Infrastructure as a Service provides virtual machines, block and object storage, networking and related building blocks on demand. Organisations use it to host applications and databases, build private networks and scale capacity, either as a replacement for their own data centres or alongside them.
IaaS is the layer on which everything else rests, so every workload inherits its sovereignty properties. Encryption keys are the pivotal point: if the provider manages them, it can in principle be compelled to decrypt, while customer-held keys, for example in your own HSM, limit that exposure but add operational duties. Data location is not the same as operational control, since staff, support access and management planes may sit elsewhere. Lock-in comes from proprietary managed services, network designs and large data volumes that are costly to move. The EU Data Act gives customers rights to switch between providers of data-processing services, and the Commission points to a European cloud certification scheme in development.
When choosing a European option, compare who owns the operator, where the management and support plane sits, which key-management options exist, whether open interfaces such as standard virtualisation and S3-compatible storage are supported, how transparent the exit terms are, and which independent certifications apply.