.
Not automatically. Score each line item against the three-question audit above. If it also serves Safari/iOS attribution or DPDP consent logging, it earns its cost on those grounds alone. Only cut the pieces whose sole justification was “Chrome will remove cookies” — that threat is now cancelled twice over.
No. Safari’s Intelligent Tracking Prevention and Firefox’s Enhanced Tracking Protection have blocked third-party cookies by default since 2020 and 2019 respectively, and neither was part of Google’s announcement. iOS App Tracking Transparency is a separate Apple policy and remains untouched. If your traffic skews iOS, this reversal delivers you nothing.
Correct — they’re legally and technically separate. DPDP governs how you collect, store, and process personal data in India, regardless of which browser a user is on or what cookies that browser allows. Chrome’s decision affects tracking mechanics; DPDP affects your legal exposure. Treating them as one issue is the most common mistake in this whole story.
Not directly, and the figure itself is an industry estimate from agency sources, not a Meta-disclosed statistic — treat it as directional. CPM inflation in India over 2023–2026 tracks auction competition, iOS ATT signal loss, and overall ad-market growth far more than it tracks Chrome’s cookie policy, which never actually changed anything in the market during that period.
Pull every invoice or SOW tagged “cookieless” or “Privacy Sandbox” from 2023–2025, run each through the Keep/Reprioritise/Cut scorecard above, and get cancellation dates on the calendar for anything that scores 0–1. That’s a fifteen-minute exercise per vendor, and it’s the only response to this news that produces a rupee number instead of an opinion.
Google’s reversal didn’t hand you a discount, a shortcut, or permission to stop thinking about tracking. It handed you back a Tuesday afternoon: run the three-question audit against every “cookieless readiness” line item you approved between 2023 and 2025, and reallocate whatever scores a Cut toward the two threats that were never Chrome’s to solve — Safari/iOS signal loss and DPDP compliance. Do that this week, before your CFO asks you why the line item is still there.
Everyone here started with one article — like this one on Chrome’s cookie reversal and the DPDP deadline it was hiding. This can be yours too.
Subscribe to the ThreadNot sure which parts of your funnel are actually leaking?
Not sure which parts of your funnel are actually leaking attribution versus just leaking budget. Start with the one number in your funnel you can actually trust.

