Privacy Sandbox
What is Privacy Sandbox?
Privacy SandboxGoogle's umbrella initiative for replacing third-party cookies and cross-site identifiers with privacy-preserving alternatives — Topics, Protected Audience (FLEDGE), Attribution Reporting, and on-device APIs — under heavy regulatory and competitor scrutiny.
Privacy Sandbox is Google's multi-year initiative, launched in 2019, to replace third-party cookies and other cross-site identifiers in Chrome and Android with a family of purpose-built, on-device, privacy-preserving APIs while keeping the ad-supported web economically viable. The web-side APIs include Topics (browser-derived interest categories), Protected Audience (FLEDGE, previously TURTLEDOVE — on-device remarketing auctions), Attribution Reporting (browser-mediated conversion measurement with noise), Shared Storage and Fenced Frames (cross-site state in a privacy-bounded form), and Trust Tokens / Private State Tokens. Android-side counterparts include Topics, Attribution Reporting, and SDK Runtime. The U.K.'s Competition and Markets Authority has supervised Privacy Sandbox since 2022, with Google committing to behavioral remedies; in July 2024 Google announced it would keep third-party cookies in Chrome with a new user-choice mechanism rather than deprecate them, while continuing Sandbox APIs alongside. For privacy and AppSec teams, Privacy Sandbox is a major architectural change that needs site-by-site impact assessment.
● Examples
- 01
An ad-tech vendor builds a FLEDGE-based remarketing prototype to compare reach and conversion against legacy cookie-based remarketing.
- 02
A publisher integrates the Attribution Reporting API and watches for the noise/budget characteristics that change downstream conversion-measurement pipelines.
● Frequently asked questions
What is Privacy Sandbox?
Google's umbrella initiative for replacing third-party cookies and cross-site identifiers with privacy-preserving alternatives — Topics, Protected Audience (FLEDGE), Attribution Reporting, and on-device APIs — under heavy regulatory and competitor scrutiny. It belongs to the Privacy & Data Protection category of cybersecurity.
What does Privacy Sandbox mean?
Google's umbrella initiative for replacing third-party cookies and cross-site identifiers with privacy-preserving alternatives — Topics, Protected Audience (FLEDGE), Attribution Reporting, and on-device APIs — under heavy regulatory and competitor scrutiny.
How does Privacy Sandbox work?
Privacy Sandbox is Google's multi-year initiative, launched in 2019, to replace third-party cookies and other cross-site identifiers in Chrome and Android with a family of purpose-built, on-device, privacy-preserving APIs while keeping the ad-supported web economically viable. The web-side APIs include Topics (browser-derived interest categories), Protected Audience (FLEDGE, previously TURTLEDOVE — on-device remarketing auctions), Attribution Reporting (browser-mediated conversion measurement with noise), Shared Storage and Fenced Frames (cross-site state in a privacy-bounded form), and Trust Tokens / Private State Tokens. Android-side counterparts include Topics, Attribution Reporting, and SDK Runtime. The U.K.'s Competition and Markets Authority has supervised Privacy Sandbox since 2022, with Google committing to behavioral remedies; in July 2024 Google announced it would keep third-party cookies in Chrome with a new user-choice mechanism rather than deprecate them, while continuing Sandbox APIs alongside. For privacy and AppSec teams, Privacy Sandbox is a major architectural change that needs site-by-site impact assessment.
How do you defend against Privacy Sandbox?
Defences for Privacy Sandbox typically combine technical controls and operational practices, as detailed in the full definition above.
What are other names for Privacy Sandbox?
Common alternative names include: Google Privacy Sandbox.
● Related terms
- privacy№ 1263
Third-Party Cookie
A cookie set by a domain different from the one in the browser's address bar, historically used to track users across websites.
- privacy№ 1286
Topics API
A Privacy Sandbox API in Chrome and Android that derives a small set of high-level interest topics from the user's recent browsing locally on the device, exposing them to participating sites instead of cross-site tracking identifiers.
- privacy№ 088
Attribution Reporting API
A Privacy Sandbox API in Chrome and Android that lets advertisers measure ad conversions across sites without cross-site identifiers, using browser-mediated, noise-injected event-level or aggregated reports.
- privacy№ 143
Browser Fingerprinting
A stateless tracking technique that identifies a user by combining browser, device, and configuration attributes into a near-unique signature.
- privacy№ 266
Cross-Site Tracking
The practice of linking a user's activity across multiple unrelated websites to build a long-lived behavioural profile.
- privacy№ 233
Consent Management
The processes and tooling used to collect, record, refresh, and honor user permissions for processing personal data and setting cookies, in line with privacy law.