Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Marketing

__Secure-3PSID Cookie (Google) – What It Is & How to Block It

__Secure-3PSID is a third-party cookie set by Google on the .google.com domain, used for account authentication and Google's cross-site advertising services. It belongs to the "PSID" family of Google account cookies and is classified as marketing because it supports personalized ads and ad measurement on third-party websites.

Name
__Secure-3PSID
Provider
Google
Category
Marketing
Type
HTTP cookie
Lifetime
2 years
Domain / notes
.google.com
Consent
Yes, before it is set (GDPR / ePrivacy)

What is the __Secure-3PSID cookie?

__Secure-3PSID is an HTTP cookie set by Google on the .google.com domain. The __Secure- prefix means it can only be sent over HTTPS connections, and the "3P" (third-party) segment indicates it is meant to be used in a cross-site context — sent to Google while the visitor is browsing another website.

It typically appears when a visitor is signed into a Google account and the site they're on loads a Google service (such as ads, an embedded video, or another Google widget) that needs to recognize the user's session across sites.

What data it stores

__Secure-3PSID stores an encrypted session identifier tied to the user's Google account. The value is not plain text but an encrypted/hashed string, so it cannot be read directly by the site displaying the Google content.

The data is sent to Google's servers, not to the site hosting the widget. Google uses this cookie, together with its counterpart __Secure-3PAPISID, to correlate account activity with interactions on third-party sites.

What it is used for

For Google, this cookie helps recognize signed-in users across multiple sites and services, supporting ad personalization, campaign performance measurement, and ad fraud prevention. For the website owner, the cookie appears indirectly, as a side effect of loading a Google service (such as embedded YouTube, Google Ads, or other Google marketing tools), and serves no direct function for the site itself.

Does it require consent?

__Secure-3PSID is classified as marketing, since it supports advertising and cross-site tracking. Under GDPR and the ePrivacy Directive (implemented in Romania via Law 506/2004), this type of cookie requires the visitor's prior, explicit consent before the Google script that sets it runs.

  • The site owner must disclose the cookie in the cookie policy, under the marketing category.
  • Scripts loading related Google services (ads, video, remarketing) must be blocked until consent is granted.
  • Declining consent should not block access to the site's core content.

How to block or delete __Secure-3PSID

Visitors can delete or block this cookie from browser settings (Chrome, Firefox, Edge, Safari) under per-site cookie management, or via dedicated tracking-blocker extensions. Removing it may sign the user's Google account out of certain embedded widgets.

On the site side, owners must ensure the Google scripts that set __Secure-3PSID don't fire automatically on page load. A CMP platform like CookieFix can automatically block these scripts until the visitor gives explicit consent for the marketing category, preventing the cookie from being placed prematurely.

Frequently asked questions

It's a third-party cookie set by Google on .google.com, used to recognize the user's Google account in a cross-site context, mainly for advertising purposes.

It's not malicious, but it is a tracking cookie that links activity across multiple sites to the person's Google account, which is why it requires consent under GDPR.

The typical duration is about 2 years from when it's set or last updated, though Google may adjust this interval.

Yes, since it's classified as marketing/tracking, it requires the visitor's prior consent before the script that sets it is allowed to run.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.