The cookieless future did not happen. Google kept third-party cookies in Chrome, then retired the technologies it spent six years building to replace them. If your marketing strategy was built on a deprecation deadline, that deadline was cancelled twice and you should stop paying for advice that assumes otherwise.
You should still build a first-party audience. The reason has nothing to do with cookies, and in South Africa it has a legal dimension that most international coverage of this subject does not touch at all.
Argument oneWhat actually happened, in order
The timeline is worth stating precisely, because a great deal of South African marketing content is still selling a version of it that was overtaken two years ago.
On 22/07/2024, Anthony Chavez, Google’s Vice President for Privacy Sandbox, announced that Chrome would not deprecate third-party cookies. Instead, users would be offered a choice. On 22/04/2025 Google dropped even that: in Chavez’s words, the company had decided to maintain its current approach to offering users third-party cookie choice in Chrome, and would not roll out a new standalone prompt. Cookie preferences stayed where they had always been, in Chrome’s privacy and security settings.
Then on 17/10/2025 came the part that settled it. Google announced the retirement of around ten Privacy Sandbox technologies, including the Topics API, the Protected Audience API and the Attribution Reporting API. The stated reason was ecosystem feedback about their expected value and, in Google’s own phrasing, their low levels of adoption. Chrome began removing them during 2026. In the same month, the United Kingdom’s Competition and Markets Authority released Google from its Privacy Sandbox commitments and closed a four year investigation, on the basis that Google was no longer removing third-party cookies.
Google kept a small residue: CHIPS, which partitions cookies per website, and FedCM for privacy-preserving sign-in, along with private state tokens. Both had seen real adoption. The advertising replacements did not.
Six years of industry planning, and the answer was that nothing changes.
Argument twoExcept that the cookieless present arrived on its own
Here is the part the reversal obscures. Safari blocks third-party cookies. Firefox blocks them. Brave blocks them. Estimates put roughly 17 to 20 percent of global traffic as cookieless by default, entirely independently of anything Chrome decides.
So the practical position for a South African business is that a meaningful share of your visitors were never trackable across websites, your attribution has been partially blind for years, and the fix that was promised has been formally abandoned. Google’s own stated path forward is a proposed interoperable attribution standard at the W3C, with no committed date.
That is a worse outcome than either the deprecation or the status quo. The measurement problem is permanent, and there is no longer a roadmap that solves it.
Argument threeThe real driver was never the browser
The argument for owning an audience does not rest on cookies at all. It rests on the fact that every channel you rent is getting worse at the same time.
Organic search visibility is being compressed by AI answers, and the mechanism is not subtle: an answer rendered above the results reduces the clicks that reach your website. Paid reach costs more each year and stops the moment you stop paying. Social platforms change their distribution whenever it suits their revenue, and the reach you built last year does not transfer. None of those are cookie problems. All of them are the same problem, which is that the relationship between you and the person who wants to buy from you is intermediated by a company whose interests are not yours.
A first-party audience is the only channel where that intermediation does not exist. An email address you obtained lawfully, held yourself, and can reach without permission from a platform, is the one marketing asset that does not depreciate when someone else changes an algorithm.
That was true before the cookie debate started, it was true during it, and it is true now that the debate has been abandoned. The cookie argument was always a convenient hook. It was never the reason. Earning visibility inside AI answers is worth doing, but it is still visibility you are granted rather than visibility you hold.
Argument fourIn South Africa, first-party data is a permission, not a database
This is where South African businesses need something different from what the international coverage tells them, because POPIA is considerably stricter about electronic marketing than most of the frameworks that content is written against.
Section 69(1) of POPIA prohibits processing personal information for the purpose of direct marketing by any form of electronic communication unless one of two bases applies: the data subject has consented, or the data subject is an existing customer and the conditions in section 69(3) are satisfied.
Consent is not a tick box you can design however you like. Section 69(2), read with regulation 6 and Form 4 of the POPIA Regulations, requires that consent for electronic direct marketing be requested in the prescribed manner and form. A responsible party may make only one approach to a non-customer to ask for that consent. Consent bundled into general terms and conditions, captured through an opaque checkbox, or reverse-engineered from an imported database is unlikely to satisfy the requirement, and a marketer relying on it in defence of a complaint is in a weak position.
The existing customer exception in section 69(3) has three legs, and all of them must hold: you obtained the contact details in the context of a sale, you are marketing your own similar products or services, and you gave an opportunity to opt out both at the point of collection and in every message since. Section 69(4) then requires every marketing communication to identify the sender, or the person on whose behalf it is sent, and to provide contact details through which the recipient can ask that the communications stop.
Three consequences follow that South African businesses routinely get wrong.
Buying, renting or scraping a list is not a shortcut with a compliance risk attached. It is the thing the section prohibits, and there is no version of it that works.
POPIA protects juristic persons as well as natural persons, so business-to-business marketing is inside the regime. The common belief that consent rules do not apply because the recipient is a company is wrong.
The Information Regulator issued a Guidance Note on direct marketing in December 2024 which treats telephone calls as electronic communications for section 69 purposes, a departure from the older Consumer Protection Act position that permitted telephonic marketing on an opt-out basis. Legal challenges to that interpretation are anticipated, but it is the Regulator’s stated view and direct marketing is one of its stated enforcement priorities.
The practical reframing is this. In South Africa a first-party audience is not a list of contacts you accumulated. It is a set of permissions you obtained correctly, each with a provenance you could evidence if asked. That is a slower asset to build and a considerably more durable one. It is also, incidentally, the same discipline that governs where that personal information ends up once you hold it.
Argument fiveA list you cannot deliver to is not an asset
The second thing nobody budgets for is that the technical bar for reaching an inbox moved sharply while everyone was arguing about cookies.
Google and Yahoo announced joint bulk sender requirements in October 2023, effective from 01/02/2024. Senders delivering 5,000 or more messages a day to personal Gmail or Yahoo accounts must authenticate with SPF and DKIM, publish a DMARC record with a policy of at least p=none and pass alignment, implement one-click unsubscribe under RFC 8058 with a deadline of 01/06/2024, honour opt-outs promptly, and keep spam complaint rates below 0.3 percent as measured in Google Postmaster Tools, with under 0.1 percent recommended. Microsoft announced equivalent authentication requirements in April 2025, enforcing from May 2025 for Outlook, Hotmail and Live addresses.
Enforcement has hardened. In November 2025 Google escalated from temporary rate-limiting failures to permanent rejections.
A rejected message is not filtered into a spam folder where a diligent recipient might find it. It never arrives anywhere.
Reported estimates suggest a substantial minority of bulk senders remain non-compliant on at least one requirement, most commonly the one-click unsubscribe header. In our experience the more common South African failure is simpler than that: no DMARC record at all on the sending domain, on a website whose owner has no idea the record is missing and no way to discover it from inside their email platform. That is a maintenance gap rather than a marketing one, which is exactly why it goes unnoticed for years.
The uncomfortable implication is that a business can spend two years lawfully building a list under POPIA and still have most of it undeliverable, because nobody configured three DNS records.
Argument sixWhat this actually asks of the website
The changes are unglamorous and mostly small.
Consent capture that meets the prescribed form rather than a generic newsletter checkbox, with the purpose stated at the point of collection and a record of when and how it was given. Separate consent for separate purposes, because consent to be contacted about an enquiry is not consent to receive a monthly newsletter. A preference and unsubscribe route that works in one click and is honoured immediately. SPF, DKIM and DMARC correctly configured on the sending domain, with DMARC moved past monitoring once the reporting is clean. And a reason for someone to give you their address that is worth the exchange, which is the part that actually decides whether any of this produces an audience.
And a retention position, because a permission obtained in 2019 for a purpose that no longer exists is not an asset either.
The honest case against
Most South African small businesses should not build a data programme, and a good deal of what is sold under this heading is expensive theatre.
A list of 300 addresses emailed twice a year is not a marketing asset. It decays through job changes and abandoned accounts, it produces spam complaints precisely because the sender is unfamiliar by the time the email arrives, and those complaints damage the sending reputation of the domain the business also uses for quotes and invoices. Sending badly is worse than not sending.
There is also an attention cost that nobody prices. Somebody has to write the thing, every month, indefinitely, and the businesses that start a newsletter and abandon it after four issues have published a visible signal that they do not finish what they start. For a plumbing business, an attorney in Randburg or a specialist manufacturer with eleven customers who each represent a fifth of revenue, the honest advice is that a working enquiry path, a complete Google Business Profile and a website that answers the questions buyers actually ask will return more than a mailing list, and will do it sooner.
The customer relationship management industry has also spent a decade selling infrastructure to businesses whose actual problem is that they do not follow up on the enquiries they already receive. A platform does not fix that. A person does.
So the position is not that every business needs a list. It is that if you are going to have one, it has to be lawful, deliverable and worth receiving, and that most of the failures happen on one of those three rather than on strategy.
Stop treating this as a cookie problem, because it never was one and the cookie problem was cancelled anyway.
Treat it as a dependency problem. Look at where your enquiries came from over the last twelve months, and ask how much of that flow you would still have if one platform changed its behaviour. For most South African businesses the honest answer is uncomfortable, and it has nothing to do with browser tracking.
If you decide to build an owned audience, build it properly: consent in the prescribed form with provenance you can evidence, authentication configured before the first send, something genuinely worth receiving, and a commitment you will still honour in a year. If you are not going to do those four things, the money is better spent making your website do the job it is actually there to do.
The businesses that will be in a strong position in three years are not the ones that reacted fastest to a deprecation that never arrived. They are the ones who noticed that the rented channels were narrowing and started building something they own, quietly, before it became urgent.
Frequently Asked Questions
Are third-party cookies still being phased out in Chrome?
No. Google announced in July 2024 that Chrome would not deprecate third-party cookies, and confirmed in April 2025 that it would not even roll out a standalone user prompt. In October 2025 it retired around ten Privacy Sandbox technologies including the Topics, Protected Audience and Attribution Reporting APIs, citing low adoption. Third-party cookies remain in Chrome, while Safari, Firefox and Brave continue to block them by default.
Can I email a purchased list in South Africa?
No. Section 69 of POPIA prohibits direct marketing by electronic communication unless the recipient has consented in the prescribed manner and form, or is an existing customer meeting the section 69(3) conditions. A bought, rented or scraped list satisfies neither basis. POPIA also protects juristic persons, so business-to-business marketing is covered by the same rules.
What is the existing customer exception under POPIA?
Section 69(3) permits electronic direct marketing to an existing customer without separate consent where three conditions are met: the contact details were obtained in the context of a sale, the marketing relates to your own similar products or services, and the person was given an opportunity to object both when the details were collected and in every subsequent communication.
Do I need a DMARC record to send marketing emails?
If you send 5,000 or more messages a day to personal Gmail or Yahoo accounts, yes. Google and Yahoo have required SPF, DKIM and a DMARC record of at least p=none since February 2024, along with one-click unsubscribe and a spam complaint rate below 0.3 percent. Microsoft introduced equivalent authentication requirements enforced from May 2025. Below that volume the requirements are strongly recommended rather than mandatory, and configuring them is cheap protection either way.
What happens if my emails fail these requirements?
Increasingly they are rejected rather than filtered. Google escalated in November 2025 from temporary rate-limiting failures to permanent rejections, and Microsoft returns permanent rejection errors for non-compliant traffic. A rejected message does not land in a spam folder where someone might still find it. It does not arrive at all.
Does POPIA apply to marketing phone calls?
The Information Regulator’s Guidance Note on direct marketing, issued in December 2024, treats telephone calls as electronic communications for the purposes of section 69, which would require opt-in consent or reliance on the existing customer exception. That is a departure from the older Consumer Protection Act position permitting telephonic marketing on an opt-out basis, and legal challenges to the interpretation are anticipated. It is nonetheless the Regulator’s stated position.
Should every small business build an email list?
No. A small list emailed sporadically decays, generates spam complaints and damages the sending reputation of the same domain used for quotes and invoices. For many South African service businesses, a working enquiry path, a complete Google Business Profile and a website that answers real buyer questions will return more, sooner. Build a list only if you will do it lawfully, authenticate it properly and sustain it.
Build the asset you actually own
We build WordPress websites for South African businesses, including the consent capture, form handling and email authentication that decide whether an audience is lawful and whether it reaches an inbox. If nobody has checked your sending domain in the last two years, that is a ten minute answer.
Take a look at our website design services, or get in touch to talk it through.







