Nearly every guide to cookieless tracking was written for a deadline that never arrived. The story went: Chrome kills third-party cookies, your ads go dark, migrate now or lose everything.
Chrome didn’t kill them. In April 2025 Google confirmed it would keep the existing third-party cookie settings and drop the planned choice prompt. Six months later it retired ten Privacy Sandbox APIs, including those meant to replace cookies for targeting and attribution. The replacement was shelved before the thing it replaced went away.
So the honest question for a Malaysian business is not “how do I survive the cookie apocalypse”. It is narrower: my conversions don’t add up — which part of that is actually a cookie problem, and which part was never about cookies at all?
This guide answers that: what cookieless tracking means now the premise has changed, what really blocks cookies here, where the missing conversions go, which fixes you qualify for, and how to tell it’s working. The benchmarks come from ZenWeb‘s work across 500+ Malaysian SME accounts — the same ground our digital marketing services cover.
Before the detail, a useful warning about the label itself.
Source video: MeasureU on YouTube
Quick Answer: Cookieless tracking is measuring visitors and conversions without relying on third-party cookies. It leans on first-party identifiers you collect yourself, events sent from your own server, and statistical modelling to fill gaps. It is a set of methods, not a single product you install.
The name is misleading in two directions, and both cost Malaysian businesses money.
It comes down to four parts: a first-party identifier you own, a delivery path that isn’t blocked, consent you can prove, and modelling for the rest. Most SMEs have the first by accident, the second not at all, and expect the fourth to rescue them. Section 6 shows why it won’t.
Not sure which part of your tracking is actually broken?
Most accounts we open have one fixable gap, not four. Run the 12-check Google Ads audit →
Quick Answer: About 15% of Malaysian browser sessions block or partition third-party cookies by default — Safari at 13.69% and Firefox at 1.46%. Chrome, at 78.02% of the market, still allows them. Malaysia is the mirror image of the US and European markets these guides are written for.
This number should set your budget. Safari blocks third-party cookies outright and caps script-written storage at seven days, per Apple’s WebKit team. Firefox partitions them into a separate jar per site under Total Cookie Protection. Chrome allows them everywhere except Incognito.
| Browser | Share of MY sessions (%) | Third-party cookies by default | First-party storage cap |
|---|---|---|---|
| Chrome | 78.02 | Allowed (blocked in Incognito) | None |
| Safari | 13.69 | Blocked | 7 days without interaction |
| Edge, Opera, Samsung Internet | 5.60 | Allowed (Chromium default) | None |
| Firefox | 1.46 | Partitioned per site | None |
| Blocked or partitioned by default | 15.15 | Safari + Firefox combined | |
Source: Statcounter Malaysia, May 2026; policies per Google, WebKit and Mozilla documentation.
Fifteen percent is not nothing — one in seven sessions, and Safari skews to higher-value iPhone buyers in Klang Valley. But it is a long way from a measurement blackout. A vendor quoting a global Safari figure to justify a rebuild is selling you someone else’s market.
Quick Answer: Across ZenWeb’s Malaysian accounts, browser restrictions explain only about a quarter to a third of unmatched conversions. The larger shares come from cross-device journeys and closes that happen off the website entirely — usually on WhatsApp. Neither is a cookie problem.
This breakdown changes what you spend money on. We take every conversion an account can prove happened but Google or Meta missed, then sort by cause. The pattern holds across industries: the browser is a supporting actor; the Malaysian habit of jumping to WhatsApp is a lead role.
| Cause of signal loss | Google Ads (%) | Meta Ads (%) | GA4 (%) |
|---|---|---|---|
| Cross-device journey | 33 | 26 | 29 |
| Closed off-site (WhatsApp, call, walk-in) | 23 | 20 | 12 |
| Safari and iOS restrictions | 24 | 31 | 27 |
| Consent declined | 11 | 10 | 18 |
| Ad blockers and extensions | 9 | 13 | 14 |
Source: ZenWeb client sample, 500+ Malaysian SME accounts, 2024–2026. Licence.
More than half of what Malaysian SMEs call “cookie loss” is a customer switching phones or opening WhatsApp — and no cookieless tool fixes either.
Read the top two rows again. A prospect browses on their phone at lunch, searches on a laptop that evening, then WhatsApps you next morning. No blocked cookie anywhere in that journey — and every cookieless product on the market still misses it. The fixes are offline conversion imports and WhatsApp lead tracking, not a new tag.
Quick Answer: Five methods carry real weight in Malaysia: first-party data capture, server-side event delivery, the Conversions API and enhanced conversions, consent mode with modelling, and offline conversion imports. Each fixes a different cause, and none fixes all of them.
Match the method to the cause you found in Section 4. Buying in the wrong order is how SMEs spend RM 5,000 fixing 9% of the gap.
| Method | Fixes | Effort |
|---|---|---|
| First-party data capture | Cross-device, Safari, everything downstream | Low — forms and CRM hygiene |
| Enhanced conversions / CAPI | Safari, ad blockers, match quality | Low to medium |
| Offline conversion import | WhatsApp, phone and walk-in closes | Medium — needs clean CRM stages |
| Server-side tagging | Ad blockers, Safari storage caps | High — hosting plus a developer |
| Consent mode + modelling | Consent declines — if you qualify | Medium — and volume-gated |
Start at the top. First-party data is the input every other method consumes — the Conversions API and enhanced conversions both need hashed emails or phones to match anything. Get capture right and the rest gets cheaper. Server-side tracking sits last for a reason: it is the most expensive item here and, in a Chrome-heavy market, rarely the highest-yield.
Quick Answer: Google requires 700 ad clicks per 7 days, per country and domain, before consent mode modelling activates in Google Ads. Most Malaysian SMEs spending under RM 6,000 a month never reach it — so the fix marketed as the answer to consent loss is switched off for them.
The pitch decks leave this part out. Modelled conversions are gated by volume thresholds Google publishes openly: 700 ad clicks over seven days per country and domain grouping for Google Ads, and 1,000 denied events a day plus 1,000 consented daily users for GA4. We applied the Google Ads threshold to real Malaysian account volumes.
| Monthly Google Ads spend | Share clearing the threshold | Accounts (%) | Typical clicks/week |
|---|---|---|---|
| RM 1,500 | 6 | 110 | |
| RM 3,000 | 18 | 210 | |
| RM 6,000 | 44 | 420 | |
| RM 12,000 | 79 | 810 | |
| RM 25,000+ | 96 | 1,700 |
Source: ZenWeb client sample, 500+ Malaysian SME accounts, 2024–2026; threshold per Google Ads Help.
An SME on RM 3,000 a month has roughly a one-in-five chance of ever seeing a modelled conversion. That is not a reason to skip consent mode — it still stops Google’s tags writing cookies without permission, which is the point of the consent mode and PDPA setup. It is a reason to stop treating modelling as your recovery plan.
Want to know if your spend clears the bar?
We’ll check your click volume against Google’s thresholds and tell you straight whether modelling is worth the wait. See how our digital marketing team handles measurement →
Quick Answer: Work in five steps: measure your real loss, capture a first-party identifier at every enquiry, turn on enhanced conversions and the Conversions API, import your offline closes, then add consent mode. Most Malaysian SMEs finish in three weeks without touching a server.
The order matters more than the tools. Each step feeds the next, so working out of sequence means redoing them.
Quick Answer: Chrome proposed removing third-party cookies in 2019, targeted 2022, delayed repeatedly, then confirmed in April 2025 that they stay. In October 2025 it retired ten Privacy Sandbox APIs. Safari and Firefox, meanwhile, have not moved since 2020 and 2022 respectively.
Seven years of roadmap, and the only vendor whose position moved is the one that kept changing its mind. The table tracks each browser’s default — and which announcements ever reached a Malaysian user.
| Track | 2019 | 2020 | 2022 | 2024 | 2025 | 2026 | 2027* |
|---|---|---|---|---|---|---|---|
| Chrome cookies | Removal proposed | 2022 target set | Delayed | Prompt floated | Prompt dropped (Apr) | Allowed | No removal signalled |
| Privacy Sandbox ad APIs | Initiative launched | Proposals published | Origin trials | Low adoption | 10 APIs retired (Oct) | CHIPS, FedCM, PST only | W3C attribution work |
| Safari cookies | ITP restrictions | Fully blocked (Mar) | Blocked | Blocked | Blocked | Blocked | Blocked |
| Firefox cookies | ETP on by default | ETP on by default | Partitioned (Jun) | Partitioned | Partitioned | Partitioned | Partitioned |
* 2027 reflects each vendor’s stated position as of July 2026, not a commitment. Source: compiled from Google Privacy Sandbox, WebKit and Mozilla announcements, 2019–2026.
The lesson for a search engine marketing budget: stop planning around vendor roadmaps. Safari has been stable six years; Chrome changed four times. Build for the defaults that exist.
Quick Answer: The common failures are double-counting after a CAPI install, treating modelled numbers as real sales, blocking your own tags with a badly configured banner, and rebuilding attribution while the actual leak is an unanswered WhatsApp message.
None are exotic. All four turn up in ordinary marketing analytics reviews, and all cost less to prevent than to unwind.
Quick Answer: Judge cookieless tracking on one number: the gap between deals closed in your CRM and conversions attributed in your ad accounts. If that gap narrows month on month, it works. Match quality scores and event counts are diagnostics, not results.
Check these four monthly, in this order:
Give it 60 days. Smart bidding needs time to train on the improved signal, and judging at week two tells you nothing about your PPC economics.
Quick Answer: Cookieless tracking is still worth doing in Malaysia — just not for the reason it was sold. The deadline died; the signal loss didn’t. Own your first-party data, send it directly, import your offline closes, and the cookie question stops mattering.
The cookie apocalypse was cancelled and hardly anyone updated the advice. Chrome kept third-party cookies, the Privacy Sandbox replacement was retired before the thing it replaced, and Malaysia was never the Safari-heavy market the warnings assumed.
What survived is simpler than the roadmap: the businesses measuring well are the ones that collected their own customer data and sent it to the platforms themselves. That was true when the deadline looked real, and it is true now it’s gone. It is also the discipline that makes Google Ads and SEO compound instead of resetting every time a browser changes its mind.
Ready to find out what your tracking is really missing?
Book a free 30-minute strategy session — we’ll compare your closed deals against what Google and Meta recorded, name the biggest cause of the gap, and give you a 90-day plan with realistic CPL and pipeline targets.
No. Google confirmed in April 2025 that Chrome will keep offering third-party cookie choice in its existing privacy settings, with no separate removal prompt. Safari has blocked them by default since 2020 and Firefox partitions them per site. In Malaysia, Chrome’s 78% share means most sessions still allow third-party cookies today.
Yes, but for different reasons than the marketing suggests. Roughly 15% of Malaysian sessions block or partition third-party cookies, and larger losses come from cross-device journeys, consent declines and WhatsApp closes. These methods address those causes; waiting for a Chrome deadline that no longer exists does not.
Capturing an email or phone number on every enquiry, then switching on enhanced conversions and the Conversions API. Both are free, take an afternoon, and use first-party identifiers instead of cookies. Server-side tagging costs hosting and developer time, and rarely pays back until the free steps are already running.
Only if you have the volume. Google Ads requires 700 ad clicks over seven days per country and domain before modelling activates, and GA4’s behavioural modelling needs 1,000 daily events with consent denied plus 1,000 consented daily users. Most Malaysian SMEs spending under RM 6,000 monthly never clear those floors.
No. Cookieless and compliant are separate tests — a tool can avoid cookies and still collect personal data like IP addresses. PDPA obligations depend on what you collect, why, and what you told people, not on the storage method your analytics uses. Treat consent and measurement as two projects.
Complete the form and our team will contact you to discuss your goals. Let’s grow your business.

Online