The problem of supporting privacy preservation of XML databases within very large publish-subscribe systems is rapidly gaining interest for both academic and industrial research. It becomes even more challenging when XML data are managed and delivered according to the P2P paradigm, since malicious accesses and unpredictable attacks could take advantage from the totally-decentralized and untrusted nature of P2P networks. In this paper, we propose XℓPPX, a distributed framework for very large publish-subscribe systems which supports (i) privacy-preserving fragmentation of XML documents stored in P2P XML databases, and (ii) the creation of trusted groups of peers by means of "self-certifying" XPath links. Furthermore, we present algorithms for querying privacy-preserving XML fragments in both schema-aware and schema-less mode, which are common scenarios when P2P XML databases operate in very large publish-subscribe systems. Finally, we complete our analytical contributions with an experimental study showing the effectiveness of our proposed framework.