Under GDPR, the organisation that determines the purpose and means of processing personal data. Employers are usually the data controller for screening data.