A third-party cookie is set by a domain different from the one in the browser's address bar — typically loaded via an embedded ad, iframe, script, or social widget. Common examples: IDE and _gcl_au from Google Ads, _fbp and fr from Meta, bcookie from LinkedIn. They're the backbone of cross-site retargeting, ad measurement, and social embeds. Under GDPR and ePrivacy Article 5(3), third-party cookies always require opt-in consent — they're never strictly necessary. Safari's ITP and Firefox's Total Cookie Protection block or partition them by default. Chrome's Privacy Sandbox is still phasing them out in 2026 — deprecation is partial, not complete.