SameSite is a cookie security attribute — set in the cookie's HTTP header — that controls whether a cookie is sent with cross-site requests. The attribute has three values: Strict (same-site requests only), Lax (same-site requests and top-level navigations), and None (all cross-site requests, requiring the Secure attribute). Google Chrome began enforcing SameSite=Lax as the default in 2020, significantly reducing cross-site tracking. Third-party advertising and analytics cookies require SameSite=None; Secure to function across different sites — and still require GDPR consent regardless of their SameSite setting.