
First-Party Data: The Deadline Never Came. Build It Anyway.
The third-party cookie deadline never arrived and the replacements were scrapped. Why a first-party data strategy was never really about cookies.
What is a first-party data strategy?
A first-party data strategy is a plan for collecting, storing and using information your customers give you directly, on your own site and in your own systems. Names, email addresses, bookings, purchases, enquiries, preferences. You hold it, you control it, and no browser setting or platform policy can take it away from you.
The deadline that never came
Google spent years telling the industry that third-party cookies would be phased out of Chrome, and the industry spent years preparing for it. The date moved. Then it moved again.
Then it stopped moving, because the plan changed. Google's own announcement is blunt about it: the company decided "to maintain our current approach to offering users third-party cookie choice in Chrome, and will not be rolling out a new standalone prompt for third-party cookies."
No phase-out. No prompt. Cookies stay, and people can change the setting themselves if they want to.
Then the replacements were scrapped too
This is the part that got much less attention, and it matters more.
Google had been building a set of technologies to replace what cookies did. Topics, to guess interests without following people around. Protected Audience, to run remarketing without sharing identities. Attribution Reporting, to measure conversions privately. Agencies learned them. Vendors built on them.
Google then retired the lot. The announcement names them one by one: Attribution Reporting API, IP Protection, On-Device Personalization, Private Aggregation, Protected Audience, Protected App Signals, Related Website Sets, SelectURL, SDK Runtime and Topics. The stated reasons were ecosystem feedback and low adoption.
So the old thing stayed, and the new thing went away. Anyone who rebuilt their measurement around the replacements spent that effort for nothing.
Why none of this changes the case for owning your data
Here is the uncomfortable part for our own industry. The case for collecting your own customer data was never really about cookies. It got sold that way because a deadline makes people act, and "you should have done this ten years ago" does not.
Think about what actually happened to the businesses that built an email list of past guests, or kept proper records of who booked what and when, or asked customers one useful question at checkout. None of them were affected by any of this. The cookie news was irrelevant to them, in both directions. They did not have to panic, and they did not have to un-panic.
What they own keeps working when a browser changes its mind, when a platform changes its algorithm, when an ad account gets suspended, when a social network you built an audience on stops showing your posts to that audience. It is the only marketing asset that does not sit on someone else's land.
What this looks like for a small business
It is less technical than the phrase suggests. For most of the businesses we work with in the Algarve, it comes down to four things.
A record of who your customers are. Not a marketing database. A list, kept properly, of the people who have bought from you or enquired, with enough detail to be useful. A spreadsheet that is actually maintained beats a CRM that nobody opens.
A reason for people to identify themselves. Nobody gives you their email for a newsletter. They give it for a booking confirmation, a guide worth having, a waiting list, a discount that applies to them. If you cannot say what the person gets, you will not get the address.
Permission you could defend. Collected clearly, with a record of when and for what. This is not only a legal point. A list built on a checkbox people did not see performs badly, because those people do not remember you.
Measurement that belongs to you. Your own analytics, your own form submissions, your own count of enquiries by source. Platform numbers are reported by the party selling you the advertising.
| Third-party data | First-party data | |
|---|---|---|
| Who controls it | The platform or browser | You |
| Survives a policy change | No | Yes |
| Accuracy about your customers | Inferred | Observed |
| Useful without ad spend | Rarely | Always |
| Setup effort | Low | Moderate and ongoing |
The mistake we see most often
Not failing to collect data. Collecting it and never using it.
We regularly meet businesses sitting on years of customer records they have never once acted on. They have the names. They have the bookings. They have the email addresses, collected properly, sitting in a system nobody has opened since it was set up.
That is worse than not having the data, because it costs the same to hold and returns nothing. If you take one thing from all of this, take that. A modest list you actually write to is worth more than a large one you do not.
What to do about it
Start with what you already hold. Find it, get it into one place, and check you are allowed to use it. Most businesses discover they are further along than they thought, and that the gap is not collection but use.
Then decide what you want to be able to answer. "Which of our customers came back?" is a better starting question than "what should we track?", because it tells you exactly which fields matter and lets you ignore the rest.
If you want a hand working out what is worth collecting for your particular business, that is what our marketing strategy work covers. Or write to us at hello@saltylavender.com and describe what you have.
Common questions
Do I still need a cookie banner if third-party cookies are staying?
Yes. The banner exists because of European privacy law, not because of Chrome. What a browser does with cookies and what the law requires you to ask are separate things, and the law did not change when Google changed its mind.
Is first-party data the same as zero-party data?
Not quite. Zero-party data is what someone tells you on purpose, like a preference they select. First-party data is the wider category and includes what you observe directly, like what they bought. In practice most small businesses should stop worrying about the distinction and collect both.
Can I still run remarketing?
You can. Third-party cookies remain available in Chrome, and other browsers have their own rules. The point of this article is not that remarketing stopped working. It is that building your business on a mechanism you do not control leaves you exposed to a decision made in another company's meeting room.
How much data is enough?
Enough to answer the questions you will actually act on. A restaurant that knows which guests booked twice has something useful. A restaurant collecting fourteen fields it never reads has a liability.
We lost our records when we changed systems. Where do we start?
From today. Set up collection properly now, and recover what you can from bookings, invoices and your email history. Businesses often find that the accounting system has been quietly keeping a decent customer list all along.
Does this replace SEO and advertising?
No. It makes both work harder. Knowing who your customers are tells you which search terms matter and who to exclude from your ads, and it gives you something to fall back on when search traffic moves.
Sources
- Anthony Chavez, VP Privacy Sandbox, Google, "Next steps for Privacy Sandbox and tracking protections in Chrome": privacysandbox.google.com
- Anthony Chavez, VP Privacy Sandbox, Google, "Update on Plans for Privacy Sandbox Technologies": privacysandbox.google.com