Chrome's reversal is not a free pass
In April 2025 Google announced it would no longer force the deprecation of third-party cookies in Chrome. By 2026 that settled into place: Chrome did NOT remove third-party cookies by default. They stay on by default, with a toggle in the Privacy settings for anyone who wants to turn them off.
For a lot of product and marketing people the takeaway was immediate and wrong: "so I don't need to change anything, third-party cookies survived". That is the trap. Chrome's reversal solved one problem (the sunset deadline), but it did not touch any of the others that were already on the table. Anyone who stopped preparing because of the announcement is building on a foundation that is already cracked.
This article is about why, for Brazilian SaaS in particular, the right technical answer is still the same: get off the third-party cookie dependency and move to first-party, LGPD-first measurement.
The landscape is fragmented, not resolved
Chrome is the biggest browser, but it is not the only one. And the others made the opposite call a long time ago:
- Safari blocks cross-site tracking by default.
- Firefox blocks cross-site tracking by default.
- Brave blocks cross-site tracking by default.
So even with Chrome keeping third-party cookies on, a meaningful slice of your traffic already arrives without them. If your measurement depends on third-party cookies to work, it is already blind on a share of your users. And that blindness is not random, it is biased: it tends to hit exactly the most privacy-conscious audience, which is often the most technical and most valuable one for a SaaS.
The technical point is this: you are not choosing between "third-party cookies work" and "third-party cookies are dead". You live in a world where they work on part of your traffic and fail on the rest, and you do not control which is which. Basing product decisions on data with a hole like that is bad.
LGPD did not back off
Here is the part the browser debate tends to hide. Regardless of what Chrome does, the law did not change. LGPD in Brazil and GDPR in Europe still require the same thing: inform the user and obtain explicit consent before setting cookies.
Notice that this is orthogonal to the technical third-party cookie discussion. Browser behavior is one thing. The legal obligation is another. Even if Chrome kept third-party cookies on forever, you, as a data controller in Brazil, are still required to:
- Clearly inform which data you collect and why.
- Obtain explicit consent before setting the cookie, not after.
- Let the user decline and still use the product.
Chrome's reversal gave you zero relief on this front. It gave you a false sense that the "cookie" topic is closed, when the part that exposes you the most legally (consent) was never in Google's hands.
The technical trade-off, no fluff
Let's be honest about the cost of each path.
Path A, keep depending on third-party cookies. Cheap to maintain in the short term because it is already wired up. But you pay in: broken coverage on the browsers that block, LGPD/GDPR exposure if consent is not rigorous, and platform risk (you depend on a Google product decision that already changed once and can change again). It is technical debt with regulatory interest.
Path B, first-party measurement with no third-party cookies. More work to build, but the foundations are stable. The three alternatives that sustain measurement without depending on third-party cookies are:
- First-party data. You measure what happens on your own domain, with identifiers that are yours. It does not rely on a third party writing a cookie in the user's browser across sites. It survives Safari/Firefox/Brave blocking by construction.
- Server-side measurement. Instead of letting the browser ship everything to a third-party script, the event goes through your server. You control what leaves, what stays and what gets anonymized. That reduces the blocking surface (adblock and ITP target third-party scripts) and gives you real control over the data before it leaves your infra.
- Consent-driven measurement. Measurement respects the consent state by design. Without consent, you set no cookie and collect only the minimal aggregate the law allows. With consent, you enrich. Consent becomes a first-class input of the system, not a decorative banner stuck on top.
The real trade-off is: Path A is cheap now and expensive later. Path B is expensive now and cheap later, and it is the only one that stands up in all three scenarios at once (browsers that block, browsers that do not, and the law that demands consent in all of them).
Why this weighs more for Brazilian SaaS
If you are a founder or dev of a SaaS in Brazil, the math tilts even harder toward Path B for three concrete reasons:
- LGPD is your home risk. It is not a distant European compliance worry. It is the law that applies directly to your product, with the ANPD able to enforce it. Botched consent is a real liability.
- Your technical audience uses the browsers that block. Devs, founders, product people, the audience that buys B2B tools tends to use Firefox, Brave, Safari and privacy extensions. You are blind precisely on the people who matter most.
- Data sovereignty and localization. Keeping analytics data in Brazil, under your own infra, simplifies the LGPD conversation and avoids unnecessary international transfers. That is a sales argument, not just a compliance one.
The resilient play
Put it all together: fragmented browsers, an LGPD that does not back off, and a technical audience that already blocks tracking. The technical conclusion is straightforward. First-party analytics, with no third-party cookies, with consent baked into the design, is the only architecture that does not depend on a Google decision to keep working. You stop betting on what Chrome will do next year and start controlling your own measurement.
This is not "privacy versus data". It is that the privacy-first approach, in this scenario, is also the one that gives you more consistent data and less legal liability. Both point to the same place.
Where RET fits
This pain is exactly the one we decided to solve. RET has a new product in beta called Métrica Pura: cookieless analytics, LGPD-first, with data hosted in Brazil and adblock-resistant via a first-party proxy, and it starts free, no card. It is beta, so we treat it as beta: we are still polishing it, and the invite is for anyone who wants to test this approach in practice and give feedback. If you want to try it, it is at métricapura.com.br.
Chrome can change its mind again. Your LGPD posture and your measurement architecture should not depend on that.




