Spoiler: it wasn’t. But there are two practical takeaways from this story, and for Ukraine they are different from Europe’s.
First, two terms you need for the rest of this
Third-party cookies are small files placed on your device not by the site you are on, but by someone else, usually an ad system. They are what makes it possible to show you the sneakers from one store on ten other sites. Privacy Sandbox is the set of technologies Google wanted to replace those cookies with: so that ads could still be targeted, but no individual person could be tracked.
How Google changed its mind twice
In April 2025 Google announced that cookies would stay in Chrome and users would not see a separate “allow or block” prompt 1. Six months later, in October, the company shut down almost all of Privacy Sandbox: Topics, Protected Audience, Attribution Reporting and a dozen other technologies the industry was supposed to migrate to 2. The official reason sounds almost insulting: nobody adopted them.
Three technologies survived: CHIPS (cookies tied to a single site), FedCM (sign-in via Google account) and Private State Tokens (a “this is not a bot” signal). None of them helps identify a person for advertising 3. So of the ambitious project to “rebuild advertising in the browser”, what remains are tools for login and anti-fraud.
What the measurements show, not the press releases
The most honest picture is not in vendor blogs but in an academic study: a team scanned the world’s top 10,000 sites every week for six months and looked at which technologies were actually deployed 4.
Three quarters of sites still set classic third-party cookies in Chrome. The Privacy Sandbox technologies Google later shut down had fallen to almost zero even before the shutdown was announced. The market abandoned them on its own; Google merely recorded the fact. And the most telling part: in Firefox, where the browser itself forcibly isolates cookies, protective technologies are present on as many sites as regular cookies are in Chrome. The researchers put it dryly, so let me translate: the industry does privacy where the browser forces it, and doesn’t where it can get away with not doing it.
Where the money went
While Google hesitated, big advertisers stopped waiting. Per SearchLab’s roundup of IAB, Winterberry, Salesforce and Criteo reports 5:
- 61% of advertisers have a first-party data strategy (data they collected themselves: email, phone, purchase history). In 2023 it was 37%.
- 44% of the top 500 advertisers use clean rooms, secure “rooms” where a brand and a platform match their data without handing it to each other raw.
- Advertising to your own CRM base delivers 3.1x higher ROAS (how much revenue each hryvnia of ad spend returns) than prospecting blind. Yet among small and mid-sized businesses only a third use it.
- 67% of CPG manufacturers (food, drinks, household chemicals, everything people buy weekly) target ads on retailer data. That is retail media, ads inside Silpo, Rozetka or Amazon, to translate it into our reality.
In other words, the market has already rebuilt itself around owned data. Not because Google forced it, but because it turned out to be more profitable.
Europe: the law does not care what Chrome decided
In the EU, cookie consent is required regardless of Google’s decisions. The ePrivacy Directive requires asking permission for any write to a user’s device, whoever’s cookies they are 1. Browser settings are not a legal basis; the consent banner stays mandatory. Even server-side tracking by IP address falls under the European regulator’s October 2024 guidance 2.
So for European colleagues Google’s reversal simplified nothing: the compliance work that was postponed for two years has to be done now.
What about Ukraine
The law everyone is afraid of still does not exist here. GDPR does not apply in Ukraine. The current law “On Personal Data Protection” was passed in 2010 and contains neither a cookie consent banner nor fines as a percentage of turnover. The new bill No. 8153, meant to bring the rules up to European standards, passed its first reading on November 20, 2024. As of September 15, 2026, the Verkhovna Rada’s bill card says “being prepared for second reading” 7,8. Not “awaiting the president’s signature”, as is sometimes written, but in committee.
In practice this means: a Ukrainian advertiser working only on the domestic market is not obliged to put up a consent banner. Obligations appear in two cases. If EU users visit your site, GDPR applies to you too. And if a platform requires it: Google via Consent Mode for European traffic, Meta via its ad account rules.
Technically we are in the same Chrome as everyone else. Chrome holds over 80% of desktops in Ukraine; on mobile, Chrome and Safari together account for almost 92% 9. Two consequences follow. First: Google’s reversal matters more to us than to Europe, because we have almost no Firefox with its forced isolation. Second, and often forgotten: Safari on iPhone has blocked third-party cookies since 2020. So part of your audience has been unreachable for classic retargeting for six years already, and no Google decision changes that.
Money: half the Ukrainian market runs on the same technologies. Per IAB Ukraine, digital display advertising reached UAH 21.6 billion in 2025, paid search UAH 25.3 billion. Programmatic (automated ad buying via real-time auction) takes 49% of display budgets, 62% in video. Google, Facebook and Instagram together take 69% of display money 10. That is the answer to “where is our place”: any change in Chrome or in Meta’s and Google’s policies hits Ukrainian campaigns the same day it hits American ones.
What Ukrainian numbers don’t exist. Neither IAB Ukraine nor the VRK counts how many advertisers have a first-party data strategy or use clean rooms. There is no Ukrainian research here, so what follows is an observation from Wideworks’ practice: in Ukraine this is still the territory of large retailers, banks and telecoms that have their own CRM. For mid-sized business the first step is banal and no less important for it: collect customers’ emails and phone numbers with consent and upload them to your ad accounts.
What to do about it
- Don’t spend resources on European compliance if you have no EU audience. But keep 8153 on your radar: once it passes, the transition period will be short.
- Look at what share of your traffic comes from iOS. Attribution there (working out which ad led to the purchase) has been broken for a long time, and server-side solutions are needed: Conversions API in Meta, Enhanced Conversions in Google.
- Start building your own base now. It is the only asset that depends neither on Google nor on the Rada.
Sources
- ↑Cookiebeam — Privacy Sandbox shutdown 2026: what it means for consent
- ↑Consenteo — Third-party cookies in 2026 after Google’s reversal
- ↑Lukas Wojcik — Eight removed, three left standing
- ↑arXiv 2607.00693 — A longitudinal measurement of Privacy Sandbox across the top 10,000 sites
- ↑SearchLab — Programmatic advertising statistics 2026
- ↑Basis — 7 programmatic advertising trends shaping 2026
- ↑Verkhovna Rada — Bill No. 8153 card
- ↑Glavcom, 20.11.2024 — Rada backs the “On Personal Data Protection” bill
- ↑UNIAN, based on StatCounter — Most popular browsers of 2026
- ↑IAB Ukraine — Ukrainian internet advertising market estimate, 2025, figures as summarized by Inweb