Join our Newsletter — 33% off our NHI Course

CHIPS

Cookies Having Independent Partitioned State, or CHIPS, is a browser feature that partitions third-party cookies by top-level site. A cookie set in an embedded context is only readable within that same site context, which reduces cross-site tracking while preserving legitimate embedded use cases.

What CHIPS Changes About Third-Party Cookies

CHIPS changes the way browsers store state for embedded content. Instead of allowing one third-party cookie to follow a user across unrelated sites, the browser partitions that cookie by top-level site, so the same embedded service gets a separate cookie jar per site context.

This matters because it preserves legitimate embedded functionality, such as payments, chat widgets, and federated components, while sharply reducing cross-site correlation. The key security and privacy property is boundary scoping: the cookie remains usable inside the site where it was set, but loses its value as a universal tracking identifier.

How Partitioning Works in Practice

CHIPS is not a generic replacement for all third-party cookies, it is a more constrained storage model. A partitioned cookie is still a cookie, but its readable scope is tied to the top-level site that created the context. That means the same embedded origin can maintain state for site A and site B without those sessions collapsing into one shared cross-site identifier.

For browser vendors and application teams, the practical effect is that embedded services must stop assuming that one persistent cookie can represent the same user everywhere. Any design that depends on cross-site continuity now needs a different trust model, because the browser intentionally breaks that assumption to reduce tracking reach.

Where CHIPS Fits in Privacy and Trust Boundaries

CHIPS sits between full third-party cookie blocking and unconstrained third-party tracking. It is designed for the cases where embedded functionality is still needed, but site-level separation is important enough that the browser should enforce it by default. This makes CHIPS especially relevant for privacy-preserving integration patterns where the embedding site should not leak state to another site.

The model also shifts how trust is interpreted. An embedded provider can still operate, but it no longer gets a single ambient identity across the web from cookie state alone. That is useful when the service needs continuity inside a site, yet should not accumulate a broad cross-site profile from the browser.

Operational Trade-offs and Browser Compatibility

CHIPS is useful, but it is not a universal solution. Existing applications that rely on a shared third-party cookie for login, analytics, or session correlation may find that partitioning changes expected behaviour. In practice, teams need to distinguish between state that is legitimate inside one site context and state that was previously being reused as a cross-site identifier.

Browser support and implementation details matter as well. CHIPS only solves the storage boundary problem for the browsers and versions that implement it, so product teams still need graceful degradation paths and a clear understanding of which embedded experiences depend on partitioned state versus broader browser capabilities.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-4 — Information Flow Enforcement CHIPS enforces a browser-side flow boundary for third-party cookie state.
SC-7 — Boundary Protection Partitioned cookies create a tighter trust boundary between top-level sites.
PT-2 — Authority and Purpose CHIPS reduces cross-site tracking by limiting cookie use to the intended site context.
Recommendation — Use AC-4 to constrain cross-site state exposure and prevent unintended cookie reuse. Apply SC-7 to limit how embedded content shares state across site boundaries. Apply PT-2 to ensure browser state supports only the approved privacy purpose.
ISO/IEC 27001:2022 A.5.15 — Access control Cookie partitioning narrows who can access state and under what context.
Recommendation — Define access control rules for embedded state so reuse stays context-bound.
NIST CSF 2.0 PR.DS-01 — Data-at-rest is protected Partitioned cookie state is a stored data object whose scope should be constrained.
Recommendation — Protect stored cookie state by limiting its accessibility to the intended partition.