RGM-202 · Paid Social Mastery · Module 2 of 7

Audiences in the Cookieless Era

iOS 14.5, ITP, third-party cookie deprecation, Privacy Sandbox, GDPR, state-by-state US privacy laws — the audience-building playbook of 2018 doesn't work in 2026. This module covers the audience tiers that work now (first-party data, modeled audiences, platform aggregation), per-platform custom audience types, the lookalike playbook for high-LTV seeds, aggregated measurement (SKAN, Privacy Sandbox), identity resolution and CDPs, consent management, and the 10 mistakes operators make trying to recreate the old playbook.

What you will learn10 sections
Broad + signalslet the model expandLookalike & Advantage+modeled from your seedCustom audiencesretargeting & CRMFirst-party dataowned · consented · durable

1. What "cookieless era" actually means in 2026

The “cookieless era” means the third-party cookie and cross-site tracking are gone or dying, and a big share of users decline app tracking — so platforms model and estimate audiences instead of observing them deterministically. You plan for incomplete signal, not perfect tracking.

For 20 years, digital advertising audiences were built on third-party cookies — identifiers set by ad platforms that followed users across the web. That model is dying. Apple Safari blocks third-party cookies (since 2020). Firefox blocks them by default (since 2019). Chrome's Privacy Sandbox transition continues to evolve in 2026, with most third-party cookie functions either removed or routed through aggregation APIs (Topics, Protected Audience). Combined with iOS 14.5 ATT (2021) and ongoing US state privacy laws, the audience-building playbook of 2018 doesn't work.

What replaces it: first-party data, modeled audiences, and platform-native aggregation. Operators who internalize this in 2024-2026 are positioned for the next 10 years; operators who keep trying to recreate the 2018 audience playbook are losing measurable ground.

Interactive · tap a date The cookie that wouldn’t die
Six years of ‘the end of cookies’ — and how it actually played out

The deprecation everyone planned for kept slipping, then reversed. Tap through what really happened.

2020 · Chrome announces the end

Google says Chrome will phase out third-party cookies “within two years.” The industry braces for the end of cookie-based targeting.

2022–24 · Delay, delay, delay

Deprecation slips from 2022 to 2023 to 2024 to 2025. Each delay buys time, but the direction still looks settled.

Jul 2024 · The reversal

Google says it will not force-deprecate cookies, pivoting to a Chrome “user choice” model instead.

Apr 2025 · Cancelled outright

Deprecation is scrapped; Google drops even the separate consent prompt. Cookies stay, user-controlled in Chrome settings.

Oct 2025 · Privacy Sandbox dies

Google shuts down all ten Privacy Sandbox APIs — Topics, Protected Audience, Attribution Reporting. The replacement is gone too.

Yet Safari and Firefox — ~36% of traffic — already block third-party cookies, and iOS limits tracking. The cookieless era arrived through the back door anyway. Sources: CookieYes · Privacy Sandbox.

Claim: As of 2025, roughly a third of prompted users opt in to app tracking (App Tracking Transparency), with figures varying by methodology and category. Source: Adjust — ATT opt-in benchmarks 2025. Context: The majority opting out is exactly why first-party data and modeled audiences replaced deterministic cross-app tracking.

2. The audience tiers that work now

The audience tiers that still work are, in order: your own first-party data (customers, site visitors via server-side events), platform-modeled lookalikes built on that data, and broad targeting steered by creative. Hyper-narrow interest stacks are the tier that quietly stopped working.

  1. First-party data (highest signal) — your customer email list, your CRM, your subscription database, your loyalty program. Hashed and uploaded to platforms as Custom Audiences (Meta), Customer Lists (Google), Custom Audiences (TikTok), Matched Audiences (LinkedIn). Used directly for retargeting and as seeds for lookalikes.
  2. Behavioral first-party data — website visitors, app users, video viewers, ad-engagement audiences, all captured via Pixel/SDK. Useful for retargeting (7-30 day windows).
  3. Lookalike / Similar audiences — built from your first-party seeds. Quality depends entirely on seed quality. 1-3% lookalikes of high-LTV customers remain useful; 5-10%+ are essentially broad audiences.
  4. Platform interest / in-market audiences — Google's in-market audiences, Meta's detailed targeting, LinkedIn's skill/title/company filters. Increasingly used as "signals" (suggestions) rather than hard targeting.
  5. Broad audiences with Smart Bidding / Advantage+ — let the platform's machine learning find converters from a wide pool. Has become the dominant pattern for prospecting in 2024-2026.
Interactive · tap a tier The audience stack that works now
Four tiers, one foundation — tap each to see its job

Build from the bottom up. Each tier feeds the one above it; skip the base and the whole stack gets weaker.

owned · consented

Your CRM, purchasers, app users, site events — data you own with consent. It’s the foundation: durable, compliant, and the seed for everything above it.

retargeting + CRM match

Uploaded lists and engagement audiences. Match them server-side (CAPI) so rates survive the browser, and segment by recency and value, not size.

modeled reach

Seed from your purest converters — 180-day buyers, high-LTV — then let Advantage+ expand past the percentage. Seed quality decides the outcome.

the model’s job

Hand the algorithm a good signal and room to run. In 2026 broad + signals beats hand-built micro-audiences, and the manual interest levers are shrinking anyway.

Claim: Privacy-driven signal loss is why platforms shifted to modeled conversions and broad-plus-creative targeting rather than deterministic interest stacks. Source: RGM analysis. Context: Build for incomplete observation: first-party seeds, fresh lists, and creative as the steering signal.

3. First-party data — the new strategic moat

First-party data is the new strategic moat because it is the one signal privacy changes can’t take from you. The brands winning in paid social are the ones systematically capturing emails, purchases, and consented identifiers, then feeding them back to the platforms.

Brands with rich first-party data dramatically outperform brands without it on every paid social and paid search platform. The strategic imperatives:

The match-rate reality: A 100K-email customer list typically matches 60-80% on Meta, 70-85% on Google Customer Match, 50-70% on LinkedIn, 40-60% on TikTok. Match rates improve dramatically when you pass multiple identifiers (email + phone + name + address all hashed).
RGM Expert Trick
We score first-party lists by recency and value, not size

A two-million-row list of cold leads seeds a worse lookalike than fifty thousand recent, high-value buyers. Bigger is not better — purer is.

We upload value-segmented, recency-weighted lists (LTV tiers, 30/90-day purchasers) so the model learns from our best customers, not merely our most numerous ones.

WHY IT’S RARE · ‘Upload your whole CRM’ is the advice; it’s usually wrong.
By the numbers First-party data is the moat
The data you own outperforms the data you rent — measurably
2.9×
revenue uplift for marketers who activate first-party data well (BCG × Google).
1.5×
better cost efficiency vs limited data integration.
12–35%
ROI lift from first-party-data personalisation, by channel.
87%
of brands agree first-party data is very important to marketing.

Source: BCG × Google, Think with Google.

In a cookieless world, the audience you own beats the audience you rent. First-party data is the one signal privacy can’t take from you — and the one your competitors can’t buy.
— RGM, paid social practice
What the data shows · BCG × Google
up to 2×incremental revenue / placement1.5×cost efficiency

Brands that connect all their first-party data sources — not a siloed few — earn up to twice the incremental revenue per placement and run about 1.5× more cost-efficiently than peers with fragmented data. Integration is the unlock, not collection alone.

RGM EXPERT TRICK
Refresh customer lists on a schedule, or they silently decay

A customer list uploaded once and forgotten loses match rate every month as emails change and the audience ages. Performance erodes slowly enough that nobody notices the cause.

I automate a weekly or monthly push of the current customer and high-LTV lists, and I exclude churned customers from prospecting on the same cadence.

Fresh, consented, well-matched lists are the single highest-leverage thing most accounts neglect — it’s free performance sitting in the CRM.

WHY IT’S RARE · Stale lists are everywhere because the upload feels like a one-time task. Treating list freshness as a recurring job is the unglamorous edge that compounds.

4. Custom audience types per platform

Each platform has its own custom-audience types — customer lists, site/app activity, engagement, and video viewers — but the highest-value one everywhere is a clean, hashed customer list uploaded and refreshed regularly.

Meta Custom Audiences

Google Customer Match + Audiences

TikTok Custom Audiences

LinkedIn Matched Audiences

RGM EXPERT TRICK
Seed lookalikes on LTV, not on conversions

Everyone builds a lookalike from ‘all purchasers.’ That teaches the platform to find more average buyers — including the bargain-hunters and one-time discounters you’d rather not clone.

I seed from the top quartile by lifetime value, or repeat purchasers only. The model then hunts for people who resemble your best customers, and the quality difference downstream is stark.

Same tool, radically better input. The lookalike is only ever as good as the list you feed it.

WHY IT’S RARE · Most teams seed on raw conversions and wonder why the audience attracts discount-chasers. Seeding on LTV quietly upgrades who the algorithm goes looking for.

5. The lookalike playbook in 2024-2026

The modern lookalike playbook is to build seeds from your best customers (high-LTV, repeat) rather than all converters, keep seeds fresh, and let the platform widen the percentage; quality of seed beats clever percentage tuning every time.

Lookalikes work when fed high-quality seeds:

Lookalike size strategy

RGM Expert Trick
We seed lookalikes from converters, then let the system expand

Building a 1% lookalike off all site visitors hands the model a muddy seed. We build off the 180-day purchaser or high-LTV segment instead — a small, clean seed beats a big noisy one.

And we stop hand-stacking 1/3/5/10% tiers; we give Advantage+ the pure seed and let it expand past the percentage on its own.

WHY IT’S RARE · The seed quality decides everything, and it’s the step everyone rushes.

6. Aggregated measurement and modeled audiences

Because deterministic tracking has holes, platforms now report modeled conversions and build modeled audiences to fill the gaps. Treat these as useful estimates, not ground truth, and validate direction with holdout or geo tests.

Apple's SKAdNetwork (SKAN) and Google's Privacy Sandbox introduce aggregated measurement: instead of per-user conversion data, platforms report aggregated conversion counts grouped by campaign / ad set / time window. This breaks individual-level remarketing but enables continued optimization at the aggregated level.

Implications:

What survives Consent Mode recovers most of the gap
A consent banner doesn’t have to mean losing the conversion

When a user rejects cookies the click-to-conversion link breaks. Advanced Consent Mode signals the consent state and lets Google model the missing journeys — recovering most of them, compliantly.

Banner only
~52% seen
+ Advanced Consent Mode
~88% recovered

Consent Mode modeling recovers 70%+ of ad-click-to-conversion journeys lost to consent choices. Source: Google.

7. Privacy sandbox: Topics, FLEDGE / Protected Audience, Attribution Reporting

The Privacy Sandbox — Topics, Protected Audience (FLEDGE), and the Attribution Reporting API — is Google’s browser-level replacement for third-party cookies, moving targeting and measurement into the browser with privacy limits baked in. Know it’s coming and design for aggregate, not individual, signal.

Google's Privacy Sandbox is the post-third-party-cookie set of browser APIs:

Adoption is uneven; the APIs work in Chrome but require platform integration. Meta and TikTok largely rely on alternative paths (CAPI, Events API, in-app SDKs).

8. Identity resolution and customer data platforms (CDPs)

Identity resolution and CDPs stitch a person together across touchpoints from first-party data, then push clean, consented audiences out to ad platforms. They are how larger organizations turn scattered data into activatable, durable audiences.

Brands serious about first-party data invest in identity resolution:

RGM Expert Trick
We push audiences server-side so match rates survive the browser

Post-iOS, the browser quietly drops a big share of your audience matches. The CDP-to-CAPI path carries hashed email and phone straight to the platform, where it actually lands.

We sync first-party segments server-side, which lifts match rates and Event Match Quality at once — the same plumbing that rescues measurement rescues targeting.

WHY IT’S RARE · Audience match and event match are the same lost signal; few fix both.
By the numbers The CDP becomes the backbone
As cookies fade, the first-party data layer needs an owner
41%
of companies have implemented a CDP; another 36% are evaluating one.
$37B
projected CDP market by 2030, up from ~$9.7B in 2025 (30.7% CAGR).
3:1
typical ROI from identity resolution + unified profiles.
47%
of CDP capability the average buyer actually uses — most value is left on the table.

Sources: MarketsandMarkets · CDP.com.

9. Consent management

Consent management is now a design input, not a legal afterthought: consent state governs whether you may build and activate an audience at all, and consent mode signals shape what data the platforms receive. Get it wrong and you risk both fines and broken measurement.

GDPR, CCPA, state-by-state US privacy laws, and emerging UK/Canada/Australia regulations all require explicit consent for cross-site data sharing. Operators need:

How to · step by step Build a first-party data foundation
Six moves that turn scattered data into durable, activatable audiences
  1. Capture consented identifiers everywhere.Email and phone at every touch — checkout, account, lead form, loyalty. This is the raw material; without it nothing downstream works.
  2. Unify into one profile.Resolve identity into a single consented record in a CDP or warehouse — deterministic stitching beats probabilistic guessing.
  3. Segment by recency and value.LTV tiers, 30/90-day purchasers, churn-risk. Purity beats size: a clean segment outperforms a giant cold list.
  4. Push segments server-side.Sync via CAPI so hashed identifiers match where the browser would have dropped them — lifting match rate and EMQ together.
  5. Seed lookalikes from your best.Build Advantage+ / lookalikes off your purest converters, then let the model expand past the percentage.
  6. Wire Consent Mode + modeling.Stay compliant and recover the 70%+ of journeys consent would otherwise cost you.
Why did my narrow interest audiences stop performing?
Signal loss and the algorithm’s improvement both favor breadth. Narrow audiences starve the system of data and overlap with each other; broad targeting plus strong creative now usually wins.
Are modeled conversions real conversions?
They are statistical estimates filling the gaps left by tracking restrictions. Useful for direction and optimization, but validate magnitude with holdout or geo tests before betting budget on them.
How big should a lookalike seed be?
Large enough to be stable (often 1,000+ quality records) but composed of your best customers, not just anyone who converted. Seed quality beats seed size beyond that floor.

10. The 10 most common audience mistakes in 2024-2026

Audience mistakes cluster predictably: over-narrow targeting that starves the algorithm, stale customer lists, ignoring first-party capture, treating modeled numbers as exact, and building audiences without a lawful basis. Each wastes spend or invites risk.

  1. Trying to recreate 2018 playbook. Layered interest stacks; narrow demographic targeting. Doesn't work post-iOS 14.5. Fix: broad + first-party + Smart Bidding/Advantage+.
  2. Stale first-party lists. Customer Match list uploaded once, never refreshed. Fix: weekly sync via API.
  3. No CAPI / Events API. Missing 30-50% of iOS audience-build signal. Fix: server-side conversion + audience-build infrastructure.
  4. Too-large lookalikes treated as targeting. 10% lookalike is broad audience with nudge; treat as such.
  5. Ignoring engagement audiences. Free, high-signal audiences (video viewers, page engagers) sitting unused.
  6. One-off audience builds. Custom Audience created for a campaign, never updated. Fix: automated refresh.
  7. No retention segment for retargeting. Retargeting all visitors equally; not separating cart-abandoners from blog-readers. Fix: behavioral segmentation of retargeting audiences.
  8. No CDP / identity strategy. Identifiers fragmented across tools. Fix: CDP or identity provider for cross-system consolidation.
  9. Consent management missing. Sending events for users who didn't consent. Legal liability; platform-level penalties. Fix: CMP integrated with all marketing tags.
  10. Over-investing in audience strategy vs creative. In 2026 creative outperforms audience for performance lift on Meta and TikTok. Fix: balance investment.

Quick reference: the “good audience strategy” checklist

  • ✓ First-party data capture aggressive (email, phone, behavior)
  • ✓ CRM segments built (top LTV, repeat, lapsed, etc.)
  • ✓ Customer Match / Custom Audience uploads weekly (or automated)
  • ✓ CAPI / Events API / Enhanced Conversions implemented
  • ✓ Engagement audiences active (video viewers, page engagers, etc.)
  • ✓ Lookalikes built from high-LTV seeds (1-3% for precision, 5%+ for scale)
  • ✓ Broad audience prospecting with Smart Bidding / Advantage+
  • ✓ Retargeting segmented by behavior (cart abandoners ≠ blog readers)
  • ✓ CDP or identity provider for cross-system identity
  • ✓ Consent Management Platform integrated; Consent Mode enabled
  • ✓ Documentation of audience definitions for cross-team alignment
CASE-method test

Prove it. Earn your passcode.

Ten questions, CASE method (Context · Analysis · Strategy · Execution). Pass at 90% to unlock this module’s completion passcode — retake as many times as you like.