= Privacy Sandbox =

Infobox
- Logo: File:Google_Privacy_Sandbox_logo.png
- Logo Alt: Privacy Sandbox logo
- Founder: Google
- Type: Initiative
- Purpose: Development of web standards

The Privacy Sandbox was an initiative led by Google which aimed to create web standards for websites to access user information without compromising privacy. Announced in 2019, the core purpose of the project was to facilitate online advertising by sharing a subset of user private information without the use of third-party cookies. The technology included Topics API (formerly Federated Learning of Cohorts or FLoC), Protected Audience, Attribution Reporting, Private Aggregation, Shared Storage, and Fenced Frames as well as other proposed technologies like IP Protection, Related Website Sets, CHIPS, and Bounce Tracking Mitigation. On September 7, 2023, Google announced general availability of majority of proposed APIs. In April 2025, Google officially discontinued the Privacy Sandbox initiative, citing lack of interest from websites, low and dropping adoption and regulatory pressure.

The initiative has been described as anti-competitive and generated an antitrust response due to concerns that the introduced proposals limited tracking through traditional methods and pushed advertisers to use Google as a middleman in order to show advertisements.

== Model ==
Proposals in the Privacy Sandbox follow the idea of k-anonymity and are based on advertising to groups of people called cohorts instead of tracking individuals. They generally place the web browser in control of the user's privacy, moving some of the data collection and processing that facilitates advertising onto the user's device itself. There are three focuses within the Privacy Sandbox initiative: replacing the functionality of cross-site tracking, removing third-party cookies, and mitigating the risk of device fingerprinting.

== History ==
The first announcement of the Privacy Sandbox initiative took place in August 2019. The initiative included a number of proposals, many of which had bird-themed names which were changed once the corresponding feature reached general availability. The initial plan was for Privacy Sandbox to be long-term plan to deploy a set of standards that would help advertisers (like Google) to perform targeted advertising without exposing the user to privacy-invasive technologies like third-party cookies. Over the next two years, Google worked with the World Wide Web Consortium (W3C) to experiment and propose standards for the web. Work on the Privacy Sandbox initiative during these two years included the development of the TURTLEDOVE and the subsequent FLEDGE proposals, both which centered around providing APIs to enable privacy preserving advertising, the tightening of the SameSite cookie policy, the introduction of private state tokens and the development of the Client Hints proposal.

In 2021, Google committed to a timeline to implement and deploy the technologies to its Chrome browser by the end of 2022 with an expected third-party cookie deprecation date of 2023. Following the 2021 announcement, Google's Privacy Sandbox proposals came under scrutiny from privacy-advocacy groups like the Electronic Frontier Foundation and Brave and competition regulatory bodies like the United Kingdom's Competition and Markets Authority (CMA). In response to the privacy concerns, Google discontinued proposals like Federated Learning of Cohorts (also known as FLoC) and replaced it with the Topics API.

In February 2022, the CMA secured commitments from Google to commit to performing quantitative testing on the performance of Privacy Sandbox APIs and the effects of the third-party cookie deprecation on advertisers. The CMA would also stipulate that Google write quarterly reports of its progress on Privacy Sandbox with the CMA acting as an oversight body helping shape the Privacy Sandbox proposals. In November 2022 CMA released a report on Google's quantitative testing of its Privacy Sandbox technologies that called for the advertising industry to adopt a common testing framework so that performance tests could be conducted more widely across multiple testing entities. Google committed to developing such a testing framework in cooperation with the CMA before its technologies became generally available in 2023.

On March 31, 2022, Google announced the start of a single origin trial, for the Topic, FLEDGE and Attribution Reporting APIs. This was done to allow sites to run unified experiments across the APIs. In October 2022 RTB House published its findings of actively testing FLEDGE by adding users to interest groups. Google and Criteo, also ran tests. The report highlighted that, while positive, the FLEDGE origin trials were limited in scope. It noted that a number of essential features of FLEDGE, specifically k-anonymity requirements, were not available for testing, and would require adjustments after industry feedback.

On September 7, 2023, Google announced general availability of Privacy Sandbox APIs, naming explicitly Topics, Protected Audience, Attribution Reporting, Private Aggregation, Shared Storage and Fenced Frames, meaning these features were enabled for more than half of Google Chrome users. Privacy Sandbox features were also made available on Android around the same time. Following this, in July 2024, Google announced that they would not be completely phasing out third-party cookies but rather allowing the user to opt in to blocking third-party cookies.

In April 2025, Google officially discontinued the Privacy Sandbox initiative. The company confirmed it would no longer proceed with plans to remove third-party cookies from Chrome, opting to maintain existing cookie controls without introducing a new standalone consent prompt. In 2025, following Google discontinuing the Privacy Sandbox proposal, CMA decided to release Google from their legally binding commitments related to third-party cookie deprecation. The Privacy Sandbox APIs are being retired due to limited adoption and continued regulatory pressure. Google's official Privacy Sandbox status page lists several technologies as "scheduled for phase-out".

== Proposals ==
In January 2020, Google invited advertising technology companies to join the Improving Web Advertising Business Group (IWABG) of the World Wide Web Consortium (W3C) as a way to participate in the proposal process for the Privacy Sandbox. The IWABG group was chaired by Wendy Seltzer and had 258 participants in the group in August 2020, of which 33 were Google employees.

  - Proposals**

| Proposal | Description | Status |
| Federated Learning of Cohorts (FLoC) | | Discontinued |
| TURTLEDOVE | TURTLEDOVE, which stands for "Two Uncorrelated Requests, Then Locally-Executed Decision On Victory", is a framework proposed by Google to serve ads through the browser. | Discontinued |
| Private state tokens | Private state tokens will be able to be issued by websites to verify those browsers whose behavior denotes a real person rather than a bot or malicious attacker. Private state tokens are encrypted, so that an individual's identity is protected. | Implemented |
| Related Website Sets | Related Website Sets (formerly known as first-party sets) will allow domains that belong to the same entity, that have related sites with different domain names, to declare themselves, and be recognized, as a "related set." The exchange of information outside of a related website set is restricted to safeguard the privacy of users. | Discontinued |
| CHIPS | CHIPS (Cookies Having Independent Partitioned State) takes into account that certain embedded services need to know a given user's activity on a site to function. CHIPS are partitioned cookies that will inform browsers that the necessary cookie is allowed to function only between a particular site and another embedded site. | Implemented |
| Storage Partitioning | Storage Partitioning will isolate certain web platform APIs that are used for storage or communication when used by an embedded service on a given site. This will enhance web privacy while still allowing web compatibility with existing sites. | Implemented |
| Network State Partitioning | Network State Partitioning will partition a browser's network resources to prevent these resources from being shared across first-party contexts. It requires each request to have an additional "network partition key" for resources to be reused and safeguards user privacy by disallowing access to shared resources and metadata learned from loading other sites. | Implemented |
| Federated Credential Management | Federated Credential Management is an API that will provide support for single sign-on designs that previously depended on third-party cookies. | Implemented |
| Client Hints | Client Hints API allows sites to request required information directly rather than via a User-Agent String, a significant surface vulnerable to passive fingerprinting, therefore reducing details that can be shared about a user online. | Implemented |
| User Agent reduction | User Agent reduction minimizes the information in a User-Agent String thereby reducing its vulnerability to passive fingerprinting. | Implemented |
| Privacy Budget | Privacy Budget aimed to limit fingerprinting by restricting the identifying information that a site is allowed to access. | Discontinued |
| HTTP Cache Partitioning | HTTP Cache Partitioning assigns cached resources with a 'network isolation key' along with the resource URL, composed of the top-level site and current-frame site. This prevents other websites from being able to infer details about the status of cached resources on a different website. | Implemented |
| IP Protection | IP Protection is a proposal that will hide a user's IP address from third parties using double-hop anonymous proxy. | Discontinued |
| DNS-over-HTTPS | The DNS-over-HTTPS protocol prevents attackers from observing the sites a user visits by encrypting Domain Name System (DNS) queries. | Implemented |
| Topics API | Topics API aims to provide the means for advertisers to show relevant content and ads by sharing interest-based categories, or 'topics', based on recent browsing history processed on the user device. | Discontinued |
| Fenced Frames API | Fenced frames are an embedded frame type that is not permitted to communicate with a given host page, making it safe to access its unpartitioned storage as joining its identifier with the top site is impossible. Advertisements using FLEDGE-based APIs will only be allowed to be displayed within Fenced Frames. | Implemented |
| Attribution Reporting API | The Attribution Reporting API facilitates conversion tracking, for example, recording whenever a click on an ad or a view results in a purchase, while suppressing the ability to track users across multiple websites. | Discontinued |
| Protected Audience API | Protected Audience API is designed for targeting of interested audiences, including through retargeting. It allows vendors selected for advertising to take an advertiser's website data and to place users in interest groups specifically defined for a given advertiser, meaning that users can see tailored ads, with no infringement on their privacy. Prior to reaching global availability on August 17, 2023, the technology was known as "First Locally-Executed Decision over Groups Experiment", (FLEDGE). | Discontinued |
| Private Aggregation | Private Aggregation API can be used to track aggregated statistics across ad campaigns. | Discontinued |

== Criticism ==
Google's proposals during Privacy Sandbox surrounding privacy preserving ads have garnered significant pushback. Concerns have been raised that the proposals are anticompetitive and privacy compromising. Google's initial proposal for privacy preserving ads under the Privacy Sandbox umbrella (codenamed FLoC) received significant opposition from browser vendors. Mozilla, the company that makes Firefox, released a statement committing to not implementing FLoC or other related web advertising proposals. Apple, the makers of Safari took a negative position against the proposal. Chromium derivatives like Brave, Vivaldi and Microsoft Edge disabled the feature by default on their browsers. Concerns were raised that the FLoC's proposal could allow websites to track users in new ways that were previously not possible through third-party cookies, the technology that FLoC was meant to replace. Multiple media outlets and privacy advocacy groups criticised Google's decision to enable the feature by default for all users during the testing phase. This led to Google to withdrawing the proposal in early 2022.

Google's replacement for FLoC, known as the Topics API, faced similar criticism from various groups. Mozilla pointed out flaws in the Topics API's design, highlighting that it could allow large advertising networks to reidentify and track users by aggregating their interests across numerous websites. Apple echoed similar concerns, also noting that the proposal contradicted efforts made by other browsers to partition data on a per-site basis. Furthermore, when the proposal was initially announced, there were uncertainties about how Google or other browser vendors would establish a taxonomy of topics, a critical aspect of the API that was left underspecified. Alongside the Topics API, Google's other proposals within the Privacy Sandbox, such as Client Hints, have also sparked significant privacy concerns among other browsers. These concerns primarily revolved around the potential for Client Hints to expand the surface area for passive fingerprinting on browsers.

Due to Google's ownership of the browser with the largest market share, concerns have been raised about the anticompetitive nature of its proposals. Consequently, in January 2021, the Competition and Markets Authority (CMA) in the United Kingdom announced plans to investigate the Privacy Sandbox initiative, with a focus on its potential impacts on both publishers and users. CMA subsequently accepted legally binding commitments offered by Google concerning its proposals to remove third party cookies on Chrome and develop the Privacy Sandbox. The formal acceptance of these commitments by the CMA resulted in the closure of the investigation, with no decision on whether the Competition Act 1998 was infringed. CMA reported that Google was complying with its legally-binding commitments between July 2022 and September 2022. In March 2021, 15 attorneys general of U.S. states and Puerto Rico amended an antitrust complaint filed the previous December; the updated complaint says that Google Chrome's phase-out of third-party cookies in 2022 will "disable the primary cookie-tracking technology almost all non-Google publishers currently use to track users and target ads. Then [...] Chrome, will offer [...] new and alternative tracking mechanisms [...] dubbed Privacy Sandbox. Overall, the changes are anticompetitive". The lawsuit suggests that the proposed changes in the Privacy Sandbox would effectively require advertisers to use Google as a middleman in order to advertise. In 2025, following Google discontinuing the Privacy Sandbox proposal, CMA decided to release Google from their legally binding commitments related to third-party cookie deprecation.
