Another component of Privacy Sandbox is Turtledove (https://github.com/WICG/turtledove), where advertisers can tag a user as belonging to a "interest group" and then later on can target ads against that interest group. Which groups a user is in is maintained entirely by the browser, and never sent to the server, And any ads that are rendered based on interest group targeting have to execute in a special "fenced frame" which prevents them from leaking information to the surrounding page or to the advertiser in a non-aggregated way.
(Disclosure: I work on ads at Google, so I'm following these proposals. Speaking only for myself)